Vulnerabilities

Summary — last 7 days

New vulnerabilities2,633▼ 304 vs. last week
Critical / high1,352▲ 80 vs. last week
New active exploitation (KEV)5▼ 3 vs. last week
Unscored (no CVSS)58▼ 469 vs. last week
–

4 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
AnalyzedCritical (9.6)0.85%—Streetwriters Notesnook DesktopStreetwriters Notesnook Mobile5/4/20266/17/2026
Notesnook is a note-taking app focused on user privacy & ease of use. Prior to Notesnook Web/Desktop version 3.3.15 and prior to Notesnook iOS/Android version 3.3.20, a stored XSS vulnerability in the note export flow can be escalated to remote code execution in the desktop app. The root cause is that exported note…
AnalyzedMedium (6.1)0.34%—Streetwriters Notesnook Mobile4/1/20266/17/2026
Notesnook is a note-taking app focused on user privacy & ease of use. Prior to version 3.3.17, a stored XSS vulnerability exists in the mobile share / web clip flow because attacker-controlled clip metadata is concatenated into HTML without escaping and then rendered with innerHTML inside the mobile share editor…
AnalyzedCritical (9.6)0.69%—Streetwriters Notesnook DesktopStreetwriters Notesnook Mobile3/27/20266/17/2026
Notesnook is a note-taking app. Prior to version 3.3.11 on Web/Desktop and 3.3.17 on Android/iOS, a stored XSS in the Web Clipper rendering flow can be escalated to remote code execution in the desktop app. The root cause is that the clipper preserves attacker-controlled attributes from the source page’s root element…
AnalyzedMedium (5.4)0.24%—Streetwriters Notesnook DesktopStreetwriters Notesnook Mobile3/11/20266/17/2026
Notesnook is a note-taking app focused on user privacy & ease of use. Prior to 3.3.9, a Stored Cross-Site Scripting (XSS) vulnerability existed in Notesnook's editor embed component when rendering Twitter/X embed URLs. The tweetToEmbed() function in component.tsx interpolated the user-supplied URL directly into an…