Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2724▼ 13 respecto a la semana anterior
Críticas / altas1452▲ 315 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
18 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.4) | 0.23% | — | Triliumnotes Trilium NotesAI | 14/9/2026 | 16/9/2026 | Trilium Notes, version v0.103.0 and earlier, contains a stored cross-site scripting (XSS) vulnerability in the share renderer for webView notes due to improper HTML escaping of user-controlled #webViewSrc values. This vulnerability allows attackers with note-authoring privileges to inject arbitrary JavaScript that… | |
| En análisis | Alta (7.5) | 0.41% | — | TriliumAI | 27/8/2026 | 9/9/2026 | Trilium is an open-source hierarchical note-taking application. In versions up to and including 0.103.0, the public share-search endpoint does not enforce the per-note shareCredentials and shareHiddenFromTree controls, allowing an unauthenticated visitor to read the titles, tree paths, and content of protected shared… | |
| En análisis | Alta (8.1) | 0.48% | — | TriliumAI | 27/8/2026 | 9/9/2026 | Trilium is an open-source hierarchical note-taking application. In versions prior to 0.104.0, the automatic image-download feature accepts file:// URLs in a note's img tags and reads the referenced local file with no path validation, allowing any authenticated user to disclose arbitrary files readable by the Trilium… | |
| En análisis | Crítica (9.3) | 0.30% | — | TriliumAI | 27/8/2026 | 9/9/2026 | Trilium is an open-source hierarchical note-taking application. In versions up to and including 0.103.0, the default-on "Safe import" filter sanitizes HTML only for text notes and excludes the book note type, whose content is stored without sanitization and later rendered as HTML, allowing an attacker-supplied import… | |
| En análisis | Crítica (9.3) | 0.30% | — | TriliumAIMind ElixirAIElectronAI | 27/8/2026 | 9/9/2026 | Trilium is an open-source hierarchical note-taking application. In versions up to and including 0.103.0, the default-on "Safe import" filter sanitizes HTML only for text notes and excludes the mindMap note type, whose JSON content is stored without sanitization, allowing an attacker-supplied import archive to embed a… | |
| En análisis | Crítica (9.3) | 0.30% | — | TriliumAI | 27/8/2026 | 9/9/2026 | Trilium is an open-source hierarchical note-taking application. In versions up to and including 0.103.0, the default-on "Safe import" filter does not sanitize note titles, and the GeoMap note view interpolates a marker note's title into raw HTML that is rendered as innerHTML, allowing an attacker-supplied import… | |
| En análisis | Alta (8.6) | 0.73% | — | TriliumAI | 27/8/2026 | 9/9/2026 | Trilium is an open-source hierarchical note-taking application. In versions prior to 0.104.0, the default-on "Safe import" filter fails to neutralize the shareTemplate relation because that relation is not marked as dangerous, allowing an attacker-supplied import archive to plant a server-side template that leads to… | |
| Aplazada | Alta (8.3) | 0.43% | — | Triliumnotes Trilium NotesAI | 18/8/2026 | 18/9/2026 | Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bases. Prior to 0.103.0, the #iconClass label value is returned raw by getNoteIcon() and inserted without HTML attribute encoding into class attributes in apps/client/src/widgets/quick_search.ts and… | |
| Aplazada | Crítica (9.3) | 0.21% | — | Triliumnotes Trilium NotesAI | 29/5/2026 | 22/7/2026 | Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bases. Prior to 0.102.2, a malicious ZIP archive imported with safe import enabled achieves RCE via #docName path traversal and XSS by combining a payload note (type: code, mime: text/plain) containing… | |
| Aplazada | Media (6.8) | 0.36% | — | Triliumnotes Trilium NotesAI | 20/5/2026 | 23/7/2026 | Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bases. Versions 0.102.1 and prior contain a critical security flaw where lack of SVG sanitization combined with a disabled Content Security Policy (CSP) and a publicly reachable backend execution API… | |
| Aplazada | Alta (8.6) | 0.50% | — | Triliumnotes Trilium NotesAI | 20/5/2026 | 23/7/2026 | Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bases. In versions 0.102.1 and prior, the Clipper API in Trilium Desktop (v0.101.3) allows full authentication bypass when running in an Electron environment. When Trilium detects an Electron… | |
| Aplazada | Media (5.5) | 0.16% | — | Triliumnotes Trilium NotesAI | 20/5/2026 | 24/7/2026 | Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bases. In versions 0.102.1 and prior, the Electron configuration is vulnerable to TCC Bypass via Prompt Spoofing, allowing local attackers to trigger misleading macOS permission prompts by running… | |
| Aplazada | Media (6.8) | 0.73% | — | Triliumnotes Trilium NotesAI | 20/5/2026 | 24/7/2026 | Trilium Notes is an open-source, cross-platform hierarchical note taking application for building large personal knowledge bases. Versions 0.102.1 and prior are vulnerable to Local File Inclusion, allowing an authenticated attacker to read sensitive arbitrary files from the server's filesystem. The… | |
| Analizada | Alta (7.4) | 0.54% | — | Triliumnotes Trilium | 6/2/2026 | 17/6/2026 | Trilium Notes is an open-source, cross-platform hierarchical note taking application with focus on building large personal knowledge bases. Prior to 0.101.0, a critical timing attack vulnerability in Trilium's sync authentication endpoint allows unauthenticated remote attackers to recover HMAC authentication hashes… | |
| Aplazada | Alta (7.5) | 0.35% | — | Triliumnotes Trilium NotesAI | 5/8/2025 | 17/6/2026 | Trilium Notes is an open-source, cross-platform hierarchical note taking application with focus on building large personal knowledge bases. In versions below 0.97.0, a brute-force protection bypass in the initial sync seed retrieval endpoint allows unauthenticated attackers to guess the login password without… | |
| Modificada | Media (5.4) | 0.40% | — | Trilium Project Trilium | 2/6/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in GitHub repository zadam/trilium prior to 0.59.4. | |
| Modificada | Media (5.4) | 0.46% | — | Trilium Project Trilium | 10/7/2022 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in GitHub repository zadam/trilium prior to 0.53.3. | |
| Modificada | Media (6.1) | 2.9% | — | Triliumnotes Trilium | 3/7/2022 | 17/6/2026 | Cross-site Scripting (XSS) - Reflected in GitHub repository zadam/trilium prior to 0.52.4, 0.53.1-beta. |