Filter

IBM Cognos AnalyticsCSRF

First published (updated )

IBM Cognos AnalyticsJupyter Notebook and JupyterHub could allow a remote attacker to conduct phishing attacks, caused by…

First published (updated )

IBM Cognos Analyticsnbconvert vulnerable to cross-site scripting (XSS) via multiple exploit paths

7.5
First published (updated )

Jupyter OauthenticatorAn issue was discovered in Project Jupyter JupyterHub OAuthenticator 0.6.x before 0.6.2 and 0.7.x be…

8.8
First published (updated )

pip/jupyter-serverJupyter Server errors include tracebacks with path information

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

pip/jupyterhubincomplete logout in JupyterHub

7.5
First published (updated )

Jupyter NbdimeStored XSS in Jupyter nbdime

8.7
First published (updated )

Jupyter NotebookXSS

First published (updated )

pip/jupyter_serverJupyter server on Windows discloses Windows user password hash

7.5
First published (updated )

Jupyter NotebookXSS

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Jupyter OauthenticatorBase class whitelist configuration ignored in OAuthenticator

First published (updated )

Jupyter NotebookFailure to Sanitize Special Elements into a Different Plane (Special Element Injection) in notebook

First published (updated )

Jupyter Jupyter Servercross-site inclusion (XSSI) of files in jupyter-server

First published (updated )

Jupyter Jupyter ServerOpen Redirect Vulnerability in jupyter-server

First published (updated )

Jupyter NotebookIn Jupyter Notebook before 5.4.1, a maliciously forged notebook file can bypass sanitization to exec…

7.8
First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

pip/notebookXSS

First published (updated )

Jupyter NotebookXSS

First published (updated )

Jupyter NotebookIn Jupyter Notebook before 5.7.8, an open redirect can occur via an empty netloc. This issue exists …

First published (updated )

Jupyter NotebookOpen redirect in Jupyter Notebook

7.4
First published (updated )

Jupyter Jupyter ServerOpen redirect vulnerability

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Debian Debian LinuxExecution with Unnecessary Privileges in JupyterApp

8.8
First published (updated )

Jupyter Jupyter Server ProxySSRF vulnerability (requires authentication)

7.1
First published (updated )

Jupyter Jupyter ServerOpen redirect in Jupyter Server

First published (updated )

Jupyter JupyterlabJupyterLab: XSS due to lack of sanitization of the action attribute of an html <form>

First published (updated )

Jupyter NotebookXSS, CSRF

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Jupyter NotebookInput Validation

First published (updated )

pip/binderhubRemote code execution in Binderhub

First published (updated )

pip/jupyter-lspUnsecured endpoints in the jupyter-lsp server extension

EPSS
0.09%
First published (updated )

pip/jupyterlabHTML injection in Jupyter Notebook and JupyterLab leading to DOM Clobbering

7.6
First published (updated )

Jupyter JupyterHubJupyterHub has a privilege escalation vulnerability with the `admin:users` scope

7.2
First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203