Vulnerabilities in kovidgoyal
19 resultsVexday analysis
O fornecedor kovidgoyal apresenta 19 CVEs catalogadas, com 8 publicações recentes (últimos 90 dias) indicando atividade contínua de descoberta de vulnerabilidades. Embora nenhuma esteja sob ataque ativo documentado (KEV), 4 vulnerabilidades críticas e a predominância de CWE-22 (travessia de diretórios) sugerem riscos de impacto significativo em confidencialidade e integridade de dados. O padrão de publicações suggests que o produto requer monitoramento constante e aplicação de patches prioritários.
CVE-2026-26064CRITICALcalibre: Path Traversal Vulnerability Enables Arbitrary File Write and Remote Code ExecutionEPSS 0.9%CVE-2026-26065CRITICALcalibre: Path Traversal can Lead to Arbitrary File Write and Potential Code ExecutionEPSS 0.5%CVE-2026-25635HIGHcalibre has a Path Traversal Leading to Arbitrary File Write and Potential Code ExecutionEPSS 0.4%CVE-2026-33633HIGHKitty has a Heap Buffer Overflow in its Graphics Protocol HandlerEPSS 0.4%CVE-2026-42850HIGHKitty has a shell command injectionEPSS 0.3%CVE-2026-33642CRITICALKitty has a Heap Buffer Over-Read/Write via Integer Overflow in compose_rectangles Bounds CheckEPSS 0.3%CVE-2026-54056HIGHKitty has an arbitrary file overwrite via symlink following in `kitten dnd` remote drop stagingEPSS 0.3%CVE-2026-25731HIGHCalibre Affected by Arbitrary Code Execution via Server-Side Template Injection in Calibre HTML ExportEPSS 0.2%CVE-2026-25636HIGHcalibre has a Path Traversal Leading to Arbitrary File Corruption and Code ExecutionEPSS 0.2%CVE-2026-33206HIGHcalibre has a path traversal vulnerabilityEPSS 0.2%CVE-2026-27810MEDIUMcalibre Vulnerable to HTTP Response Header InjectionEPSS 0.2%CVE-2025-64486CRITICALcalibre is vulnerable to arbitrary code execution when opening FB2 filesEPSS 0.2%CVE-2026-30853MEDIUMcalibre has a Path Traversal Leading to Arbitrary File WriteEPSS 0.2%CVE-2026-33205MEDIUMcalibre has Server-Side Request Forgery in ebook viewer backendEPSS 0.2%CVE-2026-54057HIGHKitty vulnerable to command injection via unsanitized OSC 21 query replyEPSS 0.2%CVE-2026-42851HIGH@kitty-edit DCS + --color=geninclude vulnerable to Unauthenticated in-process RCEEPSS 0.2%CVE-2026-53511HIGHcalibre: Arbitrary Code Execution in Template Formatter via Book MetadataEPSS 0.1%CVE-2026-27824MEDIUMcalibre has IP Ban Bypass via X-Forwarded-For Header SpoofingEPSS 0.1%CVE-2026-54055MEDIUMKitty has an Arbitrary File Write via Symlink Race Condition in File Transmission ProtocolEPSS 0.1%