Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3001▼ 62 respecto a la semana anterior
Críticas / altas1373▲ 34 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)459▼ 50 respecto a la semana anterior
370 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.1) | 1.0% | — | Medhost Document Management System | 28/7/2017 | 17/6/2026 | MEDHOST Document Management System contains hard-coded credentials that are used for customer database access. An attacker with knowledge of the hard-coded credentials and the ability to communicate directly with the database may be able to obtain or modify sensitive patient and financial information. PostgreSQL is… | |
| Modificada | Alta (8.8) | 4.2% | — | Opentext Documentum Content Server | 25/4/2017 | 17/6/2026 | OpenText Documentum Content Server has an inadequate protection mechanism against SQL injection, which allows remote authenticated users to execute arbitrary code with super-user privileges by leveraging the availability of the dm_bp_transition docbase method with a user-created dm_procedure object, as demonstrated by… | |
| Modificada | Alta (8.8) | 2.0% | — | Opentext Documentum Content Server | 21/4/2017 | 17/6/2026 | OpenText Documentum Content Server allows superuser access via sys_obj_save or save of a crafted object, followed by an unauthorized "UPDATE dm_dbo.dm_user_s SET user_privileges=16" command, aka an "RPC save-commands" attack. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-4532. | |
| Modificada | Baja (3.3) | 0.91% | — | Lexmark Perceptive Document Filters | 20/4/2017 | 17/6/2026 | An exploitable arbitrary read exists in the XLS parsing of the Lexmark Perspective Document Filters conversion functionality. A crafted XLS document can lead to a arbitrary read resulting in memory disclosure. The vulnerability was confirmed on versions 11.3.0.2228 and 11.3.0.2400 | |
| Modificada | Media (6.1) | 1.2% | — | Open-xchange Documentconverter-apiOpen-xchange Office WEBOpen-xchange Appsuite BackendOpen-xchange Appsuite Frontend | 29/3/2017 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Open-Xchange (OX) AppSuite backend before 7.6.2-rev59, 7.8.0 before 7.8.0-rev38, 7.8.2 before 7.8.2-rev8; AppSuite frontend before 7.6.2-rev47, 7.8.0 before 7.8.0-rev30, and 7.8.2 before 7.8.2-rev8; Office Web before 7.6.2-rev16, 7.8.0 before 7.8.0-rev10, and 7.8.2 before… | |
| Modificada | Media (4.3) | 0.58% | — | Huawei Document Security Management | 20/3/2017 | 17/6/2026 | The permission control module in Huawei Document Security Management (aka DSM) before V100R002C05SPC670 allows remote authenticated users to obtain sensitive information from encrypted documents by leveraging incorrect control of permissions on the PrintScreen button. | |
| Modificada | Crítica (9.8) | 25% | — | Opentext Documentum D2 | 22/2/2017 | 17/6/2026 | OpenText Documentum D2 (formerly EMC Documentum D2) 4.x allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the BeanShell (bsh) and Apache Commons Collections (ACC) libraries. | |
| Modificada | Alta (8.8) | 2.0% | — | Opentext Documentum Content Server | 22/2/2017 | 17/6/2026 | OpenText Documentum Content Server (formerly EMC Documentum Content Server) 7.3, when PostgreSQL Database is used and return_top_results_row_based config option is false, does not properly restrict DQL hints, which allows remote authenticated users to conduct DQL injection attacks and execute arbitrary DML or DDL… | |
| Modificada | Crítica (9.8) | 1.6% | — | EMC Documentum Eroom | 3/2/2017 | 17/6/2026 | EMC Documentum eRoom version 7.4.4, EMC Documentum eRoom version 7.4.4 SP1, EMC Documentum eRoom version prior to 7.4.5 P04, EMC Documentum eRoom version prior to 7.5.0 P01 includes an unverified password change vulnerability that could potentially be exploited by malicious users to compromise the affected system. | |
| Modificada | Media (6.3) | 1.6% | — | EMC Documentum D2 | 3/2/2017 | 17/6/2026 | EMC Documentum D2 version 4.5 and EMC Documentum D2 version 4.6 has a DQL Injection Vulnerability that could potentially be exploited by malicious users to compromise the affected system. An authenticated low-privileged attacker could potentially exploit this vulnerability to access information, modify data or disrupt… | |
| Modificada | Media (6.1) | 1.3% | — | EMC Documentum D2 | 3/2/2017 | 17/6/2026 | EMC Documentum D2 version 4.5 and EMC Documentum D2 version 4.6 has Reflected Cross-Site Scripting Vulnerabilities that could potentially be exploited by malicious users to compromise the affected system. | |
| Modificada | Media (6.1) | 0.97% | — | EMC Documentum AdministratorEMC Documentum Capital ProjectsEMC Documentum TaskspaceEMC Documentum Webtop | 23/1/2017 | 17/6/2026 | EMC Documentum WebTop Version 6.8, prior to P18 and Version 6.8.1, prior to P06; and EMC Documentum TaskSpace version 6.7SP3, prior to P02; and EMC Documentum Capital Projects Version 1.9, prior to P30 and Version 1.10, prior to P17; and EMC Documentum Administrator Version 7.0, Version 7.1, and Version 7.2 prior to… | |
| Modificada | Alta (7.8) | 2.0% | — | Lexmark Perceptive Document Filters | 6/1/2017 | 17/6/2026 | An exploitable heap overflow vulnerability exists in the Compound Binary File Format (CBFF) parser functionality of Lexmark Perceptive Document Filters library. A specially crafted CBFF file can cause a code execution. An attacker can send a malformed file to trigger this vulnerability. | |
| Modificada | Crítica (9.8) | 3.9% | — | Lexmark Perceptive Document Filters | 6/1/2017 | 17/6/2026 | An exploitable out-of-bounds write exists in the Bzip2 parsing of the Lexmark Perspective Document Filters conversion functionality. A crafted Bzip2 document can lead to a stack-based buffer overflow causing an out-of-bounds write which under the right circumstance could potentially be leveraged by an attacker to gain… | |
| Modificada | Alta (8.4) | 3.8% | — | Lexmark Perceptive Document Filters | 6/1/2017 | 17/6/2026 | An exploitable buffer overflow exists in the XLS parsing of the Lexmark Perspective Document Filters conversion functionality. A crafted XLS document can lead to a stack based buffer overflow resulting in remote code execution. | |
| Modificada | Media (5.3) | 1.9% | — | EMC Documentum D2 | 17/9/2016 | 17/6/2026 | EMC Documentum D2 4.5 before patch 15 and 4.6 before patch 03 allows remote attackers to read arbitrary Docbase documents by leveraging knowledge of an r_object_id value. | |
| Modificada | Media (6.3) | 1.3% | — | EMC Documentum AdministratorEMC Documentum Capital ProjectsEMC Documentum TaskspaceEMC Documentum Webtop | 23/6/2016 | 17/6/2026 | EMC Documentum WebTop 6.8 before Patch 13 and 6.8.1 before Patch 02, Documentum Administrator 7.x before 7.2 Patch 13, Documentum Capital Projects 1.9 before Patch 23 and 1.10 before Patch 10, and Documentum TaskSpace 6.7 SP3 allow remote authenticated users to bypass intended access restrictions and execute arbitrary… | |
| Modificada | Alta (8.8) | 3.1% | — | EMC Documentum D2 | 7/4/2016 | 17/6/2026 | EMC Documentum D2 before 4.6 lacks intended ACLs for configuration objects, which allows remote authenticated users to modify objects via unspecified vectors. | |
| Modificada | Media (4.3) | 1.8% | — | EMC Documentum XCP | 9/3/2016 | 17/6/2026 | EMC Documentum xCP 2.1 before patch 24 and 2.2 before patch 12 allows remote authenticated users to obtain sensitive user-account metadata via a members/xcp_member API call. | |
| Modificada | Media (5.4) | 1.7% | — | EMC Documentum XCP | 12/2/2016 | 17/6/2026 | EMC Documentum xCP 2.1 before patch 23 and 2.2 before patch 11 allows remote authenticated users to read arbitrary files via a POST request containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue. | |
| Modificada | Media (6.5) | 1.7% | — | EMC Documentum XCP | 12/2/2016 | 17/6/2026 | EMC Documentum xCP 2.1 before patch 23 and 2.2 before patch 11 allows remote authenticated users to conduct Documentum Query Language (DQL) injection attacks and obtain sensitive repository information by appending a query to a REST request. | |
| Modificada | Media (4) | 0.21% | — | Huawei Document Security Management | 8/1/2016 | 17/6/2026 | Huawei Document Security Management (DSM) with software before V100R002C05SPC661 does not clear the clipboard when closing a secure file, which allows local users to obtain sensitive information by pasting the contents to another file. | |
| Modificada | Alta (9) | 2.6% | — | EMC Documentum Content Server | 4/9/2015 | 17/6/2026 | EMC Documentum Content Server before 7.1P20 and 7.2.x before 7.2P04 does not properly verify authorization for dm_job object access, which allows remote authenticated users to obtain superuser privileges via crafted object operations. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-4626. | |
| Modificada | Media (4.3) | 7.3% | — | Navis Documentcloud | 1/9/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in js/window.php in the Navis DocumentCloud plugin before 0.1.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the wpbase parameter. | |
| Modificada | Baja (3.5) | 1.2% | — | EMC Documentum D2 | 22/8/2015 | 17/6/2026 | Lockbox in EMC Documentum D2 before 4.5 uses a hardcoded passphrase when a server lacks a D2.Lockbox file, which makes it easier for remote authenticated users to decrypt admin tickets by locating this passphrase in a decompiled D2 JAR archive. |