Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3028▼ 62 respecto a la semana anterior
Críticas / altas1422▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
370 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Baja (3.5) | 1.4% | — | EMC Documentum Content Server | 20/8/2015 | 17/6/2026 | EMC Documentum Content Server before 7.0 P20, 7.1 before P18, and 7.2 before P02, when RPC tracing is configured, stores certain obfuscated password data in a log file, which allows remote authenticated users to obtain sensitive information by reading this file. | |
| Modificada | Alta (7.5) | 1.9% | — | EMC Documentum Content Server | 20/8/2015 | 17/6/2026 | Java Method Server (JMS) in EMC Documentum Content Server before 6.7SP1 P32, 6.7SP2 before P25, 7.0 before P19, 7.1 before P16, and 7.2 before P02, when __debug_trace__ is configured, allows remote authenticated users to gain super-user privileges by leveraging the ability to read a log file containing a login ticket. | |
| Modificada | Alta (9) | 3.9% | — | EMC Documentum Content Server | 20/8/2015 | 17/6/2026 | Java Method Server (JMS) in EMC Documentum Content Server before 6.7SP1 P32, 6.7SP2 before P25, 7.0 before P19, 7.1 before P16, and 7.2 before P02 allows remote authenticated users to execute arbitrary code by forging a signature for a query string that lacks the method_verb parameter. | |
| Modificada | Alta (9) | 3.9% | — | EMC Documentum Content Server | 20/8/2015 | 17/6/2026 | EMC Documentum Content Server before 6.7SP1 P32, 6.7SP2 before P25, 7.0 before P19, 7.1 before P16, and 7.2 before P02 does not properly check authorization after creation of an object, which allows remote authenticated users to execute arbitrary code with super-user privileges via a custom script. NOTE: this… | |
| Modificada | Alta (9) | 3.1% | — | EMC Documentum Content Server | 20/8/2015 | 17/6/2026 | EMC Documentum Content Server before 6.7SP1 P32, 6.7SP2 before P25, 7.0 before P19, 7.1 before P16, and 7.2 before P02 does not properly check authorization and does not properly restrict object types, which allows remote authenticated users to run save RPC commands with super-user privileges, and consequently execute… | |
| Modificada | Alta (9) | 2.4% | — | EMC Documentum Content Server | 20/8/2015 | 17/6/2026 | EMC Documentum Content Server before 6.7SP1 P32, 6.7SP2 before P25, 7.0 before P19, 7.1 before P16, and 7.2 before P02 does not properly check authorization for subgroups of privileged groups, which allows remote authenticated sysadmins to gain super-user privileges, and bypass intended restrictions on data access and… | |
| Modificada | Media (6.8) | 0.58% | — | EMC Documentum AdministratorEMC Documentum Digital Asset ManagerEMC Documentum TaskspaceEMC Documentum WEB Publisher+1 | 20/8/2015 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in EMC Documentum WebTop before 6.8P01, Documentum Administrator through 7.2, Documentum Digital Assets Manager through 6.5SP6, Documentum Web Publishers through 6.5SP7, and Documentum Task Space through 6.7SP2 allows remote attackers to hijack the authentication of… | |
| Modificada | Media (5.8) | 1.8% | — | EMC Documentum AdministratorEMC Documentum Digital Asset ManagerEMC Documentum TaskspaceEMC Documentum WEB Publisher+1 | 16/7/2015 | 17/6/2026 | Open redirect vulnerability in EMC Documentum WebTop before 6.8P02, Documentum Administrator before 7.2P01, Documentum Digital Assets Manager through 6.5SP6, Documentum Web Publishers through 6.5SP7, and Documentum Task Space through 6.7SP2 allows remote attackers to redirect users to arbitrary web sites and conduct… | |
| Modificada | Baja (3.5) | 1.4% | — | EMC Documentum Centerstage | 16/7/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in EMC Documentum CenterStage 1.2SP1 and 1.2SP2 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (6.5) | 2.4% | — | EMC Documentum AdministratorEMC Documentum Digital Asset ManagerEMC Documentum TaskspaceEMC Documentum WEB Publisher+1 | 4/7/2015 | 17/6/2026 | Unrestricted file upload vulnerability in EMC Documentum WebTop 6.7SP1 before P31, 6.7SP2 before P23, and 6.8 before P01; Documentum Administrator 6.7SP1 before P31, 6.7SP2 before P23, 7.0 before P18, 7.1 before P15, and 7.2 before P01; Documentum Digital Assets Manager 6.5SP6 before P25; Documentum Web Publishers 6.5… | |
| Modificada | Baja (3.5) | 1.1% | — | EMC Documentum AdministratorEMC Documentum Digital Asset ManagerEMC Documentum TaskspaceEMC Documentum WEB Publisher+1 | 4/7/2015 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in EMC Documentum WebTop 6.7SP1 before P31, 6.7SP2 before P23, and 6.8 before P01; Documentum Administrator 6.7SP1 before P31, 6.7SP2 before P23, 7.0 before P18, 7.1 before P15, and 7.2 before P01; Documentum Digital Assets Manager 6.5SP6 before P25; Documentum Web… | |
| Modificada | Media (4) | 1.4% | — | EMC Documentum D2 | 4/7/2015 | 17/6/2026 | The D2DownloadService.getDownloadUrls service method in EMC Documentum D2 4.1 and 4.2 before 4.2 P16 and 4.5 before P03 allows remote authenticated users to conduct Documentum Query Language (DQL) injection attacks and bypass intended read-access restrictions via unspecified vectors. | |
| Modificada | Media (4) | 1.4% | — | EMC Documentum D2 | 4/7/2015 | 17/6/2026 | The D2CenterstageService.getComments service method in EMC Documentum D2 4.1 and 4.2 before 4.2 P16 and 4.5 before P03 allows remote authenticated users to conduct Documentum Query Language (DQL) injection attacks and bypass intended read-access restrictions via unspecified vectors. | |
| Modificada | Alta (8.5) | 4.4% | — | EMC Documentum Thumbnail Server | 28/6/2015 | 17/6/2026 | Directory traversal vulnerability in EMC Documentum Thumbnail Server 6.7SP1 before P32, 6.7SP2 before P25, 7.0 before P19, 7.1 before P16, and 7.2 before P01 allows remote attackers to bypass intended Content Server access restrictions via unspecified vectors. | |
| Modificada | Baja (3.5) | 1.1% | — | EMC Documentum D2 | 28/6/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in EMC Documentum D2 before 4.5 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Baja (3.5) | 0.95% | — | Site Documentation Project Site Documentation | 15/6/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Site Documentation module before 6.x-1.5 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via vectors related to taxonomy terms. | |
| Modificada | Media (6.5) | 0.97% | — | EMC Document Sciences Xpression | 25/5/2015 | 17/6/2026 | SQL injection vulnerability in the xAdmin interface in EMC Document Sciences xPression 4.2 before P44 and 4.5 SP1 before P03 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Baja (2.1) | 0.48% | — | EMC Documentum Xcelerated Management System | 24/3/2015 | 17/6/2026 | EMC Documentum xCelerated Management System (xMS) 1.1 before P14 stores cleartext Windows Service credentials in a batch file during Documentum Platform and xCelerated Composition Platform (xCP) provisioning, which allows local users to obtain sensitive information by reading a file. | |
| Modificada | Alta (9) | 3.7% | — | EMC Documentum D2 | 14/2/2015 | 17/6/2026 | The Properties service in the D2FS web-service component in EMC Documentum D2 3.1 through SP1, 4.0 and 4.1 before 4.1 P22, and 4.2 before P11 allows remote authenticated users to obtain superuser privileges via an unspecified method call that modifies group permissions. | |
| Modificada | Media (4) | 1.2% | — | EMC Documentum D2 | 14/2/2015 | 17/6/2026 | The D2-API component in EMC Documentum D2 3.1 through SP1, 4.0 and 4.1 before 4.1 P22, and 4.2 before P11 places the MD5 hash of an encryption passphrase in log files, which allows remote authenticated users to obtain sensitive information by reading a file. | |
| Modificada | Alta (7.5) | 2.3% | — | Tecorange Simple E-document | 13/1/2015 | 17/6/2026 | SQL injection vulnerability in login.php in Simple e-document 1.31 allows remote attackers to execute arbitrary SQL commands via the username parameter. | |
| Modificada | Media (5) | 2.2% | — | EMC Documentum WDK | 7/1/2015 | 17/6/2026 | EMC Documentum Web Development Kit (WDK) before 6.8 does not properly generate random numbers for a certain parameter related to Webtop components, which makes it easier for remote attackers to conduct phishing attacks via brute-force attempts to predict the parameter value. | |
| Modificada | Media (5) | 2.3% | — | EMC Documentum WDK | 7/1/2015 | 17/6/2026 | EMC Documentum Web Development Kit (WDK) before 6.8 allows remote attackers to conduct frame-injection attacks and obtain sensitive information via unspecified vectors. | |
| Modificada | Media (6.4) | 2.3% | — | EMC Documentum WDK | 7/1/2015 | 17/6/2026 | Open redirect vulnerability in EMC Documentum Web Development Kit (WDK) before 6.8 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via an unspecified parameter. | |
| Modificada | Media (6.8) | 1.1% | — | EMC Documentum WDK | 7/1/2015 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in EMC Documentum Web Development Kit (WDK) before 6.8 allows remote attackers to hijack the authentication of arbitrary users for requests that perform Docbase operations. |