Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

370 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)0.91%💥 ExploitCafuego Simple Document Management System1/11/201116/6/2026
SQL injection vulnerability in detail.php in Simple Document Management System (SDMS) allows remote attackers to execute arbitrary SQL commands via the doc_id parameter.
ModificadaAlta (10)8.2%—EMC Documentum Eroom19/7/201116/6/2026
Stack-based buffer overflow in ftserver.exe in the OpenText Hummingbird Client Connector, as used in the Indexing Server in EMC Documentum eRoom 7.x before 7.4.3.f and other products, allows remote attackers to execute arbitrary code by sending a crafted message over TCP.
ModificadaAlta (7.5)2.6%💥 ExploitDigitalinterchange Digital Interchange Document Library23/4/201016/6/2026
admin/save_user.asp in Digital Interchange Document Library 1.0.1 does not require administrative authentication, which allows remote attackers to read or modify the administrator's credentials via unspecified vectors. NOTE: some of these details are obtained from third party information.
ModificadaAlta (7.5)1.1%—Dmanager Documentmanager11/2/201016/6/2026
Unspecified vulnerability in DocumentManager before 4.0 has unknown impact and attack vectors, related to file rights.
ModificadaAlta (7.5)1.0%—Daniel Ptzinger Danp Documentdirs22/12/200916/6/2026
SQL injection vulnerability in the Document Directorys (danp_documentdirs) extension 1.10.7 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
ModificadaAlta (10)13%—EMC Documentum Applicationxtender Workflow Manager22/10/200916/6/2026
Directory traversal vulnerability in aws_tmxn.exe in the Admin Agent service in the server in EMC Documentum ApplicationXtender Workflow, possibly 5.40 SP1 and earlier, allows remote attackers to upload arbitrary files, and execute arbitrary code, via directory traversal sequences in requests to TCP port 2606.
ModificadaAlta (10)5.6%—EMC Documentum Applicationxtender22/10/200916/6/2026
Heap-based buffer overflow in aws_tmxn.exe in the Admin Agent service in the server in EMC Documentum ApplicationXtender Workflow, possibly 5.40 SP1 and earlier, allows remote attackers to execute arbitrary code via crafted packet data to TCP port 2606.
ModificadaAlta (7.5)0.96%💥 ExploitBpowerhouse Bplawyercasedocuments30/9/200916/6/2026
SQL injection vulnerability in employee.aspx in BPowerHouse BPLawyerCaseDocuments 1.0 allows remote attackers to execute arbitrary SQL commands via the cat parameter.
ModificadaBaja (3.5)0.84%—Meridio Document AND Records Management14/9/200916/6/2026
Cross-site scripting (XSS) vulnerability in Meridio Document and Records Management before 4.3 SR1 allows remote authenticated users to inject arbitrary web script or HTML via the Title field in a (1) document (subGeneralProps:dmpvDocTitle:PROP_W_title) or (2) container…
ModificadaAlta (7.5)0.99%💥 ExploitCOM Phocadocumentation23/2/200916/6/2026
SQL injection vulnerability in the Phoca Documentation (com_phocadocumentation) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a section action to index.php.
ModificadaAlta (7.5)0.97%💥 ExploitCafuego Simple Document Management System21/2/200916/6/2026
SQL injection vulnerability in login.php in Simple Document Management System (SDMS) 1.1.5 and 1.1.4, and possibly earlier, allows remote attackers to execute arbitrary SQL commands via the login parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party…
ModificadaAlta (7.5)1.2%💥 ExploitCafuego Simple Document Management System20/2/200916/6/2026
SQL injection vulnerability in login.php in Simple Document Management System (SDMS) 1.1.5 and 1.1.4, and possibly earlier, allows remote attackers to execute arbitrary SQL commands via the pass parameter.
ModificadaAlta (7.5)1.2%💥 ExploitDmxready Secure Document Library5/2/200916/6/2026
SQL injection vulnerability in CategoryManager/upload_image_category.asp in DMXReady Secure Document Library 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the cid parameter.
ModificadaMedia (4.3)1.0%—Knowledgetree Document Management6/1/200916/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in KnowledgeTree before 3.5.4a allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different issue than CVE-2007-4281.
ModificadaMedia (6.5)1.1%—Knowledgetree Document Management6/1/200916/6/2026
The DropDocuments plugin in KnowledgeTree before 3.5.4a allows remote authenticated users to gain administrative privileges via a certain sequence of "browse documents" and dashboard requests.
ModificadaMedia (4.3)1.1%—Nordicwind NoahNordicwind Document Management System20/8/200816/6/2026
Cross-site scripting (XSS) vulnerability in Nordicwind Document Management System (NOAH) before 3.2.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaAlta (9.3)6.0%💥 ExploitBlackice Black ICE Document Imaging SDK18/7/200816/6/2026
Heap-based buffer overflow in the OpenGifFile function in BiGif.dll in Black Ice Document Imaging SDK 10.95 allows remote attackers to execute arbitrary code via a long string argument to the GetNumberOfImagesInGifFile method in the BIImgFrm Control ActiveX control in biimgfrm.ocx. NOTE: some of these details are…
ModificadaMedia (5)2.0%—Site Documentation Project Site Documentation16/5/200816/6/2026
The Site Documentation Drupal module 5.x before 5.x-1.8 and 6.x before 6.x-1.1 allows remote authenticated users to gain privileges of other users by leveraging the "access content" permission to list tables and obtain session IDs from the database.
ModificadaAlta (10)2.6%—EMC Documentum AdministratorEMC Documentum Webtop7/2/200816/6/2026
Unrestricted file upload vulnerability in dmclTrace.jsp in EMC Documentum Administrator 5.3.0.313 and Webtop 5.3.0.317 allows remote attackers to overwrite arbitrary files via the filename attribute.
ModificadaMedia (5)2.8%💥 ExploitPoldoc Document Management System17/12/200716/6/2026
Directory traversal vulnerability in download_file.php in PolDoc CMS (aka PDDMS) 0.96 allows remote attackers to read arbitrary files via a .. (dot dot) or absolute pathname in the filename parameter.
ModificadaBaja (3.5)1.8%—Xythos Enterprise Document Manager27/6/200716/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Xythos Enterprise Document Manager (XEDM) before 5.0.25.8, and 6.x before 6.0.46.1, allow remote authenticated users to inject arbitrary web script or HTML via (1) a saved Workflow name; (2) a Workflow name, related to deletion of a Workflow template; (3) the…
ModificadaMedia (4)1.4%—Xythos Digital LockerXythos Enterprise Document ManagerXythos Webfile Server27/6/200716/6/2026
Xythos Enterprise Document Manager (XEDM), Digital Locker (XDL), and possibly WebFile Server before 6.0.46.1 allow remote authenticated users to associate arbitrary Content-Type HTTP headers with documents, which might facilitate malware distribution.
ModificadaMedia (6.5)1.9%—Xythos Enterprise Document Manager27/6/200716/6/2026
Multiple cross-site request forgery (CSRF) vulnerabilities in Xythos Enterprise Document Manager (XEDM) before 5.0.25.8, and 6.x before 6.0.46.1, allow remote authenticated users to execute commands as arbitrary users via (1) a saved Workflow name or (2) the Content-Type HTTP header. NOTE: item 2 also affects the same…
ModificadaAlta (9.3)6.4%💥 ExploitLead Technologies Leadtools Raster OCR Document Object Library1/6/200716/6/2026
Buffer overflow in a certain ActiveX control in LEAD Technologies LEADTOOLS Raster OCR Document Object Library (ltrdc14e.dll) 14.5.0.44 allows remote attackers to execute arbitrary code via a long DictionaryFileName property.
ModificadaAlta (10)2.7%—Knowledgetree Document Management24/5/200716/6/2026
KnowledgeTree Document Management (aka KnowledgeTree Open Source) before STABLE 3.3.7 does not require a password for an unregistered user, when the user exists in Active Directory, which allows remote attackers to log onto KTDMS without the intended authorization check.
Orbitaley — Vulnerabilidades