Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
370 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.91% | 💥 Exploit | Cafuego Simple Document Management System | 1/11/2011 | 16/6/2026 | SQL injection vulnerability in detail.php in Simple Document Management System (SDMS) allows remote attackers to execute arbitrary SQL commands via the doc_id parameter. | |
| Modificada | Alta (10) | 8.2% | — | EMC Documentum Eroom | 19/7/2011 | 16/6/2026 | Stack-based buffer overflow in ftserver.exe in the OpenText Hummingbird Client Connector, as used in the Indexing Server in EMC Documentum eRoom 7.x before 7.4.3.f and other products, allows remote attackers to execute arbitrary code by sending a crafted message over TCP. | |
| Modificada | Alta (7.5) | 2.6% | 💥 Exploit | Digitalinterchange Digital Interchange Document Library | 23/4/2010 | 16/6/2026 | admin/save_user.asp in Digital Interchange Document Library 1.0.1 does not require administrative authentication, which allows remote attackers to read or modify the administrator's credentials via unspecified vectors. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (7.5) | 1.1% | — | Dmanager Documentmanager | 11/2/2010 | 16/6/2026 | Unspecified vulnerability in DocumentManager before 4.0 has unknown impact and attack vectors, related to file rights. | |
| Modificada | Alta (7.5) | 1.0% | — | Daniel Ptzinger Danp Documentdirs | 22/12/2009 | 16/6/2026 | SQL injection vulnerability in the Document Directorys (danp_documentdirs) extension 1.10.7 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Alta (10) | 13% | — | EMC Documentum Applicationxtender Workflow Manager | 22/10/2009 | 16/6/2026 | Directory traversal vulnerability in aws_tmxn.exe in the Admin Agent service in the server in EMC Documentum ApplicationXtender Workflow, possibly 5.40 SP1 and earlier, allows remote attackers to upload arbitrary files, and execute arbitrary code, via directory traversal sequences in requests to TCP port 2606. | |
| Modificada | Alta (10) | 5.6% | — | EMC Documentum Applicationxtender | 22/10/2009 | 16/6/2026 | Heap-based buffer overflow in aws_tmxn.exe in the Admin Agent service in the server in EMC Documentum ApplicationXtender Workflow, possibly 5.40 SP1 and earlier, allows remote attackers to execute arbitrary code via crafted packet data to TCP port 2606. | |
| Modificada | Alta (7.5) | 0.96% | 💥 Exploit | Bpowerhouse Bplawyercasedocuments | 30/9/2009 | 16/6/2026 | SQL injection vulnerability in employee.aspx in BPowerHouse BPLawyerCaseDocuments 1.0 allows remote attackers to execute arbitrary SQL commands via the cat parameter. | |
| Modificada | Baja (3.5) | 0.84% | — | Meridio Document AND Records Management | 14/9/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Meridio Document and Records Management before 4.3 SR1 allows remote authenticated users to inject arbitrary web script or HTML via the Title field in a (1) document (subGeneralProps:dmpvDocTitle:PROP_W_title) or (2) container… | |
| Modificada | Alta (7.5) | 0.99% | 💥 Exploit | COM Phocadocumentation | 23/2/2009 | 16/6/2026 | SQL injection vulnerability in the Phoca Documentation (com_phocadocumentation) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a section action to index.php. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Cafuego Simple Document Management System | 21/2/2009 | 16/6/2026 | SQL injection vulnerability in login.php in Simple Document Management System (SDMS) 1.1.5 and 1.1.4, and possibly earlier, allows remote attackers to execute arbitrary SQL commands via the login parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party… | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Cafuego Simple Document Management System | 20/2/2009 | 16/6/2026 | SQL injection vulnerability in login.php in Simple Document Management System (SDMS) 1.1.5 and 1.1.4, and possibly earlier, allows remote attackers to execute arbitrary SQL commands via the pass parameter. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Dmxready Secure Document Library | 5/2/2009 | 16/6/2026 | SQL injection vulnerability in CategoryManager/upload_image_category.asp in DMXReady Secure Document Library 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the cid parameter. | |
| Modificada | Media (4.3) | 1.0% | — | Knowledgetree Document Management | 6/1/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in KnowledgeTree before 3.5.4a allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different issue than CVE-2007-4281. | |
| Modificada | Media (6.5) | 1.1% | — | Knowledgetree Document Management | 6/1/2009 | 16/6/2026 | The DropDocuments plugin in KnowledgeTree before 3.5.4a allows remote authenticated users to gain administrative privileges via a certain sequence of "browse documents" and dashboard requests. | |
| Modificada | Media (4.3) | 1.1% | — | Nordicwind NoahNordicwind Document Management System | 20/8/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Nordicwind Document Management System (NOAH) before 3.2.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (9.3) | 6.0% | 💥 Exploit | Blackice Black ICE Document Imaging SDK | 18/7/2008 | 16/6/2026 | Heap-based buffer overflow in the OpenGifFile function in BiGif.dll in Black Ice Document Imaging SDK 10.95 allows remote attackers to execute arbitrary code via a long string argument to the GetNumberOfImagesInGifFile method in the BIImgFrm Control ActiveX control in biimgfrm.ocx. NOTE: some of these details are… | |
| Modificada | Media (5) | 2.0% | — | Site Documentation Project Site Documentation | 16/5/2008 | 16/6/2026 | The Site Documentation Drupal module 5.x before 5.x-1.8 and 6.x before 6.x-1.1 allows remote authenticated users to gain privileges of other users by leveraging the "access content" permission to list tables and obtain session IDs from the database. | |
| Modificada | Alta (10) | 2.6% | — | EMC Documentum AdministratorEMC Documentum Webtop | 7/2/2008 | 16/6/2026 | Unrestricted file upload vulnerability in dmclTrace.jsp in EMC Documentum Administrator 5.3.0.313 and Webtop 5.3.0.317 allows remote attackers to overwrite arbitrary files via the filename attribute. | |
| Modificada | Media (5) | 2.8% | 💥 Exploit | Poldoc Document Management System | 17/12/2007 | 16/6/2026 | Directory traversal vulnerability in download_file.php in PolDoc CMS (aka PDDMS) 0.96 allows remote attackers to read arbitrary files via a .. (dot dot) or absolute pathname in the filename parameter. | |
| Modificada | Baja (3.5) | 1.8% | — | Xythos Enterprise Document Manager | 27/6/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Xythos Enterprise Document Manager (XEDM) before 5.0.25.8, and 6.x before 6.0.46.1, allow remote authenticated users to inject arbitrary web script or HTML via (1) a saved Workflow name; (2) a Workflow name, related to deletion of a Workflow template; (3) the… | |
| Modificada | Media (4) | 1.4% | — | Xythos Digital LockerXythos Enterprise Document ManagerXythos Webfile Server | 27/6/2007 | 16/6/2026 | Xythos Enterprise Document Manager (XEDM), Digital Locker (XDL), and possibly WebFile Server before 6.0.46.1 allow remote authenticated users to associate arbitrary Content-Type HTTP headers with documents, which might facilitate malware distribution. | |
| Modificada | Media (6.5) | 1.9% | — | Xythos Enterprise Document Manager | 27/6/2007 | 16/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in Xythos Enterprise Document Manager (XEDM) before 5.0.25.8, and 6.x before 6.0.46.1, allow remote authenticated users to execute commands as arbitrary users via (1) a saved Workflow name or (2) the Content-Type HTTP header. NOTE: item 2 also affects the same… | |
| Modificada | Alta (9.3) | 6.4% | 💥 Exploit | Lead Technologies Leadtools Raster OCR Document Object Library | 1/6/2007 | 16/6/2026 | Buffer overflow in a certain ActiveX control in LEAD Technologies LEADTOOLS Raster OCR Document Object Library (ltrdc14e.dll) 14.5.0.44 allows remote attackers to execute arbitrary code via a long DictionaryFileName property. | |
| Modificada | Alta (10) | 2.7% | — | Knowledgetree Document Management | 24/5/2007 | 16/6/2026 | KnowledgeTree Document Management (aka KnowledgeTree Open Source) before STABLE 3.3.7 does not require a password for an unregistered user, when the user exists in Active Directory, which allows remote attackers to log onto KTDMS without the intended authorization check. |