Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
–

370 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.8)3.4%—Sourceforge Wordperfect Document Importer-exporter16/3/200716/6/2026
Integer overflow in the WP6GeneralTextPacket::_readContents function in WordPerfect Document importer/exporter (libwpd) before 0.8.9 allows user-assisted remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted WordPerfect file, a different vulnerability than…
ModificadaBaja (2.6)1.9%—Adobe Document Server13/4/200616/6/2026
Adobe Document Server for Reader Extensions 6.0, during log on, provides different error messages depending on whether the user ID is valid or invalid, which allows remote attackers to more easily identify valid user IDs via brute force attacks.
ModificadaBaja (2.6)1.9%—Adobe Document Server13/4/200616/6/2026
Adobe Document Server for Reader Extensions 6.0 includes a user's session (jsession) ID in the HTTP Referer header, which allows remote attackers to gain access to PDF files that are being processed within that session.
ModificadaBaja (2.1)1.5%—Adobe Document Server13/4/200616/6/2026
Adobe Document Server for Reader Extensions 6.0 allows remote authenticated users to inject arbitrary web script via a leading (1) ftp or (2) http URI in the ReaderURL variable in the "Update Download Site" section of ads-readerext. NOTE: it is not clear whether the vendor advisory addresses this issue. In addition,…
ModificadaBaja (2.6)12%💥 ExploitAdobe Document Server13/4/200616/6/2026
Cross-site scripting (XSS) vulnerability in Adobe Document Server for Reader Extensions 6.0 allows remote attackers to inject arbitrary web script or HTML via (1) the actionID parameter in ads-readerext and (2) the op parameter in AlterCast. NOTE: it is not clear whether the vendor advisory addresses this issue.
ModificadaBaja (2.6)0.77%—Adobe Document ServerAdobe Graphics Server16/3/200616/6/2026
Adobe Graphics Server 2.0 and 2.1 (formerly AlterCast) and Adobe Document Server (ADS) 5.0 and 6.0 allows local users to read files with certain extensions or overwrite arbitrary files and execute code via a crafted SOAP request to the AlterCast web service in which the request uses the (1) saveContent or (2)…
ModificadaBaja (2.6)0.92%—Ncipher Dse200 Document Sealing EngineNcipher NcoreNcipher NforceNcipher Securedb+49/3/200616/6/2026
nCipher firmware before V10, as used by (1) nShield, (2) nForce, (3) netHSM, (4) payShield, (5) SecureDB, (6) DSE200 Document Sealing Engine, (7) Time Source Master Clock (TSMC), and possibly other products, contains certain options that were only intended for testing and not production, which might allow remote…
ModificadaAlta (7.5)14%💥 ExploitJoshua Eichorn Phpdocumentor31/12/200516/6/2026
PHP remote file inclusion vulnerability in phpDocumentor 1.3.0 rc4 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary code via a URL in the (1) FORUM[LIB] parameter in Documentation/tests/bug-559668.php and (2) the root_dir parameter in docbuilder/file_dialog.php.
ModificadaAlta (7.5)1.2%💥 ExploitCafuego Simple Document Management System29/11/200516/6/2026
Multiple SQL injection vulnerabilities in Simple Document Management System (SDMS) 2.0-CVS and earlier allow remote attackers to execute arbitrary SQL commands via the (1) folder_id parameter in list.php and (2) mid parameter in a view action to messages.php.
ModificadaMedia (4.3)1.8%—Xerox Document Centre 265Xerox Document Centre 332Xerox Document Centre 340Xerox Document Centre 420+323/8/200516/6/2026
Cross-site scripting (XSS) vulnerability in Xerox MicroServer Web Server in Document Centre 220 through 265, 332 and 340, 420 through 490, and 535 through 555 allows remote attackers to inject arbitrary web script or HTML and modify web pages via unknown vectors.
ModificadaMedia (6.4)2.1%—Xerox Document Centre 220Xerox Document Centre 230Xerox Document Centre 240Xerox Document Centre 255+1623/8/200516/6/2026
Unknown vulnerability in Xerox MicroServer Web Server in Document Centre 220 through 265, 332 and 340, 420 through 490, and 535 through 555 allows remote attackers to cause a denial of service or read files via unknown vectors involving crafted HTTP requests.
ModificadaAlta (7.5)2.5%—Xerox Document Centre 265Xerox Document Centre 332Xerox Document Centre 340Xerox Document Centre 420+323/8/200516/6/2026
Unknown vulnerability in Xerox MicroServer Web Server in Document Centre 220 through 265, 332 and 340, 420 through 490, and 535 through 555 allows remote attackers to bypass authentication.
ModificadaAlta (7.5)1.5%—Xerox Document Centre 220Xerox Document Centre 230Xerox Document Centre 240Xerox Document Centre 255+1613/6/200516/6/2026
Unknown vulnerability in the web server for the ESS/ Network Controller for Xerox Document Centre 240 through 555 running System Software 27.18.017 and earlier allows attackers to "gain unauthorized access."
ModificadaAlta (7.5)5.6%💥 ExploitNokia Electronic Documentation6/10/200316/6/2026
Nokia Electronic Documentation (NED) 5.0 allows remote attackers to use NED as an open HTTP proxy via a URL in the location parameter, which NED accesses and returns to the user.
ModificadaMedia (5)6.6%💥 ExploitNokia Electronic Documentation6/10/200316/6/2026
Nokia Electronic Documentation (NED) 5.0 allows remote attackers to obtain a directory listing of the WebLogic web root, and the physical path of the NED server, via a "retrieve" action with a location parameter of . (dot).
ModificadaMedia (4.3)12%💥 ExploitNokia Electronic Documentation6/10/200316/6/2026
Cross-site scripting (XSS) vulnerability in Nokia Electronic Documentation (NED) 5.0 allows remote attackers to execute arbitrary web script and steal cookies via a URL to the docs/ directory that contains the script.
ModificadaAlta (10)6.2%💥 ExploitMobius Documentdirect FOR THE Internet14/11/200016/6/2026
Buffer overflow in ddicgi.exe in Mobius DocumentDirect for the Internet 1.2 allows remote attackers to execute arbitrary commands via a long User-Agent parameter.
ModificadaAlta (10)4.1%—Mobius Documentdirect FOR THE Internet14/11/200016/6/2026
Buffer overflow in the web authorization form of Mobius DocumentDirect for the Internet 1.2 allows remote attackers to cause a denial of service or execute arbitrary commands via a long username.
ModificadaAlta (10)5.9%—Mobius Documentdirect FOR THE Internet14/11/200016/6/2026
Buffer overflow in ddicgi.exe program in Mobius DocumentDirect for the Internet 1.2 allows remote attackers to execute arbitrary commands via a long GET request.
ModificadaAlta (7.5)1.6%—Axis 700 Network Document Server7/2/200016/6/2026
Axis 700 Network Scanner does not properly restrict access to administrator URLs, which allows users to bypass the password protection via a .. (dot dot) attack.
Orbitaley — Vulnerabilidades