Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2500▼ 420 respecto a la semana anterior
Críticas / altas1284▲ 11 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 465 respecto a la semana anterior
369 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (6.3) | 0.29% | — | SAP Netweaver Application Server JavaAIAdobe Document ServiceAI | 11/8/2026 | 26/8/2026 | SAP NetWeaver Application Server Java (Adobe Document Service) uses outdated open source cryptographic and data transfer libraries that contain known vulnerabilities addressed in later versions. A low-privileged authenticated attacker could potentially leverage these weaknesses against the affected component, though… | |
| Analizada | Media (5.7) | 0.16% | — | Amazon Documentdb MCP Server | 5/8/2026 | 10/8/2026 | Incorrect authorization in the aggregation pipeline tool in Amazon AWS Labs DocumentDB MCP Server before 1.0.12 might allow an authenticated MCP client to perform inappropriate write operations on the connected database via write-capable aggregation pipeline stages that bypass the read-only mode enforcement logic. To… | |
| Aplazada | Media (6.1) | 0.27% | — | Document GalleryAI | 27/7/2026 | 27/7/2026 | The Document Gallery WordPress plugin before 5.1.1 does not properly sanitise and escape user input before reflecting it back in the response of an unauthenticated AJAX action, leading to a Reflected Cross-Site Scripting vulnerability which can be exploited against unauthenticated users. | |
| Analizada | Alta (7.3) | 0.31% | — | Oracle Document Management AND Collaboration | 21/7/2026 | 19/8/2026 | Vulnerability in the Oracle Document Management and Collaboration product of Oracle E-Business Suite (component: Attachments). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Document Management… | |
| Aplazada | Media (5.3) | 0.26% | — | Perfect Support Ticketing & Document Management SystemAI | 16/7/2026 | 16/7/2026 | Perfect Support Ticketing & Document Management System through 1.7 contains a broken access control vulnerability that allows authenticated attackers with Agent-level privileges to manipulate the Support Agent assignment field of tickets by bypassing intended authorization checks. Attackers can add or remove any user,… | |
| Aplazada | Media (5.1) | 0.24% | — | Perfect Support Ticketing AND Document Management SystemAI | 16/7/2026 | 18/7/2026 | Perfect Support Ticketing & Document Management System through 1.7 contains a stored cross-site scripting vulnerability that allows authenticated attackers with Agent-level privileges to inject malicious payloads into the Notes field of assigned support tickets. Attackers can store malicious scripts that execute in… | |
| Aplazada | Alta (7.1) | 0.25% | — | DAN Rossiter Document GalleryAI | 13/7/2026 | 13/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dan Rossiter Document Gallery document-gallery allows Reflected XSS.This issue affects Document Gallery: from n/a through <= 5.1.0. | |
| Aplazada | Media (6.3) | 0.22% | — | Arket Globe Document IntelligenceAI | 4/6/2026 | 22/7/2026 | Cross Site Scripting (XSS) vulnerability in the "Task in Progress / Recent" page in Arket Globe Document Intelligence 5.0.0.559 due to improper sanitization of user input in text fields when creating a new document. Specifically, when an authenticated attacker submits data containing JavaScript code within these… | |
| Aplazada | Alta (7.5) | 0.45% | — | SP Project Document ManagerAI | 4/6/2026 | 22/7/2026 | The SP Project & Document Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the view_file function in all versions up to, and including, 4.71. This makes it possible for unauthenticated attackers to read file metadata and obtain download links for arbitrary files… | |
| Aplazada | Alta (7.5) | 0.39% | — | BEN Balter WP Document RevisionsAI | 1/6/2026 | 22/7/2026 | Missing Authorization vulnerability in Ben Balter WP Document Revisions allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP Document Revisions: from n/a before 4.0.0. | |
| Aplazada | Media (5.3) | 0.39% | — | ILM Informatique JopenddocumentAI | 4/5/2026 | 17/6/2026 | Improper restriction of XML external entity reference vulnerability in ILM Informatique jOpenDocument allows Data Serialization External Entities Blowup. This issue affects jOpenDocument: 1.5. | |
| Pendiente de análisis | Media (5) | 0.32% | — | Onlyoffice DocumentserverAI | 16/4/2026 | 17/6/2026 | ONLYOFFICE DocumentServer before 9.3.0 has an untrusted pointer dereference in XLS processing/conversion (via pictFmla.cbBufInCtlStm and other vectors), leading to an information leak and ASLR bypass. | |
| Analizada | Crítica (9.8) | 0.83% | — | Deftpdf Document Translator | 31/3/2026 | 24/7/2026 | An arbitrary file overwrite vulnerability in DeftPDF Document Translator v54.0 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure. | |
| Analizada | Media (5.5) | 0.61% | — | Admerc Document Management System | 25/2/2026 | 17/6/2026 | A vulnerability has been found in itsourcecode Document Management System 1.0. Impacted is an unknown function of the file /register.php. Such manipulation of the argument Username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. | |
| Analizada | Media (5.5) | 0.59% | — | Admerc Document Management System | 25/2/2026 | 17/6/2026 | A vulnerability has been found in itsourcecode Document Management System 1.0. This issue affects some unknown processing of the file /loging.php of the component Login. The manipulation of the argument Username leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed to… | |
| Analizada | Media (5.5) | 0.59% | — | Admerc Document Management System | 24/2/2026 | 17/6/2026 | A security vulnerability has been detected in itsourcecode Document Management System 1.0. Affected is an unknown function of the file /edtlbls.php. The manipulation of the argument field1 leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. | |
| Analizada | Media (5.5) | 0.59% | — | Admerc Document Management System | 24/2/2026 | 17/6/2026 | A weakness has been identified in itsourcecode Document Management System 1.0. This impacts an unknown function of the file /deluser.php. Executing a manipulation of the argument user2del can lead to sql injection. The attack can be launched remotely. The exploit has been made available to the public and could be used… | |
| Aplazada | Media (4.3) | 0.19% | — | Echoplugins Knowledge Base FOR Documentation Faqs With AI AssistanceAI | 19/2/2026 | 17/6/2026 | Missing Authorization vulnerability in echoplugins Knowledge Base for Documentation, FAQs with AI Assistance echo-knowledge-base allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Knowledge Base for Documentation, FAQs with AI Assistance: from n/a through <= 16.011.0. | |
| Aplazada | Media (6.5) | 0.16% | — | Smartypants SP Project AND Document ManagerAI | 17/2/2026 | 17/6/2026 | Missing Authorization vulnerability in Smartypants SP Project & Document Manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SP Project & Document Manager: from n/a through 4.70. | |
| Analizada | Media (6.1) | 0.22% | — | SAP Document Management SystemSAP ERPSAP S4core | 10/2/2026 | 17/6/2026 | The BSP applications allow an unauthenticated user to inject malicious script content via user-controlled URL parameters that are not sufficiently sanitized. When a victim accesses a crafted URL, the injected script is executed in the victim�s browser, leading to a low impact on confidentiality and integrity, and no… | |
| Analizada | Media (6.1) | 0.22% | — | SAP Document Management SystemSAP ERPSAP S4core | 10/2/2026 | 17/6/2026 | The BSP applications allow an unauthenticated user to manipulate user-controlled URL parameters that are not sufficiently validated. This could result in unvalidated redirection to attacker-controlled websites, leading to a low impact on confidentiality and integrity, and no impact on the availability of the… | |
| Aplazada | Media (5.3) | 0.34% | — | Magic Import Document ExtractorAI | 4/2/2026 | 17/6/2026 | The Magic Import Document Extractor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.4 via the get_frontend_settings() function. This makes it possible for unauthenticated attackers to extract the site's magicimport.ai license key from the page source on… | |
| Aplazada | Media (5.3) | 0.34% | — | Magic Import Document ExtractorAI | 4/2/2026 | 17/6/2026 | The Magic Import Document Extractor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_sync_usage() function in all versions up to, and including, 1.0.5. This makes it possible for unauthenticated attackers to modify the plugin's license status and… | |
| Aplazada | Media (4.3) | 0.22% | — | Bplugins Document EmbedderAI | 28/1/2026 | 17/6/2026 | The Document Embedder – Embed PDFs, Word, Excel, and Other Files plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.0.4. This is due to the plugin not verifying that a user has permission to access the requested resource in the 'bplde_save_document_library',… | |
| Aplazada | Alta (7.1) | 0.29% | — | 2100 Technology Official Document Management SystemAI | 28/1/2026 | 17/6/2026 | Official Document Management System developed by 2100 Technology has a Incorrect Authorization vulnerability, allowing authenticated remote attackers to modify front-end code to read all official documents. |