Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
46 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9) | 0.86% | — | Wpdeveloper Betterdocs | 28/3/2024 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in WPDeveloper BetterDocs.This issue affects BetterDocs: from n/a through 3.3.3. | |
| Analizada | Media (6.1) | 1.1% | — | Yardoc YardFedoraproject FedoraDebian Linux | 28/2/2024 | 17/6/2026 | YARD is a Ruby Documentation tool. The "frames.html" file within the Yard Doc's generated documentation is vulnerable to Cross-Site Scripting (XSS) attacks due to inadequate sanitization of user input within the JavaScript segment of the "frames.erb" template file. This vulnerability is fixed in 0.9.36. | |
| Modificada | Alta (8.8) | 0.28% | — | Underdock Open Graph Metabox | 25/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Niels van Renselaar Open Graph Metabox plugin <= 1.4.4 versions. | |
| Modificada | Alta (7.8) | 0.89% | — | Renderdoc | 7/6/2023 | 17/6/2026 | RenderDoc before 1.27 allows local privilege escalation via a symlink attack. It relies on the /tmp/RenderDoc directory regardless of ownership. | |
| Modificada | Crítica (9.8) | 4.2% | — | Renderdoc | 7/6/2023 | 17/6/2026 | StreamReader::ReadFromExternal in RenderDoc before 1.27 allows an Integer Overflow with a resultant Buffer Overflow. It uses uint32_t(m_BufferSize-m_InputSize) even though m_InputSize can exceed m_BufferSize. | |
| Modificada | Crítica (9.8) | 4.2% | — | Renderdoc | 7/6/2023 | 17/6/2026 | SerialiseValue in RenderDoc before 1.27 allows an Integer Overflow with a resultant Buffer Overflow. 0xffffffff is sign-extended to 0xffffffffffffffff (SIZE_MAX) and then there is an attempt to add 1. | |
| Modificada | Crítica (9.3) | 1.3% | — | Thunderatz Thunderdocs | 11/7/2022 | 17/6/2026 | The ThundeRatz/ThunderDocs repository through 2020-05-01 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | |
| Modificada | Alta (7.8) | 0.82% | — | Mrdoc | 6/9/2021 | 17/6/2026 | mrdoc is vulnerable to Deserialization of Untrusted Data | |
| Modificada | Alta (7) | 1.5% | — | Debian LinuxRuby-lang RdocOracle JD Edwards Enterpriseone Tools | 30/7/2021 | 17/6/2026 | In RDoc 3.11 through 6.x before 6.3.1, as distributed with Ruby through 3.0.1, it is possible to execute arbitrary code via | and tags in a filename. | |
| Modificada | Crítica (9.8) | 1.8% | — | Renderdocs-rs Project Renderdocs-rs | 9/9/2019 | 17/6/2026 | An issue was discovered in the renderdoc crate before 0.5.0 for Rust. Multiple exposed methods take self by immutable reference, which is incompatible with a multi-threaded application. | |
| Modificada | Alta (7.5) | 2.3% | — | Yardoc Yard | 29/7/2019 | 17/6/2026 | yard before 0.9.20 allows path traversal. | |
| Modificada | Crítica (9.8) | 3.6% | — | Supermicro Superdoctor 5 | 1/7/2019 | 17/6/2026 | Super Micro SuperDoctor 5, when restrictions are not implemented in agent.cfg, allows remote attackers to execute arbitrary commands via NRPE. | |
| Modificada | Alta (7.5) | 2.9% | — | Yardoc Yard | 28/11/2017 | 17/6/2026 | lib/yard/core_ext/file.rb in the server in YARD before 0.9.11 does not block relative paths with an initial ../ sequence, which allows attackers to conduct directory traversal attacks and read arbitrary files. | |
| Modificada | Media (5.4) | 0.27% | — | Surdoc - 100gb+ Free Storage | 18/9/2014 | 17/6/2026 | The SurDoc - 100GB+ FREE storage (aka com.jd.surdoc) application 1.3.4.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (4.3) | 3.0% | — | Ruby-lang RdocRuby-lang RubyCanonical Ubuntu Linux | 1/3/2013 | 16/6/2026 | darkfish.js in RDoc 2.3.0 through 3.12 and 4.x before 4.0.0.preview2.1, as used in Ruby, does not properly generate documents, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted URL. | |
| Modificada | Alta (7.5) | 2.6% | 💥 Exploit | PHP Errordocs | 14/12/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in includes/common.php in the ErrorDocs 1.0.0 and earlier module for mxBB (mx_errordocs) allows remote attackers to execute arbitrary PHP code via a URL in the module_root_path parameter. | |
| Modificada | Alta (7.5) | 1.3% | — | Cyberdoc Sitesuite CMS | 10/1/2006 | 16/6/2026 | SQL injection vulnerability in index.php in CyberDoc SiteSuite CMS allows remote attackers to execute arbitrary SQL commands via the page parameter. | |
| Modificada | Media (4.3) | 1.5% | — | Hummingbird Cyberdocs | 31/12/2003 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Hummingbird CyberDOCS 3.5.1, 3.9, and 4.0 allow remote attackers to inject arbitrary web script or HTML via certain vectors. | |
| Modificada | Media (5) | 1.8% | — | Hummingbird Cyberdocs | 31/12/2003 | 16/6/2026 | Hummingbird CyberDOCS 3.5.1, 3.9, and 4.0 allows remote attackers to obtain the full path of the DM Web Server via invalid login credentials, which reveals the path in an error message. | |
| Modificada | Alta (7.5) | 1.5% | — | Hummingbird Cyberdocs | 31/12/2003 | 16/6/2026 | SQL injection vulnerability in loginact.asp for Hummingbird CyberDOCS before 3.9 allows remote attackers to execute arbitrary SQL commands. | |
| Modificada | Media (5) | 1.8% | — | Hummingbird CyberdocsAIMicrosoft IISAI | 31/12/2003 | 16/6/2026 | Hummingbird CyberDOCS 3.5, 3.9, and 4.0, when running on IIS, uses insecure permissions for script source code files, which allows remote attackers to read the source code. |