Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3005▼ 85 respecto a la semana anterior
Críticas / altas1403▲ 41 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
66 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (10) | 4.2% | — | Paperthin Commonspot Content Server | 15/4/2014 | 17/6/2026 | Multiple absolute path traversal vulnerabilities in PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allow remote attackers to have an unspecified impact via a full pathname in a parameter. | |
| Modificada | Media (6.5) | 1.8% | — | Paperthin Commonspot Content Server | 15/4/2014 | 17/6/2026 | PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 does not check authorization in unspecified situations, which allows remote authenticated users to perform actions via unknown vectors. | |
| Modificada | Media (4.3) | 2.1% | — | Paperthin Commonspot Content Server | 15/4/2014 | 17/6/2026 | Incomplete blacklist vulnerability in PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted string, as demonstrated by bypassing a protection mechanism that removes only the "alert" string. | |
| Modificada | Media (4.3) | 2.0% | — | Paperthin Commonspot Content Server | 15/4/2014 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allow remote attackers to inject arbitrary web script or HTML via a crafted HTTP request to a (1) ColdFusion or (2) JavaScript component. | |
| Modificada | Alta (7.5) | 2.5% | — | Paperthin Commonspot Content Server | 15/4/2014 | 17/6/2026 | PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to bypass intended access restrictions via a direct request. | |
| Modificada | Media (5.5) | 1.0% | — | EMC Documentum Content Server | 15/4/2014 | 17/6/2026 | EMC Documentum Content Server before 6.7 SP1 P26, 6.7 SP2 before P13, 7.0 before P13, and 7.1 before P02 allows remote authenticated users to bypass intended access restrictions and read metadata from certain folders via unspecified vectors. | |
| Modificada | Media (6.8) | 0.28% | — | EMC Documentum Content ServerCentos | 2/2/2012 | 16/6/2026 | Unspecified vulnerability in EMC Documentum Content Server 6.0, 6.5 before SP2 P02, 6.5 SP3 before SP3 P02, and 6.6 before P02 allows local users to obtain "highest super user privileges" by leveraging system administrator privileges. | |
| Modificada | Media (4.3) | 1.5% | — | Paperthin Commonspot Content Server | 2/2/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in utilities/longproc.cfm in PaperThin CommonSpot Content Server allows remote attackers to inject arbitrary web script or HTML via the url parameter. | |
| Modificada | Alta (7.5) | 55% | — | Gianni Tommasi Kr-php WEB Content Server | 7/12/2009 | 16/6/2026 | PHP remote file inclusion vulnerability in adm/krgourl.php in KR-Web 1.1b2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the DOCUMENT_ROOT parameter. | |
| Modificada | Media (4.3) | 1.9% | — | Fatwire Content Server | 10/11/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Fatwire Content Server (CS) CMS 6.3.0 allow remote attackers to inject arbitrary web script or HTML via unspecified form fields related to the (1) search function, (2) advanced search function, and possibly other components. | |
| Modificada | Alta (7.5) | 1.9% | — | Fatwire Content Server | 21/7/2006 | 16/6/2026 | FatWire Content Server 5.5.0 allows remote attackers to bypass access restrictions and obtain administrative privileges via unspecified attack vectors in the authentication process. | |
| Modificada | Media (4.3) | 1.7% | — | Paperthin Commonspot Content Server | 29/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in loader.cfm in PaperThin CommonSpot Content Server 4.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the bNewWindow parameter. | |
| Modificada | Media (5) | 1.4% | — | Paperthin Commonspot Content Server | 29/12/2005 | 16/6/2026 | PaperThin CommonSpot Content Server 4.5 and earlier allow remote attackers to obtain sensitive information via an invalid errmsg parameter to loader.cfm with a url parameter set to email-login-info.cfm, which leaks the full pathname in the resulting error message. | |
| Modificada | Media (5) | 2.5% | — | Adobe Content Server | 4/10/2002 | 16/6/2026 | The library feature for Adobe Content Server 3.0 does not verify if a customer has already checked out an eBook, which allows remote attackers to cause a denial of service (resource exhaustion) by checking out the same book multiple times. | |
| Modificada | Media (5) | 2.6% | — | Adobe Content Server | 4/10/2002 | 16/6/2026 | The library feature for Adobe Content Server 3.0 allows a remote attacker to check out an eBook for an arbitrary length of time via a modified loanMin parameter to download.asp. | |
| Modificada | Media (5) | 2.3% | — | Adobe Content Server | 4/10/2002 | 16/6/2026 | The library feature for Adobe Content Server 3.0 allows a remote attacker to check out an eBook even when the maximum number of loans is exceeded by accessing the "Add to bookbag" feature when the server reports that no more copies are available. |