Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2797▼ 203 respecto a la semana anterior
Críticas / altas1352▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)255▼ 266 respecto a la semana anterior
156 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.35% | — | WedocsAI | 9/1/2026 | 17/6/2026 | The weDocs plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.1.15 via the `/wp-json/wp/v2/docs/settings` REST API endpoint. This makes it possible for unauthenticated attackers to extract sensitive data including third party services API keys. | |
| Aplazada | Media (6.4) | 0.18% | — | Onlyoffice DocsAI | 24/12/2025 | 17/6/2026 | ONLYOFFICE Docs before 9.2.1 allows XSS in the textarea of the comment editing form. This is related to DocumentServer. | |
| Analizada | Alta (8.2) | 0.30% | — | Newgensoft Omnidocs | 15/12/2025 | 17/6/2026 | An unauthenticated Broken Function Level Authorization (BFLA) vulnerability in Newgen OmniDocs v11.0 allows attackers to obtain sensitive information and execute a full account takeover via a crafted API request. | |
| Aplazada | Media (5.4) | 0.22% | — | WedocsAI | 6/12/2025 | 17/6/2026 | The weDocs plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 2.1.14. This is due to the plugin not properly verifying that a user is authorized to perform an action in the create_item_permissions_check function. This makes it possible for authenticated attackers, with… | |
| Analizada | Media (5.1) | 0.19% | — | Qdocs Smart School | 10/11/2025 | 17/6/2026 | Stored Cross Site Scripting (XSS) vulnerability in Smart School 7.0 due to lack of proper validation of user input when sending a POST request to '/online_admission', wich affects the parameters 'firstname', 'lastname', 'guardian_name' and others. This vulnerability could allow a remote user to send a specially… | |
| Analizada | Alta (7.5) | 0.23% | — | Tencent Docs | 4/11/2025 | 17/6/2026 | Tencent Docs Desktop 3.9.20 and earlier suffers from Missing SSL Certificate Validation in the update component. | |
| Analizada | Alta (7.2) | 0.53% | — | Qdocs Smart School | 21/10/2025 | 17/6/2026 | QDocs Smart School Management System 7.1 allows authenticated users with roles such as "accountant" or "admin" to bypass file type restrictions in the media upload feature by abusing the alternate YouTube URL option. This logic flaw permits uploading of arbitrary PHP files, which are stored in a web-accessible… | |
| Analizada | Baja (2.1) | 0.80% | — | Docsys Project Docsys | 12/10/2025 | 17/6/2026 | A vulnerability was determined in RainyGao DocSys up to 2.02.36. Affected by this vulnerability is an unknown functionality of the file /Doc/deleteDoc.do. Executing manipulation of the argument path can lead to path traversal. The attack can be launched remotely. The exploit has been publicly disclosed and may be… | |
| Analizada | Baja (2.1) | 0.72% | — | Docsys Project Docsys | 12/10/2025 | 17/6/2026 | A vulnerability was found in RainyGao DocSys up to 2.02.36. Affected is the function updateRealDoc of the file /Doc/uploadDoc.do of the component File Upload. Performing manipulation of the argument path results in path traversal. The attack can be initiated remotely. The exploit has been made public and could be… | |
| Analizada | Baja (2.1) | 0.41% | — | Docsys Project Docsys | 12/10/2025 | 30/9/2026 | A vulnerability has been found in RainyGao DocSys up to 2.02.36. This impacts the function getUserList of the file /Manage/getUserList.do. Such manipulation leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early… | |
| Aplazada | Media (5.5) | 0.22% | — | Archalj Smart DocsAI | 3/10/2025 | 17/6/2026 | The Smart Docs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject… | |
| Aplazada | Media (6.5) | 0.34% | — | Mkdocs-include-markdown-pluginAI | 29/9/2025 | 17/6/2026 | mkdocs-include-markdown-plugin is an Mkdocs Markdown includer plugin. In versions 7.1.7 and below, there is a vulnerability where unvalidated input can collide with substitution placeholders. This issue is fixed in version 7.1.8. | |
| Aplazada | Media (5.3) | 0.29% | — | Wpdeveloper BetterdocsAI | 16/8/2025 | 17/6/2026 | The BetterDocs – Advanced AI-Driven Documentation, FAQ & Knowledge Base Tool for Elementor & Gutenberg with Encyclopedia, AI Support, Instant Answers plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_response function in all versions up to and including… | |
| Analizada | Alta (7.5) | 0.22% | — | Hcltech Connections Docs | 14/8/2025 | 17/6/2026 | HCL Connections Docs may mishandle validation of certain uploaded documents leading to denial of service due to resource exhaustion. | |
| Aplazada | Crítica (9.8) | 0.75% | — | Onlyoffice DocsAI | 24/7/2025 | 17/6/2026 | The ONLYOFFICE Docs plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization within its oo.callback REST endpoint in versions 1.1.0 to 2.2.0. The plugin’s permission callback only verifies that the supplied, encrypted attachment ID maps to an existing attachment post, but does not verify… | |
| Analizada | Baja (2.1) | 0.57% | — | Wikidocs | 20/7/2025 | 17/6/2026 | A vulnerability has been found in Zavy86 WikiDocs up to 1.0.78 and classified as problematic. This vulnerability affects unknown code of the file template.inc.php. The manipulation of the argument path leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and… | |
| Aplazada | Alta (7.5) | 9.8% | — | Mcp-package-docsAI | 18/7/2025 | 17/6/2026 | mcp-package-docs is an MCP (Model Context Protocol) server that provides LLMs with efficient access to package documentation across multiple programming languages and language server protocol (LSP) capabilities. A command injection vulnerability exists in the `mcp-package-docs` MCP Server prior to the fix in commit… | |
| Aplazada | Media (5.1) | 0.44% | — | WikidocsAI | 14/7/2025 | 17/6/2026 | A vulnerability has been found in Zavy86 WikiDocs up to 1.0.77 and classified as critical. Affected by this vulnerability is the function image_drop_upload_ajax/image_delete_ajax of the file submit.php. The manipulation leads to path traversal. The attack can be launched remotely. Upgrading to version 1.0.78 is able… | |
| Modificada | Media (5.4) | 0.26% | — | Archalj Smart Docs | 4/7/2025 | 17/6/2026 | The Smart Docs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'smartdocs_search' shortcode in all versions up to, and including, 1.1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Analizada | Media (5.6) | 0.25% | — | Jackphoenix Googledocs4mw | 3/7/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - GoogleDocs4MW Extension allows Cross-Site Scripting (XSS).This issue affects Mediawiki - GoogleDocs4MW Extension: from 1.42.X before 1.42.7, from 1.43.X before 1.43.2. | |
| Analizada | Media (6.5) | 0.26% | — | Yaronkoren Mintydocs | 2/7/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - MintyDocs Extension allows Stored XSS.This issue affects Mediawiki - MintyDocs Extension: from 1.43.X before 1.43.2. | |
| Analizada | Baja (3.7) | 0.27% | — | Yaronkoren Mintydocs | 2/7/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - MintyDocs Extension allows Stored XSS.This issue affects Mediawiki - MintyDocs Extension: from 1.43.X before 1.43.2. | |
| Analizada | Media (4.3) | 0.26% | — | Boonebgorges Buddypress Docs | 27/6/2025 | 17/6/2026 | The BuddyPress Docs WordPress plugin before 2.2.5 lacks proper access controls and allows a logged in user to view and download files belonging to another user | |
| Aplazada | Media (6.1) | 62% | — | Onlyoffice DocsAI | 12/6/2025 | 17/6/2026 | ONLYOFFICE Docs (DocumentServer) in versions equal and below 8.3.1 are affected by a reflected cross-site scripting (XSS) issue when opening files via the WOPI protocol. Attackers could inject malicious scripts via crafted HTTP POST requests, which are then reflected in the server's HTML response. | |
| Aplazada | Media (4.3) | 0.30% | — | NK DocspressAI | 6/6/2025 | 17/6/2026 | Missing Authorization vulnerability in nK DocsPress docspress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects DocsPress: from n/a through <= 2.5.2. |