Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2597▼ 310 respecto a la semana anterior
Críticas / altas1338▲ 74 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 463 respecto a la semana anterior
–

369 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.7)0.23%—Viafirma DocumentsViafirma Documents Compose12/1/202617/6/2026
Weaknesses in the authorization mechanisms of Viafirma Documents v3.7.129 allow an authenticated user without privileges to list and access other user data, use user creation, modification, and deletion features, and escalate privileges by impersonating other users of the application in the generation and signing of…
AplazadaMedia (6.5)0.17%—Basepress Knowledge Base Documentation & Wiki PluginAI31/12/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BasePress Knowledge Base documentation & wiki plugin – BasePress basepress allows Stored XSS.This issue affects Knowledge Base documentation & wiki plugin – BasePress: from n/a through <= 2.17.0.1.
AnalizadaMedia (6.1)0.20%—Onlyoffice Document Server25/12/202517/6/2026
ONLYOFFICE Docs before 9.2.1 allows XSS via the Color theme name. This is related to DocumentServer.
AnalizadaMedia (6.1)0.20%—Onlyoffice Document Server25/12/202517/6/2026
ONLYOFFICE Docs before 9.2.1 allows XSS via the Font field for the Multilevel list settings window. This is related to DocumentServer.
AplazadaBaja (2.7)0.24%—BEN Balter WP Document RevisionsAI24/12/202517/6/2026
Missing Authorization vulnerability in Ben Balter WP Document Revisions wp-document-revisions allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Document Revisions: from n/a through <= 3.7.2.
AplazadaMedia (5.3)0.27%—F70 Lead Document DownloadAI20/12/20251/10/2026
The F70 Lead Document Download plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'file_download' function in all versions up to, and including, 1.4.4. This makes it possible for unauthenticated attackers to download any file from the WordPress media library by…
AplazadaMedia (6.4)0.26%—Awsm Embed ANY DocumentAI18/12/202517/6/2026
The Embed Any Document – Embed PDF, Word, PowerPoint and Excel Files plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the sanitize_pdf_src function regex bypass in all versions up to, and including, 2.7.10 due to insufficient input sanitization and output escaping. This makes it possible for…
AplazadaMedia (5.9)0.21%—Barn2 Plugins Document Library LiteAI16/12/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Barn2 Plugins Document Library Lite document-library-lite allows DOM-Based XSS.This issue affects Document Library Lite: from n/a through <= 1.1.7.
AplazadaMedia (5.3)0.30%—Barn2 Plugins Document Library LiteAI16/12/202517/6/2026
Authorization Bypass Through User-Controlled Key vulnerability in Barn2 Plugins Document Library Lite document-library-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Document Library Lite: from n/a through <= 1.1.7.
AnalizadaMedia (6.5)0.57%—Uniteddevelopers Document Reader\10/12/202517/6/2026
A lack of security checks in the file import process of AB TECHNOLOGY Document Reader: PDF, DOC, PPT v65.0 allows attackers to execute a directory traversal.
AplazadaMedia (5.3)0.28%—Nixos OnlyofficeAIOnlyoffice Document ServerAI17/11/202517/6/2026
NixOS's Onlyoffice is a software suite that offers online and offline tools for document editing, collaboration, and management. In versions from 22.11 to before 25.05 and versions before Unstable 25.11, a hard-coded secret was used in the NixOS module for the OnlyOffice document server to protect its file cache. An…
AplazadaMedia (5.3)0.37%—Document PRO ElementorAI11/11/202517/6/2026
The Document Pro Elementor – Documentation & Knowledge Base plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.0.9. This is due to the plugin exposing sensitive Algolia API keys through the frontend JavaScript code via wp_localize_script without proper access…
AplazadaAlta (8.6)0.31%—Bplugins Document EmbedderAI5/11/202517/6/2026
The Document Embedder – Embed PDFs, Word, Excel, and Other Files plugin for WordPress is vulnerable to unauthorized access/modification/loss of data in all versions up to, and including, 2.0.0. This is due to the plugin not properly verifying that a user is authorized to perform an action in the…
AplazadaMedia (5.3)0.37%—Document Library LiteAI1/11/202517/6/2026
The Document Library Lite plugin for WordPress is vulnerable to Improper Authorization in all versions up to, and including, 1.1.6. This is due to the plugin exposing an unauthenticated AJAX action dll_load_posts which returns a JSON table of document data without performing nonce or capability checks. The handler…
RechazadaSin puntuar——Wazuh-documentationAI28/10/202519/12/2025
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as the behavior originates from a documentation-published Active Response example script. Please refer to this advisory ( https://github.com/wazuh/wazuh-documentation/security/advisories/GHSA-46r5-xp98-fpgg ) for further…
AplazadaCrítica (9.3)1.0%—Excellent Infotek Document Management SystemAI20/10/202517/6/2026
Document Management System developed by Excellent Infotek has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.
AplazadaMedia (6.5)0.20%—Awsm Embed ANY DocumentAI26/9/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in awsm.in Embed Any Document embed-any-document allows Stored XSS.This issue affects Embed Any Document: from n/a through <= 2.7.7.
AplazadaMedia (5.3)0.36%—Min-documentAI24/9/202517/6/2026
A vulnerability exists in the 'min-document' package prior to version 2.19.0, stemming from improper handling of namespace operations in the removeAttributeNS method. By processing malicious input involving the __proto__ property, an attacker can manipulate the prototype chain of JavaScript objects, leading to denial…
AplazadaBaja (2.1)0.42%—JSC R7 Office Document ServerAI22/9/202517/6/2026
A flaw has been found in JSC R7 R7-Office Document Server up to 20250820. Impacted is an unknown function of the file /downloadas/. Executing manipulation of the argument cmd can lead to path traversal. The attack can be launched remotely. Upgrading to version 2025.3.1.923 is recommended to address this issue. The…
AplazadaMedia (6.4)0.13%—Bimser Solution Software Trade EBA Document AND Workflow Management SystemAI19/9/202517/6/2026
Authorization Bypass Through User-Controlled Key, Improper Authorization vulnerability in Bimser Solution Software Trade Inc. EBA Document and Workflow Management System allows Forceful Browsing. This issue affects eBA Document and Workflow Management System: from 6.7.164 before 6.7.166.
ModificadaMedia (5.4)0.17%—Fabian Document Management System16/9/20255/7/2026
code-projects Document Management System 1.0 has a Cross Site Scripting (XSS) vulnerability, where attackers can leak admin's cookie information by entering malicious XSS code in the Company field when adding files.
AplazadaBaja (3.4)0.14%—SAP Netweaver AS JavaAIAdobe Document ServiceAIOpensslAI9/9/202517/6/2026
SAP NetWeaver AS Java application uses Adobe Document Service, installed with a vulnerable version of OpenSSL.Successful exploitation of known vulnerabilities in the outdated OpenSSL library would allow user with high system privileges to access and modify system information.This vulnerability has a low impact on…
AplazadaMedia (6.5)0.17%—Matrixaddons Document EngineAI3/9/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MatrixAddons Document Engine document-engine allows Stored XSS.This issue affects Document Engine: from n/a through <= 1.2.
AplazadaMedia (6.1)0.26%—SAP Netweaver Application Server AbapAISAP BIC DocumentAI12/8/202517/6/2026
SAP NetWeaver Application Server ABAP (BIC Document) allows an unauthenticated attacker to craft a URL link which, when accessed on the BIC Document application, embeds a malicious script. When a victim clicks on this link, the script executes in the victim's browser, allowing the attacker to access and/or modify…
AplazadaCrítica (9.3)0.71%—2100 Technology Official Document Management SystemAI11/8/202517/6/2026
Official Document Management System developed by 2100 Technology has an Authentication Bypass vulnerability, allowing unauthenticated remote attackers to obtain any user's connection token and use it to log into the system as that user.