Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2597▼ 310 respecto a la semana anterior
Críticas / altas1338▲ 74 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 463 respecto a la semana anterior
369 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.7) | 0.23% | — | Viafirma DocumentsViafirma Documents Compose | 12/1/2026 | 17/6/2026 | Weaknesses in the authorization mechanisms of Viafirma Documents v3.7.129 allow an authenticated user without privileges to list and access other user data, use user creation, modification, and deletion features, and escalate privileges by impersonating other users of the application in the generation and signing of… | |
| Aplazada | Media (6.5) | 0.17% | — | Basepress Knowledge Base Documentation & Wiki PluginAI | 31/12/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BasePress Knowledge Base documentation & wiki plugin – BasePress basepress allows Stored XSS.This issue affects Knowledge Base documentation & wiki plugin – BasePress: from n/a through <= 2.17.0.1. | |
| Analizada | Media (6.1) | 0.20% | — | Onlyoffice Document Server | 25/12/2025 | 17/6/2026 | ONLYOFFICE Docs before 9.2.1 allows XSS via the Color theme name. This is related to DocumentServer. | |
| Analizada | Media (6.1) | 0.20% | — | Onlyoffice Document Server | 25/12/2025 | 17/6/2026 | ONLYOFFICE Docs before 9.2.1 allows XSS via the Font field for the Multilevel list settings window. This is related to DocumentServer. | |
| Aplazada | Baja (2.7) | 0.24% | — | BEN Balter WP Document RevisionsAI | 24/12/2025 | 17/6/2026 | Missing Authorization vulnerability in Ben Balter WP Document Revisions wp-document-revisions allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Document Revisions: from n/a through <= 3.7.2. | |
| Aplazada | Media (5.3) | 0.27% | — | F70 Lead Document DownloadAI | 20/12/2025 | 1/10/2026 | The F70 Lead Document Download plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'file_download' function in all versions up to, and including, 1.4.4. This makes it possible for unauthenticated attackers to download any file from the WordPress media library by… | |
| Aplazada | Media (6.4) | 0.26% | — | Awsm Embed ANY DocumentAI | 18/12/2025 | 17/6/2026 | The Embed Any Document – Embed PDF, Word, PowerPoint and Excel Files plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the sanitize_pdf_src function regex bypass in all versions up to, and including, 2.7.10 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Aplazada | Media (5.9) | 0.21% | — | Barn2 Plugins Document Library LiteAI | 16/12/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Barn2 Plugins Document Library Lite document-library-lite allows DOM-Based XSS.This issue affects Document Library Lite: from n/a through <= 1.1.7. | |
| Aplazada | Media (5.3) | 0.30% | — | Barn2 Plugins Document Library LiteAI | 16/12/2025 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Barn2 Plugins Document Library Lite document-library-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Document Library Lite: from n/a through <= 1.1.7. | |
| Analizada | Media (6.5) | 0.57% | — | Uniteddevelopers Document Reader\ | 10/12/2025 | 17/6/2026 | A lack of security checks in the file import process of AB TECHNOLOGY Document Reader: PDF, DOC, PPT v65.0 allows attackers to execute a directory traversal. | |
| Aplazada | Media (5.3) | 0.28% | — | Nixos OnlyofficeAIOnlyoffice Document ServerAI | 17/11/2025 | 17/6/2026 | NixOS's Onlyoffice is a software suite that offers online and offline tools for document editing, collaboration, and management. In versions from 22.11 to before 25.05 and versions before Unstable 25.11, a hard-coded secret was used in the NixOS module for the OnlyOffice document server to protect its file cache. An… | |
| Aplazada | Media (5.3) | 0.37% | — | Document PRO ElementorAI | 11/11/2025 | 17/6/2026 | The Document Pro Elementor – Documentation & Knowledge Base plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.0.9. This is due to the plugin exposing sensitive Algolia API keys through the frontend JavaScript code via wp_localize_script without proper access… | |
| Aplazada | Alta (8.6) | 0.31% | — | Bplugins Document EmbedderAI | 5/11/2025 | 17/6/2026 | The Document Embedder – Embed PDFs, Word, Excel, and Other Files plugin for WordPress is vulnerable to unauthorized access/modification/loss of data in all versions up to, and including, 2.0.0. This is due to the plugin not properly verifying that a user is authorized to perform an action in the… | |
| Aplazada | Media (5.3) | 0.37% | — | Document Library LiteAI | 1/11/2025 | 17/6/2026 | The Document Library Lite plugin for WordPress is vulnerable to Improper Authorization in all versions up to, and including, 1.1.6. This is due to the plugin exposing an unauthenticated AJAX action dll_load_posts which returns a JSON table of document data without performing nonce or capability checks. The handler… | |
| Rechazada | Sin puntuar | — | — | Wazuh-documentationAI | 28/10/2025 | 19/12/2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as the behavior originates from a documentation-published Active Response example script. Please refer to this advisory ( https://github.com/wazuh/wazuh-documentation/security/advisories/GHSA-46r5-xp98-fpgg ) for further… | |
| Aplazada | Crítica (9.3) | 1.0% | — | Excellent Infotek Document Management SystemAI | 20/10/2025 | 17/6/2026 | Document Management System developed by Excellent Infotek has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server. | |
| Aplazada | Media (6.5) | 0.20% | — | Awsm Embed ANY DocumentAI | 26/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in awsm.in Embed Any Document embed-any-document allows Stored XSS.This issue affects Embed Any Document: from n/a through <= 2.7.7. | |
| Aplazada | Media (5.3) | 0.36% | — | Min-documentAI | 24/9/2025 | 17/6/2026 | A vulnerability exists in the 'min-document' package prior to version 2.19.0, stemming from improper handling of namespace operations in the removeAttributeNS method. By processing malicious input involving the __proto__ property, an attacker can manipulate the prototype chain of JavaScript objects, leading to denial… | |
| Aplazada | Baja (2.1) | 0.42% | — | JSC R7 Office Document ServerAI | 22/9/2025 | 17/6/2026 | A flaw has been found in JSC R7 R7-Office Document Server up to 20250820. Impacted is an unknown function of the file /downloadas/. Executing manipulation of the argument cmd can lead to path traversal. The attack can be launched remotely. Upgrading to version 2025.3.1.923 is recommended to address this issue. The… | |
| Aplazada | Media (6.4) | 0.13% | — | Bimser Solution Software Trade EBA Document AND Workflow Management SystemAI | 19/9/2025 | 17/6/2026 | Authorization Bypass Through User-Controlled Key, Improper Authorization vulnerability in Bimser Solution Software Trade Inc. EBA Document and Workflow Management System allows Forceful Browsing. This issue affects eBA Document and Workflow Management System: from 6.7.164 before 6.7.166. | |
| Modificada | Media (5.4) | 0.17% | — | Fabian Document Management System | 16/9/2025 | 5/7/2026 | code-projects Document Management System 1.0 has a Cross Site Scripting (XSS) vulnerability, where attackers can leak admin's cookie information by entering malicious XSS code in the Company field when adding files. | |
| Aplazada | Baja (3.4) | 0.14% | — | SAP Netweaver AS JavaAIAdobe Document ServiceAIOpensslAI | 9/9/2025 | 17/6/2026 | SAP NetWeaver AS Java application uses Adobe Document Service, installed with a vulnerable version of OpenSSL.Successful exploitation of known vulnerabilities in the outdated OpenSSL library would allow user with high system privileges to access and modify system information.This vulnerability has a low impact on… | |
| Aplazada | Media (6.5) | 0.17% | — | Matrixaddons Document EngineAI | 3/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MatrixAddons Document Engine document-engine allows Stored XSS.This issue affects Document Engine: from n/a through <= 1.2. | |
| Aplazada | Media (6.1) | 0.26% | — | SAP Netweaver Application Server AbapAISAP BIC DocumentAI | 12/8/2025 | 17/6/2026 | SAP NetWeaver Application Server ABAP (BIC Document) allows an unauthenticated attacker to craft a URL link which, when accessed on the BIC Document application, embeds a malicious script. When a victim clicks on this link, the script executes in the victim's browser, allowing the attacker to access and/or modify… | |
| Aplazada | Crítica (9.3) | 0.71% | — | 2100 Technology Official Document Management SystemAI | 11/8/2025 | 17/6/2026 | Official Document Management System developed by 2100 Technology has an Authentication Bypass vulnerability, allowing unauthenticated remote attackers to obtain any user's connection token and use it to log into the system as that user. |