Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
193 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.19% | — | Lemmentwickler Epaper Lister FOR YumpuAI | 9/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in lemmentwickler ePaper Lister for Yumpu magazine-lister-for-yumpu allows Stored XSS.This issue affects ePaper Lister for Yumpu: from n/a through <= 1.4.0. | |
| Aplazada | Media (5.4) | 0.33% | — | Bpiwowar PaperciteAI | 27/1/2025 | 17/6/2026 | Missing Authorization vulnerability in bpiwowar PAPERCITE papercite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PAPERCITE: from n/a through <= 0.5.18. | |
| Aplazada | Media (6.4) | 0.34% | — | Yumpu E Paper PublishingAI | 9/1/2025 | 17/6/2026 | The Yumpu E-Paper publishing plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'YUMPU' shortcode in all versions up to, and including, 3.0.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (6.4) | 0.34% | — | Graphpaperpress Sell MediaAI | 7/1/2025 | 17/6/2026 | The Sell Media plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sell_media_search_form_gutenberg' shortcode in all versions up to, and including, 2.5.8.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Aplazada | Media (6.3) | 0.46% | — | Dotonpaper Pinpoint Booking SystemAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in DOTonPAPER Pinpoint Booking System booking-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Pinpoint Booking System: from n/a through <= 2.9.9.5.7. | |
| Analizada | Media (6.3) | 0.23% | — | Papercut MFPapercut NG | 10/12/2024 | 17/6/2026 | A reflected cross-site scripting (XSS) vulnerability exists in PaperCut NG/MF. This issue can be used to execute specially created JavaScript payloads in the browser. A user must click on a malicious link for this issue to occur. | |
| Aplazada | Alta (8.5) | 0.52% | — | Dotonpaper Pinpoint Booking SystemAI | 6/12/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in DOTonPAPER Pinpoint Booking System booking-system allows Blind SQL Injection.This issue affects Pinpoint Booking System: from n/a through <= 2.9.9.5.1. | |
| Analizada | Alta (7.2) | 1.8% | — | Papercut NG | 22/11/2024 | 17/6/2026 | PaperCut NG print.script.sandboxed Exposed Dangerous Function Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PaperCut NG. Authentication is required to exploit this vulnerability. The specific flaw exists within the management of… | |
| Aplazada | Crítica (9) | 0.68% | — | Decidim AwesomeAIPapertrailAI | 12/11/2024 | 17/6/2026 | An improper neutralization of special elements used in an SQL command in the papertrail/version- model of the decidim_awesome-module <= v0.11.1 (> 0.9.0) allows an authenticated admin user to manipulate sql queries to disclose information, read and write files or execute commands. | |
| Aplazada | Media (5.4) | 0.18% | — | Dotonpaper Pinpoint Booking SystemAI | 17/10/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in DOTonPAPER Pinpoint Booking System booking-system allows Stored XSS.This issue affects Pinpoint Booking System: from n/a through <= 2.9.9.5.7. | |
| Analizada | Media (5.5) | 0.24% | — | Papercut MFPapercut NG | 26/9/2024 | 17/6/2026 | An arbitrary file creation vulnerability exists in PaperCut NG/MF that only affects Windows servers with Web Print enabled. This specific flaw exists within the web-print.exe process, which can incorrectly create files that don’t exist when a maliciously formed payload is provided. This can be used to flood disk space… | |
| Modificada | Alta (7.8) | 0.39% | — | Papercut MFPapercut NG | 26/9/2024 | 17/6/2026 | An arbitrary file deletion vulnerability exists in PaperCut NG/MF, specifically affecting Windows servers with Web Print enabled. To exploit this vulnerability, an attacker must first obtain local login access to the Windows Server hosting PaperCut NG/MF and be capable of executing low-privilege code directly on the… | |
| Analizada | Crítica (9.3) | 0.48% | — | Hamastar Meetinghub Paperless Meetings | 5/8/2024 | 17/6/2026 | A Plaintext Storage of a Password vulnerability in ebooknote function in Hamastar MeetingHub Paperless Meetings 2021 allows remote attackers to obtain the other users’ credentials and gain access to the product via an XML file. | |
| Analizada | Crítica (9.3) | 0.52% | — | Hamastar Meetinghub Paperless Meetings | 5/8/2024 | 17/6/2026 | A Unrestricted upload of file with dangerous type vulnerability in meeting management function in Hamastar MeetingHub Paperless Meetings 2021 allows remote authenticated users to perform arbitrary system commands via a crafted ASP file. | |
| Modificada | Alta (8.8) | 0.21% | — | Blazethemes Digital Newspaper | 21/6/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in blazethemes Digital Newspaper.This issue affects Digital Newspaper: from n/a through 1.1.5. | |
| Modificada | Media (5.4) | 0.32% | — | Dotonpaper DOT ON Paper Shortcodes | 21/6/2024 | 17/6/2026 | The DOP Shortcodes WordPress plugin through 1.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks | |
| Modificada | Media (4.8) | 0.28% | — | Tagdiv Newspaper | 15/6/2024 | 17/6/2026 | The Newspaper theme for WordPress is vulnerable to Stored Cross-Site Scripting via attachment meta in the archive page in all versions up to, and including, 12.6.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (6.2) | 0.17% | — | Samsung Live Wallpaper PCAI | 4/6/2024 | 17/6/2026 | Arbitrary directory creation in Samsung Live Wallpaper PC prior to version 3.3.8.0 allows attacker to create arbitrary directory. | |
| Aplazada | Media (5) | 0.32% | — | Yumpu EpaperAI | 30/5/2024 | 17/6/2026 | The Yumpu ePaper publishing plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_handler function in all versions up to, and including, 2.0.24. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload PDF… | |
| Aplazada | Media (5.5) | 0.49% | — | Paperless-ngxAI | 15/5/2024 | 17/6/2026 | Paperless-ngx is a document management system that transforms physical documents into a searchable online archive. Starting in version 2.5.0 and prior to version 2.8.6, remote user authentication allows API access even if API access is explicitly disabled. Version 2.8.6 contains a patchc for the issue. | |
| Analizada | Alta (7.8) | 0.41% | — | Papercut MFPapercut NG | 14/5/2024 | 17/6/2026 | An arbitrary file creation vulnerability exists in PaperCut NG/MF that only affects Windows servers with Web Print enabled. This specific flaw exists within the image-handler process, which can incorrectly create files that don’t exist when a maliciously formed payload is provided. This can lead to local privilege… | |
| Analizada | Alta (7.8) | 0.40% | — | Papercut MFPapercut NG | 14/5/2024 | 17/6/2026 | An arbitrary file deletion vulnerability exists in PaperCut NG/MF, specifically affecting Windows servers with Web Print enabled. To exploit this vulnerability, an attacker must first obtain local login access to the Windows Server hosting PaperCut NG/MF and be capable of executing low-privilege code directly on the… | |
| Analizada | Alta (7.2) | 61% | — | Papercut MFPapercut NG | 3/5/2024 | 17/6/2026 | PaperCut NG External User Lookup Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PaperCut NG. Authentication is required to exploit this vulnerability. The specific flaw exists within the External User Lookup… | |
| Aplazada | Alta (7.8) | 0.37% | — | Flowpaper Pdf2jsonAI | 22/4/2024 | 9/7/2026 | A buffer overflow vulnerability in pdf2json v0.70 allows a local attacker to execute arbitrary code via the GString::copy() and ImgOutputDev::ImgOutputDev function. | |
| Analizada | Media (6.5) | 38% | — | Papercut MFPapercut NG | 14/3/2024 | 17/6/2026 | This is a Server-Side Request Forgery (SSRF) vulnerability in the PaperCut NG/MF server-side module that allows an attacker to induce the server-side application to make HTTP requests to an arbitrary domain of the attacker's choosing. |