Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

82 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)0.53%—Seeddms3/8/202117/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in the /op/op.Ajax.php in SeedDMS v5.1.x<5.1.23 and v6.0.x<6.0.16 allows a remote attacker to edit document name without victim's knowledge, by enticing an authenticated user to visit an attacker's web page.
ModificadaAlta (7.8)0.47%—Pleaseedit Project Pleaseedit27/5/202117/6/2026
pleaseedit in please before 0.4 uses predictable temporary filenames in /tmp and the target directory. This allows a local attacker to gain full root privileges by staging a symlink attack.
ModificadaMedia (4.3)0.49%—Seeddms18/3/20219/7/2026
SeedDMS 5.1.x is affected by cross-site request forgery (CSRF) in out.EditFolder.php.
ModificadaMedia (4.3)0.49%—Seeddms18/3/20219/7/2026
SeedDMS 5.1.x is affected by cross-site request forgery (CSRF) in out.EditDocument.php.
ModificadaMedia (6.1)0.70%—Seeddms7/12/20209/7/2026
Cross-site scripting (XSS) exists in SeedDMS 6.0.13 via the folderid parameter to views/bootstrap/class.DropFolderChooser.php.
ModificadaMedia (6.1)0.65%—Seeddms24/11/202017/6/2026
Open redirect in SeedDMS 6.0.13 via the dropfolderfileform1 parameter to out/out.AddDocument.php.
ModificadaMedia (5.4)3.8%💥 ExploitSeedprod Coming Soon Page, Under Construction & Maintenance Mode24/6/202017/6/2026
The SeedProd coming-soon plugin before 5.1.1 for WordPress allows XSS.
ModificadaAlta (7.5)2.4%—Wpseeds WP Database Backup20/1/202017/6/2026
The WP Database Backup plugin through 5.5 for WordPress stores downloads by default locally in the directory wp-content/uploads/db-backup/. This might allow attackers to read ZIP archives by guessing random ID numbers, guessing date strings with a 2020_{0..1}{0..2}_{0..3}{0..9} format, guessing UNIX timestamps, and…
ModificadaMedia (6.1)0.95%—Wpseeds WP Database Backup12/8/201917/6/2026
The wp-database-backup plugin before 5.1.2 for WordPress has XSS.
ModificadaAlta (8.8)0.69%—Wpseeds WP Database Backup12/8/201917/6/2026
The wp-database-backup plugin before 4.3.1 for WordPress has CSRF.
ModificadaMedia (6.1)0.92%—Wpseeds WP Database Backup12/8/201917/6/2026
The wp-database-backup plugin before 4.3.1 for WordPress has XSS.
ModificadaAlta (8.8)0.68%—Wpseeds WP Database Backup12/8/201917/6/2026
The wp-database-backup plugin before 4.3.3 for WordPress has CSRF.
ModificadaMedia (6.1)0.92%—Wpseeds WP Database Backup12/8/201917/6/2026
The wp-database-backup plugin before 4.3.3 for WordPress has XSS.
ModificadaMedia (6.1)0.80%—Seeddms28/6/201917/6/2026
A stored XSS vulnerability was found in SeedDMS 5.1.11 due to poorly escaping the search result in the autocomplete search form placed in the header of out/out.Viewfolder.php.
ModificadaMedia (5.4)2.6%💥 ExploitSeeddms20/6/201917/6/2026
out/out.UsrMgr.php in SeedDMS before 5.1.11 allows Stored Cross-Site Scripting (XSS) via the name field.
ModificadaAlta (7.5)12%💥 ExploitSeeddms20/6/201917/6/2026
SeedDMS before 5.1.11 allows Remote Command Execution (RCE) because of unvalidated file upload of PHP scripts, a different vulnerability than CVE-2018-12940.
ModificadaMedia (6.1)1.9%💥 ExploitSeeddms17/6/201917/6/2026
out/out.GroupMgr.php in SeedDMS 5.1.11 has Stored XSS by making a new group with a JavaScript payload as the "GROUP" Name.
ModificadaMedia (6.1)1.1%—Seeddms31/7/201817/6/2026
Persistent Cross-Site Scripting (XSS) vulnerability in the "Categories" feature in SeedDMS (formerly LetoDMS and MyDMS) before 5.1.8 allows remote attackers to inject arbitrary web script or HTML via the name field.
ModificadaMedia (6.1)1.1%—Seeddms31/7/201817/6/2026
Cross-Site Scripting (XSS) vulnerability in every page that includes the "action" URL parameter in SeedDMS (formerly LetoDMS and MyDMS) before 5.1.8 allows remote attackers to inject arbitrary web script or HTML via the action parameter.
ModificadaAlta (8.8)1.5%—Seeddms31/7/201817/6/2026
SQL injection vulnerability in the "Users management" functionality in SeedDMS (formerly LetoDMS and MyDMS) before 5.1.8 allows authenticated attackers to manipulate an SQL query within the application by sending additional SQL commands to the application server. An attacker can use this vulnerability to perform…
ModificadaAlta (8.8)3.6%—Seeddms31/7/201817/6/2026
This vulnerability allows remote attackers to execute arbitrary code in SeedDMS (formerly LetoDMS and MyDMS) before 5.1.8 by adding a system command at the end of the "cacheDir" path and following usage of the "Clear Cache" functionality. This allows an authenticated attacker, with permission to the Settings…
ModificadaAlta (8.8)2.5%—Seeddms31/7/201817/6/2026
Unrestricted file upload vulnerability in "op/op.UploadChunks.php" in SeedDMS (formerly LetoDMS and MyDMS) before 5.1.8 allows remote attackers to execute arbitrary code by uploading a file with an executable extension specified by the "qqfile" parameter. This allows an authenticated attacker to upload a malicious…
ModificadaMedia (6.5)2.0%—Seeddms31/7/201817/6/2026
A directory traversal flaw in SeedDMS (formerly LetoDMS and MyDMS) before 5.1.8 allows an authenticated attacker to write to (or potentially delete) arbitrary files via a .. (dot dot) in the "op/op.UploadChunks.php" "qquuid" parameter. NOTE: this can be leveraged to execute arbitrary code by using CVE-2018-12940.
ModificadaMedia (5.9)1.3%—Reseed Project Reseed23/10/201716/6/2026
reseed seeds random numbers from an insecure HTTP request to random.org during installation, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via a man-in-the-middle attack.
ModificadaCrítica (9.1)2.4%—Seeds Acmailer16/1/201617/6/2026
Seeds acmailer before 3.8.21 and 3.9.x before 3.9.15 Beta allows remote authenticated users to execute arbitrary OS commands via unspecified vectors.
Orbitaley — Vulnerabilidades