Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2598▼ 321 respecto a la semana anterior
Críticas / altas1342▲ 74 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 465 respecto a la semana anterior
–

369 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaBaja (2.1)0.50%—Fabian Document Management System1/8/202517/6/2026
A vulnerability was found in code-projects Document Management System 1.0 and classified as critical. This issue affects the function unlink of the file /dell.php. The manipulation of the argument ID leads to path traversal. The attack may be initiated remotely. The exploit has been disclosed to the public and may be…
AplazadaCrítica (9.2)1.8%—Simple E-documentAI31/7/202517/6/2026
An unrestricted file upload vulnerability exists in Simple E-Document versions 3.0 to 3.1 that allows an unauthenticated attacker to bypass authentication by sending a specific cookie header (access=3) with HTTP requests. The application’s upload mechanism fails to restrict file types and does not validate or sanitize…
AnalizadaBaja (2.1)0.36%—Fabian Document Management System25/7/202517/6/2026
A vulnerability, which was classified as critical, has been found in code-projects Document Management System 1.0. This issue affects some unknown processing of the file /insert.php. The manipulation of the argument uploaded_file leads to unrestricted upload. The attack may be initiated remotely. The exploit has been…
AplazadaAlta (8.6)0.29%—Digitware System Integration Corporation Cross-browser Document Creation ComponentAI14/7/202517/6/2026
The cross-browser document creation component produced by Digitware System Integration Corporation has a Remote Code Execution vulnerability. If a user visits a malicious website while the component is active, remote attackers can cause the system to download and execute arbitrary programs.
AplazadaAlta (7.1)0.28%—Reifsnyderb Document Management SystemAI23/5/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in reifsnyderb Document Management System dms allows Reflected XSS.This issue affects Document Management System: from n/a through <= 1.24.
AnalizadaCrítica (9.8)1.2%—Microsoft Azure AI Document Intelligence Studio13/5/202517/6/2026
Improper limitation of a pathname to a restricted directory ('path traversal') in Azure allows an unauthorized attacker to elevate privileges over a network.
AplazadaAlta (7.1)0.29%—Poppinsdigital Wpyog DocumentsAI17/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PoppinsDigital.com WPYog Documents wpyog-documents allows Reflected XSS.This issue affects WPYog Documents: from n/a through <= 1.3.5.
AnalizadaMedia (6.7)0.52%—Onlyoffice Document Server1/4/202517/6/2026
Path Traversal vulnerability in ONLYOFFICE Document Server before v8.0.1 allows a remote attacker to copy arbitrary files by manipulating the fileExt parameter in the /example/editor endpoint, leading to unauthorized access to sensitive files and potential Denial of Service (DoS).
AplazadaMedia (6.4)0.30%—Awsm Embed ANY DocumentAI20/2/202517/6/2026
The Embed Any Document – Embed PDF, Word, PowerPoint and Excel Files plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.7.5 via the 'embeddoc' shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to make web…
AplazadaAlta (7.1)0.15%—Mathieuhays Simple DocumentationAI13/2/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in mathieuhays Simple Documentation client-documentation allows Stored XSS.This issue affects Simple Documentation: from n/a through <= 1.2.8.
AnalizadaMedia (6.5)0.38%—Progress Telerik Document Processing Libraries12/2/202517/6/2026
In Progress® Telerik® Document Processing Libraries, versions prior to 2025 Q1 (2025.1.205), using .NET Standard 2.0, the contents of a file at an arbitrary path can be exported to RTF.
AnalizadaAlta (8.8)0.67%—Progress Telerik Document Processing Libraries12/2/202517/6/2026
In Progress® Telerik® Document Processing Libraries, versions prior to 2025 Q1 (2025.1.205), unzipping an archive can lead to arbitrary file system access.
AplazadaMedia (5.4)0.29%—Wpdeveloper Document Block Upload Embed DocsAI4/2/202517/6/2026
Missing Authorization vulnerability in WPDeveloper Document Block – Upload & Embed Docs document.This issue affects Document Block – Upload & Embed Docs: from n/a through <= 1.1.0.
AplazadaCrítica (9.8)1.3%—2100 Technology Electronic Official Document Management SystemAI31/12/202417/6/2026
The Electronic Official Document Management System from 2100 Technology has an Authentication Bypass vulnerability. Although the product enforces an IP whitelist for the API used to query user tokens, unauthenticated remote attackers can still deceive the server to obtain tokens of arbitrary users, which can then be…
AplazadaMedia (5.4)0.22%—Diversified Technology Corp DTC DocumentsAI16/12/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Diversified Technology Corp. DTC Documents dtc-documents allows Cross Site Request Forgery.This issue affects DTC Documents: from n/a through <= 1.1.05.
AplazadaAlta (7.1)0.44%—Chuhpl Board Document ManagerAI13/12/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cleveland Heights-University Heights Public Library Webdeveloper Board Document Manager from CHUHPL board-document-manager-from-chuhpl allows Reflected XSS.This issue affects Board Document Manager from CHUHPL: from…
AplazadaCrítica (9.1)0.89%—Adobe Document ServiceAI10/12/202417/6/2026
Adobe Document Service allows an attacker with administrator privileges to send a crafted request from a vulnerable web application. It is usually used to target internal systems behind firewalls that are normally inaccessible to an attacker from the external network, resulting in a Server-Side Request Forgery…
AplazadaAlta (7.1)0.17%—Docxpresso Document Data AutomationAI2/12/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in docxpresso Document & Data Automation document-data-automation allows Stored XSS.This issue affects Document & Data Automation: from n/a through <= 1.6.1.
AplazadaMedia (6.5)0.30%—Joan Boluda Embed Documents ShortcodeAI19/11/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Joan Boluda Embed documents shortcode embed-documents-shortcode allows Stored XSS.This issue affects Embed documents shortcode: from n/a through <= 1.5.
AnalizadaMedia (6.5)0.43%—Progress Telerik Document Processing Libraries13/11/202417/6/2026
In Progress Telerik Document Processing Libraries, versions prior to 2024 Q4 (2024.4.1106), importing a document with unsupported features can lead to excessive processing, leading to excessive use of computing resources leaving the application process unavailable.
ModificadaMedia (6.1)0.29%—Abdullahirfan Documentpress29/10/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in fifthsegment DocumentPress documentpress-display-any-document-on-your-site allows Reflected XSS.This issue affects DocumentPress: from n/a through <= 2.1.
AnalizadaMedia (6.1)0.61%—Onlyoffice Document Server9/9/202417/6/2026
ONLYOFFICE Docs before 8.0.1 allows XSS because a macro is an immediately-invoked function expression (IIFE), and therefore a sandbox escape is possible by directly calling the constructor of the Function object. NOTE: this issue exists because of an incorrect fix for CVE-2021-43446.
AnalizadaMedia (5.3)0.26%—SAP Document Builder13/8/202417/6/2026
SAP Document Builder does not perform necessary authorization checks for one of the function modules resulting in escalation of privileges causing low impact on confidentiality of the application.
AplazadaAlta (7.1)0.15%—Opentext Documentum ServerAI30/7/202417/6/2026
Unprotected Transport of Credentials vulnerability in OpenText™ Documentum™ Server could allow Credential Stuffing.This issue affects Documentum™ Server: from 16.7 through 23.4.
ModificadaMedia (5.3)0.52%—Document Management System Project Document Management System17/7/202417/6/2026
A vulnerability has been found in itsourcecode Document Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file insert.php. The manipulation of the argument anothercont leads to sql injection. The attack can be launched remotely. The exploit has been…