Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3017▼ 66 respecto a la semana anterior
Críticas / altas1412▲ 56 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)381▼ 129 respecto a la semana anterior
163 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.1) | 0.38% | — | Boonebgorges Buddypress DocsAI | 8/10/2024 | 17/6/2026 | The BuddyPress Docs plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.2.3. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if… | |
| Analizada | Media (5.3) | 0.53% | — | Qdocs Smart School | 13/9/2024 | 17/6/2026 | A vulnerability classified as critical was found in QDocs Smart School Management System 7.0.0. Affected by this vulnerability is an unknown functionality of the file /user/chat/mynewuser of the component Chat. The manipulation of the argument users[] with the input… | |
| Analizada | Alta (8.8) | 0.57% | — | Wpdeveloper Betterdocs | 13/8/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WPDeveloper BetterDocs allows PHP Local File Inclusion.This issue affects BetterDocs: from n/a through 3.5.8. | |
| Analizada | Media (5.4) | 0.26% | — | Wpdeveloper Betterdocs | 12/8/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPDeveloper BetterDocs allows Stored XSS.This issue affects BetterDocs: from n/a through 3.5.8. | |
| Modificada | Media (5.5) | 0.46% | — | Ivanti Docs@work | 7/8/2024 | 17/6/2026 | Ivanti Docs@Work for Android, before 2.26.0 is affected by the 'Dirty Stream' vulnerability. The application fails to properly sanitize file names, resulting in a path traversal-affiliated vulnerability. This potentially enables other malicious apps on the device to read sensitive information stored in the app root. | |
| Aplazada | Media (6.5) | 0.26% | — | Spider-themes EazydocsAI | 20/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in EazyDocs eazydocs allows Stored XSS.This issue affects EazyDocs: from n/a through 2.5.0. | |
| Modificada | Media (4.8) | 0.40% | — | Spider-themes Eazydocs | 2/7/2024 | 17/6/2026 | The EazyDocs WordPress plugin before 2.5.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Aplazada | Media (5.3) | 0.37% | — | Wedevs WedocsAI | 11/6/2024 | 17/6/2026 | Missing Authorization vulnerability in weDevs weDocs.This issue affects weDocs: from n/a through 2.1.4. | |
| Analizada | Media (6.1) | 0.33% | — | Androidbubble WP Docs | 8/6/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Fahad Mahmood WP Docs allows Reflected XSS.This issue affects WP Docs: from n/a through 2.1.3. | |
| Modificada | Media (5.4) | 0.28% | — | Fahadmahmood WP Docs | 8/6/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Fahad Mahmood WP Docs allows Stored XSS.This issue affects WP Docs: from n/a through 2.1.3. | |
| Aplazada | Media (4.4) | 0.25% | — | HCL Connections DocsAI | 8/6/2024 | 17/6/2026 | HCL Connections Docs is vulnerable to a cross-site scripting attack where an attacker may leverage this issue to execute arbitrary code. This may lead to credentials disclosure and possibly launch additional attacks. | |
| Analizada | Media (6.1) | 0.37% | — | Qdocs Smart School | 21/5/2024 | 17/6/2026 | QDOCS Smart School 7.0.0 is vulnerable to Cross Site Scripting (XSS) resulting in arbitrary code execution in admin functions related to adding or updating records. | |
| Aplazada | Media (5.3) | 0.57% | — | Arc53 DocsgptAI | 16/4/2024 | 17/6/2026 | DocsGPT is a GPT-powered chat for documentation. DocsGPT is vulnerable to unauthenticated limited file write in routes.py. This vulnerability is fixed in 0.8.1. | |
| Aplazada | Media (6.4) | 0.35% | — | Wpdeveloper BetterdocsAI | 9/4/2024 | 17/6/2026 | The BetterDocs – Best Documentation, FAQ & Knowledge Base Plugin with AI Support & Instant Answer For Elementor & Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 3.4.2 due to insufficient input sanitization and output… | |
| Modificada | Crítica (9) | 0.86% | — | Wpdeveloper Betterdocs | 28/3/2024 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in WPDeveloper BetterDocs.This issue affects BetterDocs: from n/a through 3.3.3. | |
| Modificada | Media (4.3) | 0.42% | — | Spider-themes Eazydocs | 12/2/2024 | 17/6/2026 | The EazyDocs WordPress plugin before 2.4.0 re-introduced CVE-2023-6029 (https://wpscan.com/vulnerability/7a0aaf85-8130-4fd7-8f09-f8edc929597e/) in 2.3.8, allowing any authenticated users, such as subscriber to delete arbitrary posts, as well as add and delete documents/sections. The issue was partially fixed in 2.3.9. | |
| Modificada | Alta (7.5) | 0.25% | — | Spider-themes Eazydocs | 15/1/2024 | 17/6/2026 | The EazyDocs WordPress plugin before 2.3.6 does not have authorization and CSRF checks when handling documents and does not ensure that they are documents from the plugin, allowing unauthenticated users to delete arbitrary posts, as well as add and delete documents/sections. | |
| Modificada | Media (6.1) | 0.50% | — | Gov.uk Govuk Tech Docs | 4/1/2024 | 14/7/2026 | govuk_tech_docs versions from 2.0.2 to before 3.3.1 are vulnerable to a cross-site scripting vulnerability. Malicious JavaScript may be executed in the user's browser if a malicious search result is displayed on the search page. | |
| Modificada | Alta (8.8) | 0.85% | — | Spider-themes Eazydocs | 11/12/2023 | 17/6/2026 | The EazyDocs WordPress plugin before 2.3.4 does not properly sanitize and escape "data" parameter before using it in an SQL statement via an AJAX action, which could allow any authenticated users, such as subscribers, to perform SQL Injection attacks. | |
| Modificada | Media (6.1) | 0.40% | — | Spider-themes Eazydocs | 14/11/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability on 302 response page in spider-themes EazyDocs plugin <= 2.3.3 versions. | |
| Modificada | Crítica (9.8) | 1.1% | — | Qdocs Smart School | 10/10/2023 | 17/6/2026 | A vulnerability was found in QDocs Smart School 6.4.1. It has been classified as critical. This affects an unknown part of the file /course/filterRecords/ of the component HTTP POST Request Handler. The manipulation of the argument searchdata[0][title]/searchdata[0][searchfield]/searchdata[0][searchvalue] leads to sql… | |
| Modificada | Media (6.1) | 0.38% | — | Fahad Mahmood WP Docs | 18/8/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Fahad Mahmood WP Docs plugin <= 1.9.9 versions. | |
| Modificada | Alta (7.5) | 0.80% | — | Docsys Project Docsys | 15/12/2022 | 17/6/2026 | A vulnerability has been found in RainyGao DocSys and classified as critical. Affected by this vulnerability is an unknown functionality of the component com.DocSystem.controller.UserController#getUserImg. The manipulation leads to path traversal: '../filedir'. The attack can be launched remotely. The exploit has been… | |
| Modificada | Alta (7.2) | 0.76% | — | Docsys Project Docsys | 11/12/2022 | 17/6/2026 | A vulnerability classified as critical has been found in RainyGao DocSys 2.02.37. This affects an unknown part of the component ZIP File Decompression Handler. The manipulation leads to path traversal: '../filedir'. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be… | |
| Modificada | Crítica (9.3) | 1.3% | — | Thunderatz Thunderdocs | 11/7/2022 | 17/6/2026 | The ThundeRatz/ThunderDocs repository through 2020-05-01 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. |