Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2623▼ 295 respecto a la semana anterior
Críticas / altas1347▲ 81 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 465 respecto a la semana anterior
369 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.62% | — | Electronic Official Document Management System Project Electronic Official Document Management System | 15/7/2024 | 17/6/2026 | The access control in the Electronic Official Document Management System from 2100 TECHNOLOGY is not properly implemented, allowing remote attackers with regular privileges to access the account settings functionality and create an administrator account. | |
| Aplazada | Media (5.3) | 0.44% | — | Ninjateam Filebird Document LibraryAI | 10/7/2024 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Ninja Team FileBird Document Library.This issue affects FileBird Document Library: from n/a through 2.0.6. | |
| Modificada | Media (6.5) | 0.57% | — | Smartypantsplugins SP Project & Document Manager | 9/7/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in smartypants SP Project & Document Manager.This issue affects SP Project & Document Manager: from n/a through 4.71. | |
| Modificada | Media (5.3) | 0.50% | — | Itsourcecode Document Management System Project IN PHP With Source Code | 15/6/2024 | 17/6/2026 | A vulnerability classified as critical has been found in itsourcecode Document Management System 1.0. Affected is an unknown function of the file edithis.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may… | |
| Aplazada | Alta (7.2) | 1.0% | — | Document Merge ServiceAI | 11/6/2024 | 17/6/2026 | Document Merge Service is a document template merge service providing an API to manage templates and merge them with given data. Versions 6.5.1 and prior are vulnerable to remote code execution via server-side template injection which, when executed as root, can result in full takeover of the affected system. As of… | |
| Modificada | Media (6.5) | 0.24% | — | SAP Document Builder | 11/6/2024 | 17/6/2026 | An authenticated attacker can upload malicious file to SAP Document Builder service. When the victim accesses this file, the attacker is allowed to access, modify, or make the related information unavailable in the victim’s browser. | |
| Analizada | Media (6.5) | 0.52% | — | Smartypantsplugins SP Project & Document Manager | 15/5/2024 | 17/6/2026 | The SP Project & Document Manager WordPress plugin through 4.71 lacks proper access controllers and allows a logged in user to view and download files belonging to another user | |
| Analizada | Media (6.5) | 0.43% | — | Smartypantsplugins SP Project & Document Manager | 15/5/2024 | 17/6/2026 | The SP Project & Document Manager WordPress plugin through 4.71 is missing validation in its upload function, allowing a user to manipulate the `user_id` to make it appear that a file was uploaded by another user | |
| Aplazada | Media (4.3) | 0.42% | — | SP Project Document ManagerAI | 14/5/2024 | 17/6/2026 | The SP Project & Document Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the cdm_save_category AJAX action in all versions up to, and including, 4.70. This makes it possible for authenticated attackers, with subscriber-level access and above, to… | |
| Aplazada | Media (6.3) | 0.35% | — | Smartypants SP Project AND Document ManagerAI | 3/5/2024 | 17/6/2026 | Missing Authorization vulnerability in Smartypants SP Project & Document Manager.This issue affects SP Project & Document Manager : from n/a through 4.69. | |
| Aplazada | Media (5.4) | 0.39% | — | Codesavory Knowledge Base Documentation & Wiki Plugin BasepressAI | 29/4/2024 | 17/6/2026 | Missing Authorization vulnerability in codeSavory Knowledge Base documentation & wiki plugin – BasePress.This issue affects Knowledge Base documentation & wiki plugin – BasePress: from n/a through 2.16.1. | |
| Aplazada | Media (5) | 0.35% | — | Basepress Knowledge Base Documentation Wiki PluginAI | 29/4/2024 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in codeSavory Knowledge Base documentation & wiki plugin – BasePress.This issue affects Knowledge Base documentation & wiki plugin – BasePress: from n/a through 2.16.1. | |
| Aplazada | Alta (7.6) | 0.49% | — | Smartypants SP Project AND Document ManagerAI | 18/4/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Smartypants SP Project & Document Manager.This issue affects SP Project & Document Manager : from n/a through 4.71. | |
| Aplazada | Alta (8.7) | 0.46% | — | Echo Plugins Knowledge Base FOR Documentation Faqs With AI AssistanceAI | 27/3/2024 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Echo Plugins Knowledge Base for Documentation, FAQs with AI Assistance.This issue affects Knowledge Base for Documentation, FAQs with AI Assistance: from n/a through 11.30.2. | |
| Aplazada | Crítica (9.8) | 0.55% | — | Abast Scan Visio Edocument Suite WEB ViewerAI | 21/3/2024 | 17/6/2026 | A SQL Injection has been found on SCAN_VISIO eDocument Suite Web Viewer of Abast. This vulnerability allows an unauthenticated user to retrieve, update and delete all the information of database. This vulnerability was found on login page via "user" parameter. | |
| Aplazada | Media (5.8) | 0.17% | — | Opentext Documentum D2AI | 8/3/2024 | 17/6/2026 | CWE-1385 vulnerability in OpenText Documentum D2 affecting versions16.5.1 to CE 23.2. The vulnerability could allow upload arbitrary code and execute it on the client's computer. | |
| Modificada | Alta (8.8) | 0.54% | — | Smartypantsplugins SP Project & Document Manager | 28/2/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Smartypants SP Project & Document Manager.This issue affects SP Project & Document Manager: from n/a through 4.69. | |
| Analizada | Alta (7.8) | 0.53% | — | React-native-documents Document Picker | 16/2/2024 | 17/6/2026 | Directory Traversal vulnerability in React Native Document Picker before v.9.1.1 and fixed in v.9.1.1 allows a local attacker to execute arbitrary code via a crafted script to the Android library component. | |
| Modificada | Alta (7.2) | 0.50% | — | Collaboraoffice Richdocumentscode | 8/12/2023 | 17/6/2026 | Collabora Online is a collaborative online office suite based on LibreOffice technology. Unlike a standalone dedicated Collabora Online server, the Built-in CODE Server (richdocumentscode) is run without chroot sandboxing. Vulnerable versions of the richdocumentscode app can be susceptible to attack via modified… | |
| Modificada | Media (6.1) | 0.41% | — | Collaboraoffice Richdocumentscode | 8/12/2023 | 17/6/2026 | Collabora Online is a collaborative online office suite based on LibreOffice technology. Users of Nextcloud with `Collabora Online - Built-in CODE Server` app can be vulnerable to attack via proxy.php. The bug was fixed in Collabora Online - Built-in CODE Server (richdocumentscode) release 23.5.601. Users are advised… | |
| Modificada | Alta (8.8) | 0.87% | — | Sei-info Rakrak Document Plus | 4/12/2023 | 17/6/2026 | Path traversal vulnerability exists in RakRak Document Plus Ver.3.2.0.0 to Ver.6.4.0.7 (excluding Ver.6.1.1.3a). If this vulnerability is exploited, arbitrary files on the server may be obtained or deleted by a user of the product with specific privileges. | |
| Modificada | Alta (7.5) | 1.1% | — | Henschen Court Document Management | 30/11/2023 | 17/6/2026 | Henschen & Associates court document management software does not sufficiently randomize file names of cached documents, allowing a remote, unauthenticated attacker to access restricted documents. | |
| Modificada | Alta (8.8) | 0.72% | — | Smartypantsplugins SP Project & Document Manager | 3/11/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Smartypants SP Project & Document Manager allows SQL Injection.This issue affects SP Project & Document Manager: from n/a through 4.67. | |
| Modificada | Crítica (9.8) | 61% | — | Documentlocator Document Locator | 27/10/2023 | 17/6/2026 | A vulnerability classified as critical has been found in ColumbiaSoft Document Locator. This affects an unknown part of the file /api/authentication/login of the component WebTools. The manipulation of the argument Server leads to improper authentication. It is possible to initiate the attack remotely. Upgrading to… | |
| Modificada | Crítica (9.8) | 0.63% | — | Digitatek Smartrise Document Management System | 5/9/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Digita Information Technology Smartrise Document Management System allows SQL Injection. This issue affects Smartrise Document Management System: before Hvl-2.0. |