Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3005▼ 85 respecto a la semana anterior
Críticas / altas1403▲ 41 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
163 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.86% | — | Wikidocs | 19/2/2022 | 17/6/2026 | WikiDocs version 0.1.18 has multiple reflected XSS vulnerabilities on different pages. | |
| Modificada | Alta (8.8) | 20% | — | Wikidocs | 19/2/2022 | 17/6/2026 | WikiDocs version 0.1.18 has an authenticated remote code execution vulnerability. An attacker can upload a malicious file using the image upload form through index.php. | |
| Modificada | Alta (7.5) | 15% | — | Mkdocs | 7/10/2021 | 17/6/2026 | The mkdocs 1.2.2 built-in dev-server allows directory traversal using the port 8000, enabling remote exploitation to obtain :sensitive information. NOTE: the vendor has disputed this as described in https://github.com/mkdocs/mkdocs/issues/2601.] and https://github.com/nisdn/CVE-2021-40978/issues/1 | |
| Modificada | Crítica (9.8) | 1.0% | — | Unidocs Ezpdfreader | 5/8/2021 | 17/6/2026 | An improper input validation vulnerability in the service of ezPDFReader allows attacker to execute arbitrary command. This issue occurred when the ezPDF launcher received and executed crafted input values through JSON-RPC communication. | |
| Modificada | Alta (7.2) | 0.72% | — | Unidocs Ezpdf EditorUnidocs Ezpdf Reader | 29/6/2021 | 17/6/2026 | A memory corruption vulnerability exists when ezPDF improperly handles the parameter. This vulnerability exists due to insufficient validation of the parameter. | |
| Modificada | Alta (7.3) | 1.2% | — | Linuxfoundation @backstage/plugin-techdocs | 3/6/2021 | 17/6/2026 | Backstage is an open platform for building developer portals. In versions of Backstage's Techdocs Plugin (`@backstage/plugin-techdocs`) prior to 0.9.5, a malicious internal actor can potentially upload documentation content with malicious scripts by embedding the script within an `object` element. This may give access… | |
| Modificada | Alta (8.1) | 1.3% | — | Linuxfoundation @backstage/techdocs-common | 3/6/2021 | 17/6/2026 | Backstage is an open platform for building developer portals, and techdocs-common contains common functionalities for Backstage's TechDocs. In versions of `@backstage/tehdocs-common` prior to 0.6.4, a malicious internal actor is able to upload documentation content with malicious scripts. These scripts would normally… | |
| Modificada | Media (6.1) | 0.78% | — | Docsifyjs Docsify | 2/4/2021 | 17/6/2026 | docsify 4.12.1 is affected by Cross Site Scripting (XSS) because the search component does not appropriately encode Code Blocks and mishandles the " character. | |
| Modificada | Media (6.1) | 1.7% | — | Docsifyjs Docsify | 19/2/2021 | 17/6/2026 | This affects the package docsify before 4.12.0. It is possible to bypass the remediation done by CVE-2020-7680 and execute malicious JavaScript through the following methods 1) When parsing HTML from remote URLs, the HTML code on the main page is sanitized, but this sanitization is not taking place in the sidebar. 2)… | |
| Modificada | Media (4.8) | 0.70% | — | Qdocs Smart Hospital | 26/1/2021 | 9/7/2026 | A cross-site scripting (XSS) issue in Add Patient Form in QDOCS Smart Hospital Management System 3.1 allows a remote attacker to inject arbitrary code via the Name, Guardian Name, Email, Address, Remarks, or Any Known Allergies field. | |
| Modificada | Crítica (9.8) | 2.2% | — | Docker Docs | 15/12/2020 | 17/6/2026 | The Docker Docs Docker image through 2020-12-14 contains a blank password for the root user. Systems deployed using affected versions of the Docker Docs container may allow a remote attacker to achieve root access with a blank password. | |
| Modificada | Media (6.1) | 4.5% | — | Docsifyjs Docsify | 20/7/2020 | 17/6/2026 | docsify prior to 4.11.4 is susceptible to Cross-site Scripting (XSS). Docsify.js uses fragment identifiers (parameters after # sign) to load resources from server-side .md files. Due to lack of validation here, it is possible to provide external URLs after the /#/ (domain.com/#//attacker.com) and render arbitrary… | |
| Modificada | Alta (7.5) | 0.95% | — | UPC Connect BOX Eurodocsis Firmware | 25/12/2019 | 17/6/2026 | The Administration page on Connect Box EuroDOCSIS 3.0 Voice Gateway CH7465LG-NCIP-6.12.18.25-2p6-NOSH devices accepts a cleartext password in a POST request on port 80, as demonstrated by the Password field to the xml/setter.xml URI. | |
| Modificada | Crítica (9.8) | 1.8% | — | Renderdocs-rs Project Renderdocs-rs | 9/9/2019 | 17/6/2026 | An issue was discovered in the renderdoc crate before 0.5.0 for Rust. Multiple exposed methods take self by immutable reference, which is incompatible with a multi-threaded application. | |
| Modificada | Alta (7.8) | 1.1% | — | Checkpoint Capsule Docs Standalone ClientCheckpoint Endpoint SecurityCheckpoint Remote Access Clients | 29/8/2019 | 17/6/2026 | Check Point Endpoint Security Initial Client for Windows before version E81.30 tries to load a DLL placed in any PATH location on a clean image without Endpoint Client installed. An attacker can leverage this to gain LPE using a specially crafted DLL placed in any PATH location accessible with write permissions to the… | |
| Modificada | Media (6.1) | 0.90% | — | Readthedocs Read THE Docs | 2/7/2019 | 17/6/2026 | Read the Docs before 3.5.1 has an Open Redirect if certain user-defined redirects are used. This affects private instances of Read the Docs (in addition to the public readthedocs.org web sites). | |
| Modificada | Crítica (9.8) | 1.2% | — | Checkpoint Jumbo Hotfix FOR Endpoint Security ServerCheckpoint Endpoint Security Server PackageCheckpoint Smartconsole FOR Endpoint Security ServerCheckpoint Endpoint Security Clients+2 | 20/6/2019 | 17/6/2026 | Check Point Endpoint Security Client for Windows, with the VPN blade, before version E80.83, starts a process without using quotes in the path. This can cause loading of a previously placed executable with a name similar to the parts of the path, instead of the intended one. | |
| Modificada | Media (4.4) | 0.97% | — | Checkpoint Endpoint Security ClientsCheckpoint Remote Access ClientsCheckpoint Capsule Docs | 20/6/2019 | 17/6/2026 | Check Point Endpoint Security Client for Windows, with Anti-Malware blade installed, before version E81.00, tries to load a non-existent DLL during an update initiated by the UI. An attacker with administrator privileges can leverage this to gain code execution within a Check Point Software Technologies signed binary,… | |
| Modificada | Alta (7.5) | 1.3% | — | Lwolf Loading Docs | 12/9/2018 | 17/6/2026 | Insecure permissions in Lone Wolf Technologies loadingDOCS 2018-08-13 allow remote attackers to download any confidential files via https requests for predictable URLs. | |
| Modificada | Crítica (9.8) | 1.4% | — | Ndocsoftware Ndoc | 26/10/2017 | 17/6/2026 | Before Thornberry NDoc version 8.0, laptop clients and the server have default database (Cache) users set up with a single password. This password is left behind in a cleartext log file during client installation on laptops. This password can be used to gain full admin/system access to client devices (if no firewall… | |
| Modificada | Crítica (9.8) | 7.1% | — | Cisco Dpc3928ad Docsis Wireless Router Firmware | 20/7/2017 | 17/6/2026 | Technicolor DPC3928AD DOCSIS devices allow remote attackers to read arbitrary files via a request starting with "GET /../" on TCP port 4321. | |
| Modificada | Alta (7.5) | 3.0% | — | Cisco Dpq3925 8X4 Docsis 3.0 Wireless Residential Gateway With Embedded Digital Voice Adapter | 9/3/2016 | 17/6/2026 | The administration interface on Cisco DPQ3925 devices with firmware r1 allows remote attackers to cause a denial of service (device restart) via a crafted HTTP request, aka Bug ID CSCup48105. | |
| Modificada | Media (5) | 2.4% | — | Cisco Dpq3925 8X4 Docsis 3.0 Wireless Residential Gateway With Embedded Digital Voice Adapter | 18/12/2015 | 17/6/2026 | Cisco DPQ3925 devices with EDVA r1 Base allow remote attackers to obtain sensitive information via a crafted HTTP request, aka Bug ID CSCuv03958. | |
| Modificada | Media (4.3) | 7.2% | — | Cisco Epc3928 Docsis 3.0 8X4 Wireless Residential Gateway With Embedded Digital Voice Adapter | 14/12/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the management interface on Cisco EPC3928 devices with EDVA 5.5.10, 5.5.11, and 5.7.1 allows remote attackers to inject arbitrary web script or HTML via an unspecified value, aka Bug ID CSCux24935. | |
| Modificada | Alta (7.5) | 7.6% | — | Cisco Epc3928 Docsis 3.0 8X4 Wireless Residential Gateway With Embedded Digital Voice Adapter | 14/12/2015 | 17/6/2026 | Cisco EPC3928 devices with EDVA 5.5.10, 5.5.11, and 5.7.1 allow remote attackers to bypass an intended authentication requirement and execute unspecified administrative functions via a crafted HTTP request, aka Bug ID CSCux24941. |