Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2632▼ 307 respecto a la semana anterior
Críticas / altas1348▲ 75 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 465 respecto a la semana anterior
–

369 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)0.89%—Phpjabbers Document Creator28/8/202317/6/2026
User enumeration is found in PHPJabbers Document Creator v1.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.
ModificadaAlta (7.5)2.2%—Onlyoffice Document Server14/8/20239/7/2026
Memory Exhaustion vulnerability in ONLYOFFICE Document Server 4.0.3 through 7.3.2 allows remote attackers to cause a denial of service via crafted JavaScript file.
ModificadaCrítica (9.8)2.4%—Onlyoffice Document Server14/8/20239/7/2026
An out of bounds memory access vulnerability in ONLYOFFICE DocumentServer 4.0.3 through 7.3.2 allows remote attackers to run arbitrary code via crafted JavaScript file.
ModificadaCrítica (9.8)2.3%—Onlyoffice Document Server14/8/20239/7/2026
A use after free issue discovered in ONLYOFFICE DocumentServer 4.0.3 through 7.3.2 allows remote attackers to run arbitrary code via crafted JavaScript file.
ModificadaMedia (6.1)0.44%—Phpjabbers Document Creator10/8/202317/6/2026
PHPJabbers Document Creator v1.0 is vulnerable to Cross Site Scripting (XSS) via all post parameters of "Export Requests" aside from "request_feed".
ModificadaCrítica (9.8)0.79%—Phpjabbers Document Creator10/8/202317/6/2026
There is a SQL injection (SQLi) vulnerability in the "column" parameter of index.php in PHPJabbers Document Creator v1.0.
ModificadaMedia (6.1)0.44%—Phpjabbers Document Creator10/8/202317/6/2026
There is a Cross Site Scripting (XSS) vulnerability in the "column" parameter of index.php in PHPJabbers Document Creator v1.0.
ModificadaMedia (6.1)0.44%—Phpjabbers Document Creator10/8/202317/6/2026
There is a Cross Site Scripting (XSS) vulnerability in the "action" parameter of index.php in PHPJabbers Document Creator v1.0.
ModificadaMedia (4.8)0.37%—Smartypantsplugins SP Project & Document Manager10/8/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Smartypants SP Project & Document Manager plugin <= 4.67 versions.
ModificadaAlta (7.5)0.74%—Infodoc Document On-line Submission AND Approval System20/7/202317/6/2026
InfoDoc Document On-line Submission and Approval System lacks sufficient restrictions on the available tags within its HTML to PDF conversion function, and allowing an unauthenticated attackers to load remote or local resources through HTML tags such as iframe. This vulnerability allows unauthenticated remote…
ModificadaCrítica (9.8)0.93%—Infodoc Document On-line Submission AND Approval System20/7/202317/6/2026
It is identified a vulnerability of Unrestricted Upload of File with Dangerous Type in the file uploading function in InfoDoc Document On-line Submission and Approval System, which allows an unauthenticated remote attacker can exploit this vulnerability without logging system to upload and run arbitrary executable…
ModificadaAlta (8.8)0.73%—Smartypantsplugins SP Project & Document Manager30/6/202317/6/2026
The SP Project & Document Manager plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 4.67. This is due to the plugin providing user-controlled access to objects, letting a user bypass authorization and access system resources. This makes it possible for…
ModificadaCrítica (9.8)1.5%—HP Laserjet Managed MFP E62665 3gy14a FirmwareHP Laserjet Managed MFP E62665 3gy15a FirmwareHP Laserjet Managed MFP E62665 3gy16a FirmwareHP Laserjet Managed MFP E62665 3gy17a Firmware+95314/6/202317/6/2026
A potential security vulnerability has been identified for certain HP multifunction printers (MFPs). The vulnerability may lead to Buffer Overflow and/or Remote Code Execution when running HP Workpath solutions on potentially affected products.
ModificadaAlta (7.8)0.28%—Opentext Documentum Content Server18/5/202317/6/2026
OpenText Documentum Content Server before 23.2 has a flaw that allows for privilege escalation from a non-privileged Documentum user to root. The software comes prepackaged with a root owned SUID binary dm_secure_writer. The binary has security controls in place preventing creation of a file in a non-owned directory,…
ModificadaMedia (6.5)0.74%—Nextcloud Richdocuments31/3/202317/6/2026
Nextcloud richdocuments is a Nextcloud app integrating the office suit Collabora Online. In affected versions the secure view feature of the rich documents app can be bypassed by using unprotected internal API endpoint of the rich documents app. It is recommended that the Nextcloud Office app (richdocuments) is…
ModificadaMedia (5.4)0.38%—Awsm Embed ANY Document23/3/202317/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), Unrestricted Upload of File with Dangerous Type vulnerability in Awsm Innovations Embed Any Document – Embed PDF, Word, PowerPoint and Excel Files allows Stored XSS via upload of SVG and HTML files. This issue affects Embed Any…
ModificadaAlta (7.8)0.30%—Onlyoffice Document Server19/3/202317/6/2026
ONLYOFFICE Docs through 7.3 on certain Linux distributions allows local users to gain privileges via a Trojan horse libgcc_s.so.1 in the current working directory, which may be any directory in which an ONLYOFFICE document is located.
ModificadaMedia (5.3)0.46%—Nextcloud ServerNextcloud Richdocuments13/2/202317/6/2026
Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform, and Nextcloud Office is a document collaboration app for the same platform. Nextcloud Server 24.0.x prior to 24.0.8 and 25.0.x prior to 25.0.1, Nextcloud Enterprise Server 24.0.x prior to 24.0.8 and 25.0.x prior to 25.0.1,…
ModificadaMedia (5.7)0.73%—Nextcloud Richdocuments8/2/202317/6/2026
Nextcloud office/richdocuments is an office suit for the nextcloud server platform. In affected versions the Collabora integration can be tricked to provide access to any file without proper permission validation. As a result any user with access to Collabora can obtain the content of other users files. It is…
ModificadaMedia (6.1)0.62%—Smartypantsplugins SP Project & Document Manager22/8/202217/6/2026
Reflected Cross-Site Scripting (XSS) vulnerability in smartypants SP Project & Document Manager plugin <= 4.59 at WordPress
ModificadaMedia (6.5)0.97%—Smartypantsplugins SP Project & Document Manager25/7/202217/6/2026
The SP Project & Document Manager WordPress plugin before 4.58 uses an easily guessable path to store user files, bad actors could use that to access other users' sensitive files.
ModificadaMedia (6.5)0.62%—Nextcloud Richdocuments2/6/202217/6/2026
richdocuments is the repository for NextCloud Collabra, the app for Nextcloud Office collaboration. Prior to versions 6.0.0, 5.0.4, and 4.2.6, a user could be tricked into working against a remote Office by sending them a federated share. richdocuments versions 6.0.0, 5.0.4 and 4.2.6 contain a fix for this issue.…
ModificadaCrítica (9.8)6.9%—Onlyoffice CoreOnlyoffice Document Server2/6/202217/6/2026
Onlyoffice Document Server v6.0.0 and below and Core 6.1.0.26 and below were discovered to contain a heap overflow via the component DesktopEditor/fontengine/fontconverter/FontFileBase.h.
ModificadaCrítica (9.8)6.9%—Onlyoffice CoreOnlyoffice Document Server2/6/202217/6/2026
Onlyoffice Document Server v6.0.0 and below and Core 6.1.0.26 and below were discovered to contain a stack overflow via the component DesktopEditor/common/File.cpp.
ModificadaCrítica (9.8)43%—Documentor Project Documentor2/5/202217/6/2026
The Documentor WordPress plugin through 1.5.3 fails to sanitize and escape user input before it is being interpolated in an SQL statement and then executed, leading to an SQL Injection exploitable by unauthenticated users.