Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2983▼ 79 respecto a la semana anterior
Críticas / altas1412▲ 62 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
163 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.8) | 0.82% | — | Cisco Dpq3925 8X4 Docsis 3.0 Wireless Residential Gateway With Embedded Digital Voice Adapter | 14/12/2015 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability on Cisco DPQ3925 devices with EDVA 5.5.2 allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuv05943. | |
| Modificada | Alta (9.3) | 1.8% | — | Documentcloud Karteek-docsplit | 25/4/2013 | 16/6/2026 | The extract_from_ocr function in lib/docsplit/text_extractor.rb in the Karteek Docsplit (karteek-docsplit) gem 0.5.4 for Ruby allows context-dependent attackers to execute arbitrary commands via shell metacharacters in a PDF filename. | |
| Modificada | Alta (7.5) | 2.6% | 💥 Exploit | Newgensoft Omnidocs | 27/9/2011 | 16/6/2026 | Newgen OmniDocs allows remote attackers to bypass intended access restrictions via (1) a modified FolderRights parameter to doccab/doclist.jsp, which leads to arbitrary permission changes; or (2) a modified UserIndex parameter to doccab/userprofile/editprofile.jsp, which selects the settings page of an arbitrary user. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Newgensoft Omnidocs | 23/2/2010 | 16/6/2026 | SQL injection vulnerability in ForceChangePassword.jsp in Newgen Software OmniDocs allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Baja (1.9) | 0.30% | — | Data-vision Remotedocs R-viewer | 18/9/2007 | 16/6/2026 | RemoteDocs R-Viewer before 1.6.3768 stores encrypted RDZ file data in unencrypted temporary files, which allows local users to obtain sensitive information by reading the temporary files. | |
| Modificada | Alta (9.3) | 4.6% | — | Data-vision Remotedocs R-viewer | 18/9/2007 | 16/6/2026 | Unspecified vulnerability in RemoteDocs R-Viewer before 1.6.3768 allows user-assisted remote attackers to execute arbitrary code via a crafted RDZ archive in which the first file has an executable extension. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Edocstore | 27/6/2007 | 16/6/2026 | SQL injection vulnerability in essentials/minutes/doc.php in eDocStore allows remote attackers to execute arbitrary SQL commands via the doc_id parameter in an inline action. | |
| Modificada | Alta (7.5) | 2.6% | 💥 Exploit | PHP Errordocs | 14/12/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in includes/common.php in the ErrorDocs 1.0.0 and earlier module for mxBB (mx_errordocs) allows remote attackers to execute arbitrary PHP code via a URL in the module_root_path parameter. | |
| Modificada | Media (5) | 1.8% | — | Hummingbird Cyberdocs | 31/12/2003 | 16/6/2026 | Hummingbird CyberDOCS 3.5.1, 3.9, and 4.0 allows remote attackers to obtain the full path of the DM Web Server via invalid login credentials, which reveals the path in an error message. | |
| Modificada | Media (4.3) | 1.5% | — | Hummingbird Cyberdocs | 31/12/2003 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Hummingbird CyberDOCS 3.5.1, 3.9, and 4.0 allow remote attackers to inject arbitrary web script or HTML via certain vectors. | |
| Modificada | Alta (7.5) | 1.5% | — | Hummingbird Cyberdocs | 31/12/2003 | 16/6/2026 | SQL injection vulnerability in loginact.asp for Hummingbird CyberDOCS before 3.9 allows remote attackers to execute arbitrary SQL commands. | |
| Modificada | Media (5) | 1.8% | — | Hummingbird CyberdocsAIMicrosoft IISAI | 31/12/2003 | 16/6/2026 | Hummingbird CyberDOCS 3.5, 3.9, and 4.0, when running on IIS, uses insecure permissions for script source code files, which allows remote attackers to read the source code. | |
| Modificada | Media (5) | 1.4% | — | Zendocs Zentrack | 31/12/2002 | 16/6/2026 | zenTrack 2.0.3 and earlier allows remote attackers to obtain the full path to the web root via an invalid ticket ID, which leaks the path in an error message. |