Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2638▼ 297 respecto a la semana anterior
Críticas / altas1351▲ 82 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)58▼ 469 respecto a la semana anterior
–

369 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)1.7%—Smartypantsplugins SP Project & Document Manager25/4/202217/6/2026
The SP Project & Document Manager WordPress plugin before 4.24 allows any authenticated users, such as subscribers, to upload files. The plugin attempts to prevent PHP and other similar files that could be executed on the server from being uploaded by checking the file extension. It was discovered that on Windows…
ModificadaMedia (6.1)1.9%—Onlyoffice Document Server8/4/202217/6/2026
A cross-site scripting (XSS) vulnerability in ONLYOFFICE Document Server Example before v7.0.0 allows remote attackers inject arbitrary HTML or JavaScript through /example/editor.
ModificadaMedia (4.3)0.89%—Bplugins Document Embedder1/2/202217/6/2026
The Document Embedder WordPress plugin before 1.7.9 contains a AJAX action endpoint, which could allow any authenticated user, such as subscriber to enumerate the title of arbitrary private and draft posts.
ModificadaMedia (5.3)1.3%—Bplugins Document Embedder1/2/202217/6/2026
The Document Embedder WordPress plugin before 1.7.5 contains a REST endpoint, which could allow unauthenticated users to enumerate the title of arbitrary private and draft posts.
ModificadaMedia (5.4)0.53%—Shimo Document22/11/202117/6/2026
Shimo Document v2.0.1 contains a cross-site scripting (XSS) vulnerability which allows attackers to execute arbitrary web scripts or HTML via a crafted payload inserted into the table content text field.
ModificadaMedia (6.5)1.1%—Antennahouse Office Server Document Converter1/11/202117/6/2026
Office Server Document Converter V7.2MR4 and earlier and V7.1MR7 and earlier allows a remote unauthenticated attacker to conduct an XML External Entity (XXE) attack to cause a denial of service (DoS) condition to the other servers by processing a specially crafted XML document.
ModificadaAlta (7.5)1.5%—Antennahouse Office Server Document Converter1/11/202117/6/2026
Office Server Document Converter V7.2MR4 and earlier and V7.1MR7 and earlier allows a remote unauthenticated attacker to conduct an XML External Entity (XXE) attack to cause a denial of service (DoS) condition by processing a specially crafted XML document.
ModificadaMedia (5.3)1.1%—Nextcloud Richdocuments25/10/202117/6/2026
Nextcloud is an open-source, self-hosted productivity platform. The Nextcloud Richdocuments application prior to versions 3.8.6 and 4.2.3 returned verbatim exception messages to the user. This could result in a full path disclosure on shared files. (e.g. an attacker could see that the file `shared.txt` is located…
ModificadaMedia (5.3)1.4%—Nextcloud Richdocuments7/9/202117/6/2026
Nextcloud Richdocuments is an open source collaborative office suite. In affected versions there is a lack of rate limiting on the Richdocuments OCS endpoint. This may have allowed an attacker to enumerate potentially valid share tokens. It is recommended that the Nextcloud Richdocuments app is upgraded to either…
ModificadaAlta (7.5)2.1%—Nextcloud Richdocuments7/9/202117/6/2026
Nextcloud Richdocuments is an open source collaborative office suite. In affected versions the File Drop features ("Upload Only" public link shares in Nextcloud) can be bypassed using the Nextcloud Richdocuments app. An attacker was able to read arbitrary files in such a share. It is recommended that the Nextcloud…
ModificadaMedia (6.1)0.94%—Smartypantsplugins SP Project & Document Manager16/8/202117/6/2026
The SP Project & Document Manager WordPress plugin is vulnerable to attribute-based Reflected Cross-Site Scripting via the from and to parameters in the ~/functions.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 4.25.
ModificadaMedia (4.8)0.90%—Open-xchange Documents30/7/202117/6/2026
OX Documents before 7.10.5-rev5 has Incorrect Access Control for documents that contain XML structures because hash collisions can occur, due to use of CRC32.
ModificadaMedia (6.5)1.1%—Open-xchange Documents30/7/202117/6/2026
OX Documents before 7.10.5-rev7 has Incorrect Access Control for converted documents because hash collisions can occur, due to use of CRC32.
ModificadaMedia (6.5)1.1%—Open-xchange Documents30/7/202117/6/2026
OX Documents before 7.10.5-rev5 has Incorrect Access Control of converted images because hash collisions can occur, due to use of Adler32.
ModificadaMedia (4.3)0.99%—Nextcloud Richdocuments27/7/202117/6/2026
Nextcloud Richdocuments in an open source self hosted online office. Nextcloud uses the WOPI ("Web Application Open Platform Interface") protocol to communicate with the Collabora Editor, the communication between these two services was not protected by a credentials or IP check. Whilst this does not result in gaining…
ModificadaMedia (5.3)1.1%—EIC E-document System16/6/202117/6/2026
An issue was discovered in EXCELLENT INFOTEK CORPORATION (EIC) E-document System 3.0. A remote attacker can use kw/auth/bbs/asp/get_user_email_info_bbs.asp to obtain the contact information (name and e-mail address) of everyone in the entire organization. This information can allow remote attackers to perform social…
ModificadaAlta (8.8)54%—Smartypantsplugins SP Project & Document Manager14/6/202117/6/2026
The SP Project & Document Manager WordPress plugin before 4.22 allows users to upload files, however, the plugin attempts to prevent php and other similar files that could be executed on the server from being uploaded by checking the file extension. It was discovered that php files could still be uploaded by changing…
ModificadaAlta (8.1)0.96%—Oracle Document Management AND Collaboration22/4/202117/6/2026
Vulnerability in the Oracle Document Management and Collaboration product of Oracle E-Business Suite (component: Document Management). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.10. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise…
ModificadaAlta (7.6)0.81%—Oracle Document Management AND Collaboration22/4/202117/6/2026
Vulnerability in the Oracle Document Management and Collaboration product of Oracle E-Business Suite (component: Attachments). Supported versions that are affected are 12.1.3 and 12.2.3-12.2.10. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Document…
ModificadaCrítica (9.8)2.6%—EIC E-document System17/3/202117/6/2026
EIC e-document system does not perform completed identity verification for sorting and filtering personnel data. The vulnerability allows remote attacker to obtain users’ credential information without logging in the system, and further acquire the privileged permissions and execute arbitrary commends.
ModificadaCrítica (9.8)3.8%—EIC E-document System17/3/202117/6/2026
The users’ data querying function of EIC e-document system does not filter the special characters which resulted in remote attackers can inject SQL syntax and execute arbitrary commands without privilege.
ModificadaCrítica (9.8)44%—Onlyoffice Document Server1/3/202117/6/2026
A file extension handling issue was found in [server] module of ONLYOFFICE DocumentServer v4.2.0.71-v5.6.0.21. The file extension is controlled by an attacker through the request data and leads to arbitrary file overwriting. Using this vulnerability, a remote attacker can obtain remote code execution on DocumentServer.
ModificadaCrítica (9.8)13%—Onlyoffice Document Server1/3/202117/6/2026
A heap buffer overflow vulnerability inside of BMP image processing was found at [core] module of ONLYOFFICE DocumentServer v4.0.0-9-v6.0.0. Using this vulnerability, an attacker is able to gain remote code executions on DocumentServer.
ModificadaCrítica (9.8)12%—Onlyoffice Document Server1/3/202117/6/2026
A file extension handling issue was found in [core] module of ONLYOFFICE DocumentServer v4.0.0-9-v5.6.3. An attacker must request the conversion of the crafted file from PPTT into PPTX format. Using the chain of two other bugs related to improper string handling, a remote attacker can obtain remote code execution on…
ModificadaCrítica (9.8)12%—Onlyoffice Document Server1/3/202117/6/2026
A file extension handling issue was found in [core] module of ONLYOFFICE DocumentServer v4.2.0.236-v5.6.4.13. An attacker must request the conversion of the crafted file from DOCT into DOCX format. Using the chain of two other bugs related to improper string handling, an attacker can achieve remote code execution on…