Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3007▼ 67 respecto a la semana anterior
Críticas / altas1403▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)390▼ 120 respecto a la semana anterior
83 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Sin puntuar | — | — | Logicaldoc EnterpriseAI | 6/10/2026 | 6/10/2026 | LogicalDOC Enterprise up to and for 9.1.1 is vulnerable to blind SQL injection in the WorkflowsDataServlet component, allowing authenticated user to manipulate SQL queries via crafted workflow template name. | |
| Aplazada | Alta (7.5) | 0.26% | — | Easydigitaldownloads Easy Digital DownloadsAI | 6/10/2026 | 6/10/2026 | Unauthenticated Broken Access Control in Easy Digital Downloads <= 3.7.1 versions. | |
| Aplazada | Alta (7.6) | 0.29% | — | Easydigitaldownloads Easy Digital DownloadsAI | 23/9/2026 | 23/9/2026 | Shop manager SQL Injection in Easy Digital Downloads <= 3.7.0 versions. | |
| Aplazada | Alta (7.2) | 1.2% | — | Easydigitaldownloads Easy Digital DownloadsAI | 29/7/2026 | 30/7/2026 | The Easy Digital Downloads plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to and including 3.6.9. This is due to insufficient file type validation in the edd_do_ajax_import_file_upload() function , which only checks the client-supplied $_FILES['edd-import-file']['type'] Content-Type header… | |
| Aplazada | Media (4.9) | 0.50% | — | Easydigitaldownloads Easy Digital DownloadsAI | 27/7/2026 | 27/7/2026 | Administrator Arbitrary File Deletion in Easy Digital Downloads <= 3.6.9 versions. | |
| Aplazada | Media (6.5) | 0.42% | — | Easydigitaldownloads Easy Digital DownloadsAI | 23/7/2026 | 23/7/2026 | Unauthenticated Broken Authentication in Easy Digital Downloads <= 3.6.7 versions. | |
| Aplazada | Media (6.5) | 0.49% | — | Logicaldoc EnterpriseAI | 16/7/2026 | 5/10/2026 | LogicalDOC Enterprise up to and for v9.1.1 is vulnerable to Local File Inclusion (LFI) in the OnlyOfficeEditor servlet class, allowing authenticated user to exploit path traversal flaws in the fileExt parameter, enabling unauthorized access to sensitive files outside the designated directories. | |
| Aplazada | Alta (8.8) | 0.51% | — | Logicaldoc EnterpriseAI | 16/7/2026 | 5/10/2026 | LogicalDOC Enterprise up to and for v9.1.1 is vulnerable to blind SQL injection in the ComparisonServlet component, allowing authenticated user to manipulate SQL queries via crafted input. | |
| Aplazada | Alta (7.3) | 0.34% | — | Logicaldoc EnterpriseAI | 13/7/2026 | 13/7/2026 | LogicalDOC Enterprise Version up to and before v9.1.1 is vulnerable to Server-Side Request Forgery (SSRF). An unauthenticated attacker can exploit the ShareFileCallback servlet by manipulating input parameters to trigger a server-side request to an attacker-controlled host. | |
| Aplazada | Media (6.9) | 0.62% | — | Centraldogma-server-auth-shiroAI | 22/6/2026 | 22/6/2026 | A vulnerability has been identified in centraldogma-server-auth-shiro versions prior to 0.84.0, where the SearchFirstActiveDirectoryRealm substitutes the login username into an LDAP search filter without neutralizing LDAP filter metacharacters, allowing an unauthenticated attacker to manipulate the filter to cause… | |
| Aplazada | Crítica (9.4) | 0.23% | — | Line Centraldogma-serverAIApache ZookeeperAI | 22/6/2026 | 22/6/2026 | A vulnerability has been identified in centraldogma-server versions prior to 0.84.0, where enabling ZooKeeper replication without setting replication.secret causes the server to silently fall back to a hard-coded, publicly known secret. This default credential authenticates the embedded ZooKeeper ensemble, allowing an… | |
| Aplazada | Alta (8.8) | 0.22% | — | Centraldogma-server-mirror-gitAI | 22/6/2026 | 22/6/2026 | A vulnerability has been identified in centraldogma-server-mirror-git versions prior to 0.84.0, where the Git mirror SSH client does not verify remote host keys for git+ssh:// connections, allowing an on-path attacker to perform man-in-the-middle attacks and compromise mirrored repositories. | |
| Aplazada | Alta (7.5) | 0.35% | — | Easydigitaldownloads Easy Digital DownloadsAI | 15/6/2026 | 17/6/2026 | Unauthenticated Broken Access Control in Easy Digital Downloads <= 3.6.5 versions. | |
| Aplazada | Media (4.3) | 0.20% | — | Easydigitaldownloads Easy Digital DownloadsAI | 28/5/2026 | 17/6/2026 | The Easy Digital Downloads plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.6.7. This is due to missing nonce verification in the `handle_oauth_redirect()` function, which is registered on the `admin_init` hook and processes Square OAuth tokens from a… | |
| Aplazada | Alta (8.1) | 0.58% | — | Themerex AldoAI | 5/3/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Aldo aldo allows PHP Local File Inclusion.This issue affects Aldo: from n/a through <= 1.0.10. | |
| Aplazada | Media (4.3) | 0.35% | — | Easydigitaldownloads Easy Digital DownloadsAI | 31/12/2025 | 17/6/2026 | The Easy Digital Downloads plugin for WordPress is vulnerable to Unvalidated Redirect in all versions up to, and including, 3.6.2. This is due to insufficient validation on the redirect url supplied via the 'edd_redirect' parameter. This makes it possible for unauthenticated attackers to redirect users with the… | |
| Analizada | Alta (7.1) | 1.1% | — | Logicaldoc | 24/12/2025 | 17/6/2026 | LogicalDOC Enterprise 7.7.4 contains multiple post-authentication file disclosure vulnerabilities that allow attackers to read arbitrary files through unverified 'suffix' and 'fileVersion' parameters. Attackers can exploit directory traversal techniques in /thumbnail and /convertpdf endpoints to access sensitive… | |
| Aplazada | Alta (8.7) | 0.41% | — | Logicaldoc EnterpriseAI | 24/12/2025 | 17/6/2026 | LogicalDOC Enterprise 7.7.4 contains multiple authenticated OS command execution vulnerabilities that allow attackers to manipulate binary paths when changing system settings. Attackers can exploit these vulnerabilities by modifying configuration parameters like antivirus.command, ocr.Tesseract.path, and other system… | |
| Aplazada | Media (5.3) | 0.30% | — | Easydigitaldownloads Easy Digital DownloadsAI | 6/11/2025 | 17/6/2026 | The Easy Digital Downloads plugin for WordPress is vulnerable to Order Manipulation in all versions up to, and including, 3.5.2 due to an order verification bypass. The verification is unconditionally skipped when the POST body includes verification_override=1. Because this value is attacker-supplied, an… | |
| Analizada | Baja (2.9) | 0.79% | — | Logicaldoc | 31/10/2025 | 17/6/2026 | A vulnerability was identified in LogicalDOC Community Edition up to 9.2.1. This vulnerability affects unknown code of the file /login.jsp of the component Admin Login Page. Such manipulation leads to improper restriction of excessive authentication attempts. The attack can be executed remotely. This attack is… | |
| Analizada | Baja (2) | 0.29% | — | Logicaldoc | 31/10/2025 | 17/6/2026 | A vulnerability was determined in LogicalDOC Community Edition up to 9.2.1. This affects an unknown part of the component API Key creation UI. This manipulation causes cross site scripting. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. The vendor was… | |
| Aplazada | Alta (7.1) | 0.13% | — | Digitaldonkey Multilang Contact FormAI | 27/10/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in digitaldonkey Multilang Contact Form multilang-contact-form allows Stored XSS.This issue affects Multilang Contact Form: from n/a through <= 1.5. | |
| Analizada | Baja (2) | 0.37% | — | Logicaldoc | 19/10/2025 | 17/6/2026 | A security flaw has been discovered in LogicalDOC Community Edition up to 9.2.1. This issue affects some unknown processing of the file /frontend.jsp of the component Add Contact Page. Performing manipulation of the argument First Name/Last Name/Company/Address/Phone/Mobile results in cross site scripting. Remote… | |
| Aplazada | Media (5.4) | 0.16% | — | Easydigitaldownloads Easy Digital DownloadsAI | 20/8/2025 | 17/6/2026 | The Easy Digital Downloads plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.5.0. This is due to missing nonce validations in the edd_sendwp_disconnect() and edd_sendwp_remote_install() functions. This makes it possible for unauthenticated attackers to deactivate… | |
| Aplazada | Alta (8.5) | 0.33% | — | Aldo Latino Private-contentAI | 15/3/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Aldo Latino PrivateContent private-content.This issue affects PrivateContent: from n/a through <= 8.11.4. |