Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2693▼ 76 respecto a la semana anterior
Críticas / altas1446▲ 304 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
11 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.62% | — | Docuform Gmbh FSM ClientAI | 9/7/2026 | 10/7/2026 | An issue in docuForm GmbH FSM Client v.11.11c allows a remote attacker to obtain sensitive information via the login.php component. A vulnerability was identified in the authentication mechanism that allows user enumeration through the login interface. An attacker can differentiate between valid and invalid usernames… | |
| Aplazada | Alta (8.1) | 0.55% | — | Docuform ClientAI | 9/7/2026 | 10/7/2026 | A Local File Inclusion (LFI) vulnerability exists in docuForm GmbH Client v.11.11c that allows a remote attacker to execute arbitrary code via the dfm-menu_report.php component. Attackers can exploit this flaw to read arbitrary files on the server, including sensitive configuration files, source code or system files. | |
| Aplazada | Alta (8.1) | 0.57% | — | Docuform Gmbh ClientAI | 9/7/2026 | 10/7/2026 | An issue in docuForm GmbH Client v.11.11c allows a remote attacker to execute arbitrary code via the file upload and report.php component | |
| Aplazada | Alta (8.1) | 0.68% | — | Docuform ClientAI | 9/7/2026 | 10/7/2026 | An Insecure Direct Object Reference (IDOR) vulnerability exists in docuForm GmbH Client v.11.11c allowing a remote attacker to execute arbitrary code via the user settings component, and modify or retrieve sensitive data associated with other users’ accounts. | |
| Aplazada | Alta (7.5) | 0.64% | — | Docuform Managed Print Service ClientAI | 11/5/2026 | 17/6/2026 | docuFORM Managed Print Service Client 11.11c is vulnerable to a directory traversal allowing attackers to read arbitrary files via crafted url. | |
| Aplazada | Media (6.1) | 0.24% | — | Docuform Managed Print Service ClientAI | 11/5/2026 | 17/6/2026 | docuFORM Managed Print Service Client 11.11c is vulnerable to a reflected cross site scripting attack via the login page of the application. | |
| Aplazada | Media (6.3) | 0.27% | — | Docuform Managed Print Service ClientAI | 11/5/2026 | 17/6/2026 | docuFORM Managed Print Service Client 11.11c is vulnerable to arbitrary file upload via pmupdate.php. | |
| Aplazada | Media (5.4) | 0.22% | — | Docuform Managed Print Service ClientAI | 11/5/2026 | 17/6/2026 | docuFORM Managed Print Service Client 11.11c is vulnerable to a session fixation attack via the login page of the application. | |
| Aplazada | Alta (7.3) | 0.29% | — | Gmbh Mercury Managed Print ServicesAIGmbh DocuformAI | 11/5/2026 | 17/6/2026 | A reflected cross-site scripted (XSS) vulnerability in the dfm-menu_markeralerts.php component of GmbH Mecury Managed Print Services (docuForm) v11.11c allows attackers to execute arbitrary Javascript in the context of a user's browser via injecting a crafted payload into an unfiltered variable value. | |
| Aplazada | Media (6.1) | 0.24% | — | Gmbh Mecury Managed Print ServicesAIDocuformAI | 11/5/2026 | 17/6/2026 | A reflected cross-site scripted (XSS) vulnerability in the acc-menu_papers.php component of GmbH Mecury Managed Print Services (docuForm) v11.11c allows attackers to execute arbitrary Javascript in the context of a user's browser via injecting a crafted payload into an unfiltered variable value. | |
| Aplazada | Media (6.1) | 0.24% | — | Gmbh Mecury Managed Print ServicesAIGmbh DocuformAI | 11/5/2026 | 17/6/2026 | A reflected cross-site scripted (XSS) vulnerability in the dfm-menu_coveragealerts.php component of GmbH Mecury Managed Print Services (docuForm) v11.11c allows attackers to execute arbitrary Javascript in the context of a user's browser via injecting a crafted payload into an unfiltered variable value. |