Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2570▼ 305 respecto a la semana anterior
Críticas / altas1353▲ 102 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
–

29 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.7)0.94%—2100 Technology Official Document Management SystemAI17/8/202626/8/2026
Official Document Management System developed by 2100 Technology has an Arbitrary File Upload vulnerability, allowing authenticated remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.
AplazadaMedia (5.3)0.26%—Perfect Support Ticketing & Document Management SystemAI16/7/202616/7/2026
Perfect Support Ticketing & Document Management System through 1.7 contains a broken access control vulnerability that allows authenticated attackers with Agent-level privileges to manipulate the Support Agent assignment field of tickets by bypassing intended authorization checks. Attackers can add or remove any user,…
AplazadaMedia (5.1)0.24%—Perfect Support Ticketing AND Document Management SystemAI16/7/202618/7/2026
Perfect Support Ticketing & Document Management System through 1.7 contains a stored cross-site scripting vulnerability that allows authenticated attackers with Agent-level privileges to inject malicious payloads into the Notes field of assigned support tickets. Attackers can store malicious scripts that execute in…
AnalizadaMedia (5.5)0.61%—Admerc Document Management System25/2/202617/6/2026
A vulnerability has been found in itsourcecode Document Management System 1.0. Impacted is an unknown function of the file /register.php. Such manipulation of the argument Username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
AnalizadaMedia (5.5)0.59%—Admerc Document Management System25/2/202617/6/2026
A vulnerability has been found in itsourcecode Document Management System 1.0. This issue affects some unknown processing of the file /loging.php of the component Login. The manipulation of the argument Username leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed to…
AnalizadaMedia (5.5)0.59%—Admerc Document Management System24/2/202617/6/2026
A security vulnerability has been detected in itsourcecode Document Management System 1.0. Affected is an unknown function of the file /edtlbls.php. The manipulation of the argument field1 leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used.
AnalizadaMedia (5.5)0.59%—Admerc Document Management System24/2/202617/6/2026
A weakness has been identified in itsourcecode Document Management System 1.0. This impacts an unknown function of the file /deluser.php. Executing a manipulation of the argument user2del can lead to sql injection. The attack can be launched remotely. The exploit has been made available to the public and could be used…
AnalizadaMedia (6.1)0.22%—SAP Document Management SystemSAP ERPSAP S4core10/2/202617/6/2026
The BSP applications allow an unauthenticated user to inject malicious script content via user-controlled URL parameters that are not sufficiently sanitized. When a victim accesses a crafted URL, the injected script is executed in the victim�s browser, leading to a low impact on confidentiality and integrity, and no…
AnalizadaMedia (6.1)0.22%—SAP Document Management SystemSAP ERPSAP S4core10/2/202617/6/2026
The BSP applications allow an unauthenticated user to manipulate user-controlled URL parameters that are not sufficiently validated. This could result in unvalidated redirection to attacker-controlled websites, leading to a low impact on confidentiality and integrity, and no impact on the availability of the…
AplazadaAlta (7.1)0.29%—2100 Technology Official Document Management SystemAI28/1/202617/6/2026
Official Document Management System developed by 2100 Technology has a Incorrect Authorization vulnerability, allowing authenticated remote attackers to modify front-end code to read all official documents.
AplazadaCrítica (9.3)1.0%—Excellent Infotek Document Management SystemAI20/10/202517/6/2026
Document Management System developed by Excellent Infotek has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.
ModificadaMedia (5.4)0.17%—Fabian Document Management System16/9/20255/7/2026
code-projects Document Management System 1.0 has a Cross Site Scripting (XSS) vulnerability, where attackers can leak admin's cookie information by entering malicious XSS code in the Company field when adding files.
AplazadaCrítica (9.3)0.71%—2100 Technology Official Document Management SystemAI11/8/202517/6/2026
Official Document Management System developed by 2100 Technology has an Authentication Bypass vulnerability, allowing unauthenticated remote attackers to obtain any user's connection token and use it to log into the system as that user.
AnalizadaBaja (2.1)0.50%—Fabian Document Management System1/8/202517/6/2026
A vulnerability was found in code-projects Document Management System 1.0 and classified as critical. This issue affects the function unlink of the file /dell.php. The manipulation of the argument ID leads to path traversal. The attack may be initiated remotely. The exploit has been disclosed to the public and may be…
AnalizadaBaja (2.1)0.36%—Fabian Document Management System25/7/202517/6/2026
A vulnerability, which was classified as critical, has been found in code-projects Document Management System 1.0. This issue affects some unknown processing of the file /insert.php. The manipulation of the argument uploaded_file leads to unrestricted upload. The attack may be initiated remotely. The exploit has been…
AplazadaAlta (7.1)0.28%—Reifsnyderb Document Management SystemAI23/5/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in reifsnyderb Document Management System dms allows Reflected XSS.This issue affects Document Management System: from n/a through <= 1.24.
AplazadaCrítica (9.8)1.3%—2100 Technology Electronic Official Document Management SystemAI31/12/202417/6/2026
The Electronic Official Document Management System from 2100 Technology has an Authentication Bypass vulnerability. Although the product enforces an IP whitelist for the API used to query user tokens, unauthenticated remote attackers can still deceive the server to obtain tokens of arbitrary users, which can then be…
ModificadaMedia (5.3)0.52%—Document Management System Project Document Management System17/7/202417/6/2026
A vulnerability has been found in itsourcecode Document Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file insert.php. The manipulation of the argument anothercont leads to sql injection. The attack can be launched remotely. The exploit has been…
ModificadaAlta (8.8)0.62%—Electronic Official Document Management System Project Electronic Official Document Management System15/7/202417/6/2026
The access control in the Electronic Official Document Management System from 2100 TECHNOLOGY is not properly implemented, allowing remote attackers with regular privileges to access the account settings functionality and create an administrator account.
ModificadaMedia (5.3)0.50%—Itsourcecode Document Management System Project IN PHP With Source Code15/6/202417/6/2026
A vulnerability classified as critical has been found in itsourcecode Document Management System 1.0. Affected is an unknown function of the file edithis.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may…
ModificadaCrítica (9.8)0.63%—Digitatek Smartrise Document Management System5/9/202317/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Digita Information Technology Smartrise Document Management System allows SQL Injection. This issue affects Smartrise Document Management System: before Hvl-2.0.
ModificadaCrítica (9.1)1.0%—Medhost Document Management System28/7/201717/6/2026
MEDHOST Document Management System contains hard-coded credentials that are used for Apache Solr access. An attacker with knowledge of the hard-coded credentials and the ability to communicate directly with Apache Solr may be able to obtain or modify sensitive patient and financial information. The Apache Solr account…
ModificadaCrítica (9.1)1.0%—Medhost Document Management System28/7/201717/6/2026
MEDHOST Document Management System contains hard-coded credentials that are used for customer database access. An attacker with knowledge of the hard-coded credentials and the ability to communicate directly with the database may be able to obtain or modify sensitive patient and financial information. PostgreSQL is…
ModificadaAlta (7.5)0.91%—Cafuego Simple Document Management System1/11/201116/6/2026
SQL injection vulnerability in detail.php in Simple Document Management System (SDMS) allows remote attackers to execute arbitrary SQL commands via the doc_id parameter.
ModificadaAlta (7.5)0.97%—Cafuego Simple Document Management System21/2/200916/6/2026
SQL injection vulnerability in login.php in Simple Document Management System (SDMS) 1.1.5 and 1.1.4, and possibly earlier, allows remote attackers to execute arbitrary SQL commands via the login parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party…