Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3040▲ 560 respecto a la semana anterior
Críticas / altas1452▲ 279 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
27 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (5) | 0.32% | — | Onlyoffice DocumentserverAI | 16/4/2026 | 17/6/2026 | ONLYOFFICE DocumentServer before 9.3.0 has an untrusted pointer dereference in XLS processing/conversion (via pictFmla.cbBufInCtlStm and other vectors), leading to an information leak and ASLR bypass. | |
| Analizada | Alta (8.7) | 0.23% | — | Viafirma DocumentsViafirma Documents Compose | 12/1/2026 | 17/6/2026 | Weaknesses in the authorization mechanisms of Viafirma Documents v3.7.129 allow an authenticated user without privileges to list and access other user data, use user creation, modification, and deletion features, and escalate privileges by impersonating other users of the application in the generation and signing of… | |
| Aplazada | Alta (7.1) | 0.29% | — | Poppinsdigital Wpyog DocumentsAI | 17/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PoppinsDigital.com WPYog Documents wpyog-documents allows Reflected XSS.This issue affects WPYog Documents: from n/a through <= 1.3.5. | |
| Aplazada | Media (5.4) | 0.22% | — | Diversified Technology Corp DTC DocumentsAI | 16/12/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Diversified Technology Corp. DTC Documents dtc-documents allows Cross Site Request Forgery.This issue affects DTC Documents: from n/a through <= 1.1.05. | |
| Aplazada | Media (6.5) | 0.30% | — | Joan Boluda Embed Documents ShortcodeAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Joan Boluda Embed documents shortcode embed-documents-shortcode allows Stored XSS.This issue affects Embed documents shortcode: from n/a through <= 1.5. | |
| Analizada | Alta (7.8) | 0.53% | — | React-native-documents Document Picker | 16/2/2024 | 17/6/2026 | Directory Traversal vulnerability in React Native Document Picker before v.9.1.1 and fixed in v.9.1.1 allows a local attacker to execute arbitrary code via a crafted script to the Android library component. | |
| Modificada | Alta (7.2) | 0.50% | — | Collaboraoffice Richdocumentscode | 8/12/2023 | 17/6/2026 | Collabora Online is a collaborative online office suite based on LibreOffice technology. Unlike a standalone dedicated Collabora Online server, the Built-in CODE Server (richdocumentscode) is run without chroot sandboxing. Vulnerable versions of the richdocumentscode app can be susceptible to attack via modified… | |
| Modificada | Media (6.1) | 0.41% | — | Collaboraoffice Richdocumentscode | 8/12/2023 | 17/6/2026 | Collabora Online is a collaborative online office suite based on LibreOffice technology. Users of Nextcloud with `Collabora Online - Built-in CODE Server` app can be vulnerable to attack via proxy.php. The bug was fixed in Collabora Online - Built-in CODE Server (richdocumentscode) release 23.5.601. Users are advised… | |
| Modificada | Media (6.5) | 0.74% | — | Nextcloud Richdocuments | 31/3/2023 | 17/6/2026 | Nextcloud richdocuments is a Nextcloud app integrating the office suit Collabora Online. In affected versions the secure view feature of the rich documents app can be bypassed by using unprotected internal API endpoint of the rich documents app. It is recommended that the Nextcloud Office app (richdocuments) is… | |
| Modificada | Media (5.3) | 0.46% | — | Nextcloud ServerNextcloud Richdocuments | 13/2/2023 | 17/6/2026 | Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform, and Nextcloud Office is a document collaboration app for the same platform. Nextcloud Server 24.0.x prior to 24.0.8 and 25.0.x prior to 25.0.1, Nextcloud Enterprise Server 24.0.x prior to 24.0.8 and 25.0.x prior to 25.0.1,… | |
| Modificada | Media (5.7) | 0.73% | — | Nextcloud Richdocuments | 8/2/2023 | 17/6/2026 | Nextcloud office/richdocuments is an office suit for the nextcloud server platform. In affected versions the Collabora integration can be tricked to provide access to any file without proper permission validation. As a result any user with access to Collabora can obtain the content of other users files. It is… | |
| Modificada | Media (6.5) | 0.60% | — | Nextcloud Richdocuments | 2/6/2022 | 17/6/2026 | richdocuments is the repository for NextCloud Collabra, the app for Nextcloud Office collaboration. Prior to versions 6.0.0, 5.0.4, and 4.2.6, a user could be tricked into working against a remote Office by sending them a federated share. richdocuments versions 6.0.0, 5.0.4 and 4.2.6 contain a fix for this issue.… | |
| Modificada | Media (5.3) | 1.1% | — | Nextcloud Richdocuments | 25/10/2021 | 17/6/2026 | Nextcloud is an open-source, self-hosted productivity platform. The Nextcloud Richdocuments application prior to versions 3.8.6 and 4.2.3 returned verbatim exception messages to the user. This could result in a full path disclosure on shared files. (e.g. an attacker could see that the file `shared.txt` is located… | |
| Modificada | Media (5.3) | 1.4% | — | Nextcloud Richdocuments | 7/9/2021 | 17/6/2026 | Nextcloud Richdocuments is an open source collaborative office suite. In affected versions there is a lack of rate limiting on the Richdocuments OCS endpoint. This may have allowed an attacker to enumerate potentially valid share tokens. It is recommended that the Nextcloud Richdocuments app is upgraded to either… | |
| Modificada | Alta (7.5) | 2.1% | — | Nextcloud Richdocuments | 7/9/2021 | 17/6/2026 | Nextcloud Richdocuments is an open source collaborative office suite. In affected versions the File Drop features ("Upload Only" public link shares in Nextcloud) can be bypassed using the Nextcloud Richdocuments app. An attacker was able to read arbitrary files in such a share. It is recommended that the Nextcloud… | |
| Modificada | Media (4.8) | 0.90% | — | Open-xchange Documents | 30/7/2021 | 17/6/2026 | OX Documents before 7.10.5-rev5 has Incorrect Access Control for documents that contain XML structures because hash collisions can occur, due to use of CRC32. | |
| Modificada | Media (6.5) | 1.1% | — | Open-xchange Documents | 30/7/2021 | 17/6/2026 | OX Documents before 7.10.5-rev7 has Incorrect Access Control for converted documents because hash collisions can occur, due to use of CRC32. | |
| Modificada | Media (6.5) | 1.1% | — | Open-xchange Documents | 30/7/2021 | 17/6/2026 | OX Documents before 7.10.5-rev5 has Incorrect Access Control of converted images because hash collisions can occur, due to use of Adler32. | |
| Modificada | Media (4.3) | 0.99% | — | Nextcloud Richdocuments | 27/7/2021 | 17/6/2026 | Nextcloud Richdocuments in an open source self hosted online office. Nextcloud uses the WOPI ("Web Application Open Platform Interface") protocol to communicate with the Collabora Editor, the communication between these two services was not protected by a credentials or IP check. Whilst this does not result in gaining… | |
| Modificada | Media (6.1) | 0.70% | — | Readdle Documents | 18/5/2020 | 17/6/2026 | An issue was discovered in the Readdle Documents app before 6.9.7 for iOS. The application's file-transfer web server improperly displays directory names, leading to Stored XSS, which may be used to steal a user's data. This requires user interaction because there is no known direct way for an attacker to create a… | |
| Modificada | Media (5.3) | 1.0% | — | Readdle Documents | 18/5/2020 | 17/6/2026 | An issue was discovered in the Readdle Documents app before 6.9.7 for iOS. The application's file-transfer web server allows for cross-origin requests from any domain, and the WebSocket server lacks authorization control. Any web site can execute JavaScript code (that accesses a user's data) via cross-origin requests. | |
| Modificada | Media (6.1) | 0.92% | — | Memphis Documents Library Project Memphis Documents Library | 22/8/2019 | 17/6/2026 | The memphis-documents-library plugin before 3.0 for WordPress has XSS via $_REQUEST. | |
| Modificada | Crítica (9.8) | 2.1% | — | Memphis Documents Library Project Memphis Documents Library | 22/8/2019 | 17/6/2026 | The memphis-documents-library plugin before 3.0 for WordPress has Local File Inclusion. | |
| Modificada | Crítica (9.8) | 2.7% | — | Memphis Documents Library Project Memphis Documents Library | 22/8/2019 | 17/6/2026 | The memphis-documents-library plugin before 3.0 for WordPress has Remote File Inclusion. | |
| Modificada | Alta (7.5) | 1.8% | — | Olivetoast Documents PRO File Viewer | 19/1/2013 | 16/6/2026 | Directory traversal vulnerability in the Olive Toast Documents Pro File Viewer (formerly Files HD) app before 1.11.1 for iOS allows remote attackers to read or delete files by leveraging guest access. |