Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3034▼ 62 respecto a la semana anterior
Críticas / altas1427▲ 61 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

44 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.1)0.45%—FlowintelAIPandocAIXelatexAI27/8/202628/8/2026
Affected versions of Flowintel allow attacker-controlled note content to be processed by Pandoc and XeLaTeX during PDF export in a way that can cause local files on the Flowintel server to be read and incorporated into the generated export.
AnalizadaAlta (8.8)0.33%—Opendocman5/4/20266/10/2026
OpenDocMan 1.3.4 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'where' parameter. Attackers can send GET requests to search.php with malicious SQL payloads in the 'where' parameter to extract sensitive database information.
ModificadaMedia (4.3)0.25%—Jenkins Start Windocks Container29/10/202517/6/2026
A missing permission check in Jenkins Start Windocks Containers Plugin 1.4 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL.
ModificadaMedia (4.3)0.21%—Jenkins Start Windocks Container29/10/202517/6/2026
A cross-site request forgery (CSRF) vulnerability in Jenkins Start Windocks Containers Plugin 1.4 and earlier allows attackers to connect to an attacker-specified URL.
AplazadaBaja (3.7)0.71%—PandocAI11/7/20255/7/2026
A Server-Side Request Forgery (SSRF) in JGM Pandoc v3.6.4 allows attackers to gain access to and compromise the whole infrastructure via injecting a crafted iframe. Note: Some users have stated that Pandoc by default can retrieve and parse untrusted HTML content which can enable SSRF vulnerabilities. Using the…
AnalizadaMedia (4.9)1.2%—Pwndoc Project Pwndoc28/2/202517/6/2026
PwnDoc is a penetration test reporting application. Prior to version 1.2.0, the backup restore functionality allows an administrator to import raw data into the database, including Path Traversal (`../`) sequences. This is problematic for the template update functionality as it uses the path from the database to write…
AnalizadaMedia (6.5)2.1%—Pwndoc Project Pwndoc28/2/202517/6/2026
PwnDoc is a penetration test reporting application. Prior to version 1.2.0, the backup restore functionality is vulnerable to path traversal in the TAR entry's name, allowing an attacker to overwrite any file on the system with their content. By overwriting an included `.js` file and restarting the container, this…
AnalizadaAlta (8.1)0.25%—Pwndoc Project Pwndoc20/1/202517/6/2026
PwnDoc is a penetration test report generator. There is no CSRF protection in pwndoc, allowing attackers to send requests on a logged-in user's behalf. This includes GET and POST requests due to the missing SameSite= attribute on cookies and the ability to refresh cookies. Commit…
AplazadaMedia (6.5)0.67%—PendocAI12/12/202417/6/2026
PenDoc is a penetration testing reporting application. Prior to commit 1d4219c596f4f518798492e48386a20c6e9a2fe6, an attacker can write a malicious docx template containing expressions that escape the JavaScript sandbox to execute arbitrary code on the system. An attacker who can control the contents of the template…
AnalizadaMedia (6.5)0.62%—Pwndoc Project Pwndoc10/12/202417/6/2026
PwnDoc is a penetration test report generator. In versions up to and including 0.5.3, an authenticated user is able to crash the backend by raising a `UnhandledPromiseRejection` on audits which exits the backend. The user doesn't need to know the audit id, since a bad audit id will also raise the rejection. With the…
AnalizadaAlta (8.5)0.69%—Pwndoc Project Pwndoc10/12/202417/6/2026
PwnDoc is a penetration test report generator. Prior to commit 1d4219c596f4f518798492e48386a20c6e9a2fe6, an authenticated user who is able to update and download templates can inject path traversal (`../`) sequences into the file extension property to read arbitrary files on the system. Commit…
AplazadaAlta (8.5)0.40%—Opendock Easy GalleryAI9/11/202417/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in odihost Easy Gallery simple-gallery-odihost allows SQL Injection.This issue affects Easy Gallery: from n/a through <= 1.4.
ModificadaAlta (7.5)0.41%—Bandoche Pypinksign16/11/20239/7/2026
PyPinkSign v0.5.1 uses a non-random or static IV for Cipher Block Chaining (CBC) mode in AES encryption. This vulnerability can lead to the disclosure of information and communications.
ModificadaMedia (6.3)0.25%—PandocDebian Linux25/7/202317/6/2026
Pandoc before 3.1.6 allows arbitrary file write: this can be triggered by providing a crafted image element in the input when generating files via the --extract-media option or outputting to PDF format. This allows an attacker to create or overwrite arbitrary files, depending on the privileges of the process running…
ModificadaAlta (7.5)1.2%—Microsoft Pandocupload11/7/202317/6/2026
MediaWiki PandocUpload Extension Remote Code Execution Vulnerability
ModificadaMedia (5)0.37%—PandocDebian Linux5/7/202317/6/2026
Pandoc is a Haskell library for converting from one markup format to another, and a command-line tool that uses this library. Starting in version 1.13 and prior to version 3.1.4, Pandoc is susceptible to an arbitrary file write vulnerability, which can be triggered by providing a specially crafted image element in the…
ModificadaAlta (8.8)1.9%—Pwndoc Project Pwndoc5/12/202217/6/2026
An issue in the /api/audits component of Pwndoc v0.5.3 allows attackers to escalate privileges and execute arbitrary code via uploading a crafted audit file.
ModificadaMedia (5.3)0.81%—Pwndoc Project Pwndoc30/10/202217/6/2026
PwnDoc through 0.5.3 might allow remote attackers to identify disabled user account names by leveraging response messages for authentication attempts.
ModificadaMedia (5.3)0.81%—Pwndoc Project Pwndoc30/10/202217/6/2026
PwnDoc through 0.5.3 might allow remote attackers to identify valid user account names by leveraging response timings for authentication attempts.
ModificadaAlta (7.8)0.86%—Iminho Mindoc26/5/202217/6/2026
An arbitrary file upload vulnerability in Mindoc v2.1-beta.5 allows attackers to execute arbitrary commands via a crafted Zip file.
ModificadaCrítica (9.8)2.3%—Opendocman18/3/20229/7/2026
An attacker can upload or transfer files of dangerous types to the OpenDocMan 1.4.4 portal via add.php using MIME-bypass, which may be automatically processed within the product's environment or lead to arbitrary code execution.
ModificadaAlta (8.8)2.7%—Pwndoc Project Pwndoc19/7/202117/6/2026
PwnDoc all versions until 0.4.0 (2021-08-23) has incorrect JSON Webtoken handling, leading to incorrect access control. With a valid JSON Webtoken that is used for authentication and authorization, a user can keep his admin privileges even if he is downgraded to the "user" privilege. Even after a user's account is…
ModificadaAlta (8.8)1.3%—Iminho Mindoc8/11/201817/6/2026
An issue was discovered in MinDoc through v1.0.2. It allows attackers to gain privileges by uploading an image file with contents that represent an admin session, and then sending a Cookie: header with a mindoc_id value containing the relative pathname of this uploaded file. For example, the mindoc_id (aka session ID)…
ModificadaAlta (8.8)2.5%—Opendocman10/4/201817/6/2026
OpenDocMan 1.2.7 and earlier does not properly validate allowed actions, which allows remote authenticated users to bypass an intended access restrictions and assign administrative privileges to themselves via a crafted request to signup.php.
ModificadaCrítica (9.8)1.4%—Ndocsoftware Ndoc26/10/201717/6/2026
Before Thornberry NDoc version 8.0, laptop clients and the server have default database (Cache) users set up with a single password. This password is left behind in a cleartext log file during client installation on laptops. This password can be used to gain full admin/system access to client devices (if no firewall…