Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3034▼ 62 respecto a la semana anterior
Críticas / altas1427▲ 61 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
44 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.45% | — | FlowintelAIPandocAIXelatexAI | 27/8/2026 | 28/8/2026 | Affected versions of Flowintel allow attacker-controlled note content to be processed by Pandoc and XeLaTeX during PDF export in a way that can cause local files on the Flowintel server to be read and incorporated into the generated export. | |
| Analizada | Alta (8.8) | 0.33% | — | Opendocman | 5/4/2026 | 6/10/2026 | OpenDocMan 1.3.4 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'where' parameter. Attackers can send GET requests to search.php with malicious SQL payloads in the 'where' parameter to extract sensitive database information. | |
| Modificada | Media (4.3) | 0.25% | — | Jenkins Start Windocks Container | 29/10/2025 | 17/6/2026 | A missing permission check in Jenkins Start Windocks Containers Plugin 1.4 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL. | |
| Modificada | Media (4.3) | 0.21% | — | Jenkins Start Windocks Container | 29/10/2025 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins Start Windocks Containers Plugin 1.4 and earlier allows attackers to connect to an attacker-specified URL. | |
| Aplazada | Baja (3.7) | 0.71% | — | PandocAI | 11/7/2025 | 5/7/2026 | A Server-Side Request Forgery (SSRF) in JGM Pandoc v3.6.4 allows attackers to gain access to and compromise the whole infrastructure via injecting a crafted iframe. Note: Some users have stated that Pandoc by default can retrieve and parse untrusted HTML content which can enable SSRF vulnerabilities. Using the… | |
| Analizada | Media (4.9) | 1.2% | — | Pwndoc Project Pwndoc | 28/2/2025 | 17/6/2026 | PwnDoc is a penetration test reporting application. Prior to version 1.2.0, the backup restore functionality allows an administrator to import raw data into the database, including Path Traversal (`../`) sequences. This is problematic for the template update functionality as it uses the path from the database to write… | |
| Analizada | Media (6.5) | 2.1% | — | Pwndoc Project Pwndoc | 28/2/2025 | 17/6/2026 | PwnDoc is a penetration test reporting application. Prior to version 1.2.0, the backup restore functionality is vulnerable to path traversal in the TAR entry's name, allowing an attacker to overwrite any file on the system with their content. By overwriting an included `.js` file and restarting the container, this… | |
| Analizada | Alta (8.1) | 0.25% | — | Pwndoc Project Pwndoc | 20/1/2025 | 17/6/2026 | PwnDoc is a penetration test report generator. There is no CSRF protection in pwndoc, allowing attackers to send requests on a logged-in user's behalf. This includes GET and POST requests due to the missing SameSite= attribute on cookies and the ability to refresh cookies. Commit… | |
| Aplazada | Media (6.5) | 0.67% | — | PendocAI | 12/12/2024 | 17/6/2026 | PenDoc is a penetration testing reporting application. Prior to commit 1d4219c596f4f518798492e48386a20c6e9a2fe6, an attacker can write a malicious docx template containing expressions that escape the JavaScript sandbox to execute arbitrary code on the system. An attacker who can control the contents of the template… | |
| Analizada | Media (6.5) | 0.62% | — | Pwndoc Project Pwndoc | 10/12/2024 | 17/6/2026 | PwnDoc is a penetration test report generator. In versions up to and including 0.5.3, an authenticated user is able to crash the backend by raising a `UnhandledPromiseRejection` on audits which exits the backend. The user doesn't need to know the audit id, since a bad audit id will also raise the rejection. With the… | |
| Analizada | Alta (8.5) | 0.69% | — | Pwndoc Project Pwndoc | 10/12/2024 | 17/6/2026 | PwnDoc is a penetration test report generator. Prior to commit 1d4219c596f4f518798492e48386a20c6e9a2fe6, an authenticated user who is able to update and download templates can inject path traversal (`../`) sequences into the file extension property to read arbitrary files on the system. Commit… | |
| Aplazada | Alta (8.5) | 0.40% | — | Opendock Easy GalleryAI | 9/11/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in odihost Easy Gallery simple-gallery-odihost allows SQL Injection.This issue affects Easy Gallery: from n/a through <= 1.4. | |
| Modificada | Alta (7.5) | 0.41% | — | Bandoche Pypinksign | 16/11/2023 | 9/7/2026 | PyPinkSign v0.5.1 uses a non-random or static IV for Cipher Block Chaining (CBC) mode in AES encryption. This vulnerability can lead to the disclosure of information and communications. | |
| Modificada | Media (6.3) | 0.25% | — | PandocDebian Linux | 25/7/2023 | 17/6/2026 | Pandoc before 3.1.6 allows arbitrary file write: this can be triggered by providing a crafted image element in the input when generating files via the --extract-media option or outputting to PDF format. This allows an attacker to create or overwrite arbitrary files, depending on the privileges of the process running… | |
| Modificada | Alta (7.5) | 1.2% | — | Microsoft Pandocupload | 11/7/2023 | 17/6/2026 | MediaWiki PandocUpload Extension Remote Code Execution Vulnerability | |
| Modificada | Media (5) | 0.37% | — | PandocDebian Linux | 5/7/2023 | 17/6/2026 | Pandoc is a Haskell library for converting from one markup format to another, and a command-line tool that uses this library. Starting in version 1.13 and prior to version 3.1.4, Pandoc is susceptible to an arbitrary file write vulnerability, which can be triggered by providing a specially crafted image element in the… | |
| Modificada | Alta (8.8) | 1.9% | — | Pwndoc Project Pwndoc | 5/12/2022 | 17/6/2026 | An issue in the /api/audits component of Pwndoc v0.5.3 allows attackers to escalate privileges and execute arbitrary code via uploading a crafted audit file. | |
| Modificada | Media (5.3) | 0.81% | — | Pwndoc Project Pwndoc | 30/10/2022 | 17/6/2026 | PwnDoc through 0.5.3 might allow remote attackers to identify disabled user account names by leveraging response messages for authentication attempts. | |
| Modificada | Media (5.3) | 0.81% | — | Pwndoc Project Pwndoc | 30/10/2022 | 17/6/2026 | PwnDoc through 0.5.3 might allow remote attackers to identify valid user account names by leveraging response timings for authentication attempts. | |
| Modificada | Alta (7.8) | 0.86% | — | Iminho Mindoc | 26/5/2022 | 17/6/2026 | An arbitrary file upload vulnerability in Mindoc v2.1-beta.5 allows attackers to execute arbitrary commands via a crafted Zip file. | |
| Modificada | Crítica (9.8) | 2.3% | — | Opendocman | 18/3/2022 | 9/7/2026 | An attacker can upload or transfer files of dangerous types to the OpenDocMan 1.4.4 portal via add.php using MIME-bypass, which may be automatically processed within the product's environment or lead to arbitrary code execution. | |
| Modificada | Alta (8.8) | 2.7% | — | Pwndoc Project Pwndoc | 19/7/2021 | 17/6/2026 | PwnDoc all versions until 0.4.0 (2021-08-23) has incorrect JSON Webtoken handling, leading to incorrect access control. With a valid JSON Webtoken that is used for authentication and authorization, a user can keep his admin privileges even if he is downgraded to the "user" privilege. Even after a user's account is… | |
| Modificada | Alta (8.8) | 1.3% | — | Iminho Mindoc | 8/11/2018 | 17/6/2026 | An issue was discovered in MinDoc through v1.0.2. It allows attackers to gain privileges by uploading an image file with contents that represent an admin session, and then sending a Cookie: header with a mindoc_id value containing the relative pathname of this uploaded file. For example, the mindoc_id (aka session ID)… | |
| Modificada | Alta (8.8) | 2.5% | — | Opendocman | 10/4/2018 | 17/6/2026 | OpenDocMan 1.2.7 and earlier does not properly validate allowed actions, which allows remote authenticated users to bypass an intended access restrictions and assign administrative privileges to themselves via a crafted request to signup.php. | |
| Modificada | Crítica (9.8) | 1.4% | — | Ndocsoftware Ndoc | 26/10/2017 | 17/6/2026 | Before Thornberry NDoc version 8.0, laptop clients and the server have default database (Cache) users set up with a single password. This password is left behind in a cleartext log file during client installation on laptops. This password can be used to gain full admin/system access to client devices (if no firewall… |