Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

193 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.5)0.90%💥 PoCPapermergeAI5/10/20266/10/2026
Papermerge 3.5.3 allows remote code execution by a standard user via directory traversal in a /api/documents/upload call. A Python .pth file can be written to site-packages, and its code is executed upon the next start of the Python interpreter.
AplazadaAlta (7.1)0.18%—GG Soft Software Services PaperworkAI2/10/20262/10/2026
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in GG Soft Software Services Inc. Paperwork allows SQL Injection. This issue affects Paperwork: through 2026-09-09.
Pendiente de análisisMedia (6.9)0.38%—Papercut MFAIPapercut NGAI24/9/202624/9/2026
An improper authentication vulnerability in PaperCut MF/NG allows an unauthenticated, remote attacker to trigger report generation. By submitting report generation requests without valid credentials, an attacker can generate reports and gain unauthorized access to sensitive information.
Pendiente de análisisAlta (7.3)0.74%—Papercut NGAIPapercut MFAI24/9/202625/9/2026
An improper limitation of a pathname to a restricted directory (path traversal) vulnerability in the Scan-to-Fax component of PaperCut NG and PaperCut MF allows an authenticated administrator to execute arbitrary commands on the underlying host via crafted fax provider settings.
Pendiente de análisisBaja (3.8)0.17%—Papercut HiveAIRicohAI24/9/202624/9/2026
An input validation vulnerability exists in the PaperCut Hive embedded application for Ricoh devices. The application fails to properly sanitize input received during the NFC card reading process before passing it to the application's web view interface. A local attacker with physical access to the device and a…
Pendiente de análisisAlta (7.5)0.31%—Papercut NGAIPapercut MFAI24/9/202625/9/2026
A vulnerability exists in the PaperCut NG/MF platform's device-scripting functionality due to insufficient sanitization and access restrictions within the embedded execution engine. An authenticated user with administrative access to the management interface can supply a malicious script that escapes the runtime…
AplazadaCrítica (10)0.52%—Silk Themes Newspapers XAI31/8/20261/9/2026
Improper Validation of Specified Quantity in Input vulnerability in Silk Themes Newspapers X allows Malicious Software Implanted. This issue affects Newspapers X: from 1.0.46 through 1.0.48.
AplazadaMedia (5.9)0.12%—Ash-project ASH Paper TrailAI30/8/20261/9/2026
Cleartext Storage of Sensitive Information vulnerability in ash-project ash_paper_trail allows an attacker with read access to the generated version resource to recover sensitive values nested inside embedded resources, unions, or lists. sensitive_attributes :redact and :ignore only act on the tracked resource's…
AplazadaBaja (2.1)0.18%—Ash-project ASH Paper TrailAI30/8/20261/9/2026
Inefficient Algorithmic Complexity vulnerability in ash-project ash_paper_trail allows a user who can submit a large array attribute to a paper-trailed create or update action to cause a denial of service through excessive CPU and memory use. With full-diff change tracking,…
AplazadaMedia (5.9)0.12%—Ash-project ASH Paper TrailAI30/8/20261/9/2026
Cleartext Storage of Sensitive Information vulnerability in ash-project ash_paper_trail allows an attacker with read access to the generated version resource to recover the plaintext of sensitive? attributes. AshPaperTrail stores the values of tracked sensitive? attributes in the generated version resource's changes…
AnalizadaCrítica (9.4)61%⚠ Explotación activa💥 ExploitPapercut MFPapercut NG28/8/202614/9/2026
An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and PaperCut NG. The application instantiates database driver classes based on configurable driver names without validating against an allowlist of approved drivers. If an attacker can manipulate system…
AnalizadaAlta (8.8)85%⚠ Explotación activa💥 ExploitPapercut MFPapercut NG28/8/202614/9/2026
An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG. Under specific conditions, unauthenticated remote requests targeting administrative functions can trigger backend actions prior to the completion of access validation checks. This allows an unauthenticated…
AplazadaMedia (6.1)0.28%—Nopaperforms Niaa-chatbotAI24/8/20269/9/2026
A cross-site scripting (XSS) vulnerability in Support chatbot in Nopaperforms Niaa-Chatbot through 2022-05-17 allows remote attackers to inject arbitrary web script or HTML via the Enter email parameter.
AplazadaCrítica (9.4)0.49%—PaperclipAI21/8/202624/9/2026
Paperclip before 0.3.1 in default local_trusted mode fails to validate Host headers, allowing attackers to execute arbitrary commands via DNS rebinding. An attacker can craft a malicious webpage that, when visited by a developer running Paperclip locally, uses DNS rebinding to make authenticated API requests and…
AplazadaCrítica (9.4)0.56%—Papersgpt FOR ZoteroAI11/8/202624/9/2026
PapersGPT for Zotero 0.6.1 contains a remote code execution vulnerability that allows attackers to execute arbitrary JavaScript by returning malicious code from an LLM endpoint that is passed unsanitized to window.eval() in views.ts. Attackers can exploit this through prompt injection in PDFs, MITM interception of API…
AplazadaMedia (6.5)0.34%—Paperless-ngxAI5/8/202626/8/2026
Paperless-ngx's MailAccountViewSet.test action, when called with an existing account's ID and a masked password field, reuses the stored password, account_type, refresh_token, and expiration from that existing account while allowing the caller to supply a different imap_server, imap_port, and imap_security in the same…
Pendiente de análisisMedia (6.9)0.68%💥 PoCPapercut NGAIPapercut MFAI3/8/20269/9/2026
PaperCut NG/MF contains an observable timing discrepancy in its authentication component. An unauthenticated remote attacker can exploit this vulnerability to perform username enumeration by measuring response times during login attempts. The system executes a password hash comparison only when a valid account is…
Pendiente de análisisMedia (6.9)0.68%💥 PoCPapercut NGAIPapercut MFAI3/8/20269/9/2026
PaperCut NG/MF does not properly restrict excessive authentication attempts within its login component. An unauthenticated remote attacker can exploit this vulnerability to perform unrestricted brute-force or credential-stuffing attacks without triggering account lockout or rate-limiting mechanisms in some…
AplazadaAlta (8.5)0.11%—Asus Aura Wallpaper ServiceAI15/7/202615/7/2026
Improper Restriction of Communication Channel to Intended Endpoints and External Control of File Name or Path in Aura Wallpaper Service allow a local user to perform file operations by sending crafted commands containing an arbitrary file path and bypassing the service’s path restrictions . On specific models , this…
AplazadaMedia (6.7)0.17%—Samsung Wallpaper ServiceAI10/7/202611/7/2026
Path traversal in Wallpaper service prior to SMR Jul-2026 Release 1 allows local privileged attackers to access files with system server privilege.
AplazadaBaja (2.3)0.44%—PapermarkAI29/6/202614/7/2026
Papermark through 0.22.0 contains a cross-origin resource sharing (CORS) misconfiguration vulnerability that allows unauthenticated remote attackers to perform credentialed cross-origin requests by exploiting the TUS-based viewer upload endpoint reflecting arbitrary request Origins with…
AplazadaAlta (7.3)0.18%—Papercut Print Deploy ClientAI22/6/202623/6/2026
An insecure process execution vulnerability exists in the pc-printer-updater.exe component of the PaperCut Print Deploy Client for Windows. The application, which typically operates with high-level system privileges, attempts to perform an internal validation check by invoking a secondary system utility using an…
AplazadaMedia (6.4)0.32%—Epaperflip PublisherAI9/6/202623/7/2026
The ePaperFlip Publisher plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'publicationid' attribute of the `epaperflip_embed` shortcode in all versions up to, and including, 1. This is due to insufficient input sanitization and output escaping on the shortcode attribute which is injected…
AnalizadaAlta (8.6)0.14%—Gallagher Active Directory SyncGallagher Cardholder Sync UtilityGallagher Command CentreGallagher Diagnostics Service+1125/5/202617/8/2026
Insertion of Sensitive Information into Log File (CWE-532) in some Command Centre Service installers could lead to Service Account credentials exposure. Mitigating Factor: Only sites that install Command Centre Services with a custom Service Account (not the default Network Service account) are potentially impacted.…
Pendiente de análisisMedia (5.9)0.41%—Papercut HiveAI5/5/202617/6/2026
An issue was discovered in the PaperCut Hive Ricoh embedded application. When the "Deep Logging" (diagnostic) mode is enabled, the application inadvertently records administrative credentials in plain text within the log files. An attacker with administrative access to the PaperCut Hive management portal could…
Orbitaley — Vulnerabilidades