Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2533▼ 411 respecto a la semana anterior
Críticas / altas1305▲ 22 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)59▼ 467 respecto a la semana anterior
17 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9) | 1.3% | — | R-soft DMSAI | 10/7/2026 | 10/7/2026 | R-SOFT DMS is vulnerable to OS Command Injection in the Optical Character Recognition (OCR) module. Multiple command execution functions accept user-controllable file paths without proper sanitization before passing them to the system shell via SSH. In current infrastructure the URL encoding neutralizes the injection… | |
| Aplazada | Alta (8.2) | 0.27% | — | R-soft DMSAI | 10/7/2026 | 10/7/2026 | R-SOFT DMS stores superadmin credentials using a non-salted nested MD5 hash. This allows an attacker who obtain password hash to decode superadmin credentials. Critically, this password cannot be changed except by modifying the configuration file. This issue was fixed in version v3.17-2000. | |
| Aplazada | Alta (7.1) | 0.47% | — | R-soft DMSAI | 10/7/2026 | 10/7/2026 | R-SOFT DMS is vulnerable to Insecure Direct Object Reference (IDOR) attack in multiple file download endpoints. The application fetches files from the database by ID and serves them to whoever requests them, relying only on session authentication, meaning any valid user can access any file. This issue was fixed in… | |
| Aplazada | Media (5.1) | 0.39% | — | R-soft DMSAI | 10/7/2026 | 10/7/2026 | R-SOFT DMS is vulnerable to Stored XSS in file upload functionality. Authenticated attacker can inject arbitrary HTML and JS into the name of the file being uploaded, which will be executed when visiting file list or upload status by other users. This issue was fixed in version v3.19-2832 and v3.17-2580. | |
| Aplazada | Alta (8.7) | 1.2% | — | R-soft DMSAI | 10/7/2026 | 10/7/2026 | R-SOFT DMS is vulnerable to OS Command Injection in konwertujAction() function. The document converter executes shell commands using unsanitized file paths and format parameters. This allows an authenticated attacker to execute arbitrary system commands with the privileges of the web server user. This issue was fixed… | |
| Modificada | Alta (7.8) | 0.30% | — | Power-software-download Viewpower | 16/8/2022 | 17/6/2026 | upsMonitor in ViewPower (aka ViewPowerHTML) 1.04-21012 through 1.04-21353 has insecure permissions for the service binary that enable an Authenticated User to modify files, allowing for privilege escalation. | |
| Modificada | Media (5.3) | 3.7% | — | Avanquest Expert PDF UltimateAvanquest PDF Experte UltimateFoxitsoftware Foxit ReaderGonitro Nitro PRO+13 | 7/1/2021 | 17/6/2026 | The Portable Document Format (PDF) specification does not provide any information regarding the concrete procedure of how to validate signatures. Consequently, a Signature Wrapping vulnerability exists in multiple products. An attacker can use /ByteRange and xref manipulations that are not detected by the… | |
| Modificada | Alta (7.8) | 2.5% | — | Tracker-software Pdf-xchange ViewerTracker-software Viewer AX SDK | 31/1/2018 | 17/6/2026 | Tracker PDF-XChange Viewer and Viewer AX SDK before 2.5.322.8 mishandle conversion from YCC to RGB colour spaces by calculating on the basis of 1 bpc instead of 8 bpc, which might allow remote attackers to execute arbitrary code via a crafted PDF document. | |
| Modificada | Alta (7.8) | 5.6% | — | Tracker-software Pdf-xchange Viewer | 27/12/2017 | 17/6/2026 | The launchURL function in PDF-XChange Viewer 2.5 (Build 314.0) might allow remote attackers to execute arbitrary code via a crafted PDF file. | |
| Modificada | Alta (9.3) | 6.2% | — | Tracker-software Pdf-xchange Viewer | 2/4/2014 | 16/6/2026 | Heap-based buffer overflow in Tracker Software PDF-XChange before 2.5.208 allows remote attackers to execute arbitrary code via a crafted Define Huffman Table header in a JPEG image file stream in a PDF file. | |
| Modificada | Alta (9.3) | 6.3% | — | Tracker-software Pdf-xchange | 8/10/2012 | 16/6/2026 | Multiple buffer overflows in the Pdf Printer Preferences ActiveX Control in pdfxctrl.dll in Tracker Software PDF-XChange 3.60.0128 allow remote attackers to execute arbitrary code via a long string in the (1) sub_path parameter to the StoreInRegistry function or (2) sub_key parameter to the InitFromRegistry function. | |
| Modificada | Media (6.9) | 0.40% | — | Tracker-software Pdf-xchange Viewer | 7/9/2012 | 16/6/2026 | Untrusted search path vulnerability in PDF-XChange Viewer 2.0 Build 54.0 allows local users to gain privileges via a Trojan horse wintab32.dll file in the current working directory, as demonstrated by a directory that contains a .pdf file. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (7.8) | 3.8% | — | Hammer-software Metagauge | 7/10/2008 | 16/6/2026 | Directory traversal vulnerability in MetaGauge 1.0.0.17, and probably other versions before 1.0.3.38, allows remote attackers to read arbitrary files via a "..\" (dot dot backslash) in the URL. | |
| Modificada | Alta (7.5) | 1.5% | — | Call-center-software | 7/3/2007 | 16/6/2026 | SQL injection vulnerability in Call Center Software 0.93 and earlier allows remote attackers to execute arbitrary SQL commands and bypass authentication via the user name in the login page. | |
| Modificada | Media (5.8) | 1.4% | — | Call-center-software | 7/3/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Call Center Software 0.93 and earlier allows remote attackers to inject arbitrary web script or HTML via the problem description field. | |
| Modificada | Media (5.5) | 1.3% | — | Call-center-software | 7/3/2007 | 16/6/2026 | edit_user.php in Call Center Software 0.93 and earlier allows remote attackers to obtain sensitive information such as account passwords via a modified user_id parameter. | |
| Modificada | Alta (9.3) | 5.6% | — | Rsbr-software News File Grabber | 21/2/2007 | 16/6/2026 | Stack-based buffer overflow in News File Grabber 4.1.0.1 and earlier allows remote attackers to execute arbitrary code via a .nzb file with a long subject field. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. |