Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2587▼ 296 respecto a la semana anterior
Críticas / altas1355▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
46 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.4) | 0.35% | — | Wpdeveloper BetterdocsAI | 1/9/2026 | 1/9/2026 | The BetterDocs – AI Documentation, Knowledge Base, Docs, Wikis, FAQ with Chatbot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Heading 'id' Attribute in Post Content in all versions up to, and including, 4.8.1 due to insufficient input sanitization and output escaping. This makes it possible… | |
| Aplazada | Media (6.5) | 0.22% | — | Wpdeveloper BetterdocsAI | 27/7/2026 | 27/7/2026 | Contributor Cross Site Scripting (XSS) in BetterDocs <= 4.6.2 versions. | |
| Aplazada | Media (6.1) | 0.27% | — | Wpdeveloper BetterdocsAI | 16/7/2026 | 16/7/2026 | The BetterDocs WordPress plugin before 4.5.5 does not sanitise an AI-generated documentation summary before storing and outputting it, and the feature that generates it is exposed to unauthenticated users, allowing them to store a malicious payload via prompt injection that executes in the browser of any visitor who… | |
| Aplazada | Media (6.5) | 0.41% | — | Wpdeveloper BetterdocsAI | 10/7/2026 | 10/7/2026 | The BetterDocs – AI Documentation, Knowledge Base, Docs, Wikis, FAQ with Chatbot plugin for WordPress is vulnerable to generic SQL Injection via the 'lang' parameter in all versions up to, and including, 4.6.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the… | |
| Aplazada | Media (5.3) | 0.40% | — | Yardoc YardAI | 19/6/2026 | 23/6/2026 | YARD is a documentation generation tool for the Ruby programming language. Prior to version 0.9.44, YARD's static cache lookup reads a request path before the router's path cleanup runs. When a server is configured with a document root, a traversal path such as `/../yard-cache-secret.html` is joined against that root… | |
| Aplazada | Crítica (9.8) | 0.94% | — | Betterdocs PROAI | 19/6/2026 | 22/6/2026 | The BetterDocs Pro plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.8.0 via the `doc_style` parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files.… | |
| Aplazada | Media (6.4) | 0.35% | — | Wpdeveloper BetterdocsAI | 19/6/2026 | 22/6/2026 | The BetterDocs - Knowledge Base Docs & FAQ Solution for Elementor & Block Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the blockId attribute of the betterdocs/category-slate-layout Gutenberg block in versions up to, and including, 4.5.3. This is due to insufficient input sanitization… | |
| Analizada | Media (6.9) | 0.52% | — | Yardoc Yard | 8/5/2026 | 17/6/2026 | YARD is a Ruby Documentation tool. Prior to version 0.9.42, a path traversal vulnerability was discovered in YARD when using yard server to serve documentation. This bug would allow unsanitized HTTP requests to access arbitrary files on the machine of a yard server host under certain conditions. This issue has been… | |
| Aplazada | Alta (7.5) | 0.46% | — | Wptrio Betterdocs PROAI | 7/5/2026 | 17/6/2026 | The BetterDocs Pro plugin for WordPress is vulnerable to SQL Injection via the `get_current_letter_docs` and `docs_sort_by_letter` AJAX actions in all versions up to, and including, 3.7.0. This is due to the `limit` POST parameter being interpolated directly into a SQL query string before being passed to… | |
| Aplazada | Media (5.3) | 0.31% | — | Wpdeveloper BetterdocsAI | 29/4/2026 | 17/6/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in WPDeveloper BetterDocs betterdocs allows Retrieve Embedded Sensitive Data.This issue affects BetterDocs: from n/a through <= 4.3.10. | |
| Aplazada | Media (4.3) | 0.35% | — | Wpdeveloper BetterdocsAI | 24/4/2026 | 17/6/2026 | The BetterDocs plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 4.3.11. This is due to a missing capability check in the generate_openai_content_callback() function, which relies solely on a nonce rather than verifying user permissions. This makes it possible for… | |
| Aplazada | Media (6.4) | 0.26% | — | Wpsoul BetterdocsAI | 16/4/2026 | 17/6/2026 | The BetterDocs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'betterdocs_feedback_form' shortcode in all versions up to, and including, 4.3.8. This is due to insufficient input sanitization and output escaping on user supplied shortcode attributes. This makes it possible for authenticated… | |
| Analizada | Alta (7.8) | 0.49% | — | Modery Powerdocu | 9/2/2026 | 17/6/2026 | PowerDocu contains a Windows GUI executable to perform technical documentations. Prior to 2.4.0, PowerDocu contains a critical security vulnerability in how it parses JSON files within Flow or App packages. The application blindly trusts the $type property in JSON files, allowing an attacker to instantiate arbitrary… | |
| Aplazada | Media (6.5) | 0.36% | — | Wpdeveloper BetterdocsAI | 9/1/2026 | 17/6/2026 | The BetterDocs plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.3.3 via the scripts() function. This makes it possible for authenticated attackers, with contributor-level access and above, to extract sensitive data including the OpenAI API key stored in… | |
| Analizada | Alta (7) | 0.24% | — | CHT Tenderdoctransfer | 17/11/2025 | 17/6/2026 | TenderDocTransfer developed by Chunghwa Telecom has a Arbitrary File Copy and Paste vulnerability. The application sets up a simple local web server and provides APIs for communication with the target website. Due to the lack of CSRF protection in the APIs, unauthenticated remote attackers could use these APIs through… | |
| Analizada | Alta (7) | 0.27% | — | CHT Tenderdoctransfer | 17/11/2025 | 17/6/2026 | TenderDocTransfer developed by Chunghwa Telecom has a Arbitrary File Delete vulnerability. The application sets up a simple local web server and provides APIs for communication with the target website. Due to the lack of CSRF protection in the APIs, unauthenticated remote attackers could use these APIs through… | |
| Aplazada | Media (5.3) | 0.29% | — | Wpdeveloper BetterdocsAI | 16/8/2025 | 17/6/2026 | The BetterDocs – Advanced AI-Driven Documentation, FAQ & Knowledge Base Tool for Elementor & Gutenberg with Encyclopedia, AI Support, Instant Answers plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_response function in all versions up to and including… | |
| Analizada | Media (5.5) | 0.29% | — | Mrdoc | 6/5/2025 | 17/6/2026 | MrDoc v0.95 and before is vulnerable to Server-Side Request Forgery (SSRF) in the validate_url function of the app_doc/utils.py file. | |
| Analizada | Alta (8.1) | 0.37% | — | CHT Tenderdoctransfer | 16/12/2024 | 17/6/2026 | TenderDocTransfer from Chunghwa Telecom has an Arbitrary File Write vulnerability. The application sets up a simple local web server and provides APIs for communication with the target website. Due to the lack of CSRF protection for the APIs, unauthenticated remote attackers could use these APIs through phishing.… | |
| Analizada | Crítica (9.6) | 1.4% | — | CHT Tenderdoctransfer | 16/12/2024 | 17/6/2026 | TenderDocTransfer from Chunghwa Telecom has a Reflected Cross-site scripting vulnerability. The application sets up a simple local web server and provides APIs for communication with the target website. Due to the lack of CSRF protection for the APIs, unauthenticated remote attackers could use specific APIs through… | |
| Modificada | Media (4.3) | 0.34% | — | Wpdeveloper Betterdocs | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in WPDeveloper BetterDocs betterdocs allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects BetterDocs: from n/a through <= 2.5.2. | |
| Analizada | Alta (8.8) | 0.57% | — | Wpdeveloper Betterdocs | 13/8/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WPDeveloper BetterDocs allows PHP Local File Inclusion.This issue affects BetterDocs: from n/a through 3.5.8. | |
| Analizada | Media (5.4) | 0.26% | — | Wpdeveloper Betterdocs | 12/8/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPDeveloper BetterDocs allows Stored XSS.This issue affects BetterDocs: from n/a through 3.5.8. | |
| Aplazada | Media (4.5) | 1.6% | — | Ruby-lang RdocAI | 14/5/2024 | 17/6/2026 | An issue was discovered in RDoc 6.3.3 through 6.6.2, as distributed in Ruby 3.x through 3.3.0. When parsing .rdoc_options (used for configuration in RDoc) as a YAML file, object injection and resultant remote code execution are possible because there are no restrictions on the classes that can be restored. (When… | |
| Aplazada | Media (6.4) | 0.35% | — | Wpdeveloper BetterdocsAI | 9/4/2024 | 17/6/2026 | The BetterDocs – Best Documentation, FAQ & Knowledge Base Plugin with AI Support & Instant Answer For Elementor & Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 3.4.2 due to insufficient input sanitization and output… |