Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2568▼ 310 respecto a la semana anterior
Críticas / altas1351▲ 96 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
369 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.2) | 0.49% | — | Document Merge ServiceAI | 1/10/2026 | 2/10/2026 | Document Merge Service is a document template merge service providing an API to manage templates and merge them with given data. Prior to version 9.1.0, a remote code execution (RCE) via server-side template injection (SSTI) allows for user supplied code to be executed in the server's context where it is executed as… | |
| Pendiente de análisis | Crítica (9.8) | 0.96% | — | Onlyoffice Document EditingAI | 25/9/2026 | 29/9/2026 | When OnlyOffice/Document Editing is available, an unauthenticated remote attacker with access to an existing supported public Briefcase document can abuse unsigned save fields to perform path-traversal writes and execute commands as zimbra. | |
| Aplazada | Alta (8.8) | 0.57% | — | MCP Documentation ServerAI | 17/9/2026 | 30/9/2026 | MCP Documentation Server is a local-first document management and semantic search server for AI coding agents. From 1.13.0 until 1.13.1, the automatically started Web UI in src/server.ts calls startWebServer in src/web-server.ts with START_WEB_UI enabled by default and WEB_PORT set to 3080. startWebServer uses… | |
| Pendiente de análisis | Alta (7.1) | 0.41% | — | QT QdomdocumentAI | 16/9/2026 | 18/9/2026 | QDomDocument XML parsing is vulnerable to a remotely-triggerable denial-of-service crash when processing untrusted input. | |
| Pendiente de análisis | Alta (8.8) | 0.42% | — | Oracle Document Management AND CollaborationAIOracle E-business SuiteAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Oracle Document Management and Collaboration product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Document… | |
| Pendiente de análisis | Alta (7.2) | 0.46% | — | Oracle Document Management AND CollaborationAIOracle E-business SuiteAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Oracle Document Management and Collaboration product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Document… | |
| Pendiente de análisis | Crítica (9.8) | 0.48% | — | Oracle Document Management AND CollaborationAIOracle E-business SuiteAI | 15/9/2026 | 16/9/2026 | Vulnerability in the Oracle Document Management and Collaboration product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Document… | |
| Aplazada | Media (6.5) | 0.34% | — | Nl.nl-portal Documenten-apiAINl.nl-portal BesluitenAI | 11/9/2026 | 30/9/2026 | NL Portal Backend Libraries provide backend components for Dutch government portals that interact with residents, customers, suppliers, and partner organizations. The `nl.nl-portal:documenten-api` package through version 3.0.0 and the `nl.nl-portal:besluiten` package from version 1.5.0 through 3.0.0 lack per-user… | |
| Aplazada | Media (6.1) | 0.24% | — | Yordam Informatics Technology Consulting Training AND Electronic Systems Industry AND Trade Library Information AND Document Automation ProgramAI | 9/9/2026 | 9/9/2026 | URL redirection to untrusted site ('open redirect') vulnerability in Yordam Informatics Technology Consulting, Training, and Electronic Systems Industry and Trade Inc. Library Information and Document Automation Program allows Phishing. This issue affects Library Information and Document Automation Program: from v22.1… | |
| Aplazada | Media (5.3) | 0.19% | — | Yordam Informatics Technology Consulting Training AND Electronic Systems Industry AND Trade Library Information AND Document Automation ProgramAI | 9/9/2026 | 9/9/2026 | Server-Side request forgery (SSRF) vulnerability in Yordam Informatics Technology Consulting, Training, and Electronic Systems Industry and Trade Inc. Library Information and Document Automation Program allows Server Side Request Forgery. This issue affects Library Information and Document Automation Program: before… | |
| Aplazada | Media (4.8) | 0.23% | — | Opentext Documentum WebtopAI | 9/9/2026 | 9/9/2026 | Documentum Webtop versions prior to 16.7.1 software is vulnerable to an XSS | |
| Aplazada | Media (6.8) | 0.43% | — | Catfolders Document Gallery PDF LibraryAI | 5/9/2026 | 8/9/2026 | The CatFolders Document Gallery & PDF Library WordPress plugin before 2.0.7 does not properly validate a block attribute before using it as an HTML tag name in its gallery output, allowing users with the Author role and above to inject arbitrary web scripts that execute in the browser of anyone who views the affected… | |
| Aplazada | Media (6.1) | 0.15% | — | Yordam Information Technology Consulting Training AND Electronic Systems Industry AND Trade INC Library Information AND Document Automation ProgramAI | 4/9/2026 | 8/9/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Yordam Information Technology Consulting, Training and Electronic Systems Industry and Trade Inc. Library Information and Document Automation Program allows XSS Targeting HTML Attributes. This issue affects Library… | |
| Aplazada | Media (6.1) | 0.25% | — | Yordam Information Technology Consulting Training AND Electronic Systems Industry AND Trade INC Library Information AND Document Automation ProgramAI | 4/9/2026 | 8/9/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Yordam Information Technology Consulting, Training and Electronic Systems Industry and Trade Inc. Library Information and Document Automation Program allows Content Spoofing. This issue affects Library Information and… | |
| Aplazada | Alta (8.7) | 0.48% | — | OWL DocumentprocessingtoolkitAI | 4/9/2026 | 24/9/2026 | OWL's DocumentProcessingToolkit contains a server-side request forgery vulnerability in the extract_document_content tool that fetches caller-supplied URLs with no scheme, host, or IP filtering. Attackers can inject malicious URLs through prompt injection to make the server fetch internal resources, with responses… | |
| Aplazada | Media (5.3) | 0.19% | — | Catfolders Document Gallery PROAI | 29/8/2026 | 31/8/2026 | The Catfolders Document Gallery Pro WordPress plugin before 2.0.7 does not authorise some of its REST API routes, and the token identifying the requested content is forgeable client side, allowing unauthenticated users to list and download the contents of folders that were never published on the site. | |
| Aplazada | Media (5.3) | 0.19% | — | Bplugins Document EmbedderAI | 27/8/2026 | 28/8/2026 | The Document Embedder WordPress plugin before 2.3.1 does not check a document's status before issuing a download token and streaming the file, allowing unauthenticated attackers to download arbitrary Document Embedder WordPress plugin before 2.3.1 documents, including private and draft ones, by enumerating IDs. | |
| Aplazada | Alta (8.7) | 0.94% | — | 2100 Technology Official Document Management SystemAI | 17/8/2026 | 26/8/2026 | Official Document Management System developed by 2100 Technology has an Arbitrary File Upload vulnerability, allowing authenticated remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server. | |
| Analizada | Crítica (9.8) | 0.80% | — | IBM Documentation Offline | 13/8/2026 | 17/8/2026 | IBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote attacker to execute arbitrary code due to improper control of file paths. | |
| Analizada | Crítica (9.8) | 0.92% | — | IBM Documentation Offline | 13/8/2026 | 17/8/2026 | IBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote attacker to execute arbitrary code due to improper output neutralization for logs. | |
| Analizada | Alta (7.5) | 0.62% | — | IBM Documentation Offline | 13/8/2026 | 25/8/2026 | IBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote attacker to read arbitrary files due to improper limitation of a pathname to a restricted directory. | |
| Analizada | Media (5.3) | 0.36% | — | IBM Documentation Offline | 13/8/2026 | 25/8/2026 | IBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote attacker to forge valid session tokens due to the use of a hardcoded cryptographic key. | |
| Analizada | Media (5.3) | 0.46% | — | IBM Documentation Offline | 13/8/2026 | 17/8/2026 | IBM Documentation Offline 1.0.0 through 1.4.1 IBM Documentation could allow a remote attacker to obtain sensitive information due to a security misconfiguration where the documentation server binds to an unrestricted IP address. | |
| Aplazada | Alta (7.1) | 0.25% | — | Knowledge Base FOR Documentation Faqs With AI AssistanceAI | 13/8/2026 | 14/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Knowledge Base for Documentation, FAQs with AI Assistance <= 17.211.0 versions. | |
| Aplazada | Media (6.3) | 0.17% | — | Ministry OF Justice Uyap Document EditorAI | 12/8/2026 | 26/8/2026 | Improper restriction of XML external entity reference vulnerability in Ministry of Justice UYAP Document Editor allows Serialized Data External Linking. This issue affects UYAP Document Editor: from 4.5.17 before 5.4.17. |