Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▲ 10 respecto a la semana anterior
Críticas / altas1458▲ 322 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
19 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.8) | 0.23% | — | Opentext Documentum WebtopAI | 9/9/2026 | 9/9/2026 | Documentum Webtop versions prior to 16.7.1 software is vulnerable to an XSS | |
| Modificada | Media (6.1) | 1.5% | — | Opentext Documentum Webtop | 21/3/2019 | 17/6/2026 | XSS and/or a Client Side URL Redirect exists in OpenText Documentum Webtop 5.3 SP2. The parameter startat in "/webtop/help/en/default.htm" is vulnerable. | |
| Modificada | Alta (8.8) | 1.4% | — | Opentext Documentum AdministratorOpentext Documentum Webtop | 28/9/2017 | 17/6/2026 | Multiple XML external entity (XXE) vulnerabilities in the OpenText Documentum Webtop 6.8.0160.0073 allow remote authenticated users to list the contents of arbitrary directories, read arbitrary files, cause a denial of service, or, on Windows, obtain Documentum user hashes via a (1) crafted DTD, involving unspecified… | |
| Modificada | Alta (8.8) | 1.2% | — | Opentext Documentum AdministratorOpentext Documentum Webtop | 28/9/2017 | 17/6/2026 | Multiple XML external entity (XXE) vulnerabilities in the OpenText Documentum Administrator 7.2.0180.0055 allow remote authenticated users to list the contents of arbitrary directories, read arbitrary files, cause a denial of service, or, on Windows, obtain Documentum user hashes via a (1) crafted DTD, involving… | |
| Modificada | Media (6.1) | 0.83% | — | Opentext Documentum AdministratorOpentext Documentum Webtop | 28/9/2017 | 17/6/2026 | Multiple open redirect vulnerabilities in OpenText Documentum Webtop 6.8.0160.0073 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a (1) URL in the startat parameter to xda/help/en/default.htm or (2) /%09/ (slash encoded horizontal tab slash) followed by a domain in the… | |
| Modificada | Media (6.1) | 2.9% | — | Opentext Documentum AdministratorOpentext Documentum Webtop | 28/9/2017 | 17/6/2026 | Multiple open redirect vulnerabilities in OpenText Documentum Administrator 7.2.0180.0055 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a (1) URL in the startat parameter to xda/help/en/default.htm or (2) /%09/ (slash encoded horizontal tab slash) followed by a domain… | |
| Modificada | Media (6.1) | 0.97% | — | EMC Documentum AdministratorEMC Documentum Capital ProjectsEMC Documentum TaskspaceEMC Documentum Webtop | 23/1/2017 | 17/6/2026 | EMC Documentum WebTop Version 6.8, prior to P18 and Version 6.8.1, prior to P06; and EMC Documentum TaskSpace version 6.7SP3, prior to P02; and EMC Documentum Capital Projects Version 1.9, prior to P30 and Version 1.10, prior to P17; and EMC Documentum Administrator Version 7.0, Version 7.1, and Version 7.2 prior to… | |
| Modificada | Media (6.3) | 1.3% | — | EMC Documentum AdministratorEMC Documentum Capital ProjectsEMC Documentum TaskspaceEMC Documentum Webtop | 23/6/2016 | 17/6/2026 | EMC Documentum WebTop 6.8 before Patch 13 and 6.8.1 before Patch 02, Documentum Administrator 7.x before 7.2 Patch 13, Documentum Capital Projects 1.9 before Patch 23 and 1.10 before Patch 10, and Documentum TaskSpace 6.7 SP3 allow remote authenticated users to bypass intended access restrictions and execute arbitrary… | |
| Modificada | Media (6.8) | 0.58% | — | EMC Documentum AdministratorEMC Documentum Digital Asset ManagerEMC Documentum TaskspaceEMC Documentum WEB Publisher+1 | 20/8/2015 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in EMC Documentum WebTop before 6.8P01, Documentum Administrator through 7.2, Documentum Digital Assets Manager through 6.5SP6, Documentum Web Publishers through 6.5SP7, and Documentum Task Space through 6.7SP2 allows remote attackers to hijack the authentication of… | |
| Modificada | Media (5.8) | 1.8% | — | EMC Documentum AdministratorEMC Documentum Digital Asset ManagerEMC Documentum TaskspaceEMC Documentum WEB Publisher+1 | 16/7/2015 | 17/6/2026 | Open redirect vulnerability in EMC Documentum WebTop before 6.8P02, Documentum Administrator before 7.2P01, Documentum Digital Assets Manager through 6.5SP6, Documentum Web Publishers through 6.5SP7, and Documentum Task Space through 6.7SP2 allows remote attackers to redirect users to arbitrary web sites and conduct… | |
| Modificada | Media (6.5) | 2.4% | — | EMC Documentum AdministratorEMC Documentum Digital Asset ManagerEMC Documentum TaskspaceEMC Documentum WEB Publisher+1 | 4/7/2015 | 17/6/2026 | Unrestricted file upload vulnerability in EMC Documentum WebTop 6.7SP1 before P31, 6.7SP2 before P23, and 6.8 before P01; Documentum Administrator 6.7SP1 before P31, 6.7SP2 before P23, 7.0 before P18, 7.1 before P15, and 7.2 before P01; Documentum Digital Assets Manager 6.5SP6 before P25; Documentum Web Publishers 6.5… | |
| Modificada | Baja (3.5) | 1.1% | — | EMC Documentum AdministratorEMC Documentum Digital Asset ManagerEMC Documentum TaskspaceEMC Documentum WEB Publisher+1 | 4/7/2015 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in EMC Documentum WebTop 6.7SP1 before P31, 6.7SP2 before P23, and 6.8 before P01; Documentum Administrator 6.7SP1 before P31, 6.7SP2 before P23, 7.0 before P18, 7.1 before P15, and 7.2 before P01; Documentum Digital Assets Manager 6.5SP6 before P25; Documentum Web… | |
| Modificada | Media (6.8) | 0.98% | — | EMC Digital Assets ManagerEMC Documentum AdministratorEMC Documentum Capital ProjectsEMC Documentum Records Manager+5 | 20/8/2014 | 17/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in EMC Documentum WDK before 6.7SP1 P28 and 6.7SP2 before P15 allow remote attackers to hijack the authentication of arbitrary users. | |
| Modificada | Media (4.3) | 1.8% | — | EMC Digital Assets ManagerEMC Documentum AdministratorEMC Documentum Capital ProjectsEMC Documentum Webtop+4 | 20/8/2014 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in EMC Documentum WebTop before 6.7 SP1 P28 and 6.7 SP2 before P14 allow remote attackers to inject arbitrary web script or HTML via the (1) startat or (2) entryId parameter. | |
| Modificada | Media (4.3) | 1.0% | — | EMC Documentum TaskspaceEMC Documentum Capital ProjectsEMC Documentum WDKEMC Documentum Digital Asset Manager+3 | 6/11/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in EMC Documentum Webtop before 6.7 SP2 P07, Documentum WDK before 6.7 SP2 P07, Documentum Taskspace before 6.7 SP2 P07, Documentum Records Manager before 6.7 SP2 P07, Documentum Web Publisher before 6.5 SP7, Documentum Digital Asset Manager before 6.5 SP6, Documentum… | |
| Modificada | Media (5.8) | 1.1% | — | EMC Documentum Records ManagerEMC Documentum TaskspaceEMC Documentum WDKEMC Documentum Webtop | 10/5/2013 | 16/6/2026 | EMC Documentum Webtop before 6.7 SP2, Documentum WDK before 6.7 SP2, Documentum Taskspace before 6.7 SP2, and Documentum Records Manager before 6.7 SP2 allow remote attackers to obtain sensitive information via vectors involving cross-origin frame navigation, related to a "Cross Frame Scripting" issue. | |
| Modificada | Media (4.3) | 0.94% | — | EMC Documentum Records ManagerEMC Documentum TaskspaceEMC Documentum WDKEMC Documentum Webtop | 10/5/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in EMC Documentum Webtop before 6.7 SP2, Documentum WDK before 6.7 SP2, Documentum Taskspace before 6.7 SP2, and Documentum Records Manager before 6.7 SP2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (5.8) | 1.1% | — | EMC Documentum Records ManagerEMC Documentum TaskspaceEMC Documentum WDKEMC Documentum Webtop | 10/5/2013 | 16/6/2026 | Session fixation vulnerability in EMC Documentum Webtop before 6.7 SP2, Documentum WDK before 6.7 SP2, Documentum Taskspace before 6.7 SP2, and Documentum Records Manager before 6.7 SP2 allows remote attackers to hijack web sessions via unspecified vectors. | |
| Modificada | Alta (10) | 2.6% | — | EMC Documentum AdministratorEMC Documentum Webtop | 7/2/2008 | 16/6/2026 | Unrestricted file upload vulnerability in dmclTrace.jsp in EMC Documentum Administrator 5.3.0.313 and Webtop 5.3.0.317 allows remote attackers to overwrite arbitrary files via the filename attribute. |