| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2025-46448 | WordPress Document Management System plugin <= 1.24 - Cross Site Scripting (XSS) Vulnerability | reifsnyderb | Document Management System | High | 7.1 | 2025-05-23 12:43:47 | Deep Dive |
| CVE-2025-30387 | Document Intelligence Studio On-Prem Elevation of Privilege Vulnerability | Microsoft | Azure AI Document Intelligence Studio | Critical | 9.8 | 2025-05-13 16:58:47 | Deep Dive |
| CVE-2025-2866 | PDF signature forgery with adbe.pkcs7.sha1 SubFilter | The Document Foundation | LibreOffice | 中危 | - | 2025-04-27 19:04:52 | Deep Dive |
| CVE-2021-25635 | Content Manipulation with Certificate Validation Attack | The Document Foundation | LibreOffice | 中危 | - | 2025-03-21 14:52:50 | Deep Dive |
| CVE-2024-13805 | Advanced File Manager <= 5.2.14 - Authenticated (Subscriber+) Stored Cross-Site Scripting via SVG File Upload | saadiqbal | Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution | Medium | 6.4 | 2025-03-07 09:21:14 | Deep Dive |
| CVE-2025-1080 | Macro URL arbitrary script execution | The Document Foundation | LibreOffice | 超危 | - | 2025-03-04 20:04:11 | Deep Dive |
| CVE-2025-0514 | Executable hyperlink Windows path targets executed unconditionally on activation | The Document Foundation | LibreOffice | 中危 | - | 2025-02-25 21:16:31 | Deep Dive |
| CVE-2025-1043 | Embed Any Document – Embed PDF, Word, PowerPoint and Excel Files <= 2.7.5 - Authenticated (Contributor+) Blind Server-Side Request Forgery via embeddoc Shortcode | awsmin | Embed Any Document – Embed PDF, Word, PowerPoint and Excel Files | Medium | 6.4 | 2025-02-20 11:09:31 | Deep Dive |
| CVE-2024-11629 | Telerik Document Processing RTF Export of Arbitrary File Path | Progress Software | Progress® Telerik® Document Processing Libraries | High | 7.1 | 2025-02-12 16:21:52 | Deep Dive |
| CVE-2024-11343 | Telerik Document Processing Path Traversal | Progress Software | Telerik Document Processing Libraries | High | 8.3 | 2025-02-12 15:46:49 | Deep Dive |
| CVE-2025-22696 | WordPress Document Block – Upload & Embed Docs, PDF, PPT, XLS or Any Documents plugin <= 1.1.0 - Broken Access Control vulnerability | WPDeveloper | Document Block – Upload & Embed Docs | Medium | 5.4 | 2025-02-04 14:21:14 | Deep Dive |
| CVE-2024-13333 | Advanced File Manager 5.2.12 - 5.2.13 - Authenticated (Subscriber+) Arbitrary File Upload | saadiqbal | Advanced File Manager — Ultimate WordPress File Manager and Document Library Plugin | High | 7.5 | 2025-01-17 05:29:27 | Deep Dive |
| CVE-2024-12426 | URL fetching can be used to exfiltrate arbitrary INI file values and environment variables | The Document Foundation | LibreOffice | 中危 | - | 2025-01-07 12:22:33 | Deep Dive |
| CVE-2024-12425 | Path traversal leading to arbitrary .ttf file write | The Document Foundation | LibreOffice | 低危 | - | 2025-01-07 11:15:08 | Deep Dive |
| CVE-2024-13061 | 2100 Technology Electronic Official Document Management System - Authentication Bypass | 2100 Technology Electronic | Official Document Management System | Critical | 9.8 | 2024-12-31 11:13:47 | Deep Dive |
| CVE-2024-54238 | WordPress Board Document Manager from CHUHPL plugin <= 1.9.1 - Reflected Cross Site Scripting (XSS) vulnerability | Cleveland Heights-University Heights Public Library Webdeveloper | Board Document Manager from CHUHPL | High | 7.1 | 2024-12-13 14:24:32 | Deep Dive |
| CVE-2024-47580 | Multiple vulnerabilities in SAP NetWeaver AS for JAVA(Adobe Document Services) | SAP_SE | SAP NetWeaver AS for JAVA (Adobe Document Services) | Medium | 6.8 | 2024-12-10 00:12:12 | Deep Dive |
| CVE-2024-47579 | Multiple vulnerabilities in SAP NetWeaver AS for JAVA(Adobe Document Services) | SAP_SE | SAP NetWeaver AS for JAVA (Adobe Document Services) | Medium | 6.8 | 2024-12-10 00:12:05 | Deep Dive |
| CVE-2024-47578 | Multiple vulnerabilities in SAP NetWeaver AS for JAVA(Adobe Document Services) | SAP_SE | SAP NetWeaver AS for JAVA (Adobe Document Services) | Critical | 9.1 | 2024-12-10 00:11:57 | Deep Dive |
| CVE-2024-52477 | WordPress Document & Data Automation plugin <= 1.6.1 - CSRF to Stored XSS vulnerability | docxpresso | Document & Data Automation | High | 7.1 | 2024-12-02 13:48:59 | Deep Dive |