Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
–

424 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)1.9%💥 PoCSolutions-atlantic Regulatory Reporting System2/6/202217/6/2026
Solutions Atlantic Regulatory Reporting System (RRS) v500 is vulnerable to Local File Inclusion (LFI). Any authenticated user has the ability to reference internal system files within requests made to the RRSWeb/maint/ShowDocument/ShowDocument.aspx page. The server will successfully respond with the file contents of…
ModificadaAlta (7.2)4.9%💥 ExploitOnline Fire Reporting System Project Online Fire Reporting System2/6/202217/6/2026
Online Fire Reporting System v1.0 is vulnerable to SQL Injection via /ofrs/admin/requests/take_action.php?id=.
ModificadaAlta (7.2)2.6%💥 PoCOnline Fire Reporting System Project Online Fire Reporting System2/6/202217/6/2026
Online Fire Reporting System v1.0 is vulnerable to SQL Injection via /ofrs/admin/?page=requests/manage_request&id=.
ModificadaAlta (7.2)2.0%—Online Fire Reporting System Project Online Fire Reporting System2/6/202217/6/2026
Online Fire Reporting System v1.0 is vulnerable to SQL Injection via /ofrs/admin/?page=requests/view_request&id=.
ModificadaAlta (7.2)2.0%—Online Fire Reporting System Project Online Fire Reporting System2/6/202217/6/2026
Online Fire Reporting System v1.0 is vulnerable to SQL Injection via /ofrs/admin/?page=teams/view_team&id=.
ModificadaAlta (7.2)2.0%—Online Fire Reporting System Project Online Fire Reporting System2/6/202217/6/2026
Online Fire Reporting System v1.0 is vulnerable to SQL Injection via /ofrs/admin/?page=teams/manage_team&id=.
ModificadaCrítica (9.8)7.2%💥 ExploitOnline Fire Reporting System Project Online Fire Reporting System2/6/202217/6/2026
Online Fire Reporting System v1.0 is vulnerable to SQL Injection via /ofrs/classes/Master.php?f=delete_inquiry.
ModificadaCrítica (9.8)7.2%💥 ExploitOnline Fire Reporting System Project Online Fire Reporting System2/6/202217/6/2026
Online Fire Reporting System v1.0 is vulnerable to SQL Injection via /ofrs/classes/Master.php?f=delete_team.
ModificadaCrítica (9.8)7.2%💥 ExploitOnline Fire Reporting System Project Online Fire Reporting System2/6/202217/6/2026
Online Fire Reporting System v1.0 is vulnerable to SQL Injection via /ofrs/classes/Master.php?f=delete_request.
ModificadaAlta (7.2)4.9%💥 ExploitOnline Fire Reporting System Project Online Fire Reporting System2/6/202217/6/2026
Online Fire Reporting System v1.0 is vulnerable to SQL Injection via /ofrs/admin/?page=user/manage_user&id=.
ModificadaAlta (7.2)5.0%💥 ExploitOnline Fire Reporting System Project Online Fire Reporting System2/6/202217/6/2026
Online Fire Reporting System v1.0 is vulnerable to SQL Injection via /ofrs/admin/?page=reports&date=.
ModificadaMedia (6.5)0.98%—Online Fire Reporting System Project Online Fire Reporting System2/6/202217/6/2026
Online Fire Reporting System v1.0 is vulnerable to Delete any file via /ofrs/classes/Master.php?f=delete_img.
ModificadaMedia (6.1)0.81%💥 PoCSolutions-atlantic Regulatory Reporting System2/6/202217/6/2026
Solutions Atlantic Regulatory Reporting System (RRS) v500 is vulnerable to an reflected Cross-Site Scripting (XSS) vulnerability via RRSWeb/maint/ShowDocument/ShowDocument.aspx .
AnalizadaAlta (7.5)25%💥 PoCBalasys DheaterSiemens Scalance W1750d FirmwareSuse Linux Enterprise ServerF5 Big-ip Access Policy Manager+2611/11/202123/9/2026
The Diffie-Hellman Key Agreement Protocol allows remote attackers (from the client side) to send arbitrary numbers that are actually not public keys, and trigger expensive server-side DHE modular-exponentiation calculations, aka a D(HE)at or D(HE)ater attack. The client needs very little CPU resources and network…
ModificadaMedia (6.1)0.84%—Oracle Hyperion Financial Reporting20/10/202117/6/2026
Vulnerability in the Hyperion Financial Reporting product of Oracle Hyperion (component: Repository). The supported version that is affected is 11.2.6.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Hyperion Financial Reporting. Successful attacks require…
ModificadaMedia (5.4)0.60%—Tibco Webfocus ClientTibco Webfocus InstallerTibco Webfocus Reporting Server14/9/202117/6/2026
The WebFOCUS Reporting Server and WebFOCUS Client components of TIBCO Software Inc.'s TIBCO WebFOCUS Client, TIBCO WebFOCUS Installer, and TIBCO WebFOCUS Reporting Server contain easily exploitable Stored and Reflected Cross Site Scripting (XSS) vulnerabilities that allow a low privileged attacker to social engineer a…
ModificadaAlta (8.1)1.4%—Oracle Hospitality Reporting AND Analytics21/7/202117/6/2026
Vulnerability in the Oracle Hospitality Reporting and Analytics product of Oracle Food and Beverage Applications (component: iCare, Configuration). The supported version that is affected is 9.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle…
ModificadaAlta (7.5)2.4%—Oracle Advanced Networking OptionOracle Agile Engineering Data ManagementOracle Agile Product Lifecycle ManagementOracle Agile Product Lifecycle Management FOR Process+10721/7/202125/8/2026
Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Advanced Networking Option. Successful attacks…
ModificadaCrítica (9.8)58%💥 ExploitEclipse Business Intelligence AND Reporting Tools25/6/202117/6/2026
In Eclipse BIRT versions 4.8.0 and earlier, an attacker can use query parameters to create a JSP file which is accessible from remote (current BIRT viewer dir) to inject JSP code into the running instance.
ModificadaMedia (5.4)0.52%—IBM Jazz Reporting Service13/5/202117/6/2026
IBM Jazz Reporting Service 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 198834.
ModificadaCrítica (9.8)3.2%—Dell Storage Monitoring AND ReportingDell Storage Resource Manager12/4/202117/6/2026
Dell SRM versions prior to 4.5.0.1 and Dell SMR versions prior to 4.5.0.1 contain an Untrusted Deserialization Vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability, leading to arbitrary privileged code execution on the vulnerable application. The severity is Critical as this may…
ModificadaMedia (5.5)3.3%—Apache PdfboxFedoraproject FedoraOracle Banking Corporate Lending Process ManagementOracle Banking Credit Facilities Process Management+1519/3/202117/6/2026
A carefully crafted PDF file can trigger an OutOfMemory-Exception while loading the file. This issue affects Apache PDFBox version 2.0.22 and prior 2.0.x versions.
ModificadaMedia (5.5)3.0%—Apache PdfboxFedoraproject FedoraOracle Banking Trade Finance Process ManagementOracle Banking Treasury Management+1119/3/202117/6/2026
A carefully crafted PDF file can trigger an infinite loop while loading the file. This issue affects Apache PDFBox version 2.0.22 and prior 2.0.x versions.
ModificadaAlta (7.5)3.8%—Johnsoncontrols Metasys Reporting Engine19/2/202117/6/2026
Path Traversal vulnerability exists in Metasys Reporting Engine (MRE) Web Services which could allow a remote unauthenticated attacker to access and download arbitrary files from the system.
ModificadaMedia (5.4)0.56%—IBM Jazz Reporting Service18/2/202117/6/2026
IBM Jazz Reporting Service 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 191751.