Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
1305 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.4) | 0.78% | — | Hitachi OPS Center AnalyzerAIHitachi Infrastructure Analytics AdvisorAI | 17/12/2024 | 17/6/2026 | Authentication Bypass vulnerability in Hitachi Ops Center Analyzer on Linux, 64 bit (Hitachi Ops Center Analyzer detail view component), Hitachi Infrastructure Analytics Advisor on Linux, 64 bit (Hitachi Data Center Analytics component ).This issue affects Hitachi Ops Center Analyzer: from 10.0.0-00 before 11.0.3-00;… | |
| Modificada | Alta (8.8) | 0.55% | — | Analytify - Google Analytics Dashboard | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Adnan Analytify wp-analytify allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Analytify: from n/a through <= 5.1.0. | |
| Aplazada | Media (6.5) | 0.60% | — | Veronalabs Slimstat AnalyticsAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in VeronaLabs Slimstat Analytics wp-slimstat allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Slimstat Analytics: from n/a through <= 5.0.5.1. | |
| Aplazada | Media (6.1) | 0.30% | — | Fatcatapps Analytics CATAI | 12/12/2024 | 17/6/2026 | The Analytics Cat – Google Analytics Made Easy plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.1.2. This makes it possible for unauthenticated attackers to inject arbitrary web scripts… | |
| Modificada | Media (6.5) | 0.45% | — | Analytify - Google Analytics Dashboard | 9/12/2024 | 17/6/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Adnan Analytify wp-analytify.This issue affects Analytify: from n/a through <= 5.4.3. | |
| Modificada | Media (4.3) | 0.37% | — | Analytify - Google Analytics Dashboard | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Analytify Analytify allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Analytify: from n/a through 5.1.1. | |
| Aplazada | Media (5.3) | 0.57% | — | Shaon Easy Google AnalyticsAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Shaon Easy Google Analytics for WordPress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Google Analytics for WordPress: from n/a through 1.6.0. | |
| Analizada | Alta (8.1) | 1.5% | — | Zohocorp Manageengine Analytics Plus | 27/11/2024 | 17/6/2026 | Zohocorp ManageEngine Analytics Plus versions below 6100 are vulnerable to authenticated sensitive data exposure which allows the users to retrieve sensitive tokens associated to the org-admin account. | |
| Aplazada | Media (6.5) | 0.26% | — | Bnisia IA MAP Analytics BasicAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bnisia IA Map Analytics Basic ia-map-analytics-basic allows DOM-Based XSS.This issue affects IA Map Analytics Basic: from n/a through <= 20170413. | |
| Aplazada | Media (6.5) | 0.38% | — | Karam Singh Advanced Video Player With AnalyticsAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Karam Singh Advanced Video Player with Analytics advanced-video-player-with-analytics allows DOM-Based XSS.This issue affects Advanced Video Player with Analytics: from n/a through <= 1. | |
| Analizada | Media (6.1) | 0.48% | — | Cisco Secure Network Analytics | 15/11/2024 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Secure Network Analytics, formerly Stealthwatch Enterprise, could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. The vulnerability is due to insufficient validation of… | |
| Aplazada | Media (4.3) | 0.36% | — | Cornelraiu WP Search AnalyticsAI | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in Cornel Raiu WP Search Analytics search-analytics.This issue affects WP Search Analytics: from n/a through <= 1.4.9. | |
| Analizada | Alta (8.6) | 11% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+17 | 16/10/2024 | 17/6/2026 | BIG-IP monitor functionality may allow an attacker to bypass access control restrictions, regardless of the port lockdown settings. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Analizada | Media (6.1) | 0.54% | — | Wp-slimstat Slimstat Analytics | 15/10/2024 | 17/6/2026 | The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the resource parameter in all versions up to, and including, 5.2.6 due to insufficient input sanitization and output escaping when logging visitor requests. This makes it possible for unauthenticated attackers to inject… | |
| Modificada | Media (5.3) | 0.42% | — | Quarka QA Analytics | 10/10/2024 | 17/6/2026 | The QA Analytics – Web Analytics Tool with Heatmaps & Session Replay Across All Pages plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_save_plugin_config() function in all versions up to, and including, 4.1.1.1. This makes it possible for… | |
| Aplazada | Media (6.5) | 0.48% | — | Zohocorp Manageengine Analytics PlusAIZoho Analytics On-premiseAI | 3/10/2024 | 17/6/2026 | Zohocorp ManageEngine Analytics Plus versions before 5410 and Zoho Analytics On-Premise versions before 5410 are vulnerable to Path traversal. | |
| Modificada | Media (6.1) | 0.39% | — | Cornelraiu WP Search Analytics | 1/10/2024 | 17/6/2026 | The WP Search Analytics plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.4.10. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute… | |
| Analizada | Media (6.1) | 0.47% | — | Ibericode Koko Analytics | 24/9/2024 | 17/6/2026 | The Koko Analytics plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.3.12. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if… | |
| Analizada | Media (5.5) | 0.14% | — | IBM Cognos AnalyticsIBM Cognos Analytics Reports | 22/9/2024 | 17/6/2026 | IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and IBM Cognos Analytics Reports for iOS 11.0.0.7 could allow a local attacker to obtain sensitive information in the form of an API key. An attacker could use this information to launch further attacks against affected… | |
| Aplazada | Alta (8.5) | 0.27% | — | Hitachivantara Pentaho Data IntegrationAIHitachivantara Pentaho AnalyticsAI | 12/9/2024 | 17/6/2026 | Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.1.0.0 and 9.3.0.8, including 8.3.x, discloses database passwords when searching metadata injectable fields. | |
| Analizada | Baja (3.5) | 0.18% | — | Analytify - Google Analytics Dashboard | 26/8/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Analytify.This issue affects Analytify: from n/a through 5.3.1. | |
| Analizada | Alta (8.7) | 0.48% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+17 | 14/8/2024 | 17/6/2026 | In BIG-IP tenants running on r2000 and r4000 series hardware, or BIG-IP Virtual Edition (VEs) using Intel E810 SR-IOV NIC, undisclosed traffic can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Analizada | Media (5.3) | 0.30% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+17 | 14/8/2024 | 17/6/2026 | Undisclosed requests to BIG-IP iControl REST can lead to information leak of user account names. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Analizada | Alta (8.2) | 0.44% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+19 | 14/8/2024 | 17/6/2026 | When TCP profile with Multipath TCP enabled (MPTCP) is configured on a Virtual Server, undisclosed traffic along with conditions beyond the attackers control can cause TMM to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Analizada | Alta (8.7) | 0.48% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+17 | 14/8/2024 | 17/6/2026 | When a stateless virtual server is configured on BIG-IP system with a High-Speed Bridge (HSB), undisclosed requests can cause TMM to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. |