Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
–

996 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.5)0.43%—NI Woocommerce Sales ReportAI9/12/202417/6/2026
Missing Authorization vulnerability in Anzar Ahmed Ni WooCommerce Sales Report ni-woocommerce-sales-report allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ni WooCommerce Sales Report: from n/a through <= 3.7.3.
AnalizadaMedia (6.2)0.11%—Progress Telerik Report Server13/11/202417/6/2026
In Progress® Telerik® Report Server versions prior to 2024 Q4 (10.3.24.1112), the encryption of local asset data used an older algorithm which may allow a sophisticated actor to decrypt this information.
AplazadaAlta (7.1)0.27%—Tevya Happiness-reports-for-help-scoutAI9/11/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tevya Satisfaction Reports from Help Scout happiness-reports-for-help-scout allows Reflected XSS.This issue affects Satisfaction Reports from Help Scout: from n/a through <= 2.0.3.
AnalizadaAlta (8.8)0.29%—Ithemelandco Woocommerce Report5/11/202417/6/2026
The WooCommerce Report plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5.1. This is due to missing or incorrect nonce validation on the settings update functionality. This makes it possible for unauthenticated attackers to update arbitrary options that can be…
AnalizadaAlta (8.8)4.5%—Zohocorp Manageengine Exchange Reporter Plus5/11/202417/6/2026
Zohocorp ManageEngine Exchange Reporter Plus versions 5718 and prior are vulnerable to authenticated SQL Injection in reports module.
AnalizadaAlta (8.6)11%—F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+1716/10/202417/6/2026
BIG-IP monitor functionality may allow an attacker to bypass access control restrictions, regardless of the port lockdown settings. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
AplazadaMedia (6)0.42%—Mediawiki IncidentreportingAI9/10/202417/6/2026
IncidentReporting is a MediaWiki extension for moving incident reports from wikitext to database tables. There are a variety of Cross-site Scripting issues, though all of them require elevated permissions. Some are available to anyone who has the `editincidents` right, some are available to those who can edit…
ModificadaAlta (7.8)0.22%—Progress Telerik Reporting9/10/202417/6/2026
In Progress Telerik Reporting versions prior to 2024 Q3 (18.2.24.924), a code execution attack is possible using object injection via insecure expression evaluation.
AnalizadaAlta (7.2)0.82%—Progress Telerik Report Server9/10/202417/6/2026
In Progress Telerik Report Server versions prior to 2024 Q3 (10.2.24.924), a remote code execution attack is possible through object injection via an insecure type resolution vulnerability.
ModificadaAlta (8.8)0.62%—Progress Telerik Reporting9/10/202417/6/2026
In Progress Telerik Reporting versions prior to 2024 Q3 (18.2.24.924), a code execution attack is possible through object injection via an insecure type resolution vulnerability.
ModificadaAlta (7.8)0.66%—Progress Telerik Reporting9/10/202417/6/2026
In Progress Telerik Reporting versions prior to 2024 Q3 (18.2.24.924), a command injection attack is possible through improper neutralization of hyperlink elements.
AnalizadaMedia (6.5)0.34%—Progress Telerik Reporting9/10/202417/6/2026
In Progress® Telerik® Report Server versions prior to 2024 Q3 (10.2.24.806), an HTTP DoS attack is possible on anonymous endpoints without rate limiting.
AnalizadaAlta (8.8)0.33%—Progress Telerik Reporting9/10/202417/6/2026
In Progress® Telerik® Report Server versions prior to 2024 Q3 (10.2.24.806), a password brute forcing attack is possible through weak password requirements.
AnalizadaAlta (8.8)0.33%—Progress Telerik Report Server9/10/202417/6/2026
In Progress® Telerik® Report Server versions prior to 2024 Q3 (10.2.24.806), a credential stuffing attack is possible through improper restriction of excessive login attempts.
AnalizadaMedia (4.7)0.73%—Microsoft Power BI Report Server8/10/202419/8/2026
Power BI Report Server Spoofing Vulnerability
AnalizadaAlta (8.8)1.8%—Microsoft Power BI Report Server8/10/202419/8/2026
Power BI Report Server Spoofing Vulnerability
AnalizadaMedia (5.5)0.14%—IBM Cognos AnalyticsIBM Cognos Analytics Reports22/9/202417/6/2026
IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and IBM Cognos Analytics Reports for iOS 11.0.0.7 could allow a local attacker to obtain sensitive information in the form of an API key. An attacker could use this information to launch further attacks against affected…
AnalizadaCrítica (9.8)0.53%—Jeecg Jimureport10/9/202417/6/2026
An issue in the component /jeecg-boot/jmreport/dict/list of JimuReport v1.7.8 allows attacker to escalate privileges via a crafted GET request.
AnalizadaAlta (8.1)2.0%—Zohocorp Manageengine Exchange Reporter Plus30/8/202417/6/2026
Zohocorp ManageEngine Exchange Reporter Plus versions before 5715 are vulnerable to SQL Injection in the reports module.
AnalizadaAlta (8.7)0.48%—F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+1714/8/202417/6/2026
In BIG-IP tenants running on r2000 and r4000 series hardware, or BIG-IP Virtual Edition (VEs) using Intel E810 SR-IOV NIC, undisclosed traffic can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
AnalizadaMedia (5.3)0.30%—F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+1714/8/202417/6/2026
Undisclosed requests to BIG-IP iControl REST can lead to information leak of user account names. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
AnalizadaAlta (8.2)0.44%—F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+1914/8/202417/6/2026
When TCP profile with Multipath TCP enabled (MPTCP) is configured on a Virtual Server, undisclosed traffic along with conditions beyond the attackers control can cause TMM to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
AnalizadaAlta (8.7)0.48%—F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+1714/8/202417/6/2026
When a stateless virtual server is configured on BIG-IP system with a High-Speed Bridge (HSB), undisclosed requests can cause TMM to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
AplazadaAlta (8.5)0.14%—Dreamreport Dream ReportAI13/8/202417/6/2026
In Ocean Data Systems Dream Report, an incorrect permission vulnerability could allow a local unprivileged attacker to escalate their privileges and could cause a denial-of-service.
AplazadaAlta (8.5)0.30%—Dreamreport Dream ReportAI13/8/202417/6/2026
In Ocean Data Systems Dream Report, a path traversal vulnerability could allow an attacker to perform remote code execution through the injection of a malicious dynamic-link library (DLL).
Orbitaley — Vulnerabilidades