Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

2087 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.1)0.61%—Sonatype Nexus Repository Manager8/4/202618/9/2026
A reflected cross-site scripting vulnerability exists in Sonatype Nexus Repository versions 3.0.0 through 3.90.2 that allows unauthenticated remote attackers to execute arbitrary JavaScript in a victim's browser through a specially crafted URL. Exploitation requires user interaction.
AnalizadaCrítica (9.4)0.77%—Sonatype Nexus Repository Manager8/4/202618/9/2026
A vulnerability in the task management component of Sonatype Nexus Repository versions 3.22.1 through 3.90.2 allows an authenticated attacker with task creation permissions to execute arbitrary code, bypassing the nexus.scripts.allowCreation security control.
AplazadaMedia (5.3)0.44%—Mainwp Child ReportsAI8/4/202624/7/2026
The MainWP Child Reports plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 2.2.6. This is due to a missing capability check in the heartbeat_received() function in the Live_Update class. This makes it possible for authenticated attackers, with Subscriber-level access and…
Pendiente de análisisMedia (5.3)0.40%—Wikimedia MediawikiAIWikimedia ReportincidentAI7/4/202621/7/2026
Allocation of resources without limits or throttling vulnerability in Wikimedia Foundation MediaWiki - ReportIncident Extension allows HTTP DoS. This issue was remediated only on the `master` branch.
AnalizadaMedia (4.8)1.0%—Zohocorp Manageengine Exchange Reporter Plus3/4/202620/7/2026
Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Permissions Based on Mailboxes report.
AnalizadaMedia (4.8)1.0%—Zohocorp Manageengine Exchange Reporter Plus3/4/202624/7/2026
Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Non-Owner Mailbox Permission report.
AnalizadaMedia (5.4)1.0%—Zohocorp Manageengine Exchange Reporter Plus3/4/202624/7/2026
Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Folder Message Count and Size report.
AnalizadaMedia (4.8)1.0%—Zohocorp Manageengine Exchange Reporter Plus3/4/202624/7/2026
Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Public Folder Client Permissions report.
AnalizadaMedia (4.8)1.0%—Zohocorp Manageengine Exchange Reporter Plus3/4/202624/7/2026
Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Equipment Mailbox Details report.
AnalizadaMedia (4.8)1.0%—Zohocorp Manageengine Exchange Reporter Plus3/4/202624/7/2026
Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Mails Exchanged Between Users report.
AnalizadaMedia (4.8)1.0%—Zohocorp Manageengine Exchange Reporter Plus3/4/202624/7/2026
Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Permissions based on Distribution Groups report.
AnalizadaMedia (4.8)1.0%—Zohocorp Manageengine Exchange Reporter Plus3/4/202624/7/2026
Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Distribution Lists report.
AplazadaCrítica (9.3)0.28%—Wpfactory Advanced Woocommerce Product Sales ReportingAI25/3/202617/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPFactory Advanced WooCommerce Product Sales Reporting webd-woocommerce-advanced-reporting-statistics allows Blind SQL Injection.This issue affects Advanced WooCommerce Product Sales Reporting: from n/a through <=…
AnalizadaAlta (7.5)0.52%—Qameta Allure Report20/3/202617/6/2026
Allure 2 is the version 2.x branch of Allure Report, a multi-language test reporting tool. The Allure report generator prior to version 2.38.0 is vulnerable to an arbitrary file read via path traversal when processing test results. An attacker can craft a malicious result file (-result.json, -container.json, or…
AplazadaMedia (4.4)0.24%—CM Custom ReportsAI20/3/202617/6/2026
The CM Custom Reports – Flexible reporting to track what matters most plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.2.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
AnalizadaAlta (8.1)0.27%—Devolutions HUB Reporting Service18/3/202617/6/2026
Improper certificate validation in Devolutions Hub Reporting Service 2025.3.1.1 and earlier allows a network attacker to perform a man-in-the-middle attack via disabled TLS certificate verification.
Pendiente de análisisAlta (8.8)0.46%—Microsoft Dynamics 365 Customer EngagementAIMicrosoft SQL Server Reporting ServicesAI18/3/202617/6/2026
Microsoft Dynamics 365 Customer Engagement (on-premises) 1612 (9.0.2.3034) allows the generation of customized reports via raw SQL queries in an upload of a .rdl (Report Definition Language) file; this is then processed by the SQL Server Reporting Service. An account with the privilege Add Reporting Services Reports…
AnalizadaAlta (8.8)2.5%💥 PoCMicrosoft Sharepoint Server10/3/202617/6/2026
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
AnalizadaAlta (7.8)0.43%—Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Sharepoint Server10/3/202617/6/2026
Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally.
AnalizadaAlta (8.8)1.3%—Microsoft Sharepoint Server10/3/202617/6/2026
Improper input validation in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
AnalizadaCrítica (9.3)1.2%—Microsoft Sharepoint Server10/3/202617/6/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
AplazadaMedia (6.1)0.23%—CM Custom ReportsAI7/3/202617/6/2026
The CM Custom Reports plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'date_from' and 'date_to' parameters in all versions up to, and including, 1.2.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…
AplazadaMedia (6.6)0.28%—Hallo Welt Gmbh Extension NsfilerepoAIHallowelt BluespiceAI4/3/202617/6/2026
Files or Directories Accessible to External Parties, Incorrect Permission Assignment for Critical Resource vulnerability in Hallo Welt! GmbH BlueSpice (Extension:NSFileRepo modules) allows Accessing Functionality Not Properly Constrained by ACLs, Bypassing Electronic Locks and Access Controls.This issue affects…
AnalizadaMedia (6.1)0.28%—Denpiligrim Repostat25/2/202617/6/2026
Repostat is a React component to fetch and display GitHub repository info. Prior to version 1.0.1, the `RepoCard` component is vulnerable to Reflected Cross-Site Scripting (XSS). The vulnerability occurs because the component uses React's `dangerouslySetInnerHTML` to render the repository name (`repo` prop) during the…
AnalizadaAlta (7.8)0.13%—Dell Repository Manager23/2/202617/6/2026
Dell Repository Manager (DRM), versions prior to 3.4.8, contains an Uncontrolled Search Path Element vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary code execution and escalation of privileges.