Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
424 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7) | 3.0% | 💥 Exploit | Redhat Automatic BUG Reporting Tool | 9/2/2018 | 26/8/2026 | The crash reporting feature in Abrt allows local users to gain privileges by leveraging an execve by root after a chroot into a user-specified directory in a namedspaced environment. | |
| Modificada | Media (6.1) | 30% | 💥 PoC | JqueryOracle Agile Product Lifecycle Management FOR ProcessOracle Banking PlatformOracle Business Process Management Suite+43 | 18/1/2018 | 17/6/2026 | jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax request is performed without the dataType option, causing text/javascript responses to be executed. | |
| Modificada | Media (6.1) | 0.82% | — | Oracle Hospitality Reporting AND Analytics | 18/1/2018 | 17/6/2026 | Vulnerability in the Oracle Hospitality Reporting and Analytics component of Oracle Hospitality Applications (subcomponent: Report). Supported versions that are affected are 8.5.1 and 9.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality… | |
| Modificada | Alta (7.1) | 0.87% | — | Oracle Hospitality Reporting AND Analytics | 18/1/2018 | 17/6/2026 | Vulnerability in the Oracle Hospitality Reporting and Analytics component of Oracle Hospitality Applications (subcomponent: Report). Supported versions that are affected are 8.5.1 and 9.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hospitality… | |
| Modificada | Crítica (9.8) | 2.0% | — | Tibco Jasperreports ServerTibco JaspersoftTibco Jaspersoft Reporting AND Analytics | 15/11/2017 | 17/6/2026 | A vulnerability in the server content cache of TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, and TIBCO Jaspersoft Reporting and Analytics for AWS contains a vulnerability which fails to prevent… | |
| Modificada | Media (5.4) | 0.69% | — | Tibco Jasperreports ServerTibco Jasperreports LibraryTibco JaspersoftTibco Jaspersoft Reporting AND Analytics+1 | 15/11/2017 | 17/6/2026 | A vulnerability in the report renderer component of TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO JasperReports Library, TIBCO JasperReports Library for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, TIBCO Jaspersoft… | |
| Modificada | Media (5) | 0.95% | — | IBM Jazz Reporting Service | 1/11/2017 | 17/6/2026 | IBM Jazz Reporting Service (JRS) 6.0.4 could allow an authenticated user to obtain information on another server that the current report builder interacts with. IBM X-Force ID: 126455. | |
| Modificada | Crítica (10) | 1.8% | — | Oracle Hospitality Reporting AND Analytics | 19/10/2017 | 17/6/2026 | Vulnerability in the Oracle Hospitality Reporting and Analytics component of Oracle Hospitality Applications (subcomponent: Report). Supported versions that are affected are 8.5.1 and 9.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality… | |
| Modificada | Crítica (9.9) | 1.5% | — | Oracle Hospitality Reporting AND Analytics | 19/10/2017 | 17/6/2026 | Vulnerability in the Oracle Hospitality Reporting and Analytics component of Oracle Hospitality Applications (subcomponent: iQuery). Supported versions that are affected are 8.5.1 and 9.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hospitality… | |
| Modificada | Alta (8) | 0.99% | — | Oracle Hospitality Reporting AND Analytics | 19/10/2017 | 17/6/2026 | Vulnerability in the Oracle Hospitality Reporting and Analytics component of Oracle Hospitality Applications (subcomponent: iQuery). Supported versions that are affected are 8.5.1 and 9.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hospitality… | |
| Modificada | Crítica (10) | 1.8% | — | Oracle Hospitality Reporting AND Analytics | 19/10/2017 | 17/6/2026 | Vulnerability in the Oracle Hospitality Reporting and Analytics component of Oracle Hospitality Applications (subcomponent: Report). Supported versions that are affected are 8.5.1 and 9.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality… | |
| Modificada | Media (6.4) | 1.2% | — | Oracle Hyperion Financial Reporting | 19/10/2017 | 17/6/2026 | Vulnerability in the Oracle Hyperion Financial Reporting component of Oracle Hyperion (subcomponent: Workspace). The supported version that is affected is 11.1.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting. While the… | |
| Modificada | Alta (7.5) | 3.2% | — | Oracle Hyperion Financial Reporting | 19/10/2017 | 17/6/2026 | Vulnerability in the Oracle Hyperion Financial Reporting component of Oracle Hyperion (subcomponent: Security Models). The supported version that is affected is 11.1.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting.… | |
| Modificada | Alta (7.4) | 1.9% | — | Dell EMC M&RDell EMC Storage Monitoring AND ReportingDell EMC Vipr SRMDell EMC VNX Monitoring AND Reporting | 22/9/2017 | 17/6/2026 | In EMC ViPR SRM, Storage M&R, VNX M&R, and M&R (Watch4Net) for SAS Solution Packs, the Java Management Extensions (JMX) protocol used to communicate between components in the Alerting and/or Compliance components can be leveraged to create a denial of service (DoS) condition. Attackers with knowledge of JMX agent user… | |
| Modificada | Alta (8.8) | 3.0% | — | Dell EMC M&RDell EMC Storage Monitoring AND ReportingDell EMC Vipr SRMDell EMC VNX Monitoring AND Reporting | 22/9/2017 | 17/6/2026 | In EMC ViPR SRM, Storage M&R, VNX M&R, and M&R (Watch4Net) for SAS Solution Packs, the Webservice Gateway is affected by a directory traversal vulnerability. Attackers with knowledge of Webservice Gateway credentials could potentially exploit this vulnerability to access unauthorized information, and modify or delete… | |
| Modificada | Media (5.3) | 0.95% | — | IBM Jazz Reporting Service | 14/9/2017 | 17/6/2026 | An unspecified vulnerability in the Lifecycle Query Engine of Jazz Reporting Service 6.0 through 6.0.4 could disclose highly sensitive information. | |
| Modificada | Media (5.3) | 0.69% | — | Elasticsearch X-packElasticsearch X-pack Reporting | 18/8/2017 | 17/6/2026 | The Reporting feature in X-Pack in versions prior to 5.5.2 and standalone Reporting plugin versions versions prior to 2.4.6 had an impersonation vulnerability. A user with the reporting_user role could execute a report with the permissions of another reporting user, possibly gaining access to sensitive data. | |
| Modificada | Media (5.4) | 1.0% | — | Oracle Hospitality Reporting AND Analytics | 8/8/2017 | 17/6/2026 | Vulnerability in the Oracle Hospitality Reporting and Analytics component of Oracle Hospitality Applications (subcomponent: Mobile Apps). Supported versions that are affected are 8.5.1 and 9.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle… | |
| Modificada | Media (6.1) | 1.5% | — | Oracle Hospitality Reporting AND Analytics | 8/8/2017 | 17/6/2026 | Vulnerability in the Oracle Hospitality Reporting and Analytics component of Oracle Hospitality Applications (subcomponent: Reporting). Supported versions that are affected are 8.5.1 and 9.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle… | |
| Modificada | Media (5.4) | 1.2% | — | Oracle Hospitality Reporting AND Analytics | 8/8/2017 | 17/6/2026 | Vulnerability in the Oracle Hospitality Reporting and Analytics component of Oracle Hospitality Applications (subcomponent: Reporting). Supported versions that are affected are 8.5.1 and 9.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hospitality… | |
| Modificada | Alta (7.7) | 1.2% | — | Oracle Hospitality Reporting AND Analytics | 8/8/2017 | 17/6/2026 | Vulnerability in the Oracle Hospitality Reporting and Analytics component of Oracle Hospitality Applications (subcomponent: Reporting). Supported versions that are affected are 8.5.1 and 9.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hospitality… | |
| Modificada | Media (4.9) | 1.2% | — | IBM Jazz Reporting Service | 31/7/2017 | 17/6/2026 | IBM Jazz Reporting Service (JRS) 5.0 and 6.0 could disclose sensitive information, including user credentials, through an error message from the Report Builder administrator configuration page. IBM X-Force ID: 126863. | |
| Modificada | Crítica (9.8) | 14% | — | Dell EMC M&RDell EMC Storage Monitoring AND ReportingDell EMC Vipr SRMDell EMC VNX Monitoring AND Reporting | 17/7/2017 | 17/6/2026 | EMC ViPR SRM, EMC Storage M&R, EMC VNX M&R, EMC M&R for SAS Solution Packs (EMC ViPR SRM prior to 4.1, EMC Storage M&R prior to 4.1, EMC VNX M&R all versions, EMC M&R (Watch4Net) for SAS Solution Packs all versions) contain undocumented accounts with default passwords for Webservice Gateway and RMI JMX components. A… | |
| Modificada | Media (4.3) | 0.96% | — | IBM Jazz Reporting Service | 5/7/2017 | 17/6/2026 | IBM Jazz Reporting Service (JRS) 5.0 and 6.0 could allow an authenticated attacker to access report data that should be restricted to authorized users. IBM X-Force ID: 122788. | |
| Modificada | Media (5.4) | 0.72% | — | IBM Jazz Reporting Service | 5/7/2017 | 17/6/2026 | IBM Jazz Reporting Service (JRS) 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 120656. |