Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
384 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.85% | — | Oracle Business Intelligence | 21/4/2016 | 17/6/2026 | Unspecified vulnerability in the Oracle Business Intelligence Enterprise Edition component in Oracle Fusion Middleware 11.1.1.7.0, 11.1.1.9.0, and 12.2.1.0.0 allows remote authenticated users to affect confidentiality and integrity via vectors related to Analytics Web General. | |
| Modificada | Media (4) | 1.4% | — | Oracle Business Intelligence Publisher | 21/1/2016 | 17/6/2026 | Unspecified vulnerability in the Oracle BI Publisher component in Oracle Fusion Middleware 11.1.1.7.0, 11.1.1.9.0, and 12.2.1.0.0 allows remote authenticated users to affect confidentiality via unknown vectors. | |
| Modificada | Media (5) | 1.8% | — | Oracle E-business Intelligence | 21/1/2016 | 17/6/2026 | Unspecified vulnerability in the Oracle E-Business Intelligence component in Oracle E-Business Suite 11.5.10.2, 12.1.1, 12.1.2, and 12.1.3 allows remote attackers to affect confidentiality via unknown vectors. | |
| Modificada | Media (5) | 1.8% | — | Oracle E-business Intelligence | 21/1/2016 | 17/6/2026 | Unspecified vulnerability in the Oracle E-Business Intelligence component in Oracle E-Business Suite 11.5.10.2, 12.1.1, 12.1.2, and 12.1.3 allows remote attackers to affect confidentiality via unknown vectors related to Embedded Data Warehouse. | |
| Modificada | Media (5.5) | 1.4% | — | Oracle E-business Intelligence | 21/1/2016 | 17/6/2026 | Unspecified vulnerability in the Oracle E-Business Intelligence component in Oracle E-Business Suite 11.5.10.2, 12.1.1, 12.1.2, and 12.1.3 allows remote authenticated users to affect confidentiality and integrity via unknown vectors, a different vulnerability than CVE-2016-0561. | |
| Modificada | Media (5.5) | 1.4% | — | Oracle E-business Intelligence | 21/1/2016 | 17/6/2026 | Unspecified vulnerability in the Oracle E-Business Intelligence component in Oracle E-Business Suite 11.5.10.2, 12.1.1, 12.1.2, and 12.1.3 allows remote authenticated users to affect confidentiality and integrity via unknown vectors, a different vulnerability than CVE-2016-0564. | |
| Modificada | Media (6.4) | 1.8% | — | Oracle E-business Intelligence | 21/1/2016 | 17/6/2026 | Unspecified vulnerability in the Oracle E-Business Intelligence component in Oracle E-Business Suite 11.5.10.2, 12.1.1, 12.1.2, and 12.1.3 allows remote attackers to affect confidentiality and integrity via unknown vectors. | |
| Modificada | Media (6.4) | 1.8% | — | Oracle E-business Intelligence | 21/1/2016 | 17/6/2026 | Unspecified vulnerability in the Oracle E-Business Intelligence component in Oracle E-Business Suite 11.5.10.2 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Common Components, a different vulnerability than CVE-2016-0511, CVE-2016-0547, and CVE-2016-0548. | |
| Modificada | Media (6.4) | 2.2% | — | Oracle E-business Intelligence | 21/1/2016 | 17/6/2026 | Unspecified vulnerability in the Oracle E-Business Intelligence component in Oracle E-Business Suite 11.5.10.2 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Common Components, a different vulnerability than CVE-2016-0511, CVE-2016-0547, and CVE-2016-0549. | |
| Modificada | Media (6.4) | 1.8% | — | Oracle E-business Intelligence | 21/1/2016 | 17/6/2026 | Unspecified vulnerability in the Oracle E-Business Intelligence component in Oracle E-Business Suite 11.5.10.2 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Common Components, a different vulnerability than CVE-2016-0511, CVE-2016-0548, and CVE-2016-0549. | |
| Modificada | Alta (7.5) | 13% | 💥 PoC | Apache ActivemqOracle Business Intelligence PublisherOracle Fusion Middleware | 14/8/2015 | 17/6/2026 | The processControlCommand function in broker/TransportConnection.java in Apache ActiveMQ before 5.11.0 allows remote attackers to cause a denial of service (shutdown) via a shutdown command. | |
| Modificada | Baja (3.5) | 1.1% | — | IBM Cognos Business Intelligence | 12/12/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the server in IBM Cognos Business Intelligence 10.1 before IF10, 10.1.1 before IF9, 10.2 before IF11, 10.2.1 before IF8, and 10.2.1.1 before IF7 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL. | |
| Modificada | Media (5) | 1.2% | — | SAP Business Intelligence Development Workbench | 6/11/2014 | 17/6/2026 | The User & Server configuration, InfoView refresh, user rights (BI-BIP-ADM) component in SAP Business Intellignece allows remote attackers to obtain audit event details via unspecified vectors. | |
| Modificada | Media (5) | 1.2% | — | SAP Business Intelligence Development Workbench | 6/11/2014 | 17/6/2026 | The SAP Business Intelligence Development Workbench allows remote attackers to obtain sensitive information by reading unspecified files. | |
| Modificada | Media (5.4) | 0.27% | — | Magzter Business Intelligence | 19/10/2014 | 17/6/2026 | The Business Intelligence (aka com.magzter.businessintelligence) application 3.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Baja (3.5) | 1.1% | — | IBM Cognos Business Intelligence | 22/2/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the server in IBM Cognos Business Intelligence (BI) 8.4.1, 10.1 before IF6, 10.1.1 before IF5, 10.2 before IF7, 10.2.1 before IF4, and 10.2.1.1 before IF4 allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter that is not properly handled… | |
| Modificada | Media (5) | 1.8% | — | IBM Cognos Business Intelligence | 22/2/2014 | 17/6/2026 | The server in IBM Cognos Business Intelligence (BI) 8.4.1, 10.1 before IF6, 10.1.1 before IF5, 10.2 before IF7, 10.2.1 before IF4, and 10.2.1.1 before IF4 allows remote authenticated users to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity reference,… | |
| Modificada | Media (4.3) | 1.4% | — | IBM Cognos Business Intelligence | 22/2/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the server in IBM Cognos Business Intelligence (BI) 8.4.1, 10.1 before IF6, 10.1.1 before IF5, 10.2 before IF7, 10.2.1 before IF4, and 10.2.1.1 before IF4 allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter. | |
| Modificada | Media (4) | 5.6% | 💥 Exploit | IBM Cognos Business Intelligence | 18/11/2013 | 16/6/2026 | IBM Cognos Business Intelligence 8.4.1 before IF3, 10.1.0 before IF4, 10.1.1 before IF4, 10.2.0 before IF4, 10.2.1 before IF2, and 10.2.1.1 before IF1 allows remote authenticated users to read arbitrary files via an XML external entity declaration in conjunction with an entity reference, related to an XML External… | |
| Modificada | Media (5) | 2.3% | — | IBM Cognos Business Intelligence | 18/11/2013 | 16/6/2026 | The servlet gateway in IBM Cognos Business Intelligence 8.4.1 before IF3, 10.1.0 before IF4, 10.1.1 before IF4, 10.2.0 before IF4, 10.2.1 before IF2, and 10.2.1.1 before IF1 allows remote attackers to cause a denial of service (temporary gateway outage) via crafted HTTP requests. | |
| Modificada | Baja (2.6) | 1.7% | — | IBM Cognos Business Intelligence | 27/8/2013 | 16/6/2026 | Absolute path traversal vulnerability in the server in IBM Cognos Business Intelligence (BI) 8.4.1, 10.1, 10.1.1, 10.2, and 10.2.1 allows remote authenticated users to read files by leveraging the Report Author privilege, a different vulnerability than CVE-2013-2978. | |
| Modificada | Baja (2.1) | 1.3% | — | IBM Cognos Business Intelligence | 27/8/2013 | 16/6/2026 | Absolute path traversal vulnerability in the server in IBM Cognos Business Intelligence (BI) 8.4.1, 10.1, 10.1.1, 10.2, and 10.2.1 allows remote authenticated users to read files by leveraging the Report Author privilege, a different vulnerability than CVE-2013-2988. | |
| Modificada | Baja (3.5) | 1.1% | — | IBM Cognos Business Intelligence | 27/8/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the server in IBM Cognos Business Intelligence (BI) 8.4.1, 10.1, 10.1.1, 10.2, and 10.2.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (9.3) | 3.9% | — | IBM Cognos Business Intelligence | 5/3/2013 | 16/6/2026 | IBM Cognos Business Intelligence (BI) 8.4.1 before IF1, 10.1 before IF2, 10.1.1 before IF2, and 10.2 before IF1 does not properly validate Java serialized input, which allows remote attackers to execute arbitrary commands via unspecified vectors. | |
| Modificada | Media (5) | 1.3% | — | IBM Cognos Business Intelligence | 5/3/2013 | 16/6/2026 | IBM Cognos Business Intelligence (BI) 8.4.1 before IF1, 10.1 before IF2, 10.1.1 before IF2, and 10.2 before IF1 allows remote attackers to conduct XPath injection attacks, and call XPath extension functions, via unspecified vectors. |