Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1306▼ 184 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
2087 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.5) | 0.13% | — | Intego LOG ReporterAI | 12/2/2026 | 17/6/2026 | Intego Log Reporter, a macOS diagnostic utility bundled with Intego security products that collects system and application logs for support analysis, contains a local privilege escalation vulnerability. A root-executed diagnostic script creates and writes files in /tmp without enforcing secure directory handling,… | |
| Analizada | Media (6.5) | 0.26% | — | Glpi-project More Reporting | 12/2/2026 | 17/6/2026 | mreporting is the more reporting GLPI plugin. Prior to 1.9.4, there is a possible SQL injection on date change. This vulnerability is fixed in 1.9.4. | |
| Analizada | Alta (7.5) | 3.9% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Sharepoint Server+1 | 10/2/2026 | 17/6/2026 | Deserialization of untrusted data in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a network. | |
| Analizada | Alta (7.5) | 1.5% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Outlook+1 | 10/2/2026 | 17/6/2026 | Exposure of sensitive information to an unauthorized actor in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a network. | |
| Analizada | Alta (8.8) | 0.96% | — | Microsoft Power BI Report Server | 10/2/2026 | 19/8/2026 | Improper input validation in Power BI allows an authorized attacker to execute code over a network. | |
| Analizada | Baja (3.5) | 0.23% | — | IBM Jazz Reporting Service | 4/2/2026 | 17/6/2026 | IBM Jazz Reporting Service could allow an authenticated user on the network to affect the system's performance using complicated queries due to insufficient resource pooling. | |
| Analizada | Baja (3.5) | 0.22% | — | IBM Jazz Reporting Service | 4/2/2026 | 17/6/2026 | IBM Jazz Reporting Service could allow an authenticated user on the host network to obtain sensitive information about other projects that reside on the server. | |
| Analizada | Baja (3.5) | 0.23% | — | IBM Jazz Reporting Service | 4/2/2026 | 17/6/2026 | IBM Jazz Reporting Service could allow an authenticated user on the host network to cause a denial of service using specially crafted SQL query that consumes excess memory resources. | |
| Analizada | Baja (2.3) | 0.18% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+17 | 4/2/2026 | 17/6/2026 | A vulnerability exists in an undisclosed BIG-IP Configuration utility page that may allow an attacker to spoof error messages. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Aplazada | Media (5.3) | 0.23% | — | Wpfactory Advanced Woocommerce Product Sales ReportingAI | 3/2/2026 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in WPFactory Advanced WooCommerce Product Sales Reporting webd-woocommerce-advanced-reporting-statistics allows Retrieve Embedded Sensitive Data.This issue affects Advanced WooCommerce Product Sales Reporting: from n/a through <= 4.1.2. | |
| Aplazada | Alta (8.8) | 0.43% | — | Digital Crime Report Management SystemAI | 21/1/2026 | 17/6/2026 | Digital Crime Report Management System 1.0 contains a critical SQL injection vulnerability affecting multiple login pages that allows unauthenticated attackers to bypass authentication. Attackers can exploit the vulnerability by sending crafted SQL injection payloads in email and password parameters across police,… | |
| Analizada | Crítica (9.8) | 0.56% | 💥 PoC | Opensagres Xdocreport | 20/1/2026 | 17/6/2026 | An XML External Entity (XXE) vulnerability in opensagres XDocReport v0.9.2 to v2.0.3 allows attackers to execute arbitrary code via uploading a crafted .docx file. | |
| Analizada | Crítica (9.8) | 0.57% | 💥 PoC | Opensagres Xdocreport | 20/1/2026 | 17/6/2026 | A Server-Side Template Injection (SSTI) vulnerability in the FreeMarker component of opensagres XDocReport v1.0.0 to v2.1.0 allows attackers to execute arbitrary code via injecting crafted template expressions. | |
| Aplazada | Media (6.2) | 0.30% | — | Sonatype Nexus RepositoryAI | 14/1/2026 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in Sonatype Nexus Repository 3 versions 3.0.0 and later allows authenticated administrators to configure proxy repositories with URLs that can access unintended network destinations, potentially including cloud metadata services and internal network resources. A… | |
| Aplazada | Media (5.1) | 0.42% | — | Sonatype Nexus RepositoryAI | 14/1/2026 | 17/6/2026 | A reflected cross-site scripting vulnerability exists in Nexus Repository 3 that allows unauthenticated attackers to execute arbitrary JavaScript in a victim's browser through a specially crafted request requiring user interaction. | |
| Analizada | Crítica (9.8) | 30% | ⚠ Explotación activa | Microsoft Sharepoint Server | 13/1/2026 | 17/6/2026 | Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. | |
| Analizada | Media (5.4) | 7.6% | — | Microsoft Sharepoint Server | 13/1/2026 | 17/6/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | |
| Analizada | Media (5.4) | 0.34% | — | Microsoft Sharepoint Server | 13/1/2026 | 17/6/2026 | Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network. | |
| Analizada | Alta (7.8) | 0.81% | — | Microsoft Sharepoint Server | 13/1/2026 | 17/6/2026 | Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.8) | 0.61% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Sharepoint Server+1 | 13/1/2026 | 17/6/2026 | Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (8.8) | 19% | — | Microsoft Sharepoint Server | 13/1/2026 | 17/6/2026 | Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | |
| Analizada | Alta (7) | 0.66% | — | Microsoft OfficeMicrosoft Office Deployment ToolMicrosoft Sharepoint Server | 13/1/2026 | 17/6/2026 | Untrusted search path in Microsoft Office allows an unauthorized attacker to execute code locally. | |
| Analizada | Crítica (9.8) | 1.1% | — | Jeecg Jimureport | 8/1/2026 | 17/6/2026 | JimuReport thru version 2.1.3 is vulnerable to remote code execution when processing user-controlled H2 JDBC URLs. The application passes the attacker-supplied JDBC URL directly to the H2 driver, allowing the use of certain directives to execute arbitrary Java code. A different vulnerability than CVE-2025-10770. | |
| Analizada | Media (4.3) | 0.34% | — | Jenkins Redpen - Pipeline Reporter FOR Jira | 10/12/2025 | 17/6/2026 | Jenkins Redpen - Pipeline Reporter for Jira Plugin 1.054.v7b_9517b_6b_202 and earlier does not correctly perform path validation of the workspace directory while uploading artifacts to Jira, allowing attackers with Item/Configure permission to retrieve files present on the Jenkins controller workspace directory. | |
| Analizada | Crítica (9) | 1.0% | — | Microsoft Sharepoint Server | 9/12/2025 | 17/6/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. |