Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1306▼ 184 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

2087 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.5)0.13%—Intego LOG ReporterAI12/2/202617/6/2026
Intego Log Reporter, a macOS diagnostic utility bundled with Intego security products that collects system and application logs for support analysis, contains a local privilege escalation vulnerability. A root-executed diagnostic script creates and writes files in /tmp without enforcing secure directory handling,…
AnalizadaMedia (6.5)0.26%—Glpi-project More Reporting12/2/202617/6/2026
mreporting is the more reporting GLPI plugin. Prior to 1.9.4, there is a possible SQL injection on date change. This vulnerability is fixed in 1.9.4.
AnalizadaAlta (7.5)3.9%—Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Sharepoint Server+110/2/202617/6/2026
Deserialization of untrusted data in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a network.
AnalizadaAlta (7.5)1.5%—Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Outlook+110/2/202617/6/2026
Exposure of sensitive information to an unauthorized actor in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a network.
AnalizadaAlta (8.8)0.96%—Microsoft Power BI Report Server10/2/202619/8/2026
Improper input validation in Power BI allows an authorized attacker to execute code over a network.
AnalizadaBaja (3.5)0.23%—IBM Jazz Reporting Service4/2/202617/6/2026
IBM Jazz Reporting Service could allow an authenticated user on the network to affect the system's performance using complicated queries due to insufficient resource pooling.
AnalizadaBaja (3.5)0.22%—IBM Jazz Reporting Service4/2/202617/6/2026
IBM Jazz Reporting Service could allow an authenticated user on the host network to obtain sensitive information about other projects that reside on the server.
AnalizadaBaja (3.5)0.23%—IBM Jazz Reporting Service4/2/202617/6/2026
IBM Jazz Reporting Service could allow an authenticated user on the host network to cause a denial of service using specially crafted SQL query that consumes excess memory resources.
AnalizadaBaja (2.3)0.18%—F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+174/2/202617/6/2026
A vulnerability exists in an undisclosed BIG-IP Configuration utility page that may allow an attacker to spoof error messages. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
AplazadaMedia (5.3)0.23%—Wpfactory Advanced Woocommerce Product Sales ReportingAI3/2/202617/6/2026
Insertion of Sensitive Information Into Sent Data vulnerability in WPFactory Advanced WooCommerce Product Sales Reporting webd-woocommerce-advanced-reporting-statistics allows Retrieve Embedded Sensitive Data.This issue affects Advanced WooCommerce Product Sales Reporting: from n/a through <= 4.1.2.
AplazadaAlta (8.8)0.43%—Digital Crime Report Management SystemAI21/1/202617/6/2026
Digital Crime Report Management System 1.0 contains a critical SQL injection vulnerability affecting multiple login pages that allows unauthenticated attackers to bypass authentication. Attackers can exploit the vulnerability by sending crafted SQL injection payloads in email and password parameters across police,…
AnalizadaCrítica (9.8)0.56%💥 PoCOpensagres Xdocreport20/1/202617/6/2026
An XML External Entity (XXE) vulnerability in opensagres XDocReport v0.9.2 to v2.0.3 allows attackers to execute arbitrary code via uploading a crafted .docx file.
AnalizadaCrítica (9.8)0.57%💥 PoCOpensagres Xdocreport20/1/202617/6/2026
A Server-Side Template Injection (SSTI) vulnerability in the FreeMarker component of opensagres XDocReport v1.0.0 to v2.1.0 allows attackers to execute arbitrary code via injecting crafted template expressions.
AplazadaMedia (6.2)0.30%—Sonatype Nexus RepositoryAI14/1/202617/6/2026
Server-Side Request Forgery (SSRF) vulnerability in Sonatype Nexus Repository 3 versions 3.0.0 and later allows authenticated administrators to configure proxy repositories with URLs that can access unintended network destinations, potentially including cloud metadata services and internal network resources. A…
AplazadaMedia (5.1)0.42%—Sonatype Nexus RepositoryAI14/1/202617/6/2026
A reflected cross-site scripting vulnerability exists in Nexus Repository 3 that allows unauthenticated attackers to execute arbitrary JavaScript in a victim's browser through a specially crafted request requiring user interaction.
AnalizadaCrítica (9.8)30%⚠ Explotación activaMicrosoft Sharepoint Server13/1/202617/6/2026
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
AnalizadaMedia (5.4)7.6%—Microsoft Sharepoint Server13/1/202617/6/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
AnalizadaMedia (5.4)0.34%—Microsoft Sharepoint Server13/1/202617/6/2026
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.
AnalizadaAlta (7.8)0.81%—Microsoft Sharepoint Server13/1/202617/6/2026
Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code locally.
AnalizadaAlta (7.8)0.61%—Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Sharepoint Server+113/1/202617/6/2026
Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally.
AnalizadaAlta (8.8)19%—Microsoft Sharepoint Server13/1/202617/6/2026
Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
AnalizadaAlta (7)0.66%—Microsoft OfficeMicrosoft Office Deployment ToolMicrosoft Sharepoint Server13/1/202617/6/2026
Untrusted search path in Microsoft Office allows an unauthorized attacker to execute code locally.
AnalizadaCrítica (9.8)1.1%—Jeecg Jimureport8/1/202617/6/2026
JimuReport thru version 2.1.3 is vulnerable to remote code execution when processing user-controlled H2 JDBC URLs. The application passes the attacker-supplied JDBC URL directly to the H2 driver, allowing the use of certain directives to execute arbitrary Java code. A different vulnerability than CVE-2025-10770.
AnalizadaMedia (4.3)0.34%—Jenkins Redpen - Pipeline Reporter FOR Jira10/12/202517/6/2026
Jenkins Redpen - Pipeline Reporter for Jira Plugin 1.054.v7b_9517b_6b_202 and earlier does not correctly perform path validation of the workspace directory while uploading artifacts to Jira, allowing attackers with Item/Configure permission to retrieve files present on the Jenkins controller workspace directory.
AnalizadaCrítica (9)1.0%—Microsoft Sharepoint Server9/12/202517/6/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.