Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

996 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.5)0.48%—ReporticoAI27/3/202417/6/2026
SQL Injection vulnerability in Reportico Till 8.1.0 allows attackers to obtain sensitive information or other system information via the project parameter.
AnalizadaAlta (8.8)1.1%—Progress Telerik Reporting20/3/202417/6/2026
In Progress® Telerik® Reporting versions prior to 2024 Q1 (18.0.24.130), a code execution attack is possible by a remote threat actor through an insecure deserialization vulnerability.
AnalizadaAlta (7.8)0.42%—Progress Telerik Reporting20/3/202417/6/2026
In Progress® Telerik® Reporting versions prior to 2024 Q1 (18.0.24.130), a code execution attack is possible by a local threat actor through an insecure deserialization vulnerability.
AnalizadaAlta (8.8)40%💥 ExploitProgress Telerik Report Server20/3/202417/6/2026
In Progress® Telerik® Report Server versions prior to 2024 Q1 (10.0.24.130), a remote code execution attack is possible through an insecure deserialization vulnerability.
AplazadaCrítica (9.8)1.2%—Advancedplugins Reports StatisticsAI19/3/202417/6/2026
An issue in Advanced Plugins reportsstatistics v1.3.20 and before allows a remote attacker to execute arbitrary code via the Sales Reports, Statistics, Custom Fields & Export module.
AnalizadaAlta (8.8)0.54%—Code-projects Crime Reporting System23/2/202417/6/2026
A vulnerability was found in code-projects Crime Reporting System 1.0. It has been rated as critical. This issue affects some unknown processing of the file police_add.php. The manipulation of the argument police_name/police_id/police_spec/password leads to sql injection. The exploit has been disclosed to the public…
AnalizadaCrítica (9.8)0.58%—Code-projects Crime Reporting System23/2/202417/6/2026
A vulnerability was found in code-projects Crime Reporting System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file inchargelogin.php. The manipulation of the argument email/password leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to…
AnalizadaAlta (8.8)5.0%—Zohocorp Manageengine Exchange Reporter Plus16/2/202417/6/2026
Zoho ManageEngine Exchange Reporter Plus versions 5714 and below are vulnerable to the Authenticated SQL injection in report exporting feature.
ModificadaAlta (7.8)0.17%—Intel System Usage Report14/2/202417/6/2026
Incorrect default permissions in the Intel(R) SUR for Gameplay Software before version 2.0.1901 may allow privillaged user to potentially enable escalation of privilege via local access.
ModificadaMedia (6.5)0.33%—Intel System Usage Report FOR Gameplay14/2/202417/6/2026
Improper access control in some Intel(R) SUR software before version 2.4.10587 may allow an unauthenticated user to potentially enable denial of service via adjacent access.
ModificadaMedia (6.7)0.19%—Intel System Usage Report FOR Gameplay14/2/202417/6/2026
Uncontrolled search path in the Intel(R) SUR for Gameplay Software before version 2.0.1901 may allow a privillaged user to potentially enable escalation of privilege via local access.
ModificadaAlta (7.8)0.19%—Progress Telerik Reporting31/1/202417/6/2026
In Telerik Reporting versions prior to 2024 R1, a privilege elevation vulnerability has been identified in the applications installer component. In an environment where an existing Telerik Reporting install is present, a lower privileged user has the ability to manipulate the installation package to elevate their…
ModificadaMedia (6.5)0.40%—Zorem Sales Report Email FOR Woocommerce17/1/202417/6/2026
Missing Authorization vulnerability in Zorem Sales Report Email for WooCommerce.This issue affects Sales Report Email for WooCommerce: from n/a through 2.8.
ModificadaMedia (6.9)0.63%—Ocsinventory-ng Ocsinventory-ocsreports4/1/202417/6/2026
OCSInventory allow stored email template with special characters that lead to a Stored cross-site Scripting.
ModificadaCrítica (9.8)0.77%—Ureport2 Project Ureport23/1/202417/6/2026
Arbitrary File Write vulnerability in the saveReportFile method of ureport2 2.2.9 and before allows attackers to write arbitrary files and run arbitrary commands via crafted POST request.
ModificadaAlta (8.8)0.90%—Esiteq WP Report Post18/12/202317/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Alex Raven WP Report Post allows SQL Injection.This issue affects WP Report Post: from n/a through 2.1.2.
ModificadaAlta (7.5)0.95%—Ureport Project Ureport28/11/202317/6/2026
An arbitrary file read vulnerability in ureport v2.2.9 allows a remote attacker to arbitrarily read files on the server by inserting a crafted path.
ModificadaCrítica (9.8)0.84%—Jeecg Jimureport27/11/202317/6/2026
A vulnerability classified as critical was found in jeecgboot JimuReport up to 1.6.1. Affected by this vulnerability is an unknown functionality of the file /download/image. The manipulation of the argument imageUrl leads to relative path traversal. The attack can be launched remotely. The exploit has been disclosed…
ModificadaMedia (6.5)0.68%—Switchwp WP Client Reports23/11/202317/6/2026
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in SwitchWP WP Client Reports plugin <= 1.0.16 versions.
ModificadaMedia (5.5)0.69%—Zohocorp Manageengine Analytics PlusZohocorp Manageengine AppcreatorZohocorp Manageengine Application Control PlusZohocorp Manageengine Browser Security Plus+3515/11/202317/6/2026
An information disclosure vulnerability exists in multiple ManageEngine products that can result in encryption keys being exposed. A low-privileged OS user with access to the host where an affected ManageEngine product is installed can view and use the exposed key to decrypt product database passwords. This allows the…
ModificadaAlta (8.8)0.30%—Esiteq WP Report Post9/11/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Alex Raven WP Report Post plugin <= 2.1.2 versions.
ModificadaMedia (4.8)0.37%—Reportico2/11/202317/6/2026
Reportico 7.1.21 is vulnerable to Cross Site Scripting (XSS).
ModificadaMedia (4.8)0.37%—Vermeg Agile Reporter27/10/202317/6/2026
An issue was discovered in VERMEG AgileReporter 21.3. Attackers can gain privileges via an XSS payload in an Add Comment action to the Activity log.
ModificadaMedia (5.4)0.36%—Vermeg Agile Reporter27/10/202317/6/2026
An issue was discovered in VERMEG AgileReporter 21.3. An admin can enter an XSS payload in the Analysis component.
ModificadaMedia (6.5)0.67%—Vermeg Agile Reporter27/10/202317/6/2026
An issue was discovered in VERMEG AgileReporter 21.3. XXE can occur via an XML document to the Analysis component.
Orbitaley — Vulnerabilidades