Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
996 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.56% | — | Phpgurukul Online Fire Reporting System | 27/7/2023 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in PHPGurukul Online Fire Reporting System Using PHP and MySQL 1.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the website title field. | |
| Modificada | Alta (7.5) | 1.2% | — | Insightsoftware Jreport | 27/7/2023 | 9/7/2026 | Directory traversal vulnerability in Jinfornet Jreport 15.6 allows unauthenticated attackers to gain sensitive information. | |
| Modificada | Media (6.1) | 0.58% | — | Phpgurukul Online Fire Reporting System | 27/7/2023 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in PHPGurukul Online Fire Reporting System Using PHP and MySQL 1.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the team name, leader, and member fields. | |
| Modificada | Alta (7.5) | 0.63% | — | Vocera Report ServerVocera Voice Server | 25/7/2023 | 17/6/2026 | An issue was discovered in Vocera Report Server and Voice Server 5.x through 5.8. There is a Path Traversal for an Unzip operation. The Vocera Report Console contains a websocket function that allows for the restoration of the database from a ZIP archive that expects a SQL import file. During the unzip operation, the… | |
| Modificada | Alta (7.5) | 0.56% | — | Vocera Report ServerVocera Voice Server | 25/7/2023 | 17/6/2026 | An issue was discovered in Vocera Report Server and Voice Server 5.x through 5.8. There is an Access Control Violation for Database Operations. The Vocera Report Console contains a websocket interface that allows for the unauthenticated execution of various tasks and database functions. This includes system tasks, and… | |
| Modificada | Media (6.5) | 0.58% | — | Vocera Report ServerVocera Voice Server | 25/7/2023 | 17/6/2026 | An issue was discovered in Vocera Report Server and Voice Server 5.x through 5.8. There is Path Traversal in the Task Exec filename. The Vocera Report Console contains various jobs that are executed on the server at specified intervals, e.g., backup, etc. An authenticated user has the ability to modify these entries… | |
| Modificada | Alta (7.5) | 0.49% | — | Vocera Report ServerVocera Voice Server | 25/7/2023 | 17/6/2026 | An issue was discovered in Vocera Report Server and Voice Server 5.x through 5.8. There is Arbitrary File Upload. The BaseController class, that each of the service controllers derives from, allows for the upload of arbitrary files. If the HTTP request is a multipart/form-data POST request, any parameters with a… | |
| Modificada | Crítica (9.8) | 0.82% | — | Vocera Report ServerVocera Voice Server | 25/7/2023 | 17/6/2026 | An issue was discovered in Vocera Report Server and Voice Server 5.x through 5.8. There is Path Traversal via the "restore SQL data" filename. The Vocera Report Console contains a websocket function that allows for the restoration of the database from a ZIP archive that expects a SQL import file. The filename provided… | |
| Modificada | Baja (3.5) | 0.14% | — | BD Guardrails CQI Reporter | 13/7/2023 | 17/6/2026 | An insecure connection between Systems Manager and CQI Reporter application could expose infusion data to an attacker. | |
| Modificada | Media (4.8) | 0.54% | — | Phpgurukul Online Fire Reporting System | 10/7/2023 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in PHPGurukul Online Fire Reporting System Using PHP and MySQL v.1.2 allows attackers to execute arbitrary code via a crafted payload injected into the search field. | |
| Modificada | Crítica (9.8) | 0.94% | — | Tise Parking WEB Report | 10/7/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Tise Technology Parking Web Report allows SQL Injection. This issue affects Parking Web Report: before 2.1. | |
| Modificada | Media (6.1) | 0.66% | — | Techsneeze Dmarc Report | 22/6/2023 | 17/6/2026 | Cross site scripting (XSS) vulnerabiliy in dmarcts-report-viewer dashboard versions 1.1 and thru commit 8a1d882b4c481a05e296e9b38a7961e912146a0f, allows unauthenticated attackers to execute arbitrary code via the org_name or domain values. | |
| Modificada | Alta (7.8) | 2.1% | 💥 PoC | Reportlab | 5/6/2023 | 17/6/2026 | Reportlab up to v3.6.12 allows attackers to execute arbitrary code via supplying a crafted PDF file. | |
| Modificada | Alta (7.8) | 0.22% | — | Intel System Usage Report | 10/5/2023 | 17/6/2026 | Improper access control in the Intel(R) SUR software before version 2.4.8989 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Crítica (9.1) | 0.65% | — | Effectindex Tripreporter | 8/5/2023 | 17/6/2026 | `effectindex/tripreporter` is a community-powered, universal platform for submitting and analyzing trip reports. Prior to commit bd80ba833b9023d39ca22e29874296c8729dd53b, any user with an account on an instance of `effectindex/tripreporter`, e.g. `subjective.report`, may be affected by an improper password… | |
| Modificada | Crítica (10) | 1.1% | — | Jsreport | 8/5/2023 | 17/6/2026 | Code Injection in GitHub repository jsreport/jsreport prior to 3.11.3. | |
| Modificada | Alta (7.5) | 0.62% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+15 | 3/5/2023 | 17/6/2026 | When UDP profile with idle timeout set to immediate or the value 0 is configured on a virtual server, undisclosed traffic can cause TMM to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Modificada | Media (4.3) | 1.2% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+15 | 3/5/2023 | 17/6/2026 | A directory traversal vulnerability exists in an undisclosed page of the BIG-IP Configuration utility which may allow an authenticated attacker to read files with .xml extension. Access to restricted information is limited and the attacker does not control what information is obtained. Note: Software versions which… | |
| Modificada | Media (6.1) | 0.39% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+15 | 3/5/2023 | 17/6/2026 | Multiple reflected cross-site scripting (XSS) vulnerabilities exist in undisclosed pages of the BIG-IP Configuration utility which allow an attacker to run JavaScript in the context of the currently logged-in user. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Modificada | Media (5.3) | 0.56% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+16 | 3/5/2023 | 17/6/2026 | When an SSL profile is configured on a Virtual Server, undisclosed traffic can cause an increase in CPU or SSL accelerator resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Modificada | Crítica (9.8) | 0.89% | — | Moxa Miineport E1 Firmware | 27/4/2023 | 17/6/2026 | Moxa MiiNePort E1 has a vulnerability of insufficient access control. An unauthenticated remote user can exploit this vulnerability to perform arbitrary system operation or disrupt service. | |
| Modificada | Media (6.1) | 0.51% | — | Eslint-detailed-reporter Project Eslint-detailed-reporter | 20/4/2023 | 17/6/2026 | A vulnerability was found in mportuga eslint-detailed-reporter up to 0.9.0 and classified as problematic. Affected by this issue is the function renderIssue in the library lib/template-generator.js. The manipulation of the argument message leads to cross site scripting. The attack may be launched remotely. The patch… | |
| Modificada | Media (6.5) | 0.54% | — | Jenkins Report Portal | 12/4/2023 | 17/6/2026 | A missing permission check in Jenkins Report Portal Plugin 0.5 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified bearer token authentication. | |
| Modificada | Alta (8.8) | 0.78% | — | Jenkins Report Portal | 12/4/2023 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins Report Portal Plugin 0.5 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified bearer token authentication. | |
| Modificada | Media (4.3) | 0.43% | — | Jenkins Report Portal | 12/4/2023 | 17/6/2026 | Jenkins Report Portal Plugin 0.5 and earlier does not mask ReportPortal access tokens displayed on the configuration form, increasing the potential for attackers to observe and capture them. |