Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2989▼ 87 respecto a la semana anterior
Críticas / altas1458▲ 97 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

2087 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.8)0.78%—Microsoft Sharepoint Server8/9/20269/9/2026
Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
AnalizadaAlta (8.8)0.78%—Microsoft Sharepoint Server8/9/20269/9/2026
Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
AnalizadaAlta (8.8)0.78%—Microsoft Sharepoint Server8/9/20269/9/2026
Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
AplazadaCrítica (9.2)0.42%—OcsreportsAI3/9/20263/9/2026
A stored Cross-Site Scripting (XSS) vulnerability in the notification template functionality of the endpoint /ocsreports/?function=notification. A user with administrator privileges can input malicious HTML content which is subsequently stored and displayed without proper sanitisation when other administrators access…
AplazadaAlta (8.6)0.34%—OcsreportsAI3/9/20263/9/2026
SQL injection vulnerability in the endpoint /ocsreports/index.php?function=admin_double due to improper processing of the values in the ID field included in the selected_grp_dupli[] parameter. An authenticated user with operator privileges can manipulate these values to alter the SQL queries executed by the…
AplazadaAlta (8.6)0.34%—Ocsinventory OcsreportsAI3/9/20263/9/2026
SQL injection vulnerability in the del_check parameter of the /ocsreports/?function=save_query_list endpoint. Input provided by an authenticated user with operator privileges is incorporated into an SQL query without proper parameterisation or validation, allowing the query to be manipulated and information to be…
AplazadaCrítica (9.4)0.51%—OcsreportsAI3/9/20263/9/2026
Unrestricted file upload vulnerability in the CSV file upload functionality of the Ocsreports admin_info endpoint. The application validates files solely based on the name provided by the client, without properly checking their content or securely restricting the permitted file types. This allows a user with…
AnalizadaAlta (7.1)0.29%—Sonatype Nexus Repository Manager2/9/202622/9/2026
A vulnerability was identified in Sonatype Nexus Repository 3 in which two blobstore group management REST API endpoints did not correctly enforce the intended authorization check. A user granted only the nexus:blobstores:create permission could invoke these endpoints to convert an existing blobstore into a group…
AnalizadaAlta (7.5)0.72%—Sonatype Nexus Repository Manager2/9/202622/9/2026
In affected versions of Nexus Repository 3, the script execution endpoint (POST /service/rest/v1/script/{name}/run) did not verify whether script execution had been administratively disabled. An account holding script-execution permission could continue to run previously-created scripts even after an administrator set…
AnalizadaMedia (6)0.46%—Sonatype Nexus Repository Manager2/9/202622/9/2026
Nexus Repository 3 contains a sensitive information disclosure vulnerability in the capability read API. An account holding the nexus:capabilities:read privilege can retrieve the plaintext shared secret configured on a webhook capability, which is intended to be masked from all API responses. This issue affects Nexus…
AnalizadaMedia (5.3)0.28%—Sonatype Nexus Repository Manager2/9/202622/9/2026
An authorization flaw in the REST API repository details endpoint (GET /service/rest/v1/repositories/{repositoryName}) in Sonatype Nexus Repository 3 allowed an account holding read or browse permission on a group repository to retrieve metadata for member repositories on which it held no direct permission, by…
En análisisMedia (5.3)0.25%—Sonatype Nexus Repository Manager2/9/202629/9/2026
A user account with permission to deploy artifacts to a hosted Maven repository could upload a POM file containing an oversized metadata field. This causes future attempts to list or browse that repository's components to permanently fail until an administrator repairs the underlying data. Only the targeted repository…
AnalizadaBaja (2.3)0.23%—F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+172/9/202615/9/2026
A vulnerability exists in an undisclosed BIG-IP Configuration utility page that may allow an attacker to spoof error messages Impact: An attacker may trick authenticated BIG-IP users into accessing malicious links and reflect a spoofed error message in the victim's BIG-IP Configuration utility web browser session.…
AplazadaCrítica (9.8)0.32%—Trtek Technological Products Software Repository ManagementAI25/8/202626/8/2026
Unrestricted upload of file with dangerous type vulnerability in TRtek Technological Products Computer Software Hardware Industry and Trade Limited Company Software Repository Management allows Upload a Web Shell to a Web Server. This issue affects Software Repository Management: before 2fb4acee.
AplazadaBaja (2.1)0.41%—Xianrendzw EasyreportAI19/8/202621/8/2026
A vulnerability was found in xianrendzw EasyReport up to 2.0.17.0522_Beta. Affected is the function execSqlText/previewSqlText of the file DesignerController.java of the component SQL Preview Endpoint. The manipulation of the argument sqlText results in improper neutralization of special elements used in a template…
AplazadaBaja (2.1)0.37%—Xianrendzw EasyreportAI19/8/202621/8/2026
A security vulnerability has been detected in xianrendzw EasyReport up to 2.0.17.0522_Beta. The affected element is the function DataSourceController.add of the file DataSourceController.java of the component QueryerFactory. Such manipulation of the argument queryerClass leads to permission issues. The attack can be…
AnalizadaMedia (4.7)0.12%—Oracle Hyperion Financial Reporting18/8/202624/8/2026
Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Financial Reporting executes to…
AnalizadaMedia (4.2)0.19%—Oracle Hyperion Financial Reporting18/8/202624/8/2026
Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting. Successful…
AnalizadaMedia (5.9)0.25%—Oracle Hyperion Financial Reporting18/8/202624/8/2026
Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting. Successful…
AnalizadaMedia (6.5)0.27%—Oracle Hyperion Financial Reporting18/8/202624/8/2026
Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting. Successful…
AnalizadaAlta (8.8)0.43%—Oracle Hyperion Financial Reporting18/8/202625/8/2026
Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting. Successful…
AnalizadaBaja (3.7)0.26%—Oracle Hyperion Financial Reporting18/8/202625/8/2026
Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting. Successful…
AnalizadaMedia (5.3)0.12%—Oracle Hyperion Financial Reporting18/8/202625/8/2026
Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Financial Reporting executes to…
AnalizadaMedia (6.8)0.30%—Oracle Hyperion Financial Reporting18/8/202625/8/2026
Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the…
AnalizadaBaja (2.6)0.19%—Oracle Hyperion Financial Reporting18/8/202624/8/2026
Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting. Successful…
Orbitaley — Vulnerabilidades