Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
94 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.6) | 2.2% | — | Zohocorp Manageengine Exchange Reporter Plus | 9/6/2025 | 17/6/2026 | Zohocorp ManageEngine Exchange Reporter Plus versions 5721 and prior are vulnerable to Remote code execution in the Content Search module. | |
| Aplazada | Alta (7.1) | 0.26% | — | Raminmt Links Problem ReporterAI | 23/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RaminMT Links/Problem Reporter report-broken-links allows Reflected XSS.This issue affects Links/Problem Reporter: from n/a through <= 2.6.0. | |
| Aplazada | Media (6.5) | 0.37% | — | Raminmt Links Problem ReporterAI | 16/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RaminMT Links/Problem Reporter report-broken-links allows DOM-Based XSS.This issue affects Links/Problem Reporter: from n/a through <= 2.6.0. | |
| Analizada | Alta (8.8) | 4.5% | — | Zohocorp Manageengine Exchange Reporter Plus | 5/11/2024 | 17/6/2026 | Zohocorp ManageEngine Exchange Reporter Plus versions 5718 and prior are vulnerable to authenticated SQL Injection in reports module. | |
| Analizada | Alta (8.1) | 2.0% | — | Zohocorp Manageengine Exchange Reporter Plus | 30/8/2024 | 17/6/2026 | Zohocorp ManageEngine Exchange Reporter Plus versions before 5715 are vulnerable to SQL Injection in the reports module. | |
| Modificada | Alta (8.8) | 3.1% | — | Zohocorp Manageengine Exchange Reporter Plus | 26/7/2024 | 17/6/2026 | Zohocorp ManageEngine Exchange Reporter Plus versions 5717 and below are vulnerable to the authenticated SQL injection in the monitoring module. | |
| Modificada | Alta (8.8) | 3.1% | — | Zohocorp Manageengine Exchange Reporter Plus | 26/7/2024 | 17/6/2026 | Zohocorp ManageEngine Exchange Reporter Plus versions 5717 and below are vulnerable to the authenticated SQL injection in the reports module. | |
| Aplazada | Media (4.8) | 0.24% | — | Vermeg Agile ReporterAI | 17/6/2024 | 17/6/2026 | A stored cross-site scripting (XSS) in Vermeg Agile Reporter v23.2.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Message field under the Set Broadcast Message module. | |
| Aplazada | Alta (7.2) | 0.43% | — | Opentext Operations Bridge ReporterAI | 17/5/2024 | 17/6/2026 | A potential vulnerability has been identified for OpenText Operations Bridge Reporter. The vulnerability could be exploited to inject malicious SQL queries. An attack requires to be an authenticated administrator of OBR with network access to the OBR web application. | |
| Aplazada | Alta (8.8) | 1.1% | — | N-partner N-reporterAIN-partner N-cloudAI | 29/4/2024 | 17/6/2026 | N-Reporter and N-Cloud, products of the N-Partner, have an OS Command Injection vulnerability. Remote attackers with normal user privilege can execute arbitrary system commands by manipulating user inputs on a specific page. | |
| Analizada | Alta (8.8) | 5.0% | — | Zohocorp Manageengine Exchange Reporter Plus | 16/2/2024 | 17/6/2026 | Zoho ManageEngine Exchange Reporter Plus versions 5714 and below are vulnerable to the Authenticated SQL injection in report exporting feature. | |
| Modificada | Media (5.5) | 0.69% | — | Zohocorp Manageengine Analytics PlusZohocorp Manageengine AppcreatorZohocorp Manageengine Application Control PlusZohocorp Manageengine Browser Security Plus+35 | 15/11/2023 | 17/6/2026 | An information disclosure vulnerability exists in multiple ManageEngine products that can result in encryption keys being exposed. A low-privileged OS user with access to the host where an affected ManageEngine product is installed can view and use the exposed key to decrypt product database passwords. This allows the… | |
| Modificada | Media (4.8) | 0.37% | — | Vermeg Agile Reporter | 27/10/2023 | 17/6/2026 | An issue was discovered in VERMEG AgileReporter 21.3. Attackers can gain privileges via an XSS payload in an Add Comment action to the Activity log. | |
| Modificada | Media (5.4) | 0.36% | — | Vermeg Agile Reporter | 27/10/2023 | 17/6/2026 | An issue was discovered in VERMEG AgileReporter 21.3. An admin can enter an XSS payload in the Analysis component. | |
| Modificada | Media (6.5) | 0.67% | — | Vermeg Agile Reporter | 27/10/2023 | 17/6/2026 | An issue was discovered in VERMEG AgileReporter 21.3. XXE can occur via an XML document to the Analysis component. | |
| Modificada | Alta (8.1) | 2.4% | — | Zohocorp Manageengine Ad360Zohocorp Manageengine Adaudit PlusZohocorp Manageengine Admanager PlusZohocorp Manageengine Assetexplorer+13 | 28/8/2023 | 17/6/2026 | Zoho ManageEngine Active Directory 360 versions 4315 and below, ADAudit Plus 7202 and below, ADManager Plus 7200 and below, Asset Explorer 6993 and below and 7xxx 7002 and below, Cloud Security Plus 4161 and below, Data Security Plus 6110 and below, Eventlog Analyzer 12301 and below, Exchange Reporter Plus 5709 and… | |
| Modificada | Baja (3.5) | 0.14% | — | BD Guardrails CQI Reporter | 13/7/2023 | 17/6/2026 | An insecure connection between Systems Manager and CQI Reporter application could expose infusion data to an attacker. | |
| Modificada | Crítica (9.1) | 0.65% | — | Effectindex Tripreporter | 8/5/2023 | 17/6/2026 | `effectindex/tripreporter` is a community-powered, universal platform for submitting and analyzing trip reports. Prior to commit bd80ba833b9023d39ca22e29874296c8729dd53b, any user with an account on an instance of `effectindex/tripreporter`, e.g. `subjective.report`, may be affected by an improper password… | |
| Modificada | Media (6.1) | 0.51% | — | Eslint-detailed-reporter Project Eslint-detailed-reporter | 20/4/2023 | 17/6/2026 | A vulnerability was found in mportuga eslint-detailed-reporter up to 0.9.0 and classified as problematic. Affected by this issue is the function renderIssue in the library lib/template-generator.js. The manipulation of the argument message leads to cross site scripting. The attack may be launched remotely. The patch… | |
| Modificada | Alta (7.5) | 3.2% | — | Zohocorp Manageengine Exchange Reporter Plus | 17/1/2023 | 17/6/2026 | Zoho ManageEngine Exchange Reporter Plus before 5708 allows attackers to conduct XXE attacks. | |
| Modificada | Crítica (9.8) | 0.66% | — | Angular-test-reporter Project Angular-test-reporter | 9/1/2023 | 17/6/2026 | A vulnerability was found in gperson angular-test-reporter and classified as critical. This issue affects the function getProjectTables/addTest of the file rest-server/data-server.js. The manipulation leads to sql injection. The patch is named a29d8ae121b46ebfa96a55a9106466ab2ef166ae. It is recommended to apply a… | |
| Modificada | Alta (8.8) | 7.9% | 💥 Exploit | Zohocorp Manageengine Adaudit PlusZohocorp Manageengine Admanager PlusZohocorp Manageengine Adselfservice PlusZohocorp Manageengine Exchange Reporter Plus | 18/4/2022 | 17/6/2026 | Zoho ManageEngine ADSelfService Plus before 6121, ADAuditPlus 7060, Exchange Reporter Plus 5701, and ADManagerPlus 7131 allow NTLM Hash disclosure during certain storage-path configuration steps. | |
| Modificada | Media (4.3) | 0.74% | — | Jenkins Jiratestresultreporter | 29/3/2022 | 17/6/2026 | A missing permission check in Jenkins JiraTestResultReporter Plugin 165.v817928553942 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials. | |
| Modificada | Alta (8.8) | 0.72% | — | Jenkins Jiratestresultreporter | 29/3/2022 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins JiraTestResultReporter Plugin 165.v817928553942 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials. | |
| Modificada | Media (4.3) | 0.21% | — | Mcafee Content Security Reporter | 15/4/2021 | 17/6/2026 | Cleartext Transmission of Sensitive Information vulnerability in the ePO Extension of McAfee Content Security Reporter (CSR) prior to 2.8.0 allows an ePO administrator to view the unencrypted password of the McAfee Web Gateway (MWG) or the password of the McAfee Web Gateway Cloud Server (MWGCS) read only user used to… |