Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2647▼ 688 respecto a la semana anterior
Críticas / altas1257▼ 290 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 277 respecto a la semana anterior
–

996 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)0.32%—Jenkins Report Portal12/4/202317/6/2026
Jenkins Report Portal Plugin 0.5 and earlier stores ReportPortal access tokens unencrypted in job config.xml files on the Jenkins controller as part of its configuration where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system.
ModificadaMedia (6.1)0.36%—Askoc WEB Report System23/3/202317/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in As Koc Energy Web Report System allows Reflected XSS. This issue affects Web Report System: before 23.03.10.
ModificadaCrítica (9.8)0.62%—Askoc WEB Report System23/3/202317/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in As Koc Energy Web Report System allows SQL Injection. This issue affects Web Report System: before 23.03.10.
ModificadaMedia (5.3)0.44%—Schneider-electric Custom ReportsSchneider-electric Igss DashboardSchneider-electric Igss Data Server21/3/202317/6/2026
A CWE-306: Missing Authentication for Critical Function vulnerability exists in the Data Server TCP interface that could allow deletion of reports from the IGSS project report directory, this would lead to loss of data when an attacker abuses this functionality. Affected Products: IGSS Data…
ModificadaMedia (6.5)0.24%—Schneider-electric Custom ReportsSchneider-electric Igss DashboardSchneider-electric Igss Data Server21/3/202317/6/2026
A CWE-345: Insufficient Verification of Data Authenticity vulnerability exists in the Data Server that could allow the renaming of files in the IGSS project report directory, this could lead to denial of service when an attacker sends specific crafted messages to the Data Server TCP port. Affected Products: IGSS Data…
ModificadaMedia (5.3)0.24%—Schneider-electric Custom ReportsSchneider-electric Igss DashboardSchneider-electric Igss Data Server21/3/202317/6/2026
A CWE-345: Insufficient Verification of Data Authenticity vulnerability exists in the Data Server that could cause access to delete files in the IGSS project report directory, this could lead to loss of data when an attacker sends specific crafted messages to the Data Server TCP port. Affected Products: IGSS Data…
ModificadaAlta (8.8)0.61%—Schneider-electric Custom ReportsSchneider-electric Igss DashboardSchneider-electric Igss Data Server21/3/202317/6/2026
A CWE-20: Improper Input Validation vulnerability exists in Custom Reports that could cause a macro to be executed, potentially leading to remote code execution when a user opens a malicious report file planted by an attacker. Affected Products: IGSS Data Server(IGSSdataServer.exe)(V16.0.0.23040 and prior), IGSS…
ModificadaAlta (8.8)0.73%—Schneider-electric Custom ReportsSchneider-electric Igss DashboardSchneider-electric Igss Data Server21/3/202317/6/2026
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory vulnerability exists in Custom Reports that could cause a remote code execution when a victim tries to open a malicious report. Affected Products: IGSS Data Server(IGSSdataServer.exe)(V16.0.0.23040 and prior), IGSS…
ModificadaAlta (7.8)6.5%—Schneider-electric Custom ReportsSchneider-electric Igss DashboardSchneider-electric Igss Data Server21/3/202317/6/2026
A CWE-502: Deserialization of Untrusted Data vulnerability exists in the Dashboard module that could cause an interpretation of malicious payload data, potentially leading to remote code execution when an attacker gets the user to open a malicious file. Affected Products: IGSS Data…
ModificadaAlta (8.8)0.40%—Schneider-electric Custom ReportsSchneider-electric Igss DashboardSchneider-electric Igss Data Server21/3/202317/6/2026
A CWE-345: Insufficient Verification of Data Authenticity vulnerability exists in the Data Server that could cause manipulation of dashboard files in the IGSS project report directory, when an attacker sends specific crafted messages to the Data Server TCP port, this could lead to remote code execution when a victim…
ModificadaAlta (8.8)0.88%—Schneider-electric Custom ReportsSchneider-electric Igss DashboardSchneider-electric Igss Data Server21/3/202317/6/2026
A CWE-306: Missing Authentication for Critical Function vulnerability exists in the Data Server TCP interface that could allow the creation of a malicious report file in the IGSS project report directory, this could lead to remote code execution when a victim eventually opens the report. Affected Products: IGSS Data…
ModificadaAlta (8.8)0.85%—Eclipse Business Intelligence AND Reporting Tools15/3/202317/6/2026
In Eclipse BIRT, starting from version 2.6.2, the default configuration allowed to retrieve a report from the same host using an absolute HTTP path for the report parameter (e.g. __report=http://xyz.com/report.rptdesign). If the host indicated in the __report parameter matched the HTTP Host header value, the report…
ModificadaCrítica (9.8)0.83%—Anji-plus Aj-report3/3/202317/6/2026
Report v0.9.8.6 was discovered to contain a Server-Side Request Forgery (SSRF) vulnerability.
ModificadaAlta (7.8)0.17%—Intel System Usage Report16/2/202317/6/2026
Improper access control in the Intel(R) SUR software before version 2.4.8902 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaCrítica (9.8)0.65%—Intel System Usage Report16/2/202317/6/2026
Improper input validation in the Intel(R) SUR software before version 2.4.8902 may allow an unauthenticated user to potentially enable escalation of privilege via network access.
ModificadaAlta (7.8)0.18%—Intel System Usage Report16/2/202317/6/2026
Improper authentication in the Intel(R) SUR software before version 2.4.8902 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaAlta (7.8)0.23%—Intel System Usage Report16/2/202317/6/2026
Improper input validation in the Intel(R) SUR software before version 2.4.8902 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaAlta (7.2)0.44%—Intel System Usage Report16/2/202317/6/2026
Improper authentication in the Intel(R) SUR software before version 2.4.8902 may allow a privileged user to potentially enable escalation of privilege via network access.
ModificadaMedia (5.5)0.18%—Intel System Usage Report16/2/202317/6/2026
Improper access control in the Intel(R) SUR software before version 2.4.8902 may allow an authenticated user to potentially enable denial of service via local access.
ModificadaAlta (7.5)0.61%—Intel System Usage Report16/2/202317/6/2026
Improper conditions check in the Intel(R) SUR software before version 2.4.8902 may allow an unauthenticated user to potentially enable denial of service via network access.
ModificadaCrítica (9.8)0.57%—Intel System Usage Report16/2/202317/6/2026
Improper access control in the Intel(R) SUR software before version 2.4.8902 may allow an unauthenticated user to potentially enable escalation of privilege via network access.
ModificadaAlta (8.2)0.78%—Microsoft Power BI Report Server14/2/202319/8/2026
Power BI Report Server Spoofing Vulnerability
ModificadaAlta (7.8)0.93%—Ureport Project Ureport14/2/20239/7/2026
An XML External Entity (XXE) vulnerability in ureport v2.2.9 allows attackers to execute arbitrary code via uploading a crafted XML file to /ureport/designer/saveReportFile.
ModificadaCrítica (9.1)1.2%—Ureport Project Ureport13/2/20239/7/2026
Se descubrió que ureport v2.2.9 contiene una vulnerabilidad de Directory Traversal a través de la función de eliminación que permite eliminar archivos arbitrarios.
ModificadaAlta (8.1)0.54%—Oracle Hospitality Reporting AND Analytics18/1/202317/6/2026
Vulnerabilidad en el producto Oracle Hospitality Reporting and Analytics de Oracle Food and Beverage Applications (componente: Reporting). La versión compatible afectada es la 9.1.0. Una vulnerabilidad fácilmente explotable permite a un atacante con pocos privilegios y acceso a la red a través de HTTPS comprometer…
Orbitaley — Vulnerabilidades