Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

966 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)0.61%—Schneider-electric Custom ReportsSchneider-electric Igss DashboardSchneider-electric Igss Data Server21/3/202317/6/2026
A CWE-20: Improper Input Validation vulnerability exists in Custom Reports that could cause a macro to be executed, potentially leading to remote code execution when a user opens a malicious report file planted by an attacker. Affected Products: IGSS Data Server(IGSSdataServer.exe)(V16.0.0.23040 and prior), IGSS…
ModificadaAlta (8.8)0.73%—Schneider-electric Custom ReportsSchneider-electric Igss DashboardSchneider-electric Igss Data Server21/3/202317/6/2026
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory vulnerability exists in Custom Reports that could cause a remote code execution when a victim tries to open a malicious report. Affected Products: IGSS Data Server(IGSSdataServer.exe)(V16.0.0.23040 and prior), IGSS…
ModificadaAlta (7.8)6.5%—Schneider-electric Custom ReportsSchneider-electric Igss DashboardSchneider-electric Igss Data Server21/3/202317/6/2026
A CWE-502: Deserialization of Untrusted Data vulnerability exists in the Dashboard module that could cause an interpretation of malicious payload data, potentially leading to remote code execution when an attacker gets the user to open a malicious file. Affected Products: IGSS Data…
ModificadaAlta (8.8)0.40%—Schneider-electric Custom ReportsSchneider-electric Igss DashboardSchneider-electric Igss Data Server21/3/202317/6/2026
A CWE-345: Insufficient Verification of Data Authenticity vulnerability exists in the Data Server that could cause manipulation of dashboard files in the IGSS project report directory, when an attacker sends specific crafted messages to the Data Server TCP port, this could lead to remote code execution when a victim…
ModificadaAlta (8.8)0.88%—Schneider-electric Custom ReportsSchneider-electric Igss DashboardSchneider-electric Igss Data Server21/3/202317/6/2026
A CWE-306: Missing Authentication for Critical Function vulnerability exists in the Data Server TCP interface that could allow the creation of a malicious report file in the IGSS project report directory, this could lead to remote code execution when a victim eventually opens the report. Affected Products: IGSS Data…
ModificadaAlta (8.8)0.85%—Eclipse Business Intelligence AND Reporting Tools15/3/202317/6/2026
In Eclipse BIRT, starting from version 2.6.2, the default configuration allowed to retrieve a report from the same host using an absolute HTTP path for the report parameter (e.g. __report=http://xyz.com/report.rptdesign). If the host indicated in the __report parameter matched the HTTP Host header value, the report…
ModificadaCrítica (9.8)0.83%—Anji-plus Aj-report3/3/202317/6/2026
Report v0.9.8.6 was discovered to contain a Server-Side Request Forgery (SSRF) vulnerability.
ModificadaAlta (7.8)0.17%—Intel System Usage Report16/2/202317/6/2026
Improper access control in the Intel(R) SUR software before version 2.4.8902 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaCrítica (9.8)0.65%—Intel System Usage Report16/2/202317/6/2026
Improper input validation in the Intel(R) SUR software before version 2.4.8902 may allow an unauthenticated user to potentially enable escalation of privilege via network access.
ModificadaAlta (7.8)0.18%—Intel System Usage Report16/2/202317/6/2026
Improper authentication in the Intel(R) SUR software before version 2.4.8902 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaAlta (7.8)0.23%—Intel System Usage Report16/2/202317/6/2026
Improper input validation in the Intel(R) SUR software before version 2.4.8902 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaAlta (7.2)0.44%—Intel System Usage Report16/2/202317/6/2026
Improper authentication in the Intel(R) SUR software before version 2.4.8902 may allow a privileged user to potentially enable escalation of privilege via network access.
ModificadaMedia (5.5)0.18%—Intel System Usage Report16/2/202317/6/2026
Improper access control in the Intel(R) SUR software before version 2.4.8902 may allow an authenticated user to potentially enable denial of service via local access.
ModificadaAlta (7.5)0.61%—Intel System Usage Report16/2/202317/6/2026
Improper conditions check in the Intel(R) SUR software before version 2.4.8902 may allow an unauthenticated user to potentially enable denial of service via network access.
ModificadaCrítica (9.8)0.57%—Intel System Usage Report16/2/202317/6/2026
Improper access control in the Intel(R) SUR software before version 2.4.8902 may allow an unauthenticated user to potentially enable escalation of privilege via network access.
ModificadaAlta (8.2)0.78%—Microsoft Power BI Report Server14/2/202319/8/2026
Power BI Report Server Spoofing Vulnerability
ModificadaAlta (7.8)0.93%—Ureport Project Ureport14/2/20239/7/2026
An XML External Entity (XXE) vulnerability in ureport v2.2.9 allows attackers to execute arbitrary code via uploading a crafted XML file to /ureport/designer/saveReportFile.
ModificadaCrítica (9.1)1.2%—Ureport Project Ureport13/2/20239/7/2026
ureport v2.2.9 was discovered to contain a directory traversal vulnerability via the deletion function which allows for arbitrary files to be deleted.
ModificadaAlta (8.1)0.54%—Oracle Hospitality Reporting AND Analytics18/1/202317/6/2026
Vulnerability in the Oracle Hospitality Reporting and Analytics product of Oracle Food and Beverage Applications (component: Reporting). The supported version that is affected is 9.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Hospitality…
ModificadaAlta (7.6)0.51%—Oracle Hospitality Reporting AND Analytics18/1/202317/6/2026
Vulnerability in the Oracle Hospitality Reporting and Analytics product of Oracle Food and Beverage Applications (component: Reporting). The supported version that is affected is 9.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Hospitality…
ModificadaAlta (7.5)3.2%—Zohocorp Manageengine Exchange Reporter Plus17/1/202317/6/2026
Zoho ManageEngine Exchange Reporter Plus before 5708 allows attackers to conduct XXE attacks.
ModificadaCrítica (9.8)0.66%—Angular-test-reporter Project Angular-test-reporter9/1/202317/6/2026
A vulnerability was found in gperson angular-test-reporter and classified as critical. This issue affects the function getProjectTables/addTest of the file rest-server/data-server.js. The manipulation leads to sql injection. The patch is named a29d8ae121b46ebfa96a55a9106466ab2ef166ae. It is recommended to apply a…
ModificadaMedia (5.9)48%—Zabbix WEB Service Report GenerationZabbix-agent215/12/202217/6/2026
Arbitrary file read vulnerability exists in Zabbix Web Service Report Generation, which listens on the port 10053. The service does not have proper validation for URL parameters before reading the files.
ModificadaMedia (5.4)0.90%—Tibco Jasperreports Server13/12/202217/6/2026
The Dashboard component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperReports Server - Developer Edition, TIBCO JasperReports Server for AWS Marketplace, TIBCO JasperReports Server for AWS Marketplace, TIBCO JasperReports Server for Microsoft Azure, and TIBCO…
ModificadaAlta (8.4)0.74%—Tibco Jasperreports Server13/12/202217/6/2026
The HTML escaping component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperReports Server - Community Edition, TIBCO JasperReports Server - Developer Edition, TIBCO JasperReports Server for AWS Marketplace, TIBCO JasperReports Server for AWS Marketplace, TIBCO…