Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
966 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.61% | — | Schneider-electric Custom ReportsSchneider-electric Igss DashboardSchneider-electric Igss Data Server | 21/3/2023 | 17/6/2026 | A CWE-20: Improper Input Validation vulnerability exists in Custom Reports that could cause a macro to be executed, potentially leading to remote code execution when a user opens a malicious report file planted by an attacker. Affected Products: IGSS Data Server(IGSSdataServer.exe)(V16.0.0.23040 and prior), IGSS… | |
| Modificada | Alta (8.8) | 0.73% | — | Schneider-electric Custom ReportsSchneider-electric Igss DashboardSchneider-electric Igss Data Server | 21/3/2023 | 17/6/2026 | A CWE-22: Improper Limitation of a Pathname to a Restricted Directory vulnerability exists in Custom Reports that could cause a remote code execution when a victim tries to open a malicious report. Affected Products: IGSS Data Server(IGSSdataServer.exe)(V16.0.0.23040 and prior), IGSS… | |
| Modificada | Alta (7.8) | 6.5% | — | Schneider-electric Custom ReportsSchneider-electric Igss DashboardSchneider-electric Igss Data Server | 21/3/2023 | 17/6/2026 | A CWE-502: Deserialization of Untrusted Data vulnerability exists in the Dashboard module that could cause an interpretation of malicious payload data, potentially leading to remote code execution when an attacker gets the user to open a malicious file. Affected Products: IGSS Data… | |
| Modificada | Alta (8.8) | 0.40% | — | Schneider-electric Custom ReportsSchneider-electric Igss DashboardSchneider-electric Igss Data Server | 21/3/2023 | 17/6/2026 | A CWE-345: Insufficient Verification of Data Authenticity vulnerability exists in the Data Server that could cause manipulation of dashboard files in the IGSS project report directory, when an attacker sends specific crafted messages to the Data Server TCP port, this could lead to remote code execution when a victim… | |
| Modificada | Alta (8.8) | 0.88% | — | Schneider-electric Custom ReportsSchneider-electric Igss DashboardSchneider-electric Igss Data Server | 21/3/2023 | 17/6/2026 | A CWE-306: Missing Authentication for Critical Function vulnerability exists in the Data Server TCP interface that could allow the creation of a malicious report file in the IGSS project report directory, this could lead to remote code execution when a victim eventually opens the report. Affected Products: IGSS Data… | |
| Modificada | Alta (8.8) | 0.85% | — | Eclipse Business Intelligence AND Reporting Tools | 15/3/2023 | 17/6/2026 | In Eclipse BIRT, starting from version 2.6.2, the default configuration allowed to retrieve a report from the same host using an absolute HTTP path for the report parameter (e.g. __report=http://xyz.com/report.rptdesign). If the host indicated in the __report parameter matched the HTTP Host header value, the report… | |
| Modificada | Crítica (9.8) | 0.83% | — | Anji-plus Aj-report | 3/3/2023 | 17/6/2026 | Report v0.9.8.6 was discovered to contain a Server-Side Request Forgery (SSRF) vulnerability. | |
| Modificada | Alta (7.8) | 0.17% | — | Intel System Usage Report | 16/2/2023 | 17/6/2026 | Improper access control in the Intel(R) SUR software before version 2.4.8902 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Crítica (9.8) | 0.65% | — | Intel System Usage Report | 16/2/2023 | 17/6/2026 | Improper input validation in the Intel(R) SUR software before version 2.4.8902 may allow an unauthenticated user to potentially enable escalation of privilege via network access. | |
| Modificada | Alta (7.8) | 0.18% | — | Intel System Usage Report | 16/2/2023 | 17/6/2026 | Improper authentication in the Intel(R) SUR software before version 2.4.8902 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.8) | 0.23% | — | Intel System Usage Report | 16/2/2023 | 17/6/2026 | Improper input validation in the Intel(R) SUR software before version 2.4.8902 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.2) | 0.44% | — | Intel System Usage Report | 16/2/2023 | 17/6/2026 | Improper authentication in the Intel(R) SUR software before version 2.4.8902 may allow a privileged user to potentially enable escalation of privilege via network access. | |
| Modificada | Media (5.5) | 0.18% | — | Intel System Usage Report | 16/2/2023 | 17/6/2026 | Improper access control in the Intel(R) SUR software before version 2.4.8902 may allow an authenticated user to potentially enable denial of service via local access. | |
| Modificada | Alta (7.5) | 0.61% | — | Intel System Usage Report | 16/2/2023 | 17/6/2026 | Improper conditions check in the Intel(R) SUR software before version 2.4.8902 may allow an unauthenticated user to potentially enable denial of service via network access. | |
| Modificada | Crítica (9.8) | 0.57% | — | Intel System Usage Report | 16/2/2023 | 17/6/2026 | Improper access control in the Intel(R) SUR software before version 2.4.8902 may allow an unauthenticated user to potentially enable escalation of privilege via network access. | |
| Modificada | Alta (8.2) | 0.78% | — | Microsoft Power BI Report Server | 14/2/2023 | 19/8/2026 | Power BI Report Server Spoofing Vulnerability | |
| Modificada | Alta (7.8) | 0.93% | — | Ureport Project Ureport | 14/2/2023 | 9/7/2026 | An XML External Entity (XXE) vulnerability in ureport v2.2.9 allows attackers to execute arbitrary code via uploading a crafted XML file to /ureport/designer/saveReportFile. | |
| Modificada | Crítica (9.1) | 1.2% | — | Ureport Project Ureport | 13/2/2023 | 9/7/2026 | ureport v2.2.9 was discovered to contain a directory traversal vulnerability via the deletion function which allows for arbitrary files to be deleted. | |
| Modificada | Alta (8.1) | 0.54% | — | Oracle Hospitality Reporting AND Analytics | 18/1/2023 | 17/6/2026 | Vulnerability in the Oracle Hospitality Reporting and Analytics product of Oracle Food and Beverage Applications (component: Reporting). The supported version that is affected is 9.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Hospitality… | |
| Modificada | Alta (7.6) | 0.51% | — | Oracle Hospitality Reporting AND Analytics | 18/1/2023 | 17/6/2026 | Vulnerability in the Oracle Hospitality Reporting and Analytics product of Oracle Food and Beverage Applications (component: Reporting). The supported version that is affected is 9.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Hospitality… | |
| Modificada | Alta (7.5) | 3.2% | — | Zohocorp Manageengine Exchange Reporter Plus | 17/1/2023 | 17/6/2026 | Zoho ManageEngine Exchange Reporter Plus before 5708 allows attackers to conduct XXE attacks. | |
| Modificada | Crítica (9.8) | 0.66% | — | Angular-test-reporter Project Angular-test-reporter | 9/1/2023 | 17/6/2026 | A vulnerability was found in gperson angular-test-reporter and classified as critical. This issue affects the function getProjectTables/addTest of the file rest-server/data-server.js. The manipulation leads to sql injection. The patch is named a29d8ae121b46ebfa96a55a9106466ab2ef166ae. It is recommended to apply a… | |
| Modificada | Media (5.9) | 48% | — | Zabbix WEB Service Report GenerationZabbix-agent2 | 15/12/2022 | 17/6/2026 | Arbitrary file read vulnerability exists in Zabbix Web Service Report Generation, which listens on the port 10053. The service does not have proper validation for URL parameters before reading the files. | |
| Modificada | Media (5.4) | 0.90% | — | Tibco Jasperreports Server | 13/12/2022 | 17/6/2026 | The Dashboard component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperReports Server - Developer Edition, TIBCO JasperReports Server for AWS Marketplace, TIBCO JasperReports Server for AWS Marketplace, TIBCO JasperReports Server for Microsoft Azure, and TIBCO… | |
| Modificada | Alta (8.4) | 0.74% | — | Tibco Jasperreports Server | 13/12/2022 | 17/6/2026 | The HTML escaping component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperReports Server - Community Edition, TIBCO JasperReports Server - Developer Edition, TIBCO JasperReports Server for AWS Marketplace, TIBCO JasperReports Server for AWS Marketplace, TIBCO… |