Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2678▼ 660 respecto a la semana anterior
Críticas / altas1266▼ 293 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

966 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.2)1.5%—Tibco Jasperreports Server13/12/202217/6/2026
The JNDI Data Sources component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperReports Server - Community Edition, TIBCO JasperReports Server - Developer Edition, TIBCO JasperReports Server for AWS Marketplace, TIBCO JasperReports Server for AWS Marketplace, TIBCO…
ModificadaMedia (6.1)0.38%—Glpi-project Reports17/11/202217/6/2026
GLPI - Reports plugin for GLPI Reflected Cross-Site-Scripting (RXSS). Type 1: Reflected XSS (or Non-Persistent) - The server reads data directly from the HTTP request and reflects it back in the HTTP response. Reflected XSS exploits occur when an attacker causes a victim to supply dangerous content to a vulnerable web…
ModificadaCrítica (9.8)1.0%—Stimulsoft Reports29/10/202217/6/2026
Stimulsoft (aka Stimulsoft Reports) 2013.1.1600.0, when Compilation Mode is used, allows an attacker to execute arbitrary C# code on any machine that renders a report, including the application server or a user's local machine, as demonstrated by System.Diagnostics.Process.Start.
ModificadaBaja (3.7)0.27%—F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+1519/10/202217/6/2026
On specific hardware platforms, on BIG-IP versions 16.1.x before 16.1.3.1, 15.1.x before 15.1.7, 14.1.x before 14.1.5.1, and all versions of 13.1.x, while Intel QAT (QuickAssist Technology) and the AES-GCM/CCM cipher is in use, undisclosed conditions can cause BIG-IP to send data unencrypted even with an SSL Profile…
ModificadaAlta (8.8)1.4%—Anji-plus Aj-report17/10/202217/6/2026
anji-plus AJ-Report 0.9.8.6 allows remote attackers to bypass login authentication by spoofing JWT Tokens.
ModificadaAlta (8.1)0.63%—Jenkins View26 Test-reporting21/9/202217/6/2026
Jenkins View26 Test-Reporting Plugin 1.0.7 and earlier does not perform hostname validation when connecting to the configured View26 server that could be abused using a man-in-the-middle attack to intercept these connections.
ModificadaMedia (6.1)0.28%—Huawei 576up005 Hota-cm-h-shark-bd FirmwareHuawei 577hota-cm-h-shark-bd FirmwareHuawei 581up-hota-cm-h-shark-bd FirmwareHuawei 586-hota-cm-h-shark-bd Firmware+420/9/202217/6/2026
There is an out-of-bounds read and write vulnerability in some headset products. An unauthenticated attacker gets the device physically and crafts malformed message with specific parameter and sends the message to the affected products. Due to insufficient validation of message, which may be exploited to cause…
ModificadaMedia (5.4)0.78%—Crime Reporting System Project Crime Reporting System6/9/202217/6/2026
Persistent cross-site scripting (XSS) in Crime Reporting System 1.0 allows a remote attacker to introduce arbitary Javascript via manipulation of an unsanitized POST parameter
ModificadaMedia (5.4)0.52%—Online Fire Reporting System Project Online Fire Reporting System27/7/20229/7/2026
A cross-site scripting (XSS) vulnerability in /index.php/?p=report of Online Fire Reporting System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the "Contac #" text field.
ModificadaAlta (8.8)1.4%—Online Fire Reporting System Project Online Fire Reporting System26/7/202217/6/2026
Online Fire Reporting System 1.0 is vulnerable to SQL Injection via the date parameter.
ModificadaAlta (8.8)1.5%—Exports AND Reports Project Exports AND Reports25/7/202217/6/2026
The Exports and Reports WordPress plugin before 0.9.2 does not sanitize and validate data when generating the CSV to export, which could lead to a CSV injection, by the use of Microsoft Excel DDE function, or to leak data via maliciously injected hyperlinks.
ModificadaMedia (4.8)0.50%—Online Fire Reporting System Project Online Fire Reporting System16/6/202217/6/2026
Online Fire Reporting System v1.0 is vulnerable to Cross Site Scripting (XSS) via /ofrs/classes/Master.php.
ModificadaMedia (6.5)0.94%—Online Fire Reporting System Project Online Fire Reporting System14/6/202217/6/2026
Online Fire Reporting System v1.0 was discovered to contain a SQL injection vulnerability via the GET parameter in /report/list.php.
ModificadaMedia (6.5)1.9%💥 PoCSolutions-atlantic Regulatory Reporting System2/6/202217/6/2026
Solutions Atlantic Regulatory Reporting System (RRS) v500 is vulnerable to Local File Inclusion (LFI). Any authenticated user has the ability to reference internal system files within requests made to the RRSWeb/maint/ShowDocument/ShowDocument.aspx page. The server will successfully respond with the file contents of…
ModificadaAlta (7.2)4.9%💥 ExploitOnline Fire Reporting System Project Online Fire Reporting System2/6/202217/6/2026
Online Fire Reporting System v1.0 is vulnerable to SQL Injection via /ofrs/admin/requests/take_action.php?id=.
ModificadaAlta (7.2)2.6%💥 PoCOnline Fire Reporting System Project Online Fire Reporting System2/6/202217/6/2026
Online Fire Reporting System v1.0 is vulnerable to SQL Injection via /ofrs/admin/?page=requests/manage_request&id=.
ModificadaAlta (7.2)2.0%—Online Fire Reporting System Project Online Fire Reporting System2/6/202217/6/2026
Online Fire Reporting System v1.0 is vulnerable to SQL Injection via /ofrs/admin/?page=requests/view_request&id=.
ModificadaAlta (7.2)2.0%—Online Fire Reporting System Project Online Fire Reporting System2/6/202217/6/2026
Online Fire Reporting System v1.0 is vulnerable to SQL Injection via /ofrs/admin/?page=teams/view_team&id=.
ModificadaAlta (7.2)2.0%—Online Fire Reporting System Project Online Fire Reporting System2/6/202217/6/2026
Online Fire Reporting System v1.0 is vulnerable to SQL Injection via /ofrs/admin/?page=teams/manage_team&id=.
ModificadaCrítica (9.8)7.2%💥 ExploitOnline Fire Reporting System Project Online Fire Reporting System2/6/202217/6/2026
Online Fire Reporting System v1.0 is vulnerable to SQL Injection via /ofrs/classes/Master.php?f=delete_inquiry.
ModificadaCrítica (9.8)7.2%💥 ExploitOnline Fire Reporting System Project Online Fire Reporting System2/6/202217/6/2026
Online Fire Reporting System v1.0 is vulnerable to SQL Injection via /ofrs/classes/Master.php?f=delete_team.
ModificadaCrítica (9.8)7.2%💥 ExploitOnline Fire Reporting System Project Online Fire Reporting System2/6/202217/6/2026
Online Fire Reporting System v1.0 is vulnerable to SQL Injection via /ofrs/classes/Master.php?f=delete_request.
ModificadaAlta (7.2)4.9%💥 ExploitOnline Fire Reporting System Project Online Fire Reporting System2/6/202217/6/2026
Online Fire Reporting System v1.0 is vulnerable to SQL Injection via /ofrs/admin/?page=user/manage_user&id=.
ModificadaAlta (7.2)5.0%💥 ExploitOnline Fire Reporting System Project Online Fire Reporting System2/6/202217/6/2026
Online Fire Reporting System v1.0 is vulnerable to SQL Injection via /ofrs/admin/?page=reports&date=.
ModificadaMedia (6.5)0.98%—Online Fire Reporting System Project Online Fire Reporting System2/6/202217/6/2026
Online Fire Reporting System v1.0 is vulnerable to Delete any file via /ofrs/classes/Master.php?f=delete_img.