Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2678▼ 660 respecto a la semana anterior
Críticas / altas1266▼ 293 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
966 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.2) | 1.5% | — | Tibco Jasperreports Server | 13/12/2022 | 17/6/2026 | The JNDI Data Sources component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperReports Server - Community Edition, TIBCO JasperReports Server - Developer Edition, TIBCO JasperReports Server for AWS Marketplace, TIBCO JasperReports Server for AWS Marketplace, TIBCO… | |
| Modificada | Media (6.1) | 0.38% | — | Glpi-project Reports | 17/11/2022 | 17/6/2026 | GLPI - Reports plugin for GLPI Reflected Cross-Site-Scripting (RXSS). Type 1: Reflected XSS (or Non-Persistent) - The server reads data directly from the HTTP request and reflects it back in the HTTP response. Reflected XSS exploits occur when an attacker causes a victim to supply dangerous content to a vulnerable web… | |
| Modificada | Crítica (9.8) | 1.0% | — | Stimulsoft Reports | 29/10/2022 | 17/6/2026 | Stimulsoft (aka Stimulsoft Reports) 2013.1.1600.0, when Compilation Mode is used, allows an attacker to execute arbitrary C# code on any machine that renders a report, including the application server or a user's local machine, as demonstrated by System.Diagnostics.Process.Start. | |
| Modificada | Baja (3.7) | 0.27% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+15 | 19/10/2022 | 17/6/2026 | On specific hardware platforms, on BIG-IP versions 16.1.x before 16.1.3.1, 15.1.x before 15.1.7, 14.1.x before 14.1.5.1, and all versions of 13.1.x, while Intel QAT (QuickAssist Technology) and the AES-GCM/CCM cipher is in use, undisclosed conditions can cause BIG-IP to send data unencrypted even with an SSL Profile… | |
| Modificada | Alta (8.8) | 1.4% | — | Anji-plus Aj-report | 17/10/2022 | 17/6/2026 | anji-plus AJ-Report 0.9.8.6 allows remote attackers to bypass login authentication by spoofing JWT Tokens. | |
| Modificada | Alta (8.1) | 0.63% | — | Jenkins View26 Test-reporting | 21/9/2022 | 17/6/2026 | Jenkins View26 Test-Reporting Plugin 1.0.7 and earlier does not perform hostname validation when connecting to the configured View26 server that could be abused using a man-in-the-middle attack to intercept these connections. | |
| Modificada | Media (6.1) | 0.28% | — | Huawei 576up005 Hota-cm-h-shark-bd FirmwareHuawei 577hota-cm-h-shark-bd FirmwareHuawei 581up-hota-cm-h-shark-bd FirmwareHuawei 586-hota-cm-h-shark-bd Firmware+4 | 20/9/2022 | 17/6/2026 | There is an out-of-bounds read and write vulnerability in some headset products. An unauthenticated attacker gets the device physically and crafts malformed message with specific parameter and sends the message to the affected products. Due to insufficient validation of message, which may be exploited to cause… | |
| Modificada | Media (5.4) | 0.78% | — | Crime Reporting System Project Crime Reporting System | 6/9/2022 | 17/6/2026 | Persistent cross-site scripting (XSS) in Crime Reporting System 1.0 allows a remote attacker to introduce arbitary Javascript via manipulation of an unsanitized POST parameter | |
| Modificada | Media (5.4) | 0.52% | — | Online Fire Reporting System Project Online Fire Reporting System | 27/7/2022 | 9/7/2026 | A cross-site scripting (XSS) vulnerability in /index.php/?p=report of Online Fire Reporting System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the "Contac #" text field. | |
| Modificada | Alta (8.8) | 1.4% | — | Online Fire Reporting System Project Online Fire Reporting System | 26/7/2022 | 17/6/2026 | Online Fire Reporting System 1.0 is vulnerable to SQL Injection via the date parameter. | |
| Modificada | Alta (8.8) | 1.5% | — | Exports AND Reports Project Exports AND Reports | 25/7/2022 | 17/6/2026 | The Exports and Reports WordPress plugin before 0.9.2 does not sanitize and validate data when generating the CSV to export, which could lead to a CSV injection, by the use of Microsoft Excel DDE function, or to leak data via maliciously injected hyperlinks. | |
| Modificada | Media (4.8) | 0.50% | — | Online Fire Reporting System Project Online Fire Reporting System | 16/6/2022 | 17/6/2026 | Online Fire Reporting System v1.0 is vulnerable to Cross Site Scripting (XSS) via /ofrs/classes/Master.php. | |
| Modificada | Media (6.5) | 0.94% | — | Online Fire Reporting System Project Online Fire Reporting System | 14/6/2022 | 17/6/2026 | Online Fire Reporting System v1.0 was discovered to contain a SQL injection vulnerability via the GET parameter in /report/list.php. | |
| Modificada | Media (6.5) | 1.9% | 💥 PoC | Solutions-atlantic Regulatory Reporting System | 2/6/2022 | 17/6/2026 | Solutions Atlantic Regulatory Reporting System (RRS) v500 is vulnerable to Local File Inclusion (LFI). Any authenticated user has the ability to reference internal system files within requests made to the RRSWeb/maint/ShowDocument/ShowDocument.aspx page. The server will successfully respond with the file contents of… | |
| Modificada | Alta (7.2) | 4.9% | 💥 Exploit | Online Fire Reporting System Project Online Fire Reporting System | 2/6/2022 | 17/6/2026 | Online Fire Reporting System v1.0 is vulnerable to SQL Injection via /ofrs/admin/requests/take_action.php?id=. | |
| Modificada | Alta (7.2) | 2.6% | 💥 PoC | Online Fire Reporting System Project Online Fire Reporting System | 2/6/2022 | 17/6/2026 | Online Fire Reporting System v1.0 is vulnerable to SQL Injection via /ofrs/admin/?page=requests/manage_request&id=. | |
| Modificada | Alta (7.2) | 2.0% | — | Online Fire Reporting System Project Online Fire Reporting System | 2/6/2022 | 17/6/2026 | Online Fire Reporting System v1.0 is vulnerable to SQL Injection via /ofrs/admin/?page=requests/view_request&id=. | |
| Modificada | Alta (7.2) | 2.0% | — | Online Fire Reporting System Project Online Fire Reporting System | 2/6/2022 | 17/6/2026 | Online Fire Reporting System v1.0 is vulnerable to SQL Injection via /ofrs/admin/?page=teams/view_team&id=. | |
| Modificada | Alta (7.2) | 2.0% | — | Online Fire Reporting System Project Online Fire Reporting System | 2/6/2022 | 17/6/2026 | Online Fire Reporting System v1.0 is vulnerable to SQL Injection via /ofrs/admin/?page=teams/manage_team&id=. | |
| Modificada | Crítica (9.8) | 7.2% | 💥 Exploit | Online Fire Reporting System Project Online Fire Reporting System | 2/6/2022 | 17/6/2026 | Online Fire Reporting System v1.0 is vulnerable to SQL Injection via /ofrs/classes/Master.php?f=delete_inquiry. | |
| Modificada | Crítica (9.8) | 7.2% | 💥 Exploit | Online Fire Reporting System Project Online Fire Reporting System | 2/6/2022 | 17/6/2026 | Online Fire Reporting System v1.0 is vulnerable to SQL Injection via /ofrs/classes/Master.php?f=delete_team. | |
| Modificada | Crítica (9.8) | 7.2% | 💥 Exploit | Online Fire Reporting System Project Online Fire Reporting System | 2/6/2022 | 17/6/2026 | Online Fire Reporting System v1.0 is vulnerable to SQL Injection via /ofrs/classes/Master.php?f=delete_request. | |
| Modificada | Alta (7.2) | 4.9% | 💥 Exploit | Online Fire Reporting System Project Online Fire Reporting System | 2/6/2022 | 17/6/2026 | Online Fire Reporting System v1.0 is vulnerable to SQL Injection via /ofrs/admin/?page=user/manage_user&id=. | |
| Modificada | Alta (7.2) | 5.0% | 💥 Exploit | Online Fire Reporting System Project Online Fire Reporting System | 2/6/2022 | 17/6/2026 | Online Fire Reporting System v1.0 is vulnerable to SQL Injection via /ofrs/admin/?page=reports&date=. | |
| Modificada | Media (6.5) | 0.98% | — | Online Fire Reporting System Project Online Fire Reporting System | 2/6/2022 | 17/6/2026 | Online Fire Reporting System v1.0 is vulnerable to Delete any file via /ofrs/classes/Master.php?f=delete_img. |