Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 646 respecto a la semana anterior
Críticas / altas1266▼ 292 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

2087 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.8)0.86%—Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Office Online Server+18/4/202517/6/2026
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
AnalizadaAlta (7.8)0.80%—Microsoft 365 AppsMicrosoft AccessMicrosoft ExcelMicrosoft Office+38/4/202517/6/2026
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally.
AnalizadaMedia (6.9)0.56%—Phpgurukul Online Fire Reporting System4/4/202517/6/2026
A vulnerability, which was classified as critical, has been found in PHPGurukul Online Fire Reporting System 1.2. Affected by this issue is some unknown functionality of the file /admin/search.php. The manipulation of the argument searchdata leads to sql injection. The attack may be launched remotely. The exploit has…
AnalizadaMedia (6.9)0.56%—Phpgurukul Online Fire Reporting System4/4/202517/6/2026
A vulnerability classified as critical was found in PHPGurukul Online Fire Reporting System 1.2. Affected by this vulnerability is an unknown functionality of the file /admin/edit-guard-detail.php. The manipulation of the argument editid leads to sql injection. The attack can be launched remotely. The exploit has been…
AnalizadaMedia (6.9)0.56%—Phpgurukul Online Fire Reporting System4/4/202517/6/2026
A vulnerability classified as critical has been found in PHPGurukul Online Fire Reporting System 1.2. Affected is an unknown function of the file /search-request.php. The manipulation of the argument searchdata leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the…
AnalizadaAlta (7.2)0.38%—IBM Jazz Reporting Service2/4/202517/6/2026
IBM Jazz Reporting Service 7.0.2 and 7.0.3 does not invalidate session after logout which could allow an authenticated privileged user to impersonate another user on the system.
AplazadaCrítica (9.3)0.54%—Wpfactory Advanced Woocommerce Product Sales ReportingAI1/4/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPFactory Advanced WooCommerce Product Sales Reporting webd-woocommerce-advanced-reporting-statistics allows SQL Injection.This issue affects Advanced WooCommerce Product Sales Reporting: from n/a through <= 4.1.1.
AplazadaAlta (8.2)0.21%—Ieonly EZ SQL Reports Shortcode Widget AND DB BackupAI27/3/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Eli EZ SQL Reports Shortcode Widget and DB Backup elisqlreports allows SQL Injection.This issue affects EZ SQL Reports Shortcode Widget and DB Backup: from n/a through <= 5.25.08.
AplazadaAlta (7.1)0.18%—Ieonly EZ SQL Reports Shortcode Widget AND DB BackupAI27/3/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Eli EZ SQL Reports Shortcode Widget and DB Backup elisqlreports allows Stored XSS.This issue affects EZ SQL Reports Shortcode Widget and DB Backup: from n/a through <= 5.25.08.
AplazadaAlta (7.6)0.32%—Icinga ReportingAIIcinga WEB 2AI26/3/202517/6/2026
Icinga Reporting is the central component for reporting related functionality in the monitoring web frontend and framework Icinga Web 2. A vulnerability present in versions 0.10.0 through 1.0.2 allows to set up a template that allows to embed arbitrary Javascript. This enables the attacker to act on behalf of the…
AplazadaAlta (8.8)0.38%—EZ SQL ReportsAI25/3/202517/6/2026
The EZ SQL Reports Shortcode Widget and DB Backup plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions 4.11.13 to 5.25.08. This is due to missing or incorrect nonce validation on the 'ELISQLREPORTS_menu' function. This makes it possible for unauthenticated attackers to execute code on the…
AplazadaMedia (4.9)0.40%—Report Brute Force Attacks AND Login Protection ReportattacksAI13/3/202517/6/2026
The WordPress Report Brute Force Attacks and Login Protection ReportAttacks Plugins plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter in all versions up to, and including, 2.32 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing…
AplazadaMedia (5.6)0.11%—Foreseer Reporting SoftwareAI5/3/202517/6/2026
Secure flag not set and SameSIte was set to Lax in the Foreseer Reporting Software (FRS). Absence of this secure flag could lead into the session cookie being transmitted over unencrypted HTTP connections. This security issue has been resolved in the latest version of FRS v1.5.100.
AplazadaAlta (7.1)0.39%—Infosoftplugin TAX Report FOR WoocommerceAI3/3/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in infosoftplugin Tax Report for WooCommerce tax-report-for-woocommerce allows Reflected XSS.This issue affects Tax Report for WooCommerce: from n/a through <= 2.2.
AplazadaAlta (7.1)0.28%—Anzar Ahmed NI NI Woocommerce Sales Report EmailAI3/3/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Anzar Ahmed Ni WooCommerce Sales Report Email ni-woocommerce-sales-report-email allows Reflected XSS.This issue affects Ni WooCommerce Sales Report Email: from n/a through <= 3.1.4.
AplazadaMedia (6.3)0.16%—Foreseer Reporting SoftwareAI28/2/202517/6/2026
The connection string visible to users with access to FRSCore database on Foreseer Reporting Software (FRS) VM, this string can be used for gaining administrative access to the 4crXref database. This vulnerability has been resolved in the latest version 1.5.100 of FRS.
AplazadaMedia (6.7)0.19%—Foreseer Reporting SoftwareAI28/2/202517/6/2026
The user input was not sanitized on Reporting Hierarchy Management page of Foreseer Reporting Software (FRS) application which could lead into execution of arbitrary JavaScript in a browser context for all the interacting users. This security issue has been patched in the latest version 1.5.100 of the FRS.
AplazadaMedia (6.5)0.26%—Ieonly EZ SQL Reports Shortcode Widget AND DB BackupAI25/2/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Eli EZ SQL Reports Shortcode Widget and DB Backup elisqlreports allows Stored XSS.This issue affects EZ SQL Reports Shortcode Widget and DB Backup: from n/a through <= 5.21.35.
AplazadaAlta (8.6)0.15%—Intel System Security Report AND System Resources Defense FirmwareAI12/2/202517/6/2026
Race condition in some Intel(R) System Security Report and System Resources Defense firmware may allow a privileged user to potentially enable escalation of privilege via local access.
AplazadaAlta (8.7)0.21%—Intel System Security Report FirmwareAIIntel System Resources Defense FirmwareAI12/2/202517/6/2026
Improper buffer restrictions in some Intel(R) System Security Report and System Resources Defense firmware may allow a privileged user to potentially enable escalation of privilege via local access.
AplazadaAlta (8.7)0.22%—Intel System Security Report AND System Resources Defense FirmwareAI12/2/202517/6/2026
Improper input validation in some Intel(R) System Security Report and System Resources Defense firmware may allow a privileged user to potentially enable escalation of privilege via local access.
AplazadaAlta (8.7)0.16%—Intel System Security Report AND System Resources Defense FirmwareAI12/2/202517/6/2026
Race condition in some Intel(R) System Security Report and System Resources Defense firmware may allow a privileged user to potentially enable escalation of privilege via local access.
AplazadaMedia (5.6)0.16%—Intel System Security Report AND System Resources Defense FirmwareAI12/2/202517/6/2026
Race condition in some Intel(R) System Security Report and System Resources Defense firmware may allow a privileged user to potentially enable information disclosure via local access.
AplazadaAlta (8.6)0.24%—Intel System Security Report AND System Resources Defense FirmwareAI12/2/202517/6/2026
Improper buffer restrictions in some Intel(R) System Security Report and System Resources Defense firmware may allow a privileged user to potentially enable escalation of privilege via local access.
AnalizadaMedia (5.3)0.51%—Progress Telerik Reporting12/2/202517/6/2026
In Progress® Telerik® Reporting versions prior to 2025 Q1 (19.0.25.211), information disclosure is possible by a local threat actor through an absolute path vulnerability.