Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
966 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.81% | 💥 PoC | Solutions-atlantic Regulatory Reporting System | 2/6/2022 | 17/6/2026 | Solutions Atlantic Regulatory Reporting System (RRS) v500 is vulnerable to an reflected Cross-Site Scripting (XSS) vulnerability via RRSWeb/maint/ShowDocument/ShowDocument.aspx . | |
| Modificada | Media (5.4) | 0.52% | — | Tibco Jasperreports Server | 17/5/2022 | 17/6/2026 | The REST API component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server - Community Edition, TIBCO JasperReports Server - Developer Edition, TIBCO JasperReports Server for AWS Marketplace, TIBCO JasperReports Server for ActiveMatrix BPM, and TIBCO JasperReports Server for Microsoft Azure… | |
| Modificada | Crítica (9.8) | 3.2% | — | Ureport2 Project Ureport2 | 1/5/2022 | 17/6/2026 | All versions of package com.bstek.ureport:ureport2-console are vulnerable to Remote Code Execution by connecting to a malicious database server, causing arbitrary file read and deserialization of local gadgets. | |
| Modificada | Alta (8.8) | 7.9% | 💥 Exploit | Zohocorp Manageengine Adaudit PlusZohocorp Manageengine Admanager PlusZohocorp Manageengine Adselfservice PlusZohocorp Manageengine Exchange Reporter Plus | 18/4/2022 | 17/6/2026 | Zoho ManageEngine ADSelfService Plus before 6121, ADAuditPlus 7060, Exchange Reporter Plus 5701, and ADManagerPlus 7131 allow NTLM Hash disclosure during certain storage-path configuration steps. | |
| Modificada | Media (4.3) | 0.74% | — | Jenkins Jiratestresultreporter | 29/3/2022 | 17/6/2026 | A missing permission check in Jenkins JiraTestResultReporter Plugin 165.v817928553942 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials. | |
| Modificada | Alta (8.8) | 0.72% | — | Jenkins Jiratestresultreporter | 29/3/2022 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins JiraTestResultReporter Plugin 165.v817928553942 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials. | |
| Modificada | Alta (8.8) | 2.5% | — | Tibco Jasperreports LibraryTibco Jasperreports Server | 15/3/2022 | 17/6/2026 | The Server component of TIBCO Software Inc.'s TIBCO JasperReports Library, TIBCO JasperReports Library for ActiveMatrix BPM, TIBCO JasperReports Server, TIBCO JasperReports Server for AWS Marketplace, TIBCO JasperReports Server for ActiveMatrix BPM, and TIBCO JasperReports Server for Microsoft Azure contains a… | |
| Modificada | Media (4.8) | 0.56% | — | Petereport Project Petereport | 3/3/2022 | 17/6/2026 | PeteReport Version 0.5 allows an authenticated admin user to inject persistent JavaScript code inside the markdown descriptions while creating a product, report or finding. | |
| Modificada | Media (6.5) | 0.45% | — | Petereport Project Petereport | 3/3/2022 | 17/6/2026 | PeteReport Version 0.5 contains a Cross Site Request Forgery (CSRF) vulnerability allowing an attacker to trick users into deleting users, products, reports and findings on the application. | |
| Modificada | Media (5.4) | 0.52% | — | Petereport Project Petereport | 3/3/2022 | 17/6/2026 | PeteReport Version 0.5 allows an authenticated admin user to inject persistent JavaScript code while adding an 'Attack Tree' by modifying the 'svg_file' parameter. | |
| Modificada | Media (6.1) | 1.2% | 💥 PoC | SAS WEB Report Studio | 19/2/2022 | 17/6/2026 | SAS Web Report Studio 4.4 allows XSS. /SASWebReportStudio/logonAndRender.do has two parameters: saspfs_request_backlabel_list and saspfs_request_backurl_list. The first one affects the content of the button placed in the top left. The second affects the page to which the user is directed after pressing the button,… | |
| Modificada | Media (6.5) | 12% | — | Apache Xerces-jOracle Agile Engineering Data ManagementOracle Agile Product Lifecycle ManagementOracle Banking Deposits AND Lines OF Credit Servicing+25 | 24/1/2022 | 25/8/2026 | There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads. This causes, the XercesJ XML parser to wait in an infinite loop, which may sometimes consume system resources for prolonged duration. This vulnerability is present within XercesJ version… | |
| Modificada | Alta (7.3) | 1.1% | — | CTH Carinal Tien Hospital Health Report System | 29/12/2021 | 17/6/2026 | Carinal Tien Hospital Health Report System’s login page has improper authentication, a remote attacker can acquire another general user’s privilege by modifying the cookie parameter without authentication. The attacker can then perform limited operations on the system or modify data, making the service partially… | |
| Analizada | Crítica (9.8) | 97% | 💥 Exploit | Apache Http ServerFedoraproject FedoraDebian LinuxTenable.sc+10 | 20/12/2021 | 17/6/2026 | A carefully crafted request body can cause a buffer overflow in the mod_lua multipart parser (r:parsebody() called from Lua scripts). The Apache httpd team is not aware of an exploit for the vulnerabilty though it might be possible to craft one. This issue affects Apache HTTP Server 2.4.51 and earlier. | |
| Modificada | Alta (8.2) | 82% | — | Apache Http ServerFedoraproject FedoraDebian LinuxTenable.sc+8 | 20/12/2021 | 17/6/2026 | A crafted URI sent to httpd configured as a forward proxy (ProxyRequests on) can cause a crash (NULL pointer dereference) or, for configurations mixing forward and reverse proxy declarations, can allow for requests to be directed to a declared Unix Domain Socket endpoint (Server Side Request Forgery). This issue… | |
| Modificada | Media (5.9) | 100% | 💥 PoC | Apache Log4jNetapp Cloud ManagerDebian LinuxSonicwall Email Security+112 | 18/12/2021 | 25/8/2026 | Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j… | |
| Analizada | Crítica (9) | 100% | ⚠ Explotación activa💥 Exploit | Apache Log4jCvat Computer Vision Annotation ToolIntel Audio Development KITIntel Datacenter Manager+51 | 14/12/2021 | 17/6/2026 | It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows attackers with control over Thread Context Map (MDC) input data when the logging configuration uses a non-default Pattern Layout with either a Context Lookup (for example,… | |
| Analizada | Crítica (10) | 100% | ⚠ Explotación activa💥 Exploit | Siemens 6bk1602-0aa12-0tp0 FirmwareSiemens 6bk1602-0aa22-0tp0 FirmwareSiemens 6bk1602-0aa32-0tp0 FirmwareSiemens 6bk1602-0aa42-0tp0 Firmware+139 | 10/12/2021 | 11/8/2026 | Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can… | |
| Modificada | Alta (7.3) | 1.2% | — | Dreamreport Remote Connector | 8/12/2021 | 17/6/2026 | A privilege escalation vulnerability exists in the Remote Server functionality of Dream Report ODS Remote Connector 20.2.16900.0. A specially-crafted command injection can lead to elevated capabilities. An attacker can provide a malicious file to trigger this vulnerability. | |
| Modificada | Media (6.5) | 0.57% | — | Synel EharmonynewSynel Reports | 8/12/2021 | 17/6/2026 | SYNEL - eharmonynew / Synel Reports - The attacker can log in to the system with default credentials and export a report of eharmony system with sensetive data (Employee name, Employee ID number, Working hours etc') The vulnerabilety has been addressed and fixed on version 11. Default credentials , Security… | |
| Analizada | Alta (7.5) | 25% | 💥 PoC | Balasys DheaterSiemens Scalance W1750d FirmwareSuse Linux Enterprise ServerF5 Big-ip Access Policy Manager+26 | 11/11/2021 | 23/9/2026 | The Diffie-Hellman Key Agreement Protocol allows remote attackers (from the client side) to send arbitrary numbers that are actually not public keys, and trigger expensive server-side DHE modular-exponentiation calculations, aka a D(HE)at or D(HE)ater attack. The client needs very little CPU resources and network… | |
| Modificada | Crítica (9.6) | 0.68% | — | Microsoft Power BI Report Server | 10/11/2021 | 19/8/2026 | A Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF) vulnerability exists when Power BI Report Server Template file (pbix) containing HTML files is uploaded to the server and HTML files are accessed directly by the victim. Combining these 2 vulnerabilities together, an attacker is able to upload… | |
| Modificada | Media (6.1) | 0.84% | — | Oracle Hyperion Financial Reporting | 20/10/2021 | 17/6/2026 | Vulnerability in the Hyperion Financial Reporting product of Oracle Hyperion (component: Repository). The supported version that is affected is 11.2.6.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Hyperion Financial Reporting. Successful attacks require… | |
| Modificada | Alta (7.2) | 1.4% | — | Mainwp Child Reports | 18/10/2021 | 17/6/2026 | The MainWP Child Reports WordPress plugin before 2.0.8 does not validate or sanitise the order parameter before using it in a SQL statement in the admin dashboard, leading to an SQL injection issue | |
| Modificada | Alta (7.5) | 0.64% | — | Tibco Jasperreports Server | 12/10/2021 | 17/6/2026 | The XMLA Connections component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperReports Server - Community Edition, TIBCO JasperReports Server - Developer Edition, TIBCO JasperReports Server for AWS Marketplace, TIBCO… |