Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
–

2087 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.4)0.49%—Powerbi Embed ReportsAI12/12/202417/6/2026
The PowerBI Embed Reports plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'MO_API_POWER_BI' shortcode in all versions up to, and including, 1.1.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated…
AnalizadaAlta (7.4)2.3%—Microsoft Sharepoint Server12/12/202417/6/2026
Microsoft SharePoint Remote Code Execution Vulnerability
AnalizadaAlta (8.2)1.6%—Microsoft Sharepoint Server12/12/202417/6/2026
Microsoft SharePoint Elevation of Privilege Vulnerability
AnalizadaMedia (5.5)1.1%—Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Sharepoint Server+112/12/202417/6/2026
Microsoft Office Remote Code Execution Vulnerability
AnalizadaMedia (6.5)2.5%—Microsoft Sharepoint Server12/12/202417/6/2026
Microsoft SharePoint Information Disclosure Vulnerability
AnalizadaMedia (6.5)3.2%—Microsoft Sharepoint Server12/12/202417/6/2026
Microsoft SharePoint Information Disclosure Vulnerability
AplazadaMedia (6.5)0.43%—NI Woocommerce Sales ReportAI9/12/202417/6/2026
Missing Authorization vulnerability in Anzar Ahmed Ni WooCommerce Sales Report ni-woocommerce-sales-report allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ni WooCommerce Sales Report: from n/a through <= 3.7.3.
AplazadaMedia (6.5)0.55%—Onewebsite WP RepostAI9/12/202417/6/2026
Missing Authorization vulnerability in OneWebsite WP Repost allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Repost: from n/a through 0.1.
AplazadaMedia (6.1)0.43%—Cisco Adaptive Security ApplianceAICisco Firepower Threat DefenseAI18/11/202417/6/2026
A vulnerability in the web services interface of Cisco&nbsp;Adaptive Security Appliance (ASA) Software and Cisco&nbsp;Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. This vulnerability is due to…
AplazadaAlta (7.1)2.7%💥 ExploitSonatype Nexus RepositoryAI14/11/202417/6/2026
A Remote Code Execution vulnerability has been discovered in Sonatype Nexus Repository 2. This issue affects Nexus Repository 2 OSS/Pro versions up to and including 2.15.1.
AplazadaMedia (5.1)0.41%💥 PoCSonatype Nexus RepositoryAI14/11/202417/6/2026
A stored Cross-site Scripting vulnerability has been discovered in Sonatype Nexus Repository 2 This issue affects Nexus Repository 2 OSS/Pro versions up to and including 2.15.1.
AnalizadaMedia (6.2)0.11%—Progress Telerik Report Server13/11/202417/6/2026
In Progress® Telerik® Report Server versions prior to 2024 Q4 (10.3.24.1112), the encryption of local asset data used an older algorithm which may allow a sophisticated actor to decrypt this information.
AplazadaAlta (7.1)0.27%—Tevya Happiness-reports-for-help-scoutAI9/11/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tevya Satisfaction Reports from Help Scout happiness-reports-for-help-scout allows Reflected XSS.This issue affects Satisfaction Reports from Help Scout: from n/a through <= 2.0.3.
AnalizadaAlta (8.1)2.4%—Zohocorp Manageengine Sharepoint Manager Plus8/11/202417/6/2026
Zohocorp ManageEngine SharePoint Manager Plus versions 4503 and prior are vulnerable to authenticated XML External Entity (XXE) in the Management option.
AnalizadaAlta (8.8)0.29%—Ithemelandco Woocommerce Report5/11/202417/6/2026
The WooCommerce Report plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5.1. This is due to missing or incorrect nonce validation on the settings update functionality. This makes it possible for unauthenticated attackers to update arbitrary options that can be…
AnalizadaAlta (8.8)4.5%—Zohocorp Manageengine Exchange Reporter Plus5/11/202417/6/2026
Zohocorp ManageEngine Exchange Reporter Plus versions 5718 and prior are vulnerable to authenticated SQL Injection in reports module.
AnalizadaMedia (6.1)0.32%—Cisco Firepower Management CenterCisco Secure Firewall Management Center23/10/202417/6/2026
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient validation of…
AnalizadaMedia (6.1)0.32%—Cisco Firepower Management CenterCisco Secure Firewall Management Center23/10/202417/6/2026
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient validation of…
AnalizadaMedia (6.1)0.32%—Cisco Firepower Management CenterCisco Secure Firewall Management Center23/10/202417/6/2026
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient validation of…
AnalizadaMedia (5.4)0.30%—Cisco Firepower Management CenterCisco Secure Firewall Management Center23/10/202417/6/2026
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient validation of…
AnalizadaMedia (5.3)0.41%—Cisco Firepower Management CenterCisco Secure Firewall Management CenterCisco Secure Firewall Threat Defense23/10/202411/8/2026
A vulnerability in the password change feature of Cisco Firepower Management Center (FMC) software could allow an unauthenticated, remote attacker to determine valid user names on an affected device. This vulnerability is due to improper authentication of password update responses. An attacker could exploit this…
AnalizadaMedia (5.4)0.31%—Cisco Firepower Management CenterCisco Secure Firewall Management Center23/10/202417/6/2026
A vulnerability in the web-based management interface of Cisco FMC Software could allow an authenticated, remote attacker to store malicious content for use in XSS attacks. This vulnerability is due to improper input sanitization in the web-based management interface of Cisco FMC Software. An attacker could exploit…
AnalizadaMedia (6.1)0.39%—Cisco Firepower Management CenterCisco Secure Firewall Management Center23/10/202417/6/2026
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient validation of…
AnalizadaMedia (6.5)0.62%—Cisco Firepower Management CenterCisco Secure Firewall Management Center23/10/202417/6/2026
A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software, formerly Firepower Management Center Software, could allow an authenticated, remote attacker to read arbitrary files from the underlying operating system. This vulnerability exists because the web-based…
AnalizadaMedia (6.1)0.41%—Cisco Firepower Management CenterCisco Secure Firewall Management Center23/10/202417/6/2026
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient validation of…
Orbitaley — Vulnerabilidades