Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
2087 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.4) | 0.49% | — | Powerbi Embed ReportsAI | 12/12/2024 | 17/6/2026 | The PowerBI Embed Reports plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'MO_API_POWER_BI' shortcode in all versions up to, and including, 1.1.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Analizada | Alta (7.4) | 2.3% | — | Microsoft Sharepoint Server | 12/12/2024 | 17/6/2026 | Microsoft SharePoint Remote Code Execution Vulnerability | |
| Analizada | Alta (8.2) | 1.6% | — | Microsoft Sharepoint Server | 12/12/2024 | 17/6/2026 | Microsoft SharePoint Elevation of Privilege Vulnerability | |
| Analizada | Media (5.5) | 1.1% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Sharepoint Server+1 | 12/12/2024 | 17/6/2026 | Microsoft Office Remote Code Execution Vulnerability | |
| Analizada | Media (6.5) | 2.5% | — | Microsoft Sharepoint Server | 12/12/2024 | 17/6/2026 | Microsoft SharePoint Information Disclosure Vulnerability | |
| Analizada | Media (6.5) | 3.2% | — | Microsoft Sharepoint Server | 12/12/2024 | 17/6/2026 | Microsoft SharePoint Information Disclosure Vulnerability | |
| Aplazada | Media (6.5) | 0.43% | — | NI Woocommerce Sales ReportAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Anzar Ahmed Ni WooCommerce Sales Report ni-woocommerce-sales-report allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ni WooCommerce Sales Report: from n/a through <= 3.7.3. | |
| Aplazada | Media (6.5) | 0.55% | — | Onewebsite WP RepostAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in OneWebsite WP Repost allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Repost: from n/a through 0.1. | |
| Aplazada | Media (6.1) | 0.43% | — | Cisco Adaptive Security ApplianceAICisco Firepower Threat DefenseAI | 18/11/2024 | 17/6/2026 | A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. This vulnerability is due to… | |
| Aplazada | Alta (7.1) | 2.7% | 💥 Exploit | Sonatype Nexus RepositoryAI | 14/11/2024 | 17/6/2026 | A Remote Code Execution vulnerability has been discovered in Sonatype Nexus Repository 2. This issue affects Nexus Repository 2 OSS/Pro versions up to and including 2.15.1. | |
| Aplazada | Media (5.1) | 0.41% | 💥 PoC | Sonatype Nexus RepositoryAI | 14/11/2024 | 17/6/2026 | A stored Cross-site Scripting vulnerability has been discovered in Sonatype Nexus Repository 2 This issue affects Nexus Repository 2 OSS/Pro versions up to and including 2.15.1. | |
| Analizada | Media (6.2) | 0.11% | — | Progress Telerik Report Server | 13/11/2024 | 17/6/2026 | In Progress® Telerik® Report Server versions prior to 2024 Q4 (10.3.24.1112), the encryption of local asset data used an older algorithm which may allow a sophisticated actor to decrypt this information. | |
| Aplazada | Alta (7.1) | 0.27% | — | Tevya Happiness-reports-for-help-scoutAI | 9/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tevya Satisfaction Reports from Help Scout happiness-reports-for-help-scout allows Reflected XSS.This issue affects Satisfaction Reports from Help Scout: from n/a through <= 2.0.3. | |
| Analizada | Alta (8.1) | 2.4% | — | Zohocorp Manageengine Sharepoint Manager Plus | 8/11/2024 | 17/6/2026 | Zohocorp ManageEngine SharePoint Manager Plus versions 4503 and prior are vulnerable to authenticated XML External Entity (XXE) in the Management option. | |
| Analizada | Alta (8.8) | 0.29% | — | Ithemelandco Woocommerce Report | 5/11/2024 | 17/6/2026 | The WooCommerce Report plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5.1. This is due to missing or incorrect nonce validation on the settings update functionality. This makes it possible for unauthenticated attackers to update arbitrary options that can be… | |
| Analizada | Alta (8.8) | 4.5% | — | Zohocorp Manageengine Exchange Reporter Plus | 5/11/2024 | 17/6/2026 | Zohocorp ManageEngine Exchange Reporter Plus versions 5718 and prior are vulnerable to authenticated SQL Injection in reports module. | |
| Analizada | Media (6.1) | 0.32% | — | Cisco Firepower Management CenterCisco Secure Firewall Management Center | 23/10/2024 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient validation of… | |
| Analizada | Media (6.1) | 0.32% | — | Cisco Firepower Management CenterCisco Secure Firewall Management Center | 23/10/2024 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient validation of… | |
| Analizada | Media (6.1) | 0.32% | — | Cisco Firepower Management CenterCisco Secure Firewall Management Center | 23/10/2024 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient validation of… | |
| Analizada | Media (5.4) | 0.30% | — | Cisco Firepower Management CenterCisco Secure Firewall Management Center | 23/10/2024 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient validation of… | |
| Analizada | Media (5.3) | 0.41% | — | Cisco Firepower Management CenterCisco Secure Firewall Management CenterCisco Secure Firewall Threat Defense | 23/10/2024 | 11/8/2026 | A vulnerability in the password change feature of Cisco Firepower Management Center (FMC) software could allow an unauthenticated, remote attacker to determine valid user names on an affected device. This vulnerability is due to improper authentication of password update responses. An attacker could exploit this… | |
| Analizada | Media (5.4) | 0.31% | — | Cisco Firepower Management CenterCisco Secure Firewall Management Center | 23/10/2024 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco FMC Software could allow an authenticated, remote attacker to store malicious content for use in XSS attacks. This vulnerability is due to improper input sanitization in the web-based management interface of Cisco FMC Software. An attacker could exploit… | |
| Analizada | Media (6.1) | 0.39% | — | Cisco Firepower Management CenterCisco Secure Firewall Management Center | 23/10/2024 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient validation of… | |
| Analizada | Media (6.5) | 0.62% | — | Cisco Firepower Management CenterCisco Secure Firewall Management Center | 23/10/2024 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software, formerly Firepower Management Center Software, could allow an authenticated, remote attacker to read arbitrary files from the underlying operating system. This vulnerability exists because the web-based… | |
| Analizada | Media (6.1) | 0.41% | — | Cisco Firepower Management CenterCisco Secure Firewall Management Center | 23/10/2024 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient validation of… |