Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
68 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 2.2% | 💥 Exploit | Flexmonster Pivot Table & Charts | 17/12/2020 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in the To OLAP (XMLA) component Under the Connect menu in Flexmonster Pivot Table & Charts 2.7.17. | |
| Modificada | Media (6.1) | 2.2% | 💥 Exploit | Flexmonster Pivot Table & Charts | 17/12/2020 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in Remote Report component under the Open menu in Flexmonster Pivot Table & Charts 2.7.17. | |
| Modificada | Media (6.1) | 2.2% | 💥 Exploit | Flexmonster Pivot Table & Charts | 17/12/2020 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in the Remote JSON component Under the Connect menu in Flexmonster Pivot Table & Charts 2.7.17. | |
| Modificada | Media (6.5) | 0.66% | — | Stiltsoft Table Filter AND Charts FOR Confluence Server | 29/8/2020 | 17/6/2026 | The Table Filter and Charts for Confluence Server app before 5.3.26 (for Atlassian Confluence) allows SSRF via the "Table from CSV" macro (URL parameter). | |
| Modificada | Alta (8.9) | 0.94% | — | Stiltsoft Table Filter AND Charts FOR Confluence Server | 29/8/2020 | 17/6/2026 | The Table Filter and Charts for Confluence Server app before 5.3.25 (for Atlassian Confluence) allow remote attackers to inject arbitrary HTML or JavaScript via cross site scripting (XSS) through the provided Markdown markup to the "Table from CSV" macro. | |
| Modificada | Media (5.4) | 0.73% | — | Jenkins Echarts API | 3/6/2020 | 17/6/2026 | Jenkins ECharts API Plugin 4.7.0-3 and earlier does not escape the display name of the builds in the trend chart, resulting in a stored cross-site scripting vulnerability. | |
| Modificada | Media (5.4) | 0.73% | — | Jenkins Echarts API | 3/6/2020 | 17/6/2026 | Jenkins ECharts API Plugin 4.7.0-3 and earlier does not escape the parser identifier when rendering charts, resulting in a stored cross-site scripting vulnerability. | |
| Modificada | Crítica (9.8) | 82% | 💥 Exploit | Cloudfastpath Netcharts Server | 3/1/2020 | 17/6/2026 | Unrestricted file upload vulnerability in Visual Mining NetCharts Server allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via unspecified vectors. | |
| Modificada | Media (4.3) | 0.95% | — | Yithemes Yith Woocommerce WishlistYithemes Yith Woocommerce CompareYithemes Yith Woocommerce Quick ViewYithemes Yith Woocommerce Zoom Magnifier+34 | 31/10/2019 | 17/6/2026 | plugin-fw/lib/yit-plugin-panel-wc.php in the YIT Plugin Framework through 3.3.8 for WordPress allows authenticated options changes. | |
| Modificada | Alta (7.5) | 3.2% | — | Highcharts | 14/3/2019 | 17/6/2026 | In js/parts/SvgRenderer.js in Highcharts JS before 6.1.0, the use of backtracking regular expressions permitted an attacker to conduct a denial of service attack against the SVGRenderer component, aka ReDoS. | |
| Modificada | Media (6.1) | 2.2% | — | Tera-charts Project Tera-charts | 10/10/2016 | 17/6/2026 | Reflected XSS in wordpress plugin tera-charts v1.0 | |
| Modificada | Alta (10) | 2.3% | — | Visual Mining Netcharts Server | 29/5/2015 | 17/6/2026 | projectContents.jsp in the Developer tools in Visual Mining NetCharts Server allows remote attackers to rename arbitrary files, and consequently execute them, via unspecified vectors. | |
| Modificada | Alta (10) | 7.2% | — | Visualmining Netcharts Server | 29/5/2015 | 17/6/2026 | Directory traversal vulnerability in saveFile.jsp in the development installation in Visual Mining NetChart allows remote attackers to write to arbitrary files via unspecified vectors. | |
| Modificada | Media (4.3) | 0.97% | — | Amcharts Flash | 28/12/2014 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in amCharts Flash 1 allow remote attackers to inject arbitrary web script or HTML via the (1) data_file or (2) settings_file parameter to ampie.swf; the message element in the chart_data parameter to (3) amcolumn.swf, (4) amline.swf, (5) amradar.swf, or (6) amxy.sw;… | |
| Modificada | Media (5) | 19% | 💥 Exploit | Tera Charts Plugin Project Tera-charts | 11/7/2014 | 17/6/2026 | Multiple directory traversal vulnerabilities in Tera Charts (tera-charts) plugin 0.1 for WordPress allow remote attackers to read arbitrary files via a .. (dot dot) in the fn parameter to (1) charts/treemap.php or (2) charts/zoomabletreemap.php. | |
| Modificada | Media (4.3) | 2.1% | 💥 Exploit | Infosoftglobal Fusion Charts | 5/2/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in ActionScript in arbitrary Shockwave Flash (SWF) files created by InfoSoft FusionCharts allows remote attackers to inject arbitrary additional SWF content via a URL in the SRC attribute of an IMG element in the dataURL parameter. | |
| Modificada | Media (6.8) | 2.4% | 💥 Exploit | Mxbb Charts | 20/12/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in charts_constants.php in the Charts (mx_charts) 1.0.0 and earlier module for mxBB allows remote attackers to execute arbitrary PHP code via a URL in the module_root_path parameter. | |
| Modificada | Media (6.8) | 1.2% | — | Visual Mining Netcharts Xbrl Server | 31/12/2003 | 16/6/2026 | NetCharts XBRL Server 4.0.0 allows remote attackers to obtain sensitive information via an HTTP request with an invalid chunked transfer encoding specification. |