Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2769▼ 305 respecto a la semana anterior
Críticas / altas1294▼ 203 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)207▼ 114 respecto a la semana anterior
–

2087 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)0.88%—Schneider-electric Custom ReportsSchneider-electric Igss DashboardSchneider-electric Igss Data Server21/3/202317/6/2026
A CWE-306: Missing Authentication for Critical Function vulnerability exists in the Data Server TCP interface that could allow the creation of a malicious report file in the IGSS project report directory, this could lead to remote code execution when a victim eventually opens the report. Affected Products: IGSS Data…
ModificadaAlta (8.8)0.85%—Eclipse Business Intelligence AND Reporting Tools15/3/202317/6/2026
In Eclipse BIRT, starting from version 2.6.2, the default configuration allowed to retrieve a report from the same host using an absolute HTTP path for the report parameter (e.g. __report=http://xyz.com/report.rptdesign). If the host indicated in the __report parameter matched the HTTP Host header value, the report…
ModificadaBaja (3.1)0.60%—Microsoft Sharepoint FoundationMicrosoft Sharepoint Server14/3/202317/6/2026
Microsoft SharePoint Server Spoofing Vulnerability
ModificadaCrítica (9.8)0.83%—Anji-plus Aj-report3/3/202317/6/2026
Report v0.9.8.6 was discovered to contain a Server-Side Request Forgery (SSRF) vulnerability.
ModificadaMedia (6.7)0.22%—Cisco UCS Central SoftwareCisco UCS 6536 FirmwareCisco UCS 64108 FirmwareCisco UCS 6454 Firmware+823/2/202317/6/2026
A vulnerability in the CLI of Cisco Firepower 4100 Series, Cisco Firepower 9300 Security Appliances, and Cisco UCS 6200, 6300, 6400, and 6500 Series Fabric Interconnects could allow an authenticated, local attacker to inject unauthorized commands. This vulnerability is due to insufficient input validation of commands…
ModificadaAlta (7.8)0.17%—Intel System Usage Report16/2/202317/6/2026
Improper access control in the Intel(R) SUR software before version 2.4.8902 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaCrítica (9.8)0.65%—Intel System Usage Report16/2/202317/6/2026
Improper input validation in the Intel(R) SUR software before version 2.4.8902 may allow an unauthenticated user to potentially enable escalation of privilege via network access.
ModificadaAlta (7.8)0.18%—Intel System Usage Report16/2/202317/6/2026
Improper authentication in the Intel(R) SUR software before version 2.4.8902 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaAlta (7.8)0.23%—Intel System Usage Report16/2/202317/6/2026
Improper input validation in the Intel(R) SUR software before version 2.4.8902 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaAlta (7.2)0.44%—Intel System Usage Report16/2/202317/6/2026
Improper authentication in the Intel(R) SUR software before version 2.4.8902 may allow a privileged user to potentially enable escalation of privilege via network access.
ModificadaMedia (5.5)0.18%—Intel System Usage Report16/2/202317/6/2026
Improper access control in the Intel(R) SUR software before version 2.4.8902 may allow an authenticated user to potentially enable denial of service via local access.
ModificadaAlta (7.5)0.61%—Intel System Usage Report16/2/202317/6/2026
Improper conditions check in the Intel(R) SUR software before version 2.4.8902 may allow an unauthenticated user to potentially enable denial of service via network access.
ModificadaCrítica (9.8)0.57%—Intel System Usage Report16/2/202317/6/2026
Improper access control in the Intel(R) SUR software before version 2.4.8902 may allow an unauthenticated user to potentially enable escalation of privilege via network access.
ModificadaAlta (8.2)0.78%—Microsoft Power BI Report Server14/2/202319/8/2026
Power BI Report Server Spoofing Vulnerability
ModificadaAlta (8.8)1.1%—Microsoft Sharepoint Enterprise ServerMicrosoft Sharepoint FoundationMicrosoft Sharepoint Server14/2/202319/8/2026
Microsoft SharePoint Server Elevation of Privilege Vulnerability
ModificadaCrítica (9.8)85%💥 PoCMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Office Online ServerMicrosoft Office WEB Apps+414/2/202319/8/2026
Microsoft Word Remote Code Execution Vulnerability
ModificadaAlta (7.8)0.93%—Ureport Project Ureport14/2/20239/7/2026
An XML External Entity (XXE) vulnerability in ureport v2.2.9 allows attackers to execute arbitrary code via uploading a crafted XML file to /ureport/designer/saveReportFile.
ModificadaCrítica (9.1)1.2%—Ureport Project Ureport13/2/20239/7/2026
Se descubrió que ureport v2.2.9 contiene una vulnerabilidad de Directory Traversal a través de la función de eliminación que permite eliminar archivos arbitrarios.
ModificadaAlta (8.1)0.54%—Oracle Hospitality Reporting AND Analytics18/1/202317/6/2026
Vulnerabilidad en el producto Oracle Hospitality Reporting and Analytics de Oracle Food and Beverage Applications (componente: Reporting). La versión compatible afectada es la 9.1.0. Una vulnerabilidad fácilmente explotable permite a un atacante con pocos privilegios y acceso a la red a través de HTTPS comprometer…
ModificadaAlta (7.6)0.51%—Oracle Hospitality Reporting AND Analytics18/1/202317/6/2026
Vulnerabilidad en el producto Oracle Hospitality Reporting and Analytics de Oracle Food and Beverage Applications (componente: Reporting). La versión compatible afectada es la 9.1.0. Una vulnerabilidad fácilmente explotable permite a un atacante con pocos privilegios y acceso a la red a través de HTTPS comprometer…
ModificadaAlta (7.5)3.2%—Zohocorp Manageengine Exchange Reporter Plus17/1/202317/6/2026
Zoho ManageEngine Exchange Reporter Plus anterior a 5708 permite a los atacantes realizar ataques XXE.
ModificadaAlta (8.8)2.8%—Microsoft Sharepoint FoundationMicrosoft Sharepoint Server10/1/202317/6/2026
Vulnerabilidad de ejecución remota de código de Microsoft SharePoint Server
ModificadaMedia (5.3)1.1%—Microsoft Sharepoint Server10/1/202317/6/2026
Vulnerabilidad de omisión de la función de seguridad de Microsoft SharePoint Server
ModificadaAlta (8.8)56%💥 PoCMicrosoft Sharepoint FoundationMicrosoft Sharepoint Server10/1/202317/6/2026
Vulnerabilidad de ejecución remota de código de Microsoft SharePoint Server
ModificadaCrítica (9.8)0.66%—Angular-test-reporter Project Angular-test-reporter9/1/202317/6/2026
Se encontró una vulnerabilidad en gperson angular-test-reporter y fue clasificada como crítica. Este problema afecta la función getProjectTables/addTest del archivo rest-server/data-server.js. La manipulación conduce a la inyección SQL. El parche se llama a29d8ae121b46ebfa96a55a9106466ab2ef166ae. Se recomienda aplicar…