Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2720▼ 598 respecto a la semana anterior
Críticas / altas1299▼ 202 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
996 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 0.51% | — | Oracle Reports Developer | 18/8/2026 | 26/8/2026 | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 12.2.1.19.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Reports Developer.… | |
| Analizada | Alta (7.3) | 0.35% | — | Oracle Reports Developer | 18/8/2026 | 26/8/2026 | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 12.2.1.19.0. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware… | |
| Analizada | Alta (8.8) | 0.43% | — | Oracle Reports Developer | 18/8/2026 | 26/8/2026 | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 12.2.1.19.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Reports Developer.… | |
| Analizada | Crítica (9.8) | 0.51% | — | Oracle Reports Developer | 18/8/2026 | 26/8/2026 | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 12.2.1.19.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP to compromise Oracle Reports Developer.… | |
| Analizada | Crítica (9.1) | 0.43% | — | Oracle Reports Developer | 18/8/2026 | 26/8/2026 | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 12.2.1.19.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Reports Developer.… | |
| Analizada | Crítica (9.8) | 0.51% | — | Oracle Reports Developer | 18/8/2026 | 26/8/2026 | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 12.2.1.19.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Reports Developer.… | |
| Analizada | Crítica (9.9) | 0.43% | — | Oracle Reports Developer | 18/8/2026 | 26/8/2026 | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 12.2.1.19.0. Easily exploitable vulnerability allows low privileged attacker with network access via CORBA to compromise Oracle Reports Developer. While… | |
| Aplazada | Baja (2.1) | 0.33% | — | Xianrendzw EasyreportAI | 18/8/2026 | 20/8/2026 | A security vulnerability has been detected in xianrendzw EasyReport up to 2.0.17.0522_Beta. Affected by this issue is some unknown functionality of the file ModuleController.java of the component Move Operations. Such manipulation of the argument sourcePath leads to sql injection. The attack may be performed from… | |
| Aplazada | Crítica (9.1) | 1.1% | — | Reportico-webAI | 18/8/2026 | 31/8/2026 | An arbitrary file write/directory traversal vulnerability in reportico-web <= 8.1.0 allows remote attackers to create or overwrite files anywhere on the filesystem subject to the permissions of the web user by specifying a filename in the "saveTemplate" parameter in conjuction with "execute_mode=PREPARE" parameter in… | |
| Aplazada | Media (6.1) | 0.31% | — | Reportico-webAI | 18/8/2026 | 31/8/2026 | A reflected cross-site scripting (XSS) vulnerability in reportico-web <= 8.1.0 allows remote attackers to execute arbitrary JavaScript in the web browser of a user by including a malicious payload in the reportico_criteria parameter in conjunction with the execute_mode=CRITERIA parameter of run.php. | |
| Aplazada | Crítica (9.8) | 0.89% | — | Reportico-webAI | 18/8/2026 | 31/8/2026 | An incorrect access control vulnerability in reportico-web <= 8.1.0 allows an unauthenticated attacker to inject arbitrary php code into the PreExecuteCode attribute of any report regardless of the safe_mode setting leading to remote code execution. | |
| Aplazada | Media (6.5) | 0.75% | — | Reportico-webAI | 18/8/2026 | 31/8/2026 | A directory traversal vulnerability in reportico-web <= 8.1.0 allows remote attackers to expose or execute arbitrary php files on the web server by specifying the filename in the target_format parameter in conjunction with the execute_mode=EXECUTE parameter of the run.php endpoint. | |
| Aplazada | Media (6.1) | 0.31% | — | Reportico-webAI | 18/8/2026 | 31/8/2026 | A reflected cross-site scripting (XSS) vulnerability in reportico-web <= 8.1.0 allows remote attackers to execute arbitrary JavaScript in the web browser of a user by including a malicious payload in the loadTemplate parameter in conjunction with the execute_mode=PREPARE parameter of run.php. | |
| Aplazada | Crítica (9.8) | 0.87% | 💥 PoC | Apache VelocityAIOpensagres XdocreportAI | 17/8/2026 | 9/9/2026 | A Server-Side Template Injection (SSTI) vulnerability in the Velocity template engine configuration of xdocreport v0.9.2 to v2.2.0 allows attackers to execute arbitrary code via a crafted expression. | |
| Aplazada | Alta (8.7) | 0.46% | — | Jeecg JimureportAI | 17/8/2026 | 24/9/2026 | JimuReport contains an authentication bypass vulnerability in the report folder template listing endpoint that allows unauthenticated attackers to enumerate all reports and retrieve share tokens. Attackers can use disclosed share tokens to access protected report endpoints and retrieve full report definitions… | |
| Analizada | Alta (8.8) | 0.96% | — | Microsoft Power BI Report Server | 11/8/2026 | 19/8/2026 | Improper input validation in Power BI allows an authorized attacker to execute code over a network. | |
| Pendiente de análisis | Crítica (9.3) | 0.45% | — | Jaspersoft Jasperreports ServerAI | 10/8/2026 | 31/8/2026 | Improper restriction of XML external entity reference vulnerability (unauthenticated) in Jaspersoft JasperReports Server. This issue affects JasperReports Server: from 9.0.0 before HF-9 and from 10.0.0 before HF-10. | |
| Pendiente de análisis | Alta (7.1) | 0.32% | — | Jenkins IVY ReportAI | 5/8/2026 | 31/8/2026 | Jenkins Ivy Report Plugin 1.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks when processing Ivy report files. | |
| Analizada | Alta (8.7) | 0.90% | — | Syncfusion Standalone Report Designer | 23/7/2026 | 28/7/2026 | Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its file upload functionality that allows authenticated attackers to traverse outside the intended directory by supplying a crafted filename. Attackers can exploit this path traversal weakness to execute… | |
| Analizada | Crítica (9.3) | 0.87% | — | Syncfusion Standalone Report Designer | 23/7/2026 | 28/7/2026 | Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its database download feature that allows unauthenticated attackers to read arbitrary files from the server filesystem by supplying a crafted request. Attackers can exploit this path traversal weakness to… | |
| Analizada | Crítica (9.3) | 0.87% | — | Syncfusion Standalone Report Designer | 23/7/2026 | 28/7/2026 | Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its font processing feature that allows unauthenticated attackers to read arbitrary files from the server filesystem by supplying a crafted request. Attackers can exploit this path traversal weakness to… | |
| Analizada | Crítica (9.3) | 0.87% | — | Syncfusion Standalone Report Designer | 23/7/2026 | 28/7/2026 | Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its SVG processing feature that allows unauthenticated attackers to read arbitrary files from the server filesystem by supplying a crafted request. Attackers can exploit this path traversal weakness to… | |
| Aplazada | Media (6.7) | 0.15% | — | Txone Networks SafeportagentAITxone Networks StellarprotectAI | 17/7/2026 | 27/7/2026 | Improper Access Control vulnerability in the Removable Media Validation function of TXOne Networks products allows a local attacker with administrator privileges to bypass the file lockdown mechanism, resulting in unauthorized file transfer to the victim device. The attacker needs to deploy unauthorized file on the… | |
| Aplazada | Crítica (9.8) | 0.50% | — | UreportAI | 16/7/2026 | 17/7/2026 | A SQL injection vulnerability in the /ureport/datasource/previewData component of ureport v2.2.9 allows attackers to access sensitive database information via crafted SQL statements. | |
| Analizada | Media (5.4) | 0.52% | — | Microsoft Power BI Report Server | 14/7/2026 | 19/8/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Power BI allows an authorized attacker to perform spoofing over a network. |