Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
966 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 0.51% | — | Oracle Reports Developer | 18/8/2026 | 26/8/2026 | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 12.2.1.19.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Reports Developer.… | |
| Analizada | Alta (7.3) | 0.35% | — | Oracle Reports Developer | 18/8/2026 | 26/8/2026 | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 12.2.1.19.0. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware… | |
| Analizada | Alta (8.8) | 0.43% | — | Oracle Reports Developer | 18/8/2026 | 26/8/2026 | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 12.2.1.19.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Reports Developer.… | |
| Analizada | Crítica (9.8) | 0.51% | — | Oracle Reports Developer | 18/8/2026 | 26/8/2026 | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 12.2.1.19.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP to compromise Oracle Reports Developer.… | |
| Analizada | Crítica (9.1) | 0.43% | — | Oracle Reports Developer | 18/8/2026 | 26/8/2026 | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 12.2.1.19.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Reports Developer.… | |
| Analizada | Crítica (9.8) | 0.51% | — | Oracle Reports Developer | 18/8/2026 | 26/8/2026 | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 12.2.1.19.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Reports Developer.… | |
| Analizada | Crítica (9.9) | 0.43% | — | Oracle Reports Developer | 18/8/2026 | 26/8/2026 | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 12.2.1.19.0. Easily exploitable vulnerability allows low privileged attacker with network access via CORBA to compromise Oracle Reports Developer. While… | |
| Aplazada | Baja (2.1) | 0.33% | — | Xianrendzw EasyreportAI | 18/8/2026 | 20/8/2026 | A security vulnerability has been detected in xianrendzw EasyReport up to 2.0.17.0522_Beta. Affected by this issue is some unknown functionality of the file ModuleController.java of the component Move Operations. Such manipulation of the argument sourcePath leads to sql injection. The attack may be performed from… | |
| Aplazada | Crítica (9.1) | 1.1% | — | Reportico-webAI | 18/8/2026 | 31/8/2026 | An arbitrary file write/directory traversal vulnerability in reportico-web <= 8.1.0 allows remote attackers to create or overwrite files anywhere on the filesystem subject to the permissions of the web user by specifying a filename in the "saveTemplate" parameter in conjuction with "execute_mode=PREPARE" parameter in… | |
| Aplazada | Media (6.1) | 0.31% | — | Reportico-webAI | 18/8/2026 | 31/8/2026 | A reflected cross-site scripting (XSS) vulnerability in reportico-web <= 8.1.0 allows remote attackers to execute arbitrary JavaScript in the web browser of a user by including a malicious payload in the reportico_criteria parameter in conjunction with the execute_mode=CRITERIA parameter of run.php. | |
| Aplazada | Crítica (9.8) | 0.89% | — | Reportico-webAI | 18/8/2026 | 31/8/2026 | An incorrect access control vulnerability in reportico-web <= 8.1.0 allows an unauthenticated attacker to inject arbitrary php code into the PreExecuteCode attribute of any report regardless of the safe_mode setting leading to remote code execution. | |
| Aplazada | Media (6.5) | 0.75% | — | Reportico-webAI | 18/8/2026 | 31/8/2026 | A directory traversal vulnerability in reportico-web <= 8.1.0 allows remote attackers to expose or execute arbitrary php files on the web server by specifying the filename in the target_format parameter in conjunction with the execute_mode=EXECUTE parameter of the run.php endpoint. | |
| Aplazada | Media (6.1) | 0.31% | — | Reportico-webAI | 18/8/2026 | 31/8/2026 | A reflected cross-site scripting (XSS) vulnerability in reportico-web <= 8.1.0 allows remote attackers to execute arbitrary JavaScript in the web browser of a user by including a malicious payload in the loadTemplate parameter in conjunction with the execute_mode=PREPARE parameter of run.php. | |
| Aplazada | Crítica (9.8) | 0.87% | 💥 PoC | Apache VelocityAIOpensagres XdocreportAI | 17/8/2026 | 9/9/2026 | A Server-Side Template Injection (SSTI) vulnerability in the Velocity template engine configuration of xdocreport v0.9.2 to v2.2.0 allows attackers to execute arbitrary code via a crafted expression. | |
| Aplazada | Alta (8.7) | 0.46% | — | Jeecg JimureportAI | 17/8/2026 | 24/9/2026 | JimuReport contains an authentication bypass vulnerability in the report folder template listing endpoint that allows unauthenticated attackers to enumerate all reports and retrieve share tokens. Attackers can use disclosed share tokens to access protected report endpoints and retrieve full report definitions… | |
| Analizada | Alta (8.8) | 0.96% | — | Microsoft Power BI Report Server | 11/8/2026 | 19/8/2026 | Improper input validation in Power BI allows an authorized attacker to execute code over a network. | |
| Pendiente de análisis | Crítica (9.3) | 0.45% | — | Jaspersoft Jasperreports ServerAI | 10/8/2026 | 31/8/2026 | Improper restriction of XML external entity reference vulnerability (unauthenticated) in Jaspersoft JasperReports Server. This issue affects JasperReports Server: from 9.0.0 before HF-9 and from 10.0.0 before HF-10. | |
| Pendiente de análisis | Alta (7.1) | 0.32% | — | Jenkins IVY ReportAI | 5/8/2026 | 31/8/2026 | Jenkins Ivy Report Plugin 1.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks when processing Ivy report files. | |
| Analizada | Alta (8.7) | 0.90% | — | Syncfusion Standalone Report Designer | 23/7/2026 | 28/7/2026 | Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its file upload functionality that allows authenticated attackers to traverse outside the intended directory by supplying a crafted filename. Attackers can exploit this path traversal weakness to execute… | |
| Analizada | Crítica (9.3) | 0.87% | — | Syncfusion Standalone Report Designer | 23/7/2026 | 28/7/2026 | Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its database download feature that allows unauthenticated attackers to read arbitrary files from the server filesystem by supplying a crafted request. Attackers can exploit this path traversal weakness to… | |
| Analizada | Crítica (9.3) | 0.87% | — | Syncfusion Standalone Report Designer | 23/7/2026 | 28/7/2026 | Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its font processing feature that allows unauthenticated attackers to read arbitrary files from the server filesystem by supplying a crafted request. Attackers can exploit this path traversal weakness to… | |
| Analizada | Crítica (9.3) | 0.87% | — | Syncfusion Standalone Report Designer | 23/7/2026 | 28/7/2026 | Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its SVG processing feature that allows unauthenticated attackers to read arbitrary files from the server filesystem by supplying a crafted request. Attackers can exploit this path traversal weakness to… | |
| Aplazada | Crítica (9.8) | 0.50% | — | UreportAI | 16/7/2026 | 17/7/2026 | A SQL injection vulnerability in the /ureport/datasource/previewData component of ureport v2.2.9 allows attackers to access sensitive database information via crafted SQL statements. | |
| Analizada | Media (5.4) | 0.52% | — | Microsoft Power BI Report Server | 14/7/2026 | 19/8/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Power BI allows an authorized attacker to perform spoofing over a network. | |
| Aplazada | Media (6.4) | 0.35% | — | Block Suspend Report FOR BuddypressAI | 9/7/2026 | 9/7/2026 | The Block, Suspend, Report for BuddyPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link' parameter in versions up to and including 3.6.4. This is due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with subscriber-level access… |