Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
178 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.83% | — | Tibco Jasperreports Server | 12/10/2021 | 17/6/2026 | The Scheduler Connection component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperReports Server - Community Edition, TIBCO JasperReports Server - Developer Edition, TIBCO JasperReports Server for AWS Marketplace,… | |
| Modificada | Media (5.3) | 0.50% | — | Tibco Jasperreports Server | 12/10/2021 | 17/6/2026 | The Rest API component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperReports Server - Community Edition, TIBCO JasperReports Server - Developer Edition, TIBCO JasperReports Server for AWS Marketplace, TIBCO… | |
| Modificada | Alta (8.8) | 0.58% | — | Quadbase Espressreports ES | 11/3/2021 | 17/6/2026 | An issue was discovered in Quadbase EspressReports ES 7 Update 9. It allows CSRF, whereby an attacker may be able to trick an authenticated admin level user into uploading malicious files to the web server. | |
| Modificada | Alta (8.8) | 0.64% | — | Quadbase Espressreports ES | 11/3/2021 | 17/6/2026 | An issue was discovered in Quadbase EspressReports ES 7 Update 9. An unauthenticated attacker can create a malicious HTML file that houses a POST request made to the DashboardBuilder within the target web application. This request will utilise the target admin session and perform the authenticated request (to change… | |
| Modificada | Media (6.1) | 0.91% | — | Inetsoftware I-net Clear Reports | 9/3/2021 | 17/6/2026 | I-Net Software Clear Reports 20.10.136 web application accepts a user-controlled input that specifies a link to an external site, and uses the user supplied data in a Redirect. | |
| Modificada | Media (6.5) | 1.4% | — | Schneider-electric Webreports | 19/11/2020 | 17/6/2026 | A CWE-284 Improper Access Control vulnerability exists in EcoStruxure Building Operation WebReports V1.9 - V3.1 that could cause a remote attacker being able to access a restricted web resources due to improper access control. | |
| Modificada | Alta (8.8) | 1.8% | — | Schneider-electric Webreports | 19/11/2020 | 17/6/2026 | A CWE-611 Improper Restriction of XML External Entity Reference vulnerability exists in EcoStruxure Building Operation WebReports V1.9 - V3.1 that could cause an authenticated remote user being able to inject arbitrary XML code and obtain disclosure of confidential data, denial of service, server side request forgery… | |
| Modificada | Media (5.4) | 0.84% | — | Schneider-electric Webreports | 19/11/2020 | 17/6/2026 | A CWE-79 Multiple Improper Neutralization of Input During Web Page Generation (Cross-site Scripting Reflected) vulnerability exists in EcoStruxure Building Operation WebReports V1.9 - V3.1 that could cause a remote attacker to inject arbitrary web script or HTML due to incorrect sanitization of user supplied data and… | |
| Modificada | Media (5.4) | 0.84% | — | Schneider-electric Webreports | 19/11/2020 | 17/6/2026 | A CWE-79 Improper Neutralization of Input During Web Page Generation (Cross-site Scripting Stored) vulnerability exists in EcoStruxure Building Operation WebReports V1.9 - V3.1 that could cause an authenticated remote user being able to inject arbitrary web script or HTML due to incorrect sanitization of user-supplied… | |
| Modificada | Alta (8.8) | 2.4% | — | Schneider-electric Webreports | 19/11/2020 | 17/6/2026 | A CWE-434 Unrestricted Upload of File with Dangerous Type vulnerability exists in EcoStruxure Building Operation WebReports V1.9 - V3.1 that could cause an authenticated remote user being able to upload arbitrary files due to incorrect verification of user supplied files and achieve remote code execution. | |
| Modificada | Media (6.1) | 0.91% | — | Advanced Reports Project Advanced Reports | 3/9/2020 | 17/6/2026 | silverstripe-advancedreports (aka the Advanced Reports module for SilverStripe) 1.0 through 2.0 is vulnerable to Cross-Site Scripting (XSS) because it is possible to inject and store malicious JavaScript code. The affects admin/advanced-reports/DataObjectReport/EditForm/field/DataObjectReport/item (aka report preview)… | |
| Modificada | Crítica (9.8) | 5.1% | — | Stimulsoft Reports | 18/8/2020 | 17/6/2026 | A Remote Code Execution vulnerability in Stimulsoft (aka Stimulsoft Reports) 2013.1.1600.0 allows an attacker to encode C# scripts as base-64 in the report XML file so that they will be compiled and executed on the server that processes this file. This can be used to fully compromise the server. | |
| Modificada | Crítica (9.8) | 1.1% | — | Inetsoftware I-net Clear Reports | 15/7/2020 | 17/6/2026 | XXE injection can occur in i-net Clear Reports 2019 19.0.287 (Designer), as used in i-net HelpDesk and other products, when XML input containing a reference to an external entity is processed by a weakly configured XML parser. | |
| Modificada | Alta (8.8) | 5.4% | — | Tibco Jasperreports LibraryTibco Jasperreports ServerOracle Retail Order Broker | 20/5/2020 | 17/6/2026 | The report generator component of TIBCO Software Inc.'s TIBCO JasperReports Library, TIBCO JasperReports Library for ActiveMatrix BPM, TIBCO JasperReports Server, TIBCO JasperReports Server for AWS Marketplace, and TIBCO JasperReports Server for ActiveMatrix BPM contains a vulnerability that theoretically allows an… | |
| Modificada | Crítica (9.8) | 3.5% | — | Tibco Jasperreports ServerOracle Retail Order Broker | 20/5/2020 | 17/6/2026 | The administrative UI component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server for AWS Marketplace, and TIBCO JasperReports Server for ActiveMatrix BPM contains a vulnerability that theoretically allows an unauthenticated attacker to obtain the permissions of a JasperReports Server… | |
| Modificada | Crítica (9.1) | 2.1% | — | Inetsoftware Clear ReportsInetsoftware HelpdeskInetsoftware Pdfc | 7/5/2020 | 17/6/2026 | The documentation component in i-net Clear Reports 16.0 to 19.2, HelpDesk 8.0 to 8.3, and PDFC 4.3 to 6.2 allows a remote unauthenticated attacker to read arbitrary system files and directories on the target server via Directory Traversal. | |
| Modificada | Alta (8.8) | 1.3% | — | SAP Businessobjects Business Intelligence PlatformSAP Crystal Reports FOR Visual Studio | 14/4/2020 | 17/6/2026 | SAP Business Objects Business Intelligence Platform (CrystalReports WebForm Viewer), versions 4.1, 4.2, and Crystal Reports for VS version 2010, allows an attacker with basic authorization to perform deserialization attack in the application, leading to service interruptions and denial of service and unauthorized… | |
| Modificada | Alta (8.2) | 1.1% | — | SAP Crystal Reports | 10/3/2020 | 17/6/2026 | SAP Business Objects Business Intelligence Platform (Crystal Reports), versions- 4.1, 4.2, allows an attacker with basic authorization to inject code that can be executed by the application and thus allowing the attacker to control the behaviour of the application, leading to Remote Code Execution. Although the mode… | |
| Modificada | Media (6.1) | 1.00% | — | Oracle Reports Developer | 15/1/2020 | 17/6/2026 | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). Supported versions that are affected are 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Reports… | |
| Modificada | Media (6.1) | 1.0% | — | Oracle Reports Developer | 15/1/2020 | 17/6/2026 | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). Supported versions that are affected are 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Reports… | |
| Modificada | Crítica (9.8) | 6.6% | 💥 Exploit | SAP Crystal Reports | 10/4/2019 | 17/6/2026 | The .NET SDK WebForm Viewer in SAP Crystal Reports for Visual Studio (fixed in version 2010) discloses sensitive database information including credentials which can be misused by the attacker. | |
| Modificada | Alta (7.7) | 1.0% | — | Tibco Jasperreports Server | 7/3/2019 | 17/6/2026 | The SOAP API component vulnerability of TIBCO Software Inc.'s TIBCO JasperReports Server, and TIBCO JasperReports Server for ActiveMatrix BPM contains a vulnerability that may allow a malicious authenticated user to copy text files from the host operating system. Affected releases are TIBCO Software Inc.'s TIBCO… | |
| Modificada | Media (5.4) | 1.2% | — | Tibco Jasperreports ServerTibco JaspersoftTibco Jaspersoft Reporting AND Analytics | 7/3/2019 | 17/6/2026 | The repository component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, TIBCO Jaspersoft Reporting and Analytics for AWS contains a persistent cross site scripting… | |
| Modificada | Crítica (9.8) | 3.1% | — | Tibco Jasperreports ServerTibco JaspersoftTibco Jaspersoft Reporting AND Analytics | 7/3/2019 | 17/6/2026 | The REST API component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, and TIBCO Jaspersoft Reporting and Analytics for AWS contains a vulnerability that theoretically allows… | |
| Analizada | Media (6.5) | 79% | ⚠ Explotación activa💥 Exploit | Tibco Jasperreports LibraryTibco Jasperreports ServerTibco JaspersoftTibco Jaspersoft Reporting AND Analytics | 7/3/2019 | 17/6/2026 | The default server implementation of TIBCO Software Inc.'s TIBCO JasperReports Library, TIBCO JasperReports Library Community Edition, TIBCO JasperReports Library for ActiveMatrix BPM, TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO… |