Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2839▼ 348 respecto a la semana anterior
Críticas / altas1378▼ 43 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
1305 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (6.5) | 0.35% | — | SAP Business AnalyticsAISAP Content ManagementAI | 14/4/2026 | 17/6/2026 | Due to a missing authorization check in SAP Business Analytics and SAP Content Management, an authenticated user could make unauthorized calls to certain remote function modules, potentially accessing sensitive information beyond their intended permissions. This vulnerability affects confidentiality, with no impact on… | |
| Analizada | Media (6.1) | 0.25% | — | Sujanshrestha Google Analytics GA4 | 26/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Google Analytics GA4 allows Cross-Site Scripting (XSS).This issue affects Google Analytics GA4: from 0.0.0 before 1.1.14. | |
| Analizada | Media (6.1) | 0.16% | — | Hitachi Infrastructure Analytics AdvisorHitachi OPS Center Analyzer | 25/3/2026 | 12/8/2026 | Cross-Site Scripting vulnerability in Hitachi Infrastructure Analytics Advisor (Analytics probe component), Hitachi Ops Center Analyzer.This issue affects Hitachi Infrastructure Analytics Advisor:; Hitachi Ops Center Analyzer: from 10.0.0-00 before 11.0.5-00. | |
| Aplazada | Media (5.3) | 0.48% | — | Smarter AnalyticsAI | 21/3/2026 | 17/6/2026 | The Smarter Analytics plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 2.0. This is due to missing authentication and capability checks on the configuration reset functionality in the global scope of smarter-analytics.php. This makes it possible for unauthenticated… | |
| Aplazada | Alta (7.2) | 0.32% | — | Wp-slimstat Slimstat AnalyticsAI | 19/3/2026 | 17/6/2026 | The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'fh' (fingerprint) parameter in all versions up to, and including, 5.3.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in… | |
| Analizada | Media (6.5) | 0.33% | — | IBM Planning Analytics Local | 17/3/2026 | 17/6/2026 | IBM Planning Analytics Local 2.1.0 through 2.1.17 could allow an unauthorized access to sensitive application data and administrative functionalities due to lack of proper access controls. | |
| Analizada | Media (5.7) | 0.29% | — | IBM Planning Analytics Local | 17/3/2026 | 17/6/2026 | IBM Planning Analytics Local 2.1.0 through 2.1.17 could allow an attacker to trick the caching mechanism into storing and serving sensitive, user-specific responses as publicly cacheable resources. | |
| Analizada | Media (4.4) | 0.08% | — | IBM Planning Analytics Advanced Certified Containers | 10/3/2026 | 17/6/2026 | IBM Planning Analytics Advanced Certified Containers 3.1.0 through 3.1.4 could allow a local privileged user to obtain sensitive information from environment variables. | |
| Analizada | Crítica (9.1) | 0.39% | — | Hitachi Vantara Pentaho Data Integration AND Analytics | 10/3/2026 | 17/6/2026 | Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.6, including 9.3.x and 8.3.x, do not restrict Groovy scripts in new PRPT reports published by users, allowing insertion of arbitrary scripts and leading to a RCE. | |
| Aplazada | Alta (7.1) | 0.18% | — | Veronalabs Slimstat AnalyticsAI | 20/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VeronaLabs Slimstat Analytics wp-slimstat allows Reflected XSS.This issue affects Slimstat Analytics: from n/a through <= 5.3.2. | |
| Aplazada | Media (6.5) | 0.26% | — | Passionatebrains Advance WC AnalyticsAI | 20/2/2026 | 17/6/2026 | Missing Authorization vulnerability in Passionate Brains Advanced WC Analytics advance-wc-analytics allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Advanced WC Analytics: from n/a through <= 3.19.0. | |
| Aplazada | Media (6.5) | 0.26% | — | Passionatebrains Ga4wp Google Analytics FOR WordpressAI | 20/2/2026 | 17/6/2026 | Missing Authorization vulnerability in Passionate Brains GA4WP: Google Analytics for WordPress ga-for-wp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects GA4WP: Google Analytics for WordPress: from n/a through <= 2.10.0. | |
| Aplazada | Media (6.5) | 0.23% | — | Wp-slimstat Slimstat AnalyticsAI | 11/2/2026 | 17/6/2026 | The SlimStat Analytics plugin for WordPress is vulnerable to time-based SQL Injection via the ‘args’ parameter in all versions up to, and including, 5.3.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated… | |
| Aplazada | Media (4.3) | 0.15% | — | IBM Operations Analytics LOG AnalysisAIIBM Smartcloud Analytics LOG AnalysisAI | 4/2/2026 | 17/6/2026 | IBM Operations Analytics – Log Analysis versions 1.3.5.0 through 1.3.8.3 and IBM SmartCloud Analytics – Log Analysis are vulnerable to a cross-site request forgery (CSRF) vulnerability that could allow an attacker to trick a trusted user into performing unauthorized actions. | |
| Analizada | Media (4.8) | 0.17% | — | Bordeaux-metropole AT Internet Piano Analytics | 4/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal AT Internet Piano Analytics allows Cross-Site Scripting (XSS).This issue affects AT Internet Piano Analytics: from 0.0.0 before 1.0.1, from 2.0.0 before 2.3.1. | |
| Analizada | Baja (2.3) | 0.18% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+17 | 4/2/2026 | 17/6/2026 | A vulnerability exists in an undisclosed BIG-IP Configuration utility page that may allow an attacker to spoof error messages. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Aplazada | Media (5.3) | 0.35% | — | Wise AnalyticsAI | 24/1/2026 | 17/6/2026 | The Wise Analytics plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.1.9. This is due to missing capability checks on the REST API endpoint '/wise-analytics/v1/report'. This makes it possible for unauthenticated attackers to access sensitive analytics data including… | |
| Analizada | Alta (8.3) | 0.48% | — | Ibericode Koko Analytics | 19/1/2026 | 17/6/2026 | Koko Analytics is an open-source analytics plugin for WordPress. Versions prior to 2.1.3 are vulnerable to arbitrary SQL execution through unescaped analytics export/import and permissive admin SQL import. Unauthenticated visitors can submit arbitrary path (`pa`) and referrer (`r`) values to the public tracking… | |
| Aplazada | Alta (7.2) | 0.27% | — | Wp-slimstat Slimstat AnalyticsAI | 9/1/2026 | 17/6/2026 | The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `fh` (fingerprint) parameter in all versions up to, and including, 5.3.3. This is due to insufficient input sanitization and output escaping on the fingerprint value stored in the database. This makes it possible for… | |
| Aplazada | Alta (7.2) | 0.27% | — | Wp-slimstat Slimstat AnalyticsAI | 9/1/2026 | 17/6/2026 | The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'notes' and 'resource' parameters in all versions up to, and including, 5.3.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts… | |
| Aplazada | Media (5.4) | 0.20% | — | Passionatebrains Ga4wp Google Analytics FOR WordpressAI | 8/1/2026 | 17/6/2026 | Missing Authorization vulnerability in Passionate Brains GA4WP: Google Analytics for WordPress ga-for-wp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects GA4WP: Google Analytics for WordPress: from n/a through <= 2.10.0. | |
| Aplazada | Baja (2.7) | 0.25% | — | Rankology SEO AND Analytics ToolAI | 7/1/2026 | 17/6/2026 | The Rankology SEO and Analytics Tool plugin for WordPress is vulnerable to unauthorized modification of data due to an incorrect capability check on the 'rankology_code_block' page in all versions up to, and including, 2.0. This makes it possible for authenticated attackers, with Editor-level access and above, to add… | |
| Aplazada | Media (4.7) | 0.28% | — | Sharethis Dashboard FOR Google AnalyticsAI | 7/1/2026 | 17/6/2026 | The ShareThis Dashboard for Google Analytics plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.2.4. This is due to the Google Analytics client_ID and client_secret being stored in plaintext in the publicly visible plugin source. This can allow unauthenticated… | |
| Aplazada | Alta (7.1) | 0.22% | — | Hitachi Infrastructure Analytics AdvisorAIHitachi OPS Center AnalyzerAI | 24/12/2025 | 17/6/2026 | Authorization bypass vulnerability in Hitachi Infrastructure Analytics Advisor (Data Center Analytics component) and Hitachi Ops Center Analyzer (Hitachi Ops Center Analyzer detail view component).This issue affects Hitachi Infrastructure Analytics Advisor:; Hitachi Ops Center Analyzer: from 10.0.0-00 before 11.0.5-00. | |
| Aplazada | Alta (8.2) | 0.20% | — | Hitachi Infrastructure Analytics AdvisorAIHitachi OPS Center AnalyzerAI | 24/12/2025 | 17/6/2026 | Cross-site Scripting vulnerability in Hitachi Infrastructure Analytics Advisor (Data Center Analytics component) and Hitachi Ops Center Analyzer (Hitachi Ops Center Analyzer detail view component).This issue affects Hitachi Infrastructure Analytics Advisor:; Hitachi Ops Center Analyzer: from 10.0.0-00 before 11.0.5-00. |