Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 554 respecto a la semana anterior
Críticas / altas1325▼ 178 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 242 respecto a la semana anterior
178 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.7% | — | Tibco Jasperreports ServerTibco JaspersoftTibco Jaspersoft Reporting AND Analytics | 7/3/2019 | 17/6/2026 | The domain management component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, and TIBCO Jaspersoft Reporting and Analytics for AWS contains a race-condition vulnerability… | |
| Modificada | Media (6.1) | 6.5% | 💥 Exploit | Oracle Reports Developer | 16/1/2019 | 17/6/2026 | Vulnerability in the Oracle Reports Developer component of Oracle Fusion Middleware (subcomponent: Valid Session). The supported version that is affected is 12.2.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Reports Developer. Successful attacks… | |
| Modificada | Alta (8.8) | 1.7% | — | SAP Businessobjects Business IntelligenceSAP Crystal Reports | 10/7/2018 | 17/6/2026 | SAP BusinessObjects Business Intelligence Suite, versions 4.10 and 4.20, and SAP Crystal Reports (version for Visual Studio .NET, Version 2010) allows an attacker to inject code that can be executed by the application. An attacker could thereby control the behaviour of the application. | |
| Modificada | Media (6.1) | 0.81% | — | Multidots Woocommerce Quick Reports | 1/6/2018 | 17/6/2026 | The MULTIDOTS WooCommerce Quick Reports plugin 1.0.6 and earlier for WordPress is vulnerable to Stored XSS. It allows an attacker to inject malicious JavaScript code on the WooCommerce -> Orders admin page. The attack is possible by modifying the "referral_site" cookie to have an XSS payload, and placing an order. | |
| Modificada | Media (5.4) | 0.59% | — | Tibco Jasperreports ServerTibco JaspersoftTibco Jaspersoft Reporting AND Analytics | 17/4/2018 | 17/6/2026 | The domain designer component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, and TIBCO Jaspersoft Reporting and Analytics for AWS contains a vulnerability which may allow,… | |
| Analizada | Alta (8.8) | 49% | ⚠ Explotación activa💥 Exploit | Tibco Jasperreports ServerTibco JaspersoftTibco Jaspersoft Reporting AND Analytics | 17/4/2018 | 17/6/2026 | The Spring web flows of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, and TIBCO Jaspersoft Reporting and Analytics for AWS contain a vulnerability which may allow any… | |
| Modificada | Alta (8.8) | 1.5% | — | Tibco Jasperreports ServerTibco Jasperreports LibraryTibco JaspersoftTibco Jaspersoft Reporting AND Analytics+1 | 17/4/2018 | 17/6/2026 | A vulnerability in the report scripting component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO JasperReports Library, TIBCO JasperReports Library Community Edition, TIBCO JasperReports Library for ActiveMatrix… | |
| Modificada | Media (5.3) | 0.35% | — | SAP Crystal Reports Server | 10/4/2018 | 17/6/2026 | Unquoted windows search path (directory/path traversal) vulnerability in Crystal Reports Server, OEM Edition (CRSE), 4.0, 4.10, 4.20, 4.30, startup path. | |
| Modificada | Crítica (9.8) | 2.0% | — | Tibco Jasperreports ServerTibco JaspersoftTibco Jaspersoft Reporting AND Analytics | 15/11/2017 | 17/6/2026 | A vulnerability in the server content cache of TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, and TIBCO Jaspersoft Reporting and Analytics for AWS contains a vulnerability which fails to prevent… | |
| Modificada | Media (5.4) | 0.69% | — | Tibco Jasperreports ServerTibco Jasperreports LibraryTibco JaspersoftTibco Jaspersoft Reporting AND Analytics+1 | 15/11/2017 | 17/6/2026 | A vulnerability in the report renderer component of TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO JasperReports Library, TIBCO JasperReports Library for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, TIBCO Jaspersoft… | |
| Modificada | Media (6.5) | 1.0% | — | Jaspersoft Jasperreports | 2/10/2017 | 17/6/2026 | Jaspersoft JasperReports 4.7 suffers from a saved credential disclosure vulnerability, which allows a remote authenticated user to retrieve stored Data Source passwords by accessing flow.html and reading the HTML source code of the page reached in an Edit action for a Data Source connector. | |
| Modificada | Media (6.5) | 1.3% | — | Tibco Jasperreports Library Community EditionTibco Jasperreports Library FOR Activematrix BPMTibco Jasperreports ProfessionalTibco Jasperreports Server+5 | 29/6/2017 | 17/6/2026 | JasperReports library components contain an information disclosure vulnerability. This vulnerability includes the theoretical disclosure of any accessible information from the host file system. Affects TIBCO JasperReports Library Community Edition (versions 6.4.0 and below), TIBCO JasperReports Library for… | |
| Modificada | Alta (8.8) | 0.57% | — | Tibco Jasperreports ServerTibco JaspersoftTibco Jaspersoft Reporting AND Analytics | 29/6/2017 | 17/6/2026 | Multiple JasperReports Server components contain vulnerabilities which may allow authorized users to perform cross-site scripting (XSS) and cross-site request forgery (CSRF) attacks. The impact of this vulnerability includes the theoretical disclosure of sensitive information. Affects TIBCO JasperReports Server… | |
| Modificada | Media (5.9) | 1.1% | — | IBM Bigfix Webreports | 30/8/2016 | 17/6/2026 | WebReports in IBM BigFix Platform (formerly Tivoli Endpoint Manager) 9.x before 9.5.2 allows remote attackers to obtain sensitive information by sniffing the network for HTTP traffic. | |
| Modificada | Media (6.8) | 3.1% | — | SAP Crystal Reports | 4/9/2014 | 17/6/2026 | Double free vulnerability in SAP Crystal Reports allows remote attackers to execute arbitrary code via crafted connection string record in an RPT file. | |
| Modificada | Media (6.8) | 3.8% | — | SAP Crystal Reports | 4/9/2014 | 17/6/2026 | Stack-based buffer overflow in SAP Crystal Reports allows remote attackers to execute arbitrary code via a crafted data source string in an RPT file. | |
| Modificada | Baja (2.1) | 0.38% | — | Redhat Rhevm-reports | 29/5/2014 | 17/6/2026 | ovirt-engine-reports, as used in the Red Hat Enterprise Virtualization reports package (rhevm-reports) before 3.3.3, uses world-readable permissions on configuration files, which allows local users to obtain sensitive information by reading the files. | |
| Modificada | Baja (2.1) | 0.37% | — | Redhat Rhevm-reports | 29/5/2014 | 17/6/2026 | The Red Hat Enterprise Virtualization Manager reports (rhevm-reports) package before 3.3.3-1 uses world-readable permissions on the datasource configuration file (js-jboss7-ds.xml), which allows local users to obtain sensitive information by reading the file. | |
| Modificada | Baja (2.1) | 0.37% | — | Redhat Rhevm-reports | 29/5/2014 | 17/6/2026 | The setup script in ovirt-engine-reports, as used in the Red Hat Enterprise Virtualization reports (rhevm-reports) package before 3.3.3, stores the reports database password in cleartext, which allows local users to obtain sensitive information by reading an unspecified file. | |
| Modificada | Alta (9.3) | 4.1% | — | Dreamreport Dream ReportInvensys Wonderware HMI Reports | 10/2/2012 | 16/6/2026 | Invensys Wonderware HMI Reports 3.42.835.0304 and earlier, as used in Ocean Data Systems Dream Report before 4.0 and other products, allows user-assisted remote attackers to execute arbitrary code via a malformed file that triggers a "write access violation." | |
| Modificada | Media (4.3) | 2.1% | — | Dreamreport Dream ReportInvensys Wonderware HMI Reports | 10/2/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Invensys Wonderware HMI Reports 3.42.835.0304 and earlier, as used in Ocean Data Systems Dream Report before 4.0 and other products, allows remote attackers to inject arbitrary web script or HTML via unspecified parameters. | |
| Modificada | Media (4.3) | 1.1% | — | SAP Crystal Reports Server | 14/12/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in pubDBLogon.jsp in SAP Crystal Report Server 2008 allows remote attackers to inject arbitrary web script or HTML via the service parameter. | |
| Modificada | Media (5) | 1.7% | — | Schneider-electric Vijeo HistorianSchneider-electric CitecthistorianSchneider-electric Citectscada Reports | 2/12/2011 | 16/6/2026 | Directory traversal vulnerability in Schneider Electric Vijeo Historian 4.30 and earlier, CitectHistorian 4.30 and earlier, and CitectSCADAReports 4.10 and earlier allows remote attackers to read arbitrary files via unspecified vectors. | |
| Modificada | Media (4.3) | 2.0% | — | Schneider-electric Vijeo HistorianSchneider-electric CitecthistorianSchneider-electric Citectscada Reports | 2/12/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Schneider Electric Vijeo Historian 4.30 and earlier, CitectHistorian 4.30 and earlier, and CitectSCADAReports 4.10 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (9.3) | 13% | 💥 Exploit | Schneider-electric Vijeo HistorianSchneider-electric CitecthistorianSchneider-electric Citectscada Reports | 2/12/2011 | 16/6/2026 | Buffer overflow in the Steema TeeChart ActiveX control, as used in Schneider Electric Vijeo Historian 4.30 and earlier, CitectHistorian 4.30 and earlier, and CitectSCADAReports 4.10 and earlier, allows remote attackers to execute arbitrary code or cause a denial of service via unspecified vectors. |