Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 554 respecto a la semana anterior
Críticas / altas1325▼ 178 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 242 respecto a la semana anterior
–

178 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.7%—Tibco Jasperreports ServerTibco JaspersoftTibco Jaspersoft Reporting AND Analytics7/3/201917/6/2026
The domain management component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, and TIBCO Jaspersoft Reporting and Analytics for AWS contains a race-condition vulnerability…
ModificadaMedia (6.1)6.5%💥 ExploitOracle Reports Developer16/1/201917/6/2026
Vulnerability in the Oracle Reports Developer component of Oracle Fusion Middleware (subcomponent: Valid Session). The supported version that is affected is 12.2.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Reports Developer. Successful attacks…
ModificadaAlta (8.8)1.7%—SAP Businessobjects Business IntelligenceSAP Crystal Reports10/7/201817/6/2026
SAP BusinessObjects Business Intelligence Suite, versions 4.10 and 4.20, and SAP Crystal Reports (version for Visual Studio .NET, Version 2010) allows an attacker to inject code that can be executed by the application. An attacker could thereby control the behaviour of the application.
ModificadaMedia (6.1)0.81%—Multidots Woocommerce Quick Reports1/6/201817/6/2026
The MULTIDOTS WooCommerce Quick Reports plugin 1.0.6 and earlier for WordPress is vulnerable to Stored XSS. It allows an attacker to inject malicious JavaScript code on the WooCommerce -> Orders admin page. The attack is possible by modifying the "referral_site" cookie to have an XSS payload, and placing an order.
ModificadaMedia (5.4)0.59%—Tibco Jasperreports ServerTibco JaspersoftTibco Jaspersoft Reporting AND Analytics17/4/201817/6/2026
The domain designer component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, and TIBCO Jaspersoft Reporting and Analytics for AWS contains a vulnerability which may allow,…
AnalizadaAlta (8.8)49%⚠ Explotación activa💥 ExploitTibco Jasperreports ServerTibco JaspersoftTibco Jaspersoft Reporting AND Analytics17/4/201817/6/2026
The Spring web flows of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, and TIBCO Jaspersoft Reporting and Analytics for AWS contain a vulnerability which may allow any…
ModificadaAlta (8.8)1.5%—Tibco Jasperreports ServerTibco Jasperreports LibraryTibco JaspersoftTibco Jaspersoft Reporting AND Analytics+117/4/201817/6/2026
A vulnerability in the report scripting component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO JasperReports Library, TIBCO JasperReports Library Community Edition, TIBCO JasperReports Library for ActiveMatrix…
ModificadaMedia (5.3)0.35%—SAP Crystal Reports Server10/4/201817/6/2026
Unquoted windows search path (directory/path traversal) vulnerability in Crystal Reports Server, OEM Edition (CRSE), 4.0, 4.10, 4.20, 4.30, startup path.
ModificadaCrítica (9.8)2.0%—Tibco Jasperreports ServerTibco JaspersoftTibco Jaspersoft Reporting AND Analytics15/11/201717/6/2026
A vulnerability in the server content cache of TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, and TIBCO Jaspersoft Reporting and Analytics for AWS contains a vulnerability which fails to prevent…
ModificadaMedia (5.4)0.69%—Tibco Jasperreports ServerTibco Jasperreports LibraryTibco JaspersoftTibco Jaspersoft Reporting AND Analytics+115/11/201717/6/2026
A vulnerability in the report renderer component of TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO JasperReports Library, TIBCO JasperReports Library for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, TIBCO Jaspersoft…
ModificadaMedia (6.5)1.0%—Jaspersoft Jasperreports2/10/201717/6/2026
Jaspersoft JasperReports 4.7 suffers from a saved credential disclosure vulnerability, which allows a remote authenticated user to retrieve stored Data Source passwords by accessing flow.html and reading the HTML source code of the page reached in an Edit action for a Data Source connector.
ModificadaMedia (6.5)1.3%—Tibco Jasperreports Library Community EditionTibco Jasperreports Library FOR Activematrix BPMTibco Jasperreports ProfessionalTibco Jasperreports Server+529/6/201717/6/2026
JasperReports library components contain an information disclosure vulnerability. This vulnerability includes the theoretical disclosure of any accessible information from the host file system. Affects TIBCO JasperReports Library Community Edition (versions 6.4.0 and below), TIBCO JasperReports Library for…
ModificadaAlta (8.8)0.57%—Tibco Jasperreports ServerTibco JaspersoftTibco Jaspersoft Reporting AND Analytics29/6/201717/6/2026
Multiple JasperReports Server components contain vulnerabilities which may allow authorized users to perform cross-site scripting (XSS) and cross-site request forgery (CSRF) attacks. The impact of this vulnerability includes the theoretical disclosure of sensitive information. Affects TIBCO JasperReports Server…
ModificadaMedia (5.9)1.1%—IBM Bigfix Webreports30/8/201617/6/2026
WebReports in IBM BigFix Platform (formerly Tivoli Endpoint Manager) 9.x before 9.5.2 allows remote attackers to obtain sensitive information by sniffing the network for HTTP traffic.
ModificadaMedia (6.8)3.1%—SAP Crystal Reports4/9/201417/6/2026
Double free vulnerability in SAP Crystal Reports allows remote attackers to execute arbitrary code via crafted connection string record in an RPT file.
ModificadaMedia (6.8)3.8%—SAP Crystal Reports4/9/201417/6/2026
Stack-based buffer overflow in SAP Crystal Reports allows remote attackers to execute arbitrary code via a crafted data source string in an RPT file.
ModificadaBaja (2.1)0.38%—Redhat Rhevm-reports29/5/201417/6/2026
ovirt-engine-reports, as used in the Red Hat Enterprise Virtualization reports package (rhevm-reports) before 3.3.3, uses world-readable permissions on configuration files, which allows local users to obtain sensitive information by reading the files.
ModificadaBaja (2.1)0.37%—Redhat Rhevm-reports29/5/201417/6/2026
The Red Hat Enterprise Virtualization Manager reports (rhevm-reports) package before 3.3.3-1 uses world-readable permissions on the datasource configuration file (js-jboss7-ds.xml), which allows local users to obtain sensitive information by reading the file.
ModificadaBaja (2.1)0.37%—Redhat Rhevm-reports29/5/201417/6/2026
The setup script in ovirt-engine-reports, as used in the Red Hat Enterprise Virtualization reports (rhevm-reports) package before 3.3.3, stores the reports database password in cleartext, which allows local users to obtain sensitive information by reading an unspecified file.
ModificadaAlta (9.3)4.1%—Dreamreport Dream ReportInvensys Wonderware HMI Reports10/2/201216/6/2026
Invensys Wonderware HMI Reports 3.42.835.0304 and earlier, as used in Ocean Data Systems Dream Report before 4.0 and other products, allows user-assisted remote attackers to execute arbitrary code via a malformed file that triggers a "write access violation."
ModificadaMedia (4.3)2.1%—Dreamreport Dream ReportInvensys Wonderware HMI Reports10/2/201216/6/2026
Cross-site scripting (XSS) vulnerability in Invensys Wonderware HMI Reports 3.42.835.0304 and earlier, as used in Ocean Data Systems Dream Report before 4.0 and other products, allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.
ModificadaMedia (4.3)1.1%—SAP Crystal Reports Server14/12/201116/6/2026
Cross-site scripting (XSS) vulnerability in pubDBLogon.jsp in SAP Crystal Report Server 2008 allows remote attackers to inject arbitrary web script or HTML via the service parameter.
ModificadaMedia (5)1.7%—Schneider-electric Vijeo HistorianSchneider-electric CitecthistorianSchneider-electric Citectscada Reports2/12/201116/6/2026
Directory traversal vulnerability in Schneider Electric Vijeo Historian 4.30 and earlier, CitectHistorian 4.30 and earlier, and CitectSCADAReports 4.10 and earlier allows remote attackers to read arbitrary files via unspecified vectors.
ModificadaMedia (4.3)2.0%—Schneider-electric Vijeo HistorianSchneider-electric CitecthistorianSchneider-electric Citectscada Reports2/12/201116/6/2026
Cross-site scripting (XSS) vulnerability in Schneider Electric Vijeo Historian 4.30 and earlier, CitectHistorian 4.30 and earlier, and CitectSCADAReports 4.10 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaAlta (9.3)13%💥 ExploitSchneider-electric Vijeo HistorianSchneider-electric CitecthistorianSchneider-electric Citectscada Reports2/12/201116/6/2026
Buffer overflow in the Steema TeeChart ActiveX control, as used in Schneider Electric Vijeo Historian 4.30 and earlier, CitectHistorian 4.30 and earlier, and CitectSCADAReports 4.10 and earlier, allows remote attackers to execute arbitrary code or cause a denial of service via unspecified vectors.
Orbitaley — Vulnerabilidades