Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
384 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.84% | — | Oracle Business Intelligence | 19/4/2022 | 17/6/2026 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Visual Analyzer). The supported version that is affected is 5.9.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business… | |
| Modificada | Alta (7.5) | 1.6% | — | Oracle Business Intelligence | 19/4/2022 | 17/6/2026 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Analytics Web General). Supported versions that are affected are 5.5.0.0.0, 5.9.0.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via… | |
| Modificada | Media (6.1) | 0.70% | — | Oracle Business Intelligence | 19/4/2022 | 17/6/2026 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Visual Analyzer). Supported versions that are affected are 5.5.0.0.0 and 5.9.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle… | |
| Modificada | Media (6.1) | 0.83% | — | SAP Businessobjects Business Intelligence Platform | 12/4/2022 | 17/6/2026 | SAP BusinessObjects Business Intelligence Platform (BI Workspace) - version 420, is susceptible to a Cross-Site Scripting attack by an unauthenticated attacker due to improper sanitization of the user inputs on the network. On successful exploitation, an attacker can access certain reports causing a limited impact on… | |
| Modificada | Alta (8.1) | 12% | 💥 Exploit | SAP Businessobjects Business Intelligence Platform | 12/4/2022 | 17/6/2026 | When a user access SOAP Web services in SAP BusinessObjects Business Intelligence Platform - version 420, 430, it does not sufficiently validate the XML document accepted from an untrusted source, which might result in arbitrary files retrieval from the server and in successful exploits of DoS. | |
| Modificada | Media (6.5) | 1.3% | — | SAP Businessobjects Business Intelligence Platform | 12/4/2022 | 17/6/2026 | A CSRF token visible in the URL may possibly lead to information disclosure vulnerability. | |
| Modificada | Alta (7.5) | 1.4% | — | SAP Businessobjects Business Intelligence Platform | 12/4/2022 | 17/6/2026 | Under certain conditions, SAP BusinessObjects Business Intelligence platform, Client Management Console (CMC) - version 430, allows an attacker to access information which would otherwise be restricted, leading to Information Disclosure. | |
| Modificada | Media (6.5) | 0.79% | — | SAP Businessobjects Business Intelligence Platform | 12/4/2022 | 17/6/2026 | SAP BusinessObjects Business Intelligence Platform - versions 420, 430, may allow legitimate users to access information they shouldn't see through relational or OLAP connections. The main impact is the disclosure of company data to people that shouldn't or don't need to have access. | |
| Modificada | Media (6.5) | 0.80% | — | SAP Business Objects Business Intelligence Platform | 10/3/2022 | 17/6/2026 | Under certain conditions SAP Business Objects Business Intelligence Platform - versions 420, 430, allows an authenticated attacker to access information which would otherwise be restricted. | |
| Modificada | Alta (8.8) | 54% | — | Apache ChainsawApache Log4jQOS Reload4jOracle Advanced Supply Chain Planning+22 | 18/1/2022 | 17/6/2026 | CVE-2020-9493 identified a deserialization issue that was present in Apache Chainsaw. Prior to Chainsaw V2.0 Chainsaw was a component of Apache Log4j 1.2.x where the same issue exists. | |
| Modificada | Crítica (9.8) | 67% | 💥 PoC | Apache Log4jNetapp SnapmanagerBroadcom Brocade SannavQOS Reload4j+24 | 18/1/2022 | 17/6/2026 | By design, the JDBCAppender in Log4j 1.2.x accepts an SQL statement as a configuration parameter where the values to be inserted are converters from PatternLayout. The message converter, %m, is likely to always be included. This allows attackers to manipulate the SQL by entering crafted strings into input fields or… | |
| Modificada | Alta (8.8) | 64% | — | Apache Log4jNetapp SnapmanagerBroadcom Brocade SannavQOS Reload4j+22 | 18/1/2022 | 17/6/2026 | JMSSink in all versions of Log4j 1.x is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration or if the configuration references an LDAP service the attacker has access to. The attacker can provide a TopicConnectionFactoryBindingName configuration causing JMSSink… | |
| Modificada | Media (5.9) | 100% | 💥 PoC | Apache Log4jNetapp Cloud ManagerDebian LinuxSonicwall Email Security+112 | 18/12/2021 | 25/8/2026 | Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j… | |
| Modificada | Media (5.4) | 0.47% | — | SAP Businessobjects Business Intelligence Platform | 14/12/2021 | 17/6/2026 | SAP BusinessObjects Business Intelligence Platform (Web Intelligence) - version 420, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. This allows a low privileged attacker to retrieve some data from the victim but will never be able to modify the document and… | |
| Modificada | Alta (7.5) | 81% | 💥 PoC | Apache Log4jFedoraproject FedoraRedhat Codeready StudioRedhat Integration Camel K+42 | 14/12/2021 | 17/6/2026 | JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName and TopicConnectionFactoryBindingName configurations causing JMSAppender to perform JNDI requests that result in remote code execution in… | |
| Modificada | Alta (7.5) | 52% | 💥 Exploit | Hitachi Vantara PentahoHitachi Vantara Pentaho Business Intelligence Server | 8/11/2021 | 17/6/2026 | An issue was discovered in Hitachi Vantara Pentaho through 9.1 and Pentaho Business Intelligence Server through 7.x. The Security Model has different layers of Access Control. One of these layers is the applicationContext security, which is defined in the applicationContext-spring-security.xml file. The default… | |
| Modificada | Media (6.5) | 1.4% | — | Hitachi Vantara PentahoHitachi Vantara Pentaho Business Intelligence Server | 8/11/2021 | 17/6/2026 | An issue was discovered in Hitachi Vantara Pentaho through 9.1 and Pentaho Business Intelligence Server through 7.x. They implement a series of web services using the SOAP protocol to allow scripting interaction with the backend server. An authenticated user (regardless of privileges) can list all databases connection… | |
| Modificada | Media (4.3) | 0.98% | — | Hitachi Vantara PentahoHitachi Vantara Pentaho Business Intelligence Server | 8/11/2021 | 17/6/2026 | An issue was discovered in Hitachi Vantara Pentaho through 9.1 and Pentaho Business Intelligence Server through 7.x. They implement a series of web services using the SOAP protocol to allow scripting interaction with the backend server. An authenticated user (regardless of privileges) can list all valid usernames. | |
| Modificada | Alta (8.8) | 2.3% | — | Hitachi Vantara PentahoHitachi Vantara Pentaho Business Intelligence Server | 8/11/2021 | 17/6/2026 | An issue was discovered in Hitachi Vantara Pentaho through 9.1 and Pentaho Business Intelligence Server through 7.x. A reports (.prpt) file allows the inclusion of BeanShell scripts to ease the production of complex reports. An authenticated user can run arbitrary code. | |
| Modificada | Alta (7.5) | 1.3% | — | SAP Businessobjects Business Intelligence Platform | 12/10/2021 | 17/6/2026 | SAP BusinessObjects Business Intelligence Platform (Crystal Reports) - versions 420, 430, allows an unauthenticated attacker to exploit missing XML validations at endpoints to read sensitive data. These endpoints are normally exposed over the network and successful exploitation can enable the attacker to retrieve… | |
| Modificada | Media (6.1) | 0.58% | — | SAP Businessobjects Business Intelligence | 15/9/2021 | 17/6/2026 | Under certain conditions, SAP BusinessObjects Business Intelligence Platform (SAPUI5), versions - 420, 430, can allow an unauthenticated attacker to redirect users to a malicious site due to Reverse Tabnabbing vulnerabilities. | |
| Modificada | Media (5.4) | 0.47% | — | SAP Businessobjects Business Intelligence | 15/9/2021 | 17/6/2026 | SAP BusinessObjects Business Intelligence Platform (Crystal Report), versions - 420, 430, does not sufficiently encode user controlled inputs and therefore an authorized attacker can exploit a XSS vulnerability, leading to non-permanently deface or modify displayed content from a Web site. | |
| Modificada | Media (5.4) | 0.47% | — | SAP Businessobjects Business Intelligence Platform | 14/9/2021 | 17/6/2026 | The SAP BusinessObjects BI Platform version - 420 allows an attacker, who has basic access to the application, to inject a malicious script while creating a new module document, file, or folder. When another user visits that page, the stored malicious script will execute in their session, hence allowing the attacker… | |
| Modificada | Crítica (9.8) | 81% | 💥 PoC | Oracle Business Intelligence | 21/7/2021 | 17/6/2026 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Analytics Web General). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business… | |
| Modificada | Crítica (9.8) | 58% | 💥 Exploit | Eclipse Business Intelligence AND Reporting Tools | 25/6/2021 | 17/6/2026 | In Eclipse BIRT versions 4.8.0 and earlier, an attacker can use query parameters to create a JSP file which is accessible from remote (current BIRT viewer dir) to inject JSP code into the running instance. |