Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
996 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.3) | 0.18% | — | Hcltech Bigfix Webui APIHcltech Bigfix Webui Application AdministrationHcltech Bigfix Webui CmepHcltech Bigfix Webui Common+17 | 9/5/2026 | 25/7/2026 | A missing authorization vulnerability in HCL BigFix WebUI allows an authenticated user without proper permissions to view sensitive environmental information via direct URL access to the unauthorized page. | |
| Analizada | Media (5.3) | 0.22% | — | Hcltech Bigfix Webui APIHcltech Bigfix Webui Application AdministrationHcltech Bigfix Webui CmepHcltech Bigfix Webui Common+17 | 9/5/2026 | 25/7/2026 | An improper authorization vulnerability in HCL BigFix WebUI allows an authenticated user without Master Operator privileges to access internal data (site names, versions, and configuration variables) and bypass privilege requirements via unprotected endpoints lacking adequate security headers. | |
| Analizada | Media (4.8) | 0.28% | — | Apache Storm Prometheus Reporter | 27/4/2026 | 17/6/2026 | Improper Certificate Validation via Global SSL Context Downgrade in Apache Storm Prometheus Reporter Versions Affected: from 2.6.3 to 2.8.6 Description: In production deployments where an administrator enables storm.daemon.metrics.reporter.plugin.prometheus.skip_tls_validation (by default it is disabled) intending to… | |
| Aplazada | Baja (2) | 0.43% | — | Jeecg JimureportAI | 9/4/2026 | 17/6/2026 | A vulnerability was found in jeecgboot JimuReport up to 2.3.0. The affected element is the function DriverManager.getConnection of the file /drag/onlDragDataSource/testConnection of the component Data Source Handler. Performing a manipulation of the argument dbUrl results in code injection. The attack may be initiated… | |
| Aplazada | Media (5.3) | 0.44% | — | Mainwp Child ReportsAI | 8/4/2026 | 24/7/2026 | The MainWP Child Reports plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 2.2.6. This is due to a missing capability check in the heartbeat_received() function in the Live_Update class. This makes it possible for authenticated attackers, with Subscriber-level access and… | |
| Pendiente de análisis | Media (5.3) | 0.40% | — | Wikimedia MediawikiAIWikimedia ReportincidentAI | 7/4/2026 | 21/7/2026 | Allocation of resources without limits or throttling vulnerability in Wikimedia Foundation MediaWiki - ReportIncident Extension allows HTTP DoS. This issue was remediated only on the `master` branch. | |
| Analizada | Media (4.8) | 1.0% | — | Zohocorp Manageengine Exchange Reporter Plus | 3/4/2026 | 20/7/2026 | Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Permissions Based on Mailboxes report. | |
| Analizada | Media (4.8) | 1.0% | — | Zohocorp Manageengine Exchange Reporter Plus | 3/4/2026 | 24/7/2026 | Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Non-Owner Mailbox Permission report. | |
| Analizada | Media (5.4) | 1.0% | — | Zohocorp Manageengine Exchange Reporter Plus | 3/4/2026 | 24/7/2026 | Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Folder Message Count and Size report. | |
| Analizada | Media (4.8) | 1.0% | — | Zohocorp Manageengine Exchange Reporter Plus | 3/4/2026 | 24/7/2026 | Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Public Folder Client Permissions report. | |
| Analizada | Media (4.8) | 1.0% | — | Zohocorp Manageengine Exchange Reporter Plus | 3/4/2026 | 24/7/2026 | Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Equipment Mailbox Details report. | |
| Analizada | Media (4.8) | 1.0% | — | Zohocorp Manageengine Exchange Reporter Plus | 3/4/2026 | 24/7/2026 | Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Mails Exchanged Between Users report. | |
| Analizada | Media (4.8) | 1.0% | — | Zohocorp Manageengine Exchange Reporter Plus | 3/4/2026 | 24/7/2026 | Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Permissions based on Distribution Groups report. | |
| Analizada | Media (4.8) | 1.0% | — | Zohocorp Manageengine Exchange Reporter Plus | 3/4/2026 | 24/7/2026 | Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Distribution Lists report. | |
| Aplazada | Crítica (9.3) | 0.28% | — | Wpfactory Advanced Woocommerce Product Sales ReportingAI | 25/3/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPFactory Advanced WooCommerce Product Sales Reporting webd-woocommerce-advanced-reporting-statistics allows Blind SQL Injection.This issue affects Advanced WooCommerce Product Sales Reporting: from n/a through <=… | |
| Analizada | Alta (7.5) | 0.52% | — | Qameta Allure Report | 20/3/2026 | 17/6/2026 | Allure 2 is the version 2.x branch of Allure Report, a multi-language test reporting tool. The Allure report generator prior to version 2.38.0 is vulnerable to an arbitrary file read via path traversal when processing test results. An attacker can craft a malicious result file (-result.json, -container.json, or… | |
| Aplazada | Media (4.4) | 0.24% | — | CM Custom ReportsAI | 20/3/2026 | 17/6/2026 | The CM Custom Reports – Flexible reporting to track what matters most plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.2.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Analizada | Alta (8.1) | 0.27% | — | Devolutions HUB Reporting Service | 18/3/2026 | 17/6/2026 | Improper certificate validation in Devolutions Hub Reporting Service 2025.3.1.1 and earlier allows a network attacker to perform a man-in-the-middle attack via disabled TLS certificate verification. | |
| Pendiente de análisis | Alta (8.8) | 0.46% | — | Microsoft Dynamics 365 Customer EngagementAIMicrosoft SQL Server Reporting ServicesAI | 18/3/2026 | 17/6/2026 | Microsoft Dynamics 365 Customer Engagement (on-premises) 1612 (9.0.2.3034) allows the generation of customized reports via raw SQL queries in an upload of a .rdl (Report Definition Language) file; this is then processed by the SQL Server Reporting Service. An account with the privilege Add Reporting Services Reports… | |
| Aplazada | Media (6.1) | 0.23% | — | CM Custom ReportsAI | 7/3/2026 | 17/6/2026 | The CM Custom Reports plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'date_from' and 'date_to' parameters in all versions up to, and including, 1.2.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Aplazada | Alta (8.5) | 0.13% | — | Intego LOG ReporterAI | 12/2/2026 | 17/6/2026 | Intego Log Reporter, a macOS diagnostic utility bundled with Intego security products that collects system and application logs for support analysis, contains a local privilege escalation vulnerability. A root-executed diagnostic script creates and writes files in /tmp without enforcing secure directory handling,… | |
| Analizada | Media (6.5) | 0.26% | — | Glpi-project More Reporting | 12/2/2026 | 17/6/2026 | mreporting is the more reporting GLPI plugin. Prior to 1.9.4, there is a possible SQL injection on date change. This vulnerability is fixed in 1.9.4. | |
| Analizada | Alta (8.8) | 0.96% | — | Microsoft Power BI Report Server | 10/2/2026 | 19/8/2026 | Improper input validation in Power BI allows an authorized attacker to execute code over a network. | |
| Analizada | Baja (3.5) | 0.23% | — | IBM Jazz Reporting Service | 4/2/2026 | 17/6/2026 | IBM Jazz Reporting Service could allow an authenticated user on the network to affect the system's performance using complicated queries due to insufficient resource pooling. | |
| Analizada | Baja (3.5) | 0.22% | — | IBM Jazz Reporting Service | 4/2/2026 | 17/6/2026 | IBM Jazz Reporting Service could allow an authenticated user on the host network to obtain sensitive information about other projects that reside on the server. |