Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
–

996 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.3)0.18%—Hcltech Bigfix Webui APIHcltech Bigfix Webui Application AdministrationHcltech Bigfix Webui CmepHcltech Bigfix Webui Common+179/5/202625/7/2026
A missing authorization vulnerability in HCL BigFix WebUI allows an authenticated user without proper permissions to view sensitive environmental information via direct URL access to the unauthorized page.
AnalizadaMedia (5.3)0.22%—Hcltech Bigfix Webui APIHcltech Bigfix Webui Application AdministrationHcltech Bigfix Webui CmepHcltech Bigfix Webui Common+179/5/202625/7/2026
An improper authorization vulnerability in HCL BigFix WebUI allows an authenticated user without Master Operator privileges to access internal data (site names, versions, and configuration variables) and bypass privilege requirements via unprotected endpoints lacking adequate security headers.
AnalizadaMedia (4.8)0.28%—Apache Storm Prometheus Reporter27/4/202617/6/2026
Improper Certificate Validation via Global SSL Context Downgrade in Apache Storm Prometheus Reporter Versions Affected: from 2.6.3 to 2.8.6 Description: In production deployments where an administrator enables storm.daemon.metrics.reporter.plugin.prometheus.skip_tls_validation (by default it is disabled) intending to…
AplazadaBaja (2)0.43%—Jeecg JimureportAI9/4/202617/6/2026
A vulnerability was found in jeecgboot JimuReport up to 2.3.0. The affected element is the function DriverManager.getConnection of the file /drag/onlDragDataSource/testConnection of the component Data Source Handler. Performing a manipulation of the argument dbUrl results in code injection. The attack may be initiated…
AplazadaMedia (5.3)0.44%—Mainwp Child ReportsAI8/4/202624/7/2026
The MainWP Child Reports plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 2.2.6. This is due to a missing capability check in the heartbeat_received() function in the Live_Update class. This makes it possible for authenticated attackers, with Subscriber-level access and…
Pendiente de análisisMedia (5.3)0.40%—Wikimedia MediawikiAIWikimedia ReportincidentAI7/4/202621/7/2026
Allocation of resources without limits or throttling vulnerability in Wikimedia Foundation MediaWiki - ReportIncident Extension allows HTTP DoS. This issue was remediated only on the `master` branch.
AnalizadaMedia (4.8)1.0%—Zohocorp Manageengine Exchange Reporter Plus3/4/202620/7/2026
Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Permissions Based on Mailboxes report.
AnalizadaMedia (4.8)1.0%—Zohocorp Manageengine Exchange Reporter Plus3/4/202624/7/2026
Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Non-Owner Mailbox Permission report.
AnalizadaMedia (5.4)1.0%—Zohocorp Manageengine Exchange Reporter Plus3/4/202624/7/2026
Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Folder Message Count and Size report.
AnalizadaMedia (4.8)1.0%—Zohocorp Manageengine Exchange Reporter Plus3/4/202624/7/2026
Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Public Folder Client Permissions report.
AnalizadaMedia (4.8)1.0%—Zohocorp Manageengine Exchange Reporter Plus3/4/202624/7/2026
Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Equipment Mailbox Details report.
AnalizadaMedia (4.8)1.0%—Zohocorp Manageengine Exchange Reporter Plus3/4/202624/7/2026
Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Mails Exchanged Between Users report.
AnalizadaMedia (4.8)1.0%—Zohocorp Manageengine Exchange Reporter Plus3/4/202624/7/2026
Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Permissions based on Distribution Groups report.
AnalizadaMedia (4.8)1.0%—Zohocorp Manageengine Exchange Reporter Plus3/4/202624/7/2026
Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Distribution Lists report.
AplazadaCrítica (9.3)0.28%—Wpfactory Advanced Woocommerce Product Sales ReportingAI25/3/202617/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPFactory Advanced WooCommerce Product Sales Reporting webd-woocommerce-advanced-reporting-statistics allows Blind SQL Injection.This issue affects Advanced WooCommerce Product Sales Reporting: from n/a through <=…
AnalizadaAlta (7.5)0.52%—Qameta Allure Report20/3/202617/6/2026
Allure 2 is the version 2.x branch of Allure Report, a multi-language test reporting tool. The Allure report generator prior to version 2.38.0 is vulnerable to an arbitrary file read via path traversal when processing test results. An attacker can craft a malicious result file (-result.json, -container.json, or…
AplazadaMedia (4.4)0.24%—CM Custom ReportsAI20/3/202617/6/2026
The CM Custom Reports – Flexible reporting to track what matters most plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.2.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
AnalizadaAlta (8.1)0.27%—Devolutions HUB Reporting Service18/3/202617/6/2026
Improper certificate validation in Devolutions Hub Reporting Service 2025.3.1.1 and earlier allows a network attacker to perform a man-in-the-middle attack via disabled TLS certificate verification.
Pendiente de análisisAlta (8.8)0.46%—Microsoft Dynamics 365 Customer EngagementAIMicrosoft SQL Server Reporting ServicesAI18/3/202617/6/2026
Microsoft Dynamics 365 Customer Engagement (on-premises) 1612 (9.0.2.3034) allows the generation of customized reports via raw SQL queries in an upload of a .rdl (Report Definition Language) file; this is then processed by the SQL Server Reporting Service. An account with the privilege Add Reporting Services Reports…
AplazadaMedia (6.1)0.23%—CM Custom ReportsAI7/3/202617/6/2026
The CM Custom Reports plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'date_from' and 'date_to' parameters in all versions up to, and including, 1.2.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…
AplazadaAlta (8.5)0.13%—Intego LOG ReporterAI12/2/202617/6/2026
Intego Log Reporter, a macOS diagnostic utility bundled with Intego security products that collects system and application logs for support analysis, contains a local privilege escalation vulnerability. A root-executed diagnostic script creates and writes files in /tmp without enforcing secure directory handling,…
AnalizadaMedia (6.5)0.26%—Glpi-project More Reporting12/2/202617/6/2026
mreporting is the more reporting GLPI plugin. Prior to 1.9.4, there is a possible SQL injection on date change. This vulnerability is fixed in 1.9.4.
AnalizadaAlta (8.8)0.96%—Microsoft Power BI Report Server10/2/202619/8/2026
Improper input validation in Power BI allows an authorized attacker to execute code over a network.
AnalizadaBaja (3.5)0.23%—IBM Jazz Reporting Service4/2/202617/6/2026
IBM Jazz Reporting Service could allow an authenticated user on the network to affect the system's performance using complicated queries due to insufficient resource pooling.
AnalizadaBaja (3.5)0.22%—IBM Jazz Reporting Service4/2/202617/6/2026
IBM Jazz Reporting Service could allow an authenticated user on the host network to obtain sensitive information about other projects that reside on the server.
Orbitaley — Vulnerabilidades