Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 546 respecto a la semana anterior
Críticas / altas1325▼ 174 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 241 respecto a la semana anterior
966 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.8) | 0.28% | — | Apache Storm Prometheus Reporter | 27/4/2026 | 17/6/2026 | Improper Certificate Validation via Global SSL Context Downgrade in Apache Storm Prometheus Reporter Versions Affected: from 2.6.3 to 2.8.6 Description: In production deployments where an administrator enables storm.daemon.metrics.reporter.plugin.prometheus.skip_tls_validation (by default it is disabled) intending to… | |
| Aplazada | Baja (2) | 0.43% | — | Jeecg JimureportAI | 9/4/2026 | 17/6/2026 | A vulnerability was found in jeecgboot JimuReport up to 2.3.0. The affected element is the function DriverManager.getConnection of the file /drag/onlDragDataSource/testConnection of the component Data Source Handler. Performing a manipulation of the argument dbUrl results in code injection. The attack may be initiated… | |
| Aplazada | Media (5.3) | 0.44% | — | Mainwp Child ReportsAI | 8/4/2026 | 24/7/2026 | The MainWP Child Reports plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 2.2.6. This is due to a missing capability check in the heartbeat_received() function in the Live_Update class. This makes it possible for authenticated attackers, with Subscriber-level access and… | |
| Pendiente de análisis | Media (5.3) | 0.40% | — | Wikimedia MediawikiAIWikimedia ReportincidentAI | 7/4/2026 | 21/7/2026 | Allocation of resources without limits or throttling vulnerability in Wikimedia Foundation MediaWiki - ReportIncident Extension allows HTTP DoS. This issue was remediated only on the `master` branch. | |
| Analizada | Media (4.8) | 1.0% | — | Zohocorp Manageengine Exchange Reporter Plus | 3/4/2026 | 20/7/2026 | Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Permissions Based on Mailboxes report. | |
| Analizada | Media (4.8) | 1.0% | — | Zohocorp Manageengine Exchange Reporter Plus | 3/4/2026 | 24/7/2026 | Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Non-Owner Mailbox Permission report. | |
| Analizada | Media (5.4) | 1.0% | — | Zohocorp Manageengine Exchange Reporter Plus | 3/4/2026 | 24/7/2026 | Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Folder Message Count and Size report. | |
| Analizada | Media (4.8) | 1.0% | — | Zohocorp Manageengine Exchange Reporter Plus | 3/4/2026 | 24/7/2026 | Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Public Folder Client Permissions report. | |
| Analizada | Media (4.8) | 1.0% | — | Zohocorp Manageengine Exchange Reporter Plus | 3/4/2026 | 24/7/2026 | Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Equipment Mailbox Details report. | |
| Analizada | Media (4.8) | 1.0% | — | Zohocorp Manageengine Exchange Reporter Plus | 3/4/2026 | 24/7/2026 | Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Mails Exchanged Between Users report. | |
| Analizada | Media (4.8) | 1.0% | — | Zohocorp Manageengine Exchange Reporter Plus | 3/4/2026 | 24/7/2026 | Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Permissions based on Distribution Groups report. | |
| Analizada | Media (4.8) | 1.0% | — | Zohocorp Manageengine Exchange Reporter Plus | 3/4/2026 | 24/7/2026 | Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Distribution Lists report. | |
| Aplazada | Crítica (9.3) | 0.28% | — | Wpfactory Advanced Woocommerce Product Sales ReportingAI | 25/3/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPFactory Advanced WooCommerce Product Sales Reporting webd-woocommerce-advanced-reporting-statistics allows Blind SQL Injection.This issue affects Advanced WooCommerce Product Sales Reporting: from n/a through <=… | |
| Analizada | Alta (7.5) | 0.52% | — | Qameta Allure Report | 20/3/2026 | 17/6/2026 | Allure 2 is the version 2.x branch of Allure Report, a multi-language test reporting tool. The Allure report generator prior to version 2.38.0 is vulnerable to an arbitrary file read via path traversal when processing test results. An attacker can craft a malicious result file (-result.json, -container.json, or… | |
| Aplazada | Media (4.4) | 0.24% | — | CM Custom ReportsAI | 20/3/2026 | 17/6/2026 | The CM Custom Reports – Flexible reporting to track what matters most plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.2.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Analizada | Alta (8.1) | 0.27% | — | Devolutions HUB Reporting Service | 18/3/2026 | 17/6/2026 | Improper certificate validation in Devolutions Hub Reporting Service 2025.3.1.1 and earlier allows a network attacker to perform a man-in-the-middle attack via disabled TLS certificate verification. | |
| Pendiente de análisis | Alta (8.8) | 0.46% | — | Microsoft Dynamics 365 Customer EngagementAIMicrosoft SQL Server Reporting ServicesAI | 18/3/2026 | 17/6/2026 | Microsoft Dynamics 365 Customer Engagement (on-premises) 1612 (9.0.2.3034) allows the generation of customized reports via raw SQL queries in an upload of a .rdl (Report Definition Language) file; this is then processed by the SQL Server Reporting Service. An account with the privilege Add Reporting Services Reports… | |
| Aplazada | Media (6.1) | 0.23% | — | CM Custom ReportsAI | 7/3/2026 | 17/6/2026 | The CM Custom Reports plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'date_from' and 'date_to' parameters in all versions up to, and including, 1.2.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Aplazada | Alta (8.5) | 0.13% | — | Intego LOG ReporterAI | 12/2/2026 | 17/6/2026 | Intego Log Reporter, a macOS diagnostic utility bundled with Intego security products that collects system and application logs for support analysis, contains a local privilege escalation vulnerability. A root-executed diagnostic script creates and writes files in /tmp without enforcing secure directory handling,… | |
| Analizada | Media (6.5) | 0.26% | — | Glpi-project More Reporting | 12/2/2026 | 17/6/2026 | mreporting is the more reporting GLPI plugin. Prior to 1.9.4, there is a possible SQL injection on date change. This vulnerability is fixed in 1.9.4. | |
| Analizada | Alta (8.8) | 0.96% | — | Microsoft Power BI Report Server | 10/2/2026 | 19/8/2026 | Improper input validation in Power BI allows an authorized attacker to execute code over a network. | |
| Analizada | Baja (3.5) | 0.23% | — | IBM Jazz Reporting Service | 4/2/2026 | 17/6/2026 | IBM Jazz Reporting Service could allow an authenticated user on the network to affect the system's performance using complicated queries due to insufficient resource pooling. | |
| Analizada | Baja (3.5) | 0.22% | — | IBM Jazz Reporting Service | 4/2/2026 | 17/6/2026 | IBM Jazz Reporting Service could allow an authenticated user on the host network to obtain sensitive information about other projects that reside on the server. | |
| Analizada | Baja (3.5) | 0.23% | — | IBM Jazz Reporting Service | 4/2/2026 | 17/6/2026 | IBM Jazz Reporting Service could allow an authenticated user on the host network to cause a denial of service using specially crafted SQL query that consumes excess memory resources. | |
| Analizada | Baja (2.3) | 0.18% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+17 | 4/2/2026 | 17/6/2026 | A vulnerability exists in an undisclosed BIG-IP Configuration utility page that may allow an attacker to spoof error messages. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. |