Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2556▼ 319 respecto a la semana anterior
Críticas / altas1344▲ 80 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
137 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Crítica (9.3) | 0.45% | — | Jaspersoft Jasperreports ServerAI | 10/8/2026 | 31/8/2026 | Improper restriction of XML external entity reference vulnerability (unauthenticated) in Jaspersoft JasperReports Server. This issue affects JasperReports Server: from 9.0.0 before HF-9 and from 10.0.0 before HF-10. | |
| Pendiente de análisis | Alta (8.7) | 0.66% | — | Jaspersoft ReportsAI | 19/5/2026 | 24/7/2026 | Java Deserialisation Vulnerability in Jaspersoft Reports Library leads to Remote Code Execution (RCE), potentially allowing code execution on the affected system | |
| Modificada | Alta (8.7) | 0.90% | — | Cloud Jasperreports IOCloud Jasperreports LibraryCloud Jasperreports ServerCloud Jasperreports Studio+1 | 16/9/2025 | 17/6/2026 | A Java deserialisation vulnerability has been discovered in Jaspersoft Library. Improper handling of externally supplied data may allow attackers to execute arbitrary code remotely on systems that use the affected library | |
| Analizada | Baja (1.9) | 0.23% | — | Jasper Project Jasper | 11/8/2025 | 17/6/2026 | A vulnerability was identified in JasPer up to 4.2.5. This affects the function jpc_dec_dump of the file src/libjasper/jpc/jpc_dec.c of the component JPEG2000 File Handler. The manipulation leads to use after free. An attack has to be approached locally. The exploit has been disclosed to the public and may be used.… | |
| Analizada | Baja (1.9) | 0.21% | — | Jasper Project Jasper | 11/8/2025 | 17/6/2026 | A vulnerability was determined in JasPer up to 4.2.5. Affected by this issue is the function jpc_floorlog2 of the file src/libjasper/jpc/jpc_enc.c of the component JPEG2000 Encoder. The manipulation leads to reachable assertion. The attack needs to be approached locally. The exploit has been disclosed to the public… | |
| Analizada | Baja (1.9) | 0.21% | — | Jasper Project Jasper | 11/8/2025 | 17/6/2026 | A vulnerability was found in JasPer up to 4.2.5. Affected by this vulnerability is the function jas_image_chclrspc of the file src/libjasper/base/jas_image.c of the component Image Color Space Conversion Handler. The manipulation leads to null pointer dereference. It is possible to launch the attack on the local host.… | |
| Analizada | Alta (8.6) | 0.59% | — | Cloud Jasperreports Server | 10/7/2024 | 17/6/2026 | Vulnerability in Jaspersoft JasperReport Servers.This issue affects JasperReport Servers: from 8.0.4 through 9.0.0. | |
| Aplazada | Alta (7.5) | 0.74% | — | JasperAI | 19/4/2024 | 17/6/2026 | In Jasper 4.2.2, the jpc_streamlist_remove function in src/libjasper/jpc/jpc_dec.c:2407 has an assertion failure vulnerability, allowing attackers to cause a denial of service attack through a specific image file. | |
| Aplazada | Alta (8.3) | 0.44% | — | Tibco Jasperreports ServerAI | 17/4/2024 | 17/6/2026 | Cross Site Scripting in UI Request/Response Validation in TIBCO JasperReports Server 8.0.4 and 8.2.0 allows allows for the injection of malicious executable scripts into the code of a trusted application that may lead to stealing the user's active session cookie via sending malicious link, enticing the user to… | |
| Modificada | Alta (7.8) | 0.26% | — | Jasper Project Jasper | 16/1/2024 | 17/6/2026 | An invalid memory write issue in Jasper-Software Jasper v.4.1.1 and before allows a local attacker to execute arbitrary code. | |
| Modificada | Media (5.4) | 0.90% | — | Tibco Jasperreports Server | 13/12/2022 | 17/6/2026 | The Dashboard component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperReports Server - Developer Edition, TIBCO JasperReports Server for AWS Marketplace, TIBCO JasperReports Server for AWS Marketplace, TIBCO JasperReports Server for Microsoft Azure, and TIBCO… | |
| Modificada | Alta (8.4) | 0.74% | — | Tibco Jasperreports Server | 13/12/2022 | 17/6/2026 | The HTML escaping component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperReports Server - Community Edition, TIBCO JasperReports Server - Developer Edition, TIBCO JasperReports Server for AWS Marketplace, TIBCO JasperReports Server for AWS Marketplace, TIBCO… | |
| Modificada | Alta (7.2) | 1.5% | — | Tibco Jasperreports Server | 13/12/2022 | 17/6/2026 | The JNDI Data Sources component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperReports Server - Community Edition, TIBCO JasperReports Server - Developer Edition, TIBCO JasperReports Server for AWS Marketplace, TIBCO JasperReports Server for AWS Marketplace, TIBCO… | |
| Modificada | Alta (7.5) | 1.4% | — | Jasper Project JasperFedoraproject FedoraRedhat Enterprise Linux | 14/10/2022 | 17/6/2026 | A vulnerability found in jasper. This security vulnerability happens because of a memory leak bug in function cmdopts_parse that can cause a crash or segmentation fault. | |
| Modificada | Media (5.5) | 0.38% | — | Jasper Project Jasper | 16/9/2022 | 17/6/2026 | JasPer 3.0.6 allows denial of service via a reachable assertion in the function inttobits in libjasper/base/jas_image.c. | |
| Modificada | Media (5.4) | 0.51% | — | Tibco Jasperreports Server | 17/5/2022 | 17/6/2026 | The REST API component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server - Community Edition, TIBCO JasperReports Server - Developer Edition, TIBCO JasperReports Server for AWS Marketplace, TIBCO JasperReports Server for ActiveMatrix BPM, and TIBCO JasperReports Server for Microsoft Azure… | |
| Modificada | Alta (8.8) | 2.5% | — | Tibco Jasperreports LibraryTibco Jasperreports Server | 15/3/2022 | 17/6/2026 | The Server component of TIBCO Software Inc.'s TIBCO JasperReports Library, TIBCO JasperReports Library for ActiveMatrix BPM, TIBCO JasperReports Server, TIBCO JasperReports Server for AWS Marketplace, TIBCO JasperReports Server for ActiveMatrix BPM, and TIBCO JasperReports Server for Microsoft Azure contains a… | |
| Modificada | Alta (7.5) | 0.64% | — | Tibco Jasperreports Server | 12/10/2021 | 17/6/2026 | The XMLA Connections component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperReports Server - Community Edition, TIBCO JasperReports Server - Developer Edition, TIBCO JasperReports Server for AWS Marketplace, TIBCO… | |
| Modificada | Alta (8.8) | 0.83% | — | Tibco Jasperreports Server | 12/10/2021 | 17/6/2026 | The Scheduler Connection component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperReports Server - Community Edition, TIBCO JasperReports Server - Developer Edition, TIBCO JasperReports Server for AWS Marketplace,… | |
| Modificada | Media (5.3) | 0.50% | — | Tibco Jasperreports Server | 12/10/2021 | 17/6/2026 | The Rest API component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperReports Server - Community Edition, TIBCO JasperReports Server - Developer Edition, TIBCO JasperReports Server for AWS Marketplace, TIBCO… | |
| Modificada | Media (5.5) | 0.65% | — | Jasper Project Jasper | 15/7/2021 | 17/6/2026 | A Divide-by-zero vulnerability exists in JasPer Image Coding Toolkit 2.0 in jasper/src/libjasper/jpc/jpc_enc.c | |
| Modificada | Media (5.5) | 0.63% | — | Jasper Project JasperFedoraproject Fedora | 25/3/2021 | 17/6/2026 | A NULL pointer dereference flaw was found in the way Jasper versions before 2.0.26 handled component references in CDEF box in the JP2 image format decoder. A specially crafted JP2 image file could cause an application using the Jasper library to crash when opened. | |
| Modificada | Media (5.5) | 0.76% | — | Jasper Project JasperRedhat Enterprise LinuxFedoraproject Fedora | 25/3/2021 | 17/6/2026 | A NULL pointer dereference flaw was found in the way Jasper versions before 2.0.27 handled component references in the JP2 image format decoder. A specially crafted JP2 image file could cause an application using the Jasper library to crash when opened. | |
| Modificada | Media (5.5) | 1.1% | — | Jasper Project JasperFedoraproject Fedora | 23/2/2021 | 17/6/2026 | A flaw was found in jasper before 2.0.25. A null pointer dereference in jp2_decode in jp2_dec.c may lead to program crash and denial of service. | |
| Modificada | Alta (7.1) | 1.2% | — | Jasper Project JasperFedoraproject Fedora | 23/2/2021 | 17/6/2026 | A flaw was found in jasper before 2.0.25. An out of bounds read issue was found in jp2_decode function whic may lead to disclosure of information or program crash. |