Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2635▼ 214 respecto a la semana anterior
Críticas / altas1385▲ 153 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
5 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.2) | 0.42% | — | OcsreportsAI | 3/9/2026 | 3/9/2026 | A stored Cross-Site Scripting (XSS) vulnerability in the notification template functionality of the endpoint /ocsreports/?function=notification. A user with administrator privileges can input malicious HTML content which is subsequently stored and displayed without proper sanitisation when other administrators access… | |
| Aplazada | Alta (8.6) | 0.34% | — | OcsreportsAI | 3/9/2026 | 3/9/2026 | SQL injection vulnerability in the endpoint /ocsreports/index.php?function=admin_double due to improper processing of the values in the ID field included in the selected_grp_dupli[] parameter. An authenticated user with operator privileges can manipulate these values to alter the SQL queries executed by the… | |
| Aplazada | Alta (8.6) | 0.34% | — | Ocsinventory OcsreportsAI | 3/9/2026 | 3/9/2026 | SQL injection vulnerability in the del_check parameter of the /ocsreports/?function=save_query_list endpoint. Input provided by an authenticated user with operator privileges is incorporated into an SQL query without proper parameterisation or validation, allowing the query to be manipulated and information to be… | |
| Aplazada | Crítica (9.4) | 0.51% | — | OcsreportsAI | 3/9/2026 | 3/9/2026 | Unrestricted file upload vulnerability in the CSV file upload functionality of the Ocsreports admin_info endpoint. The application validates files solely based on the name provided by the client, without properly checking their content or securely restricting the permitted file types. This allows a user with… | |
| Modificada | Media (6.9) | 0.63% | — | Ocsinventory-ng Ocsinventory-ocsreports | 4/1/2024 | 17/6/2026 | OCSInventory allow stored email template with special characters that lead to a Stored cross-site Scripting. |