Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2684▼ 80 respecto a la semana anterior
Críticas / altas1442▲ 302 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
966 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.39% | — | NI Woocommerce Sales ReportAI | 16/9/2026 | 17/9/2026 | The Ni WooCommerce Sales Report WordPress plugin before 4.2.0 does not have any authentication or authorisation checks on one of its report-printing routines, allowing unauthenticated users to retrieve WooCommerce order details and customer contact information, to target an individual order, and to search the store's… | |
| Aplazada | Alta (8.6) | 0.45% | — | NI Woocommerce Sales ReportAI | 16/9/2026 | 17/9/2026 | The Ni WooCommerce Sales Report WordPress plugin before 4.2.0 does not sanitise and escape a parameter before using it in a SQL statement, allowing unauthenticated users to perform SQL injection attacks. | |
| Aplazada | Alta (8.8) | 0.42% | — | Oracle E-business SuiteAIOracle Report ManagerAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Oracle Report Manager product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Report Manager. Successful attacks… | |
| Pendiente de análisis | Alta (7.1) | 0.36% | — | Oracle Report ManagerAIOracle E-business SuiteAI | 15/9/2026 | 16/9/2026 | Vulnerability in the Oracle Report Manager product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Report Manager. Successful attacks… | |
| Aplazada | Alta (8.8) | 0.42% | — | Oracle E-business SuiteAIOracle Report ManagerAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Oracle Report Manager product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Report Manager. Successful attacks… | |
| Aplazada | Crítica (9.2) | 0.42% | — | OcsreportsAI | 3/9/2026 | 3/9/2026 | A stored Cross-Site Scripting (XSS) vulnerability in the notification template functionality of the endpoint /ocsreports/?function=notification. A user with administrator privileges can input malicious HTML content which is subsequently stored and displayed without proper sanitisation when other administrators access… | |
| Aplazada | Alta (8.6) | 0.34% | — | OcsreportsAI | 3/9/2026 | 3/9/2026 | SQL injection vulnerability in the endpoint /ocsreports/index.php?function=admin_double due to improper processing of the values in the ID field included in the selected_grp_dupli[] parameter. An authenticated user with operator privileges can manipulate these values to alter the SQL queries executed by the… | |
| Aplazada | Alta (8.6) | 0.34% | — | Ocsinventory OcsreportsAI | 3/9/2026 | 3/9/2026 | SQL injection vulnerability in the del_check parameter of the /ocsreports/?function=save_query_list endpoint. Input provided by an authenticated user with operator privileges is incorporated into an SQL query without proper parameterisation or validation, allowing the query to be manipulated and information to be… | |
| Aplazada | Crítica (9.4) | 0.51% | — | OcsreportsAI | 3/9/2026 | 3/9/2026 | Unrestricted file upload vulnerability in the CSV file upload functionality of the Ocsreports admin_info endpoint. The application validates files solely based on the name provided by the client, without properly checking their content or securely restricting the permitted file types. This allows a user with… | |
| Analizada | Baja (2.3) | 0.23% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+17 | 2/9/2026 | 15/9/2026 | A vulnerability exists in an undisclosed BIG-IP Configuration utility page that may allow an attacker to spoof error messages Impact: An attacker may trick authenticated BIG-IP users into accessing malicious links and reflect a spoofed error message in the victim's BIG-IP Configuration utility web browser session.… | |
| Aplazada | Baja (2.1) | 0.41% | — | Xianrendzw EasyreportAI | 19/8/2026 | 21/8/2026 | A vulnerability was found in xianrendzw EasyReport up to 2.0.17.0522_Beta. Affected is the function execSqlText/previewSqlText of the file DesignerController.java of the component SQL Preview Endpoint. The manipulation of the argument sqlText results in improper neutralization of special elements used in a template… | |
| Aplazada | Baja (2.1) | 0.37% | — | Xianrendzw EasyreportAI | 19/8/2026 | 21/8/2026 | A security vulnerability has been detected in xianrendzw EasyReport up to 2.0.17.0522_Beta. The affected element is the function DataSourceController.add of the file DataSourceController.java of the component QueryerFactory. Such manipulation of the argument queryerClass leads to permission issues. The attack can be… | |
| Analizada | Media (4.7) | 0.12% | — | Oracle Hyperion Financial Reporting | 18/8/2026 | 24/8/2026 | Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Financial Reporting executes to… | |
| Analizada | Media (4.2) | 0.19% | — | Oracle Hyperion Financial Reporting | 18/8/2026 | 24/8/2026 | Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting. Successful… | |
| Analizada | Media (5.9) | 0.25% | — | Oracle Hyperion Financial Reporting | 18/8/2026 | 24/8/2026 | Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting. Successful… | |
| Analizada | Media (6.5) | 0.27% | — | Oracle Hyperion Financial Reporting | 18/8/2026 | 24/8/2026 | Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting. Successful… | |
| Analizada | Alta (8.8) | 0.43% | — | Oracle Hyperion Financial Reporting | 18/8/2026 | 25/8/2026 | Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting. Successful… | |
| Analizada | Baja (3.7) | 0.26% | — | Oracle Hyperion Financial Reporting | 18/8/2026 | 25/8/2026 | Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting. Successful… | |
| Analizada | Media (5.3) | 0.12% | — | Oracle Hyperion Financial Reporting | 18/8/2026 | 25/8/2026 | Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Financial Reporting executes to… | |
| Analizada | Media (6.8) | 0.30% | — | Oracle Hyperion Financial Reporting | 18/8/2026 | 25/8/2026 | Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the… | |
| Analizada | Baja (2.6) | 0.19% | — | Oracle Hyperion Financial Reporting | 18/8/2026 | 24/8/2026 | Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting. Successful… | |
| Analizada | Media (6.5) | 0.28% | — | Oracle Hyperion Financial Reporting | 18/8/2026 | 24/8/2026 | Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting. Successful… | |
| Analizada | Media (6.1) | 0.24% | — | Oracle Hyperion Financial Reporting | 18/8/2026 | 24/8/2026 | Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting. Successful… | |
| Analizada | Media (6.5) | 0.35% | — | Oracle Hyperion Financial Reporting | 18/8/2026 | 25/8/2026 | Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting. Successful… | |
| Analizada | Media (5.4) | 0.24% | — | Oracle Hyperion Financial Reporting | 18/8/2026 | 25/8/2026 | Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting. Successful… |