Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3005▼ 72 respecto a la semana anterior
Críticas / altas1419▲ 51 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

6 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.7)0.90%—Syncfusion Standalone Report Designer23/7/202628/7/2026
Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its file upload functionality that allows authenticated attackers to traverse outside the intended directory by supplying a crafted filename. Attackers can exploit this path traversal weakness to execute…
AnalizadaCrítica (9.3)0.87%—Syncfusion Standalone Report Designer23/7/202628/7/2026
Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its database download feature that allows unauthenticated attackers to read arbitrary files from the server filesystem by supplying a crafted request. Attackers can exploit this path traversal weakness to…
AnalizadaCrítica (9.3)0.87%—Syncfusion Standalone Report Designer23/7/202628/7/2026
Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its font processing feature that allows unauthenticated attackers to read arbitrary files from the server filesystem by supplying a crafted request. Attackers can exploit this path traversal weakness to…
AnalizadaCrítica (9.3)0.87%—Syncfusion Standalone Report Designer23/7/202628/7/2026
Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its SVG processing feature that allows unauthenticated attackers to read arbitrary files from the server filesystem by supplying a crafted request. Attackers can exploit this path traversal weakness to…
ModificadaAlta (7.8)0.42%—M2soft Report Designer1/11/201817/6/2026
M2SOFT Report Designer Viewer 5.0 allows a Buffer Overflow with Extended Instruction Pointer (EIP) control via a crafted MRD file.
ModificadaMedia (5)3.7%—Reportico PHP Report Designer16/7/201417/6/2026
Directory traversal vulnerability in Reportico PHP Report Designer before 4.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the xmlin parameter.