Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2857▼ 164 respecto a la semana anterior
Críticas / altas1379▲ 45 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 258 respecto a la semana anterior
94 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.1) | 0.27% | — | Kyverno Policy-reporter-ui | 12/5/2026 | 17/6/2026 | Kyverno is a policy engine designed for cloud native platform engineering teams. Prior to 2.5.2, Vue 3's v-html directive is the framework-documented mechanism for injecting raw HTML, and it intentionally disables the auto-escaping that {{ }} interpolation provides. The PropertyCard.vue component uses v-html for the… | |
| Analizada | Media (4.8) | 0.28% | — | Apache Storm Prometheus Reporter | 27/4/2026 | 17/6/2026 | Improper Certificate Validation via Global SSL Context Downgrade in Apache Storm Prometheus Reporter Versions Affected: from 2.6.3 to 2.8.6 Description: In production deployments where an administrator enables storm.daemon.metrics.reporter.plugin.prometheus.skip_tls_validation (by default it is disabled) intending to… | |
| Analizada | Media (4.8) | 1.0% | — | Zohocorp Manageengine Exchange Reporter Plus | 3/4/2026 | 20/7/2026 | Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Permissions Based on Mailboxes report. | |
| Analizada | Media (4.8) | 1.0% | — | Zohocorp Manageengine Exchange Reporter Plus | 3/4/2026 | 24/7/2026 | Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Non-Owner Mailbox Permission report. | |
| Analizada | Media (5.4) | 1.0% | — | Zohocorp Manageengine Exchange Reporter Plus | 3/4/2026 | 24/7/2026 | Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Folder Message Count and Size report. | |
| Analizada | Media (4.8) | 1.0% | — | Zohocorp Manageengine Exchange Reporter Plus | 3/4/2026 | 24/7/2026 | Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Public Folder Client Permissions report. | |
| Analizada | Media (4.8) | 1.0% | — | Zohocorp Manageengine Exchange Reporter Plus | 3/4/2026 | 24/7/2026 | Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Equipment Mailbox Details report. | |
| Analizada | Media (4.8) | 1.0% | — | Zohocorp Manageengine Exchange Reporter Plus | 3/4/2026 | 24/7/2026 | Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Mails Exchanged Between Users report. | |
| Analizada | Media (4.8) | 1.0% | — | Zohocorp Manageengine Exchange Reporter Plus | 3/4/2026 | 24/7/2026 | Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Permissions based on Distribution Groups report. | |
| Analizada | Media (4.8) | 1.0% | — | Zohocorp Manageengine Exchange Reporter Plus | 3/4/2026 | 24/7/2026 | Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Distribution Lists report. | |
| Aplazada | Alta (8.5) | 0.13% | — | Intego LOG ReporterAI | 12/2/2026 | 17/6/2026 | Intego Log Reporter, a macOS diagnostic utility bundled with Intego security products that collects system and application logs for support analysis, contains a local privilege escalation vulnerability. A root-executed diagnostic script creates and writes files in /tmp without enforcing secure directory handling,… | |
| Analizada | Media (4.3) | 0.34% | — | Jenkins Redpen - Pipeline Reporter FOR Jira | 10/12/2025 | 17/6/2026 | Jenkins Redpen - Pipeline Reporter for Jira Plugin 1.054.v7b_9517b_6b_202 and earlier does not correctly perform path validation of the workspace directory while uploading artifacts to Jira, allowing attackers with Item/Configure permission to retrieve files present on the Jenkins controller workspace directory. | |
| Analizada | Media (6.1) | 0.49% | — | Zohocorp Manageengine Exchange Reporter Plus | 11/11/2025 | 17/6/2026 | Zohocorp ManageEngine Exchange Reporter Plus versions 5723 and below are vulnerable to the Stored XSS Vulnerability in the Custom report. | |
| Analizada | Media (5.4) | 0.49% | — | Zohocorp Manageengine Exchange Reporter Plus | 11/11/2025 | 17/6/2026 | Zohocorp ManageEngine Exchange Reporter Plus versions 5723 and below are vulnerable to the Stored XSS Vulnerability in the Public Folders report. | |
| Analizada | Media (5.4) | 0.49% | — | Zohocorp Manageengine Exchange Reporter Plus | 11/11/2025 | 17/6/2026 | Zohocorp ManageEngine Exchange Reporter Plus versions 5723 and below are vulnerable to the Stored XSS Vulnerability in the Folder Message Count and Size report. | |
| Analizada | Media (5.4) | 0.49% | — | Zohocorp Manageengine Exchange Reporter Plus | 11/11/2025 | 17/6/2026 | Zohocorp ManageEngine Exchange Reporter Plus versions 5723 and below are vulnerable to the Stored XSS Vulnerability in the Mails Deleted or Moved report. | |
| Analizada | Media (5.4) | 0.45% | — | Zohocorp Manageengine Exchange Reporter Plus | 30/10/2025 | 17/6/2026 | Zohocorp ManageEngine Exchange Reporter Plus versions before 5723 are vulnerable to Stored Cross Site Scripting in the reports module. | |
| Analizada | Media (5.4) | 0.45% | — | Zohocorp Manageengine Exchange Reporter Plus | 30/10/2025 | 17/6/2026 | Zohocorp ManageEngine Exchange Reporter Plus versions through 5721 are vulnerable to Stored Cross Site Scripting in the Instant Search option. | |
| Analizada | Media (6.5) | 1.1% | — | Zohocorp Manageengine Exchange Reporter Plus | 30/10/2025 | 17/6/2026 | Zohocorp ManageEngine Exchange Reporter Plus through 5721 are vulnerable to ReDOS vulnerability in the search module. | |
| Aplazada | Alta (8.7) | 0.95% | — | N-partner N-reporterAIN-partner N-cloudAIN-partner N-probeAI | 17/9/2025 | 17/6/2026 | The N-Reporter, N-Cloud, and N-Probe developed by N-Partner has an OS Command Injection vulnerability, allowing authenticated remote attackers to inject arbitrary OS commands and execute them on the server. | |
| Analizada | Alta (8.1) | 1.3% | — | Zohocorp Manageengine Exchange Reporter Plus | 26/6/2025 | 17/6/2026 | Zohocorp ManageEngine Exchange reporter Plus version 5722 and below are vulnerable to Stored XSS in the Attachments by filename keyword report. | |
| Analizada | Alta (8.1) | 1.3% | — | Zohocorp Manageengine Exchange Reporter Plus | 26/6/2025 | 17/6/2026 | Zohocorp ManageEngine Exchange reporter Plus version 5722 and below are vulnerable to Stored XSS in the Folder-wise read mails with subject report. | |
| Analizada | Ninguna (0) | 0.14% | — | Trellix System Information Reporter | 26/6/2025 | 17/6/2026 | A sensitive information exposure vulnerability in System Information Reporter (SIR) 1.0.3 and prior allows an authenticated non-admin local user to extract sensitive information stored in a registry backup folder. | |
| Analizada | Alta (7.2) | 0.16% | — | Trellix System Information Reporter | 26/6/2025 | 17/6/2026 | A path or symbolic link manipulation vulnerability in SIR 1.0.3 and prior versions allows an authenticated non-admin local user to overwrite system files with SIR backup files, which can potentially cause a system crash. This was achieved by adding a malicious entry to the registry under the Trellix SIR registry… | |
| Analizada | Ninguna (0) | 0.18% | — | Trellix System Information Reporter | 26/6/2025 | 17/6/2026 | A path traversal vulnerability in System Information Reporter (SIR) 1.0.3 and prior allowed an authenticated high privileged user to issue malicious ePO post requests to System Information Reporter, leading to creation of files anywhere on the filesystem and possibly overwriting existing files and exposing sensitive… |