Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2811▲ 64 respecto a la semana anterior
Críticas / altas1484▲ 296 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 448 respecto a la semana anterior
6 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.60% | — | Tibco Webfocus ClientTibco Webfocus InstallerTibco Webfocus Reporting Server | 14/9/2021 | 17/6/2026 | The WebFOCUS Reporting Server and WebFOCUS Client components of TIBCO Software Inc.'s TIBCO WebFOCUS Client, TIBCO WebFOCUS Installer, and TIBCO WebFOCUS Reporting Server contain easily exploitable Stored and Reflected Cross Site Scripting (XSS) vulnerabilities that allow a low privileged attacker to social engineer a… | |
| Modificada | Media (6.8) | 1.1% | — | Oracle Hyperion Interactive ReportingOracle Essbase ServerOracle Hyperion Production Reporting ServerOracle Integration Services Server | 21/12/2012 | 16/6/2026 | Buffer overflow in the DataDirect ODBC driver, as used in Oracle Hyperion Interactive Reporting 11.1.2.1 and 11.1.2.2, Essbase Server 11.1.2.1 and 11.1.2.2, Production Reporting Server 11.1.2.1 and 11.1.2.2, and Integration Services Server 11.1.2.1 and 11.1.2.2 has unknown impact and attack vectors. | |
| Modificada | Alta (9) | 2.2% | — | Symantec Client SecuritySymantec Norton AntivirusSymantec Reporting Server | 6/6/2007 | 16/6/2026 | Unspecified vulnerability in Symantec Reporting Server 1.0.197.0, and other versions before 1.0.224.0, as used in Symantec Client Security 3.1 and later, and Symantec AntiVirus Corporate Edition (SAV CE) 10.1 and later, allows attackers to "disable the authentication system" and bypass authentication via unknown… | |
| Modificada | Media (4.3) | 2.1% | — | Symantec Client SecuritySymantec Norton AntivirusSymantec Reporting Server | 5/6/2007 | 16/6/2026 | Symantec Reporting Server 1.0.197.0, and other versions before 1.0.224.0, as used in Symantec Client Security 3.1 and later, and Symantec AntiVirus Corporate Edition (SAV CE) 10.1 and later, displays the password hash for a user after a failed login attempt, which makes it easier for remote attackers to conduct brute… | |
| Modificada | Alta (7.5) | 2.0% | — | Symantec Client SecuritySymantec Norton AntivirusSymantec Reporting Server | 5/6/2007 | 16/6/2026 | Symantec Reporting Server 1.0.197.0, and other versions before 1.0.224.0, as used in Symantec Client Security 3.1 and later, and Symantec AntiVirus Corporate Edition (SAV CE) 10.1 and later, does not initialize a critical variable, which allows attackers to create arbitrary executable files via unknown manipulations… | |
| Modificada | Media (5) | 3.1% | — | Webtrends Enterprise Reporting ServerWebtrends Enterprise Reporting Server NT | 20/9/2001 | 16/6/2026 | WebTrends HTTP Server 3.1c and 3.5 allows a remote attacker to view script source code via a filename followed by an encoded space (%20). |