Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 166 respecto a la semana anterior
Críticas / altas1379▲ 45 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 260 respecto a la semana anterior
21 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.7) | 0.46% | — | Jeecg JimureportAI | 17/8/2026 | 24/9/2026 | JimuReport contains an authentication bypass vulnerability in the report folder template listing endpoint that allows unauthenticated attackers to enumerate all reports and retrieve share tokens. Attackers can use disclosed share tokens to access protected report endpoints and retrieve full report definitions… | |
| Aplazada | Crítica (9.8) | 0.50% | — | UreportAI | 16/7/2026 | 17/7/2026 | A SQL injection vulnerability in the /ureport/datasource/previewData component of ureport v2.2.9 allows attackers to access sensitive database information via crafted SQL statements. | |
| Aplazada | Alta (8.7) | 0.63% | — | Jeecg JimureportAI | 30/6/2026 | 14/7/2026 | JimuReport through 2.5.0 exposes the POST /jmreport/auto/export endpoint without authentication: the handler is annotated @JimuNoLoginRequired, so JimuReportTokenInterceptor skips all authentication and authorization, and the export service streams the rendered report for any supplied report id without verifying the… | |
| Aplazada | Crítica (9.1) | 0.66% | — | Jeecg JimureportAI | 17/6/2026 | 22/6/2026 | JimuReport versions 2.3.4 and below are vulnerable to remote code execution due to improper handling of Aviator expressions. The /jmreport/executeSelectApi endpoint passes user-supplied input directly to the Aviator expression engine without adequate validation allowing attackers to execute arbitrary code. | |
| Aplazada | Media (5.5) | 0.33% | — | Erzhongxmu JeewmsAIJeecg JimureportAI | 7/6/2026 | 23/7/2026 | A security flaw has been discovered in erzhongxmu JeeWMS up to 141740afb2ba14d441c82a833d0a418d07ca2d69. This vulnerability affects unknown code of the file /base-boot/jmreport/testConnection of the component JimuReport test-connection Endpoint. Performing a manipulation of the argument… | |
| Aplazada | Baja (2) | 0.43% | — | Jeecg JimureportAI | 9/4/2026 | 17/6/2026 | A vulnerability was found in jeecgboot JimuReport up to 2.3.0. The affected element is the function DriverManager.getConnection of the file /drag/onlDragDataSource/testConnection of the component Data Source Handler. Performing a manipulation of the argument dbUrl results in code injection. The attack may be initiated… | |
| Analizada | Crítica (9.8) | 1.1% | — | Jeecg Jimureport | 8/1/2026 | 17/6/2026 | JimuReport thru version 2.1.3 is vulnerable to remote code execution when processing user-controlled H2 JDBC URLs. The application passes the attacker-supplied JDBC URL directly to the H2 driver, allowing the use of certain directives to execute arbitrary Java code. A different vulnerability than CVE-2025-10770. | |
| Analizada | Baja (2.1) | 0.61% | — | Jeecg Jimureport | 21/9/2025 | 17/6/2026 | A vulnerability was determined in jeecgboot JimuReport up to 2.1.2. Affected is an unknown function of the file /drag/onlDragDataSource/testConnection of the component DB2 JDBC Handler. Executing manipulation of the argument clientRerouteServerListJNDIName can lead to deserialization. The attack can be executed… | |
| Analizada | Baja (2.1) | 0.43% | — | Jeecg Jimureport | 21/9/2025 | 17/6/2026 | A vulnerability was found in jeecgboot JimuReport up to 2.1.2. This impacts an unknown function of the file /drag/onlDragDataSource/testConnection of the component MySQL JDBC Handler. Performing manipulation results in deserialization. Remote exploitation of the attack is possible. The exploit has been made public and… | |
| Analizada | Media (5.3) | 0.49% | — | Jeecg Jimureport | 14/8/2025 | 17/6/2026 | A vulnerability was determined in jeecgboot JimuReport up to 2.1.1. Affected by this issue is some unknown functionality of the file /drag/onlDragDataSource/testConnection of the component Data Large Screen Template. The manipulation leads to deserialization. The attack may be launched remotely. The vendor response to… | |
| Analizada | Crítica (9.8) | 0.53% | — | Jeecg Jimureport | 10/9/2024 | 17/6/2026 | An issue in the component /jeecg-boot/jmreport/dict/list of JimuReport v1.7.8 allows attacker to escalate privileges via a crafted GET request. | |
| Modificada | Crítica (9.8) | 0.77% | — | Ureport2 Project Ureport2 | 3/1/2024 | 17/6/2026 | Arbitrary File Write vulnerability in the saveReportFile method of ureport2 2.2.9 and before allows attackers to write arbitrary files and run arbitrary commands via crafted POST request. | |
| Modificada | Alta (7.5) | 0.95% | — | Ureport Project Ureport | 28/11/2023 | 17/6/2026 | An arbitrary file read vulnerability in ureport v2.2.9 allows a remote attacker to arbitrarily read files on the server by inserting a crafted path. | |
| Modificada | Crítica (9.8) | 0.84% | — | Jeecg Jimureport | 27/11/2023 | 17/6/2026 | A vulnerability classified as critical was found in jeecgboot JimuReport up to 1.6.1. Affected by this vulnerability is an unknown functionality of the file /download/image. The manipulation of the argument imageUrl leads to relative path traversal. The attack can be launched remotely. The exploit has been disclosed… | |
| Modificada | Crítica (9.8) | 12% | — | Jeecg Jimureport | 21/8/2023 | 17/6/2026 | A vulnerability was found in jeecgboot JimuReport up to 1.6.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Template Handler. The manipulation leads to injection. The attack can be launched remotely. The exploit has been disclosed to the public and may… | |
| Modificada | Alta (7.8) | 0.93% | — | Ureport Project Ureport | 14/2/2023 | 9/7/2026 | An XML External Entity (XXE) vulnerability in ureport v2.2.9 allows attackers to execute arbitrary code via uploading a crafted XML file to /ureport/designer/saveReportFile. | |
| Modificada | Crítica (9.1) | 1.2% | — | Ureport Project Ureport | 13/2/2023 | 9/7/2026 | ureport v2.2.9 was discovered to contain a directory traversal vulnerability via the deletion function which allows for arbitrary files to be deleted. | |
| Modificada | Crítica (9.8) | 3.2% | — | Ureport2 Project Ureport2 | 1/5/2022 | 17/6/2026 | All versions of package com.bstek.ureport:ureport2-console are vulnerable to Remote Code Execution by connecting to a malicious database server, causing arbitrary file read and deserialization of local gadgets. | |
| Modificada | Crítica (9.8) | 1.8% | — | Ureport Project Ureport | 15/9/2021 | 17/6/2026 | An arbitrary file creation vulnerability in UReport 2.2.9 allows attackers to execute arbitrary code. | |
| Modificada | Crítica (9.8) | 2.2% | — | Ureport Project Ureport | 15/9/2021 | 17/6/2026 | UReport 2.2.9 allows attackers to execute arbitrary code due to a lack of access control to the designer page. | |
| Modificada | Media (5.3) | 0.85% | — | Ureport Project Ureport | 15/9/2021 | 17/6/2026 | UReport v2.2.9 contains a Server-Side Request Forgery (SSRF) in the designer page which allows attackers to detect intranet device ports. |