Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
1029 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.1) | 0.65% | — | Microsoft Azure Monitor Agent | 8/10/2024 | 17/6/2026 | Azure Monitor Agent Elevation of Privilege Vulnerability | |
| Modificada | Media (5.3) | 0.38% | — | Siemens Sinec Security Monitor | 8/10/2024 | 17/6/2026 | A vulnerability has been identified in SINEC Security Monitor (All versions < V4.9.0). The affected application does not properly validate that user input complies with a list of allowed values. This could allow an authenticated remote attacker to compromise the integrity of the configuration of the affected… | |
| Modificada | Media (6.9) | 0.55% | — | Siemens Sinec Security Monitor | 8/10/2024 | 17/6/2026 | A vulnerability has been identified in SINEC Security Monitor (All versions < V4.9.0). The affected application does not properly validate a file path that is supplied to an endpoint intended to create CSR files. This could allow an unauthenticated remote attacker to create files in writable directories outside the… | |
| Modificada | Crítica (9.3) | 0.27% | — | Siemens Sinec Security Monitor | 8/10/2024 | 17/6/2026 | A vulnerability has been identified in SINEC Security Monitor (All versions < V4.9.0). The affected application does not properly neutralize special elements in user input to the ```ssmctl-client``` command. This could allow an authenticated, lowly privileged local attacker to execute privileged commands in the… | |
| Modificada | Crítica (9.4) | 0.85% | — | Siemens Sinec Security Monitor | 8/10/2024 | 17/6/2026 | A vulnerability has been identified in SINEC Security Monitor (All versions < V4.9.0). The affected application does not properly validate user input to the ```ssmctl-client``` command. This could allow an authenticated, lowly privileged remote attacker to execute arbitrary code with root privileges on the underlying… | |
| Analizada | Media (4.6) | 0.32% | — | Tenable Nessus Network Monitor | 30/9/2024 | 17/6/2026 | A stored cross site scripting vulnerability exists in Nessus Network Monitor where an authenticated, privileged local attacker could inject arbitrary code into the NNM UI via the local CLI. | |
| Aplazada | Crítica (9.3) | 0.59% | — | Omntec Proteus Tank Monitoring Oel8000iii SeriesAI | 27/9/2024 | 17/6/2026 | OMNTEC Proteus Tank Monitoring OEL8000III Series could allow an attacker to perform administrative actions without proper authentication. | |
| Analizada | Alta (8.8) | 0.84% | — | IBM Cloud PAK FOR Multicloud Management Monitoring | 26/9/2024 | 17/6/2026 | IBM ManageIQ could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted yaml file request. | |
| Analizada | Media (4.9) | 0.34% | — | IBM Cloud PAK FOR Multicloud Management Monitoring | 26/9/2024 | 17/6/2026 | IBM Cloud Pak for Multicloud Management 2.3 through 2.3 FP8 stores user credentials in a log file plain clear text which can be read by a privileged user. | |
| Analizada | Media (4.3) | 0.37% | — | Wpchill Download Monitor | 26/9/2024 | 17/6/2026 | The Download Monitor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the enable_shop() function in all versions up to, and including, 5.0.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to enable shop… | |
| Aplazada | Media (6.5) | 0.23% | — | Runofast Indoor Security Camera FOR Baby MonitorAI | 18/9/2024 | 17/6/2026 | runofast Indoor Security Camera for Baby Monitor has a default password of password for the root account. This allows access to the /stream1 URI via the rtsp:// protocol to receive the video and audio stream. | |
| Modificada | Media (6.5) | 0.27% | — | Eaton Foreseer Electrical Power Monitoring System | 13/9/2024 | 17/6/2026 | The Eaton Foreseer software provides multiple customizable input fields for the users to configure parameters in the tool like alarms, reports, etc. Some of these input fields were not checking the length and bounds of the entered value. The exploit of this security flaw by a bad actor may result in excessive memory… | |
| Modificada | Alta (8.1) | 0.12% | — | Eaton Foreseer Electrical Power Monitoring System | 13/9/2024 | 17/6/2026 | The Eaton Foreseer software provides the feasibility for the user to configure external servers for multiple purposes such as network management, user management, etc. The software uses encryption to store these configurations securely on the host machine. However, the keys used for this encryption were insecurely… | |
| Analizada | Media (6.1) | 0.29% | — | Eaton Foreseer Electrical Power Monitoring System | 13/9/2024 | 17/6/2026 | The Eaton Foreseer software provides users the capability to customize the dashboard in WebView pages. However, the input fields for this feature in the Eaton Foreseer software lacked proper input sanitization on the server-side, which could lead to injection and execution of malicious scripts when abused by bad… | |
| Aplazada | Media (5.3) | 0.39% | — | Shandong Star Measurement AND Control Equipment Heating Network Wireless Monitoring SystemAI | 11/9/2024 | 17/6/2026 | A vulnerability was found in Shandong Star Measurement and Control Equipment Heating Network Wireless Monitoring System 5.6.2 and classified as critical. Affected by this issue is the function GetDataKindByType of the file /DataSrvs/UCCGSrv.asmx. The manipulation leads to sql injection. The attack may be launched… | |
| Aplazada | Alta (8.2) | 0.45% | — | Siemens Simatic CP 1242-7 V2AISiemens Simatic CP 1243-1AISiemens Simatic CP 1243-1 Dnp3AISiemens Simatic CP 1243-1 IECAI+8 | 10/9/2024 | 17/6/2026 | A vulnerability has been identified in SIMATIC CP 1242-7 V2 (incl. SIPLUS variants) (All versions < V3.5.20), SIMATIC CP 1243-1 (incl. SIPLUS variants) (All versions < V3.5.20), SIMATIC CP 1243-1 DNP3 (incl. SIPLUS variants) (All versions < V3.5.20), SIMATIC CP 1243-1 IEC (incl. SIPLUS variants) (All versions <… | |
| Aplazada | Media (5.9) | 0.43% | — | Siemens Simatic CP 1242-7 V2AISiemens Simatic CP 1243-1AISiemens Simatic CP 1243-1 Dnp3AISiemens Simatic CP 1243-1 IECAI+8 | 10/9/2024 | 17/6/2026 | A vulnerability has been identified in SIMATIC CP 1242-7 V2 (incl. SIPLUS variants) (All versions < V3.5.20), SIMATIC CP 1243-1 (incl. SIPLUS variants) (All versions < V3.5.20), SIMATIC CP 1243-1 DNP3 (incl. SIPLUS variants) (All versions < V3.5.20), SIMATIC CP 1243-1 IEC (incl. SIPLUS variants) (All versions <… | |
| Aplazada | Alta (8.2) | 0.45% | — | Siemens Simatic CP 1242-7 V2AISiemens Simatic CP 1243-1AISiemens Simatic CP 1243-1 Dnp3AISiemens Simatic CP 1243-1 IECAI+8 | 10/9/2024 | 17/6/2026 | A vulnerability has been identified in SIMATIC CP 1242-7 V2 (incl. SIPLUS variants) (All versions < V3.5.20), SIMATIC CP 1243-1 (incl. SIPLUS variants) (All versions < V3.5.20), SIMATIC CP 1243-1 DNP3 (incl. SIPLUS variants) (All versions < V3.5.20), SIMATIC CP 1243-1 IEC (incl. SIPLUS variants) (All versions <… | |
| Analizada | Media (5.3) | 0.42% | — | Rems Daily Calories Monitoring Tool | 25/8/2024 | 17/6/2026 | A vulnerability was found in SourceCodester Daily Calories Monitoring Tool 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /endpoint/delete-calorie.php. The manipulation of the argument calorie leads to cross site scripting. The attack can be initiated remotely. The… | |
| Analizada | Media (5.3) | 0.41% | — | Rems Daily Calories Monitoring Tool | 25/8/2024 | 17/6/2026 | A vulnerability was found in SourceCodester Daily Calories Monitoring Tool 1.0. It has been classified as problematic. This affects an unknown part of the file /endpoint/add-calorie.php. The manipulation of the argument calorie_date/calorie_name leads to cross site scripting. It is possible to initiate the attack… | |
| Analizada | Alta (8.8) | 7.0% | — | Zohocorp Manageengine OpmanagerZohocorp Manageengine Opmanager MSPZohocorp Manageengine Opmanager PlusZohocorp Manageengine Remote Monitoring AND Management Central | 23/8/2024 | 17/6/2026 | Zohocorp ManageEngine OpManager and Remote Monitoring and Management versions 128329 and below are vulnerable to the authenticated remote code execution in the deploy agent option. | |
| Analizada | Media (5.3) | 0.61% | — | Project Expense Monitoring System Project Project Expense Monitoring System | 20/8/2024 | 17/6/2026 | A vulnerability classified as critical was found in itsourcecode Project Expense Monitoring System 1.0. This vulnerability affects unknown code of the file printtransfer.php. The manipulation of the argument transfer_id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the… | |
| Analizada | Media (5.3) | 0.61% | — | Project Expense Monitoring System Project Project Expense Monitoring System | 20/8/2024 | 17/6/2026 | A vulnerability classified as critical has been found in itsourcecode Project Expense Monitoring System 1.0. This affects an unknown part of the file transferred_report.php. The manipulation of the argument start/end/employee leads to sql injection. It is possible to initiate the attack remotely. The exploit has been… | |
| Analizada | Media (5.3) | 0.48% | — | Project Expense Monitoring System Project Project Expense Monitoring System | 19/8/2024 | 17/6/2026 | A vulnerability was found in itsourcecode Project Expense Monitoring System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file print.php. The manipulation of the argument map_id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed… | |
| Analizada | Media (5.3) | 0.48% | — | Project Expense Monitoring System Project Project Expense Monitoring System | 19/8/2024 | 17/6/2026 | A vulnerability was found in itsourcecode Project Expense Monitoring System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file execute.php. The manipulation of the argument code leads to sql injection. The attack can be launched remotely. The exploit has been… |