Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
358 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 0.84% | — | Jenkins Dynatrace Application Monitoring | 23/10/2019 | 17/6/2026 | A missing permission check in Jenkins Dynatrace Application Monitoring Plugin allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials. | |
| Modificada | Alta (8.1) | 0.70% | — | Jenkins Dynatrace Application Monitoring | 23/10/2019 | 17/6/2026 | A cross-site request forgery vulnerability in Jenkins Dynatrace Application Monitoring Plugin 2.1.3 and earlier allowed attackers to connect to an attacker-specified URL using attacker-specified credentials. | |
| Modificada | Alta (7.8) | 0.33% | — | Jenkins Dynatrace Application Monitoring | 23/10/2019 | 17/6/2026 | Jenkins Dynatrace Application Monitoring Plugin 2.1.3 and earlier stored credentials unencrypted in its global configuration file on the Jenkins master where they could be viewed by users with access to the master file system. | |
| Modificada | Alta (7.8) | 2.1% | — | Pivotal Cloud Foundry Command Line InterfacePivotal Cloud Foundry Command Line Interface ReleasePivotal Cloud Foundry DeploymentPivotal Cloud Foundry Deployment Concourse Tasks+51 | 5/8/2019 | 17/6/2026 | CF CLI version prior to v6.45.0 (bosh release version 1.16.0) writes the client id and secret to its config file when the user authenticates with --client-credentials flag. A local authenticated malicious user with access to the CF CLI config file can act as that client, who is the owner of the leaked credentials. | |
| Modificada | Crítica (9.8) | 95% | — | XstreamOracle Banking PlatformOracle Business Activity MonitoringOracle Communications Billing AND Revenue Management Elastic Charging Engine+6 | 23/7/2019 | 17/6/2026 | It was found that xstream API version 1.4.10 before 1.4.11 introduced a regression for a previous deserialization flaw. If the security framework has not been initialized, it may allow a remote attacker to run arbitrary shell commands when unmarshalling XML or any supported format. e.g. JSON. (regression of… | |
| Modificada | Alta (7.3) | 0.85% | 💥 Exploit | Pronestor Health Monitoring | 1/4/2019 | 17/6/2026 | The Pronestor PNHM (aka Health Monitoring or HealthMonitor) add-in before 8.1.13.0 for Outlook has "BUILTIN\Users:(I)(F)" permissions for the "%PROGRAMFILES(X86)%\proNestor\Outlook add-in for Pronestor\PronestorHealthMonitor.exe" file, which allows local users to gain privileges via a Trojan horse… | |
| Modificada | Crítica (9.8) | 3.2% | 💥 Exploit | School Attendance Monitoring System Project School Attendance Monitoring System | 21/3/2019 | 17/6/2026 | Attendance Monitoring System 1.0 has SQL Injection via the 'id' parameter to student/index.php?view=view, event/index.php?view=view, and user/index.php?view=view. | |
| Modificada | Media (6.5) | 0.73% | — | Jenkins Monitoring | 6/2/2019 | 17/6/2026 | A denial of service vulnerability exists in Jenkins Monitoring Plugin 1.74.0 and earlier in PluginImpl.java that allows attackers to kill threads running on the Jenkins master. | |
| Modificada | Media (6.1) | 0.76% | — | Schneider-electric Ecostruxure Energy ExpertSchneider-electric Ecostruxure Power Monitoring ExpertSchneider-electric Ecostruxure Power Scada Operation | 17/12/2018 | 17/6/2026 | A URL redirection vulnerability exists in Power Monitoring Expert, Energy Expert (formerly Power Manager) - EcoStruxure Power Monitoring Expert (PME) v8.2 (all editions), EcoStruxure Energy Expert 1.3 (formerly Power Manager), EcoStruxure Power SCADA Operation (PSO) 8.2 Advanced Reports and Dashboards Module,… | |
| Modificada | Alta (8.1) | 2.7% | — | Siemens Simatic IT Line Monitoring SystemSiemens Simatic IT Production SuiteSiemens Simatic IT UA Discrete Manufacturing | 13/12/2018 | 17/6/2026 | A vulnerability has been identified in SIMATIC IT LMS (All versions), SIMATIC IT Production Suite (Versions V7.1 < V7.1 Upd3), SIMATIC IT UA Discrete Manufacturing (Versions < V1.2), SIMATIC IT UA Discrete Manufacturing (Versions V1.2), SIMATIC IT UA Discrete Manufacturing (Versions V1.3), SIMATIC IT UA Discrete… | |
| Modificada | Crítica (9.8) | 1.6% | — | School Equipment Monitoring System Project School Equipment Monitoring System | 16/11/2018 | 17/6/2026 | School Equipment Monitoring System 1.0 allows SQL injection via the login screen, related to include/user.vb. | |
| Modificada | Alta (8.8) | 2.4% | 💥 Exploit | School Attendance Monitoring System Project School Attendance Monitoring System | 16/11/2018 | 17/6/2026 | School Attendance Monitoring System 1.0 has CSRF via event/controller.php?action=photos. | |
| Modificada | Alta (8.8) | 2.4% | 💥 Exploit | School Attendance Monitoring System Project School Attendance Monitoring System | 16/11/2018 | 17/6/2026 | School Attendance Monitoring System 1.0 has CSRF via /user/user/edit.php. | |
| Modificada | Media (6.5) | 2.7% | — | Serverscheck Monitoring Software | 24/10/2018 | 17/6/2026 | ServersCheck Monitoring Software through 14.3.3 allows local users to cause a denial of service (menu functionality loss) by creating an LNK file that points to a second LNK file, if this second LNK file is associated with a Start menu. Ultimately, this behavior comes from a Directory Traversal bug (via the… | |
| Modificada | Media (6.1) | 1.1% | — | Serverscheck Monitoring Software | 24/10/2018 | 17/6/2026 | ServersCheck Monitoring Software through 14.3.3 has Persistent and Reflected XSS via the sensors.html status parameter, sensors.html type parameter, sensors.html device parameter, report.html location parameter, group_delete.html group parameter, report_save.html query parameter, sensors.html location parameter, or… | |
| Modificada | Alta (8.8) | 1.7% | — | Microfocus Real User Monitoring | 23/10/2018 | 17/6/2026 | A potential Remote Arbitrary Code Execution vulnerability has been identified in Micro Focus' Real User Monitoring software, versions 9.26IP, 9.30, 9.40 and 9.50. The vulnerability could be exploited to execute arbitrary code. | |
| Modificada | Alta (7.5) | 1.2% | — | IBM Tivoli Monitoring | 19/9/2018 | 17/6/2026 | IBM Tivoli Monitoring 6.2.3 through 6.2.3.5 and 6.3.0 through 6.3.0.7 are vulnerable to both TEPS user privilege escalation and possible denial of service due to unconstrained memory growth. IBM X-Force ID: 137039. | |
| Modificada | Media (5.3) | 7.1% | 💥 Exploit | Perfsonar Monitoring AND Debugging Dashboard | 18/6/2018 | 17/6/2026 | An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2. A direct request to /images/ provides a directory listing. | |
| Modificada | Media (5.3) | 7.1% | 💥 Exploit | Perfsonar Monitoring AND Debugging Dashboard | 18/6/2018 | 17/6/2026 | An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2. A direct request to /lib/ provides a directory listing. | |
| Modificada | Media (5.3) | 7.1% | 💥 Exploit | Perfsonar Monitoring AND Debugging Dashboard | 18/6/2018 | 17/6/2026 | An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2. A direct request to /etc/ provides a directory listing. | |
| Modificada | Media (5.3) | 7.1% | 💥 Exploit | Perfsonar Monitoring AND Debugging Dashboard | 18/6/2018 | 17/6/2026 | An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2. A direct request to /style/ provides a directory listing. | |
| Modificada | Crítica (9.8) | 3.2% | — | IBM Tivoli Monitoring | 22/3/2018 | 17/6/2026 | IBM Tivoli Monitoring V6 6.2.3 and 6.3.0 could allow an unauthenticated user to remotely execute code through unspecified methods. IBM X-Force ID: 137034. | |
| Modificada | Media (6.1) | 1.3% | — | SAP Process Monitoring Infrastructure | 14/3/2018 | 17/6/2026 | Cross-Site Scripting in Process Monitoring Infrastructure, from 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, due to inefficient encoding of user controlled inputs. | |
| Modificada | Media (6.1) | 0.88% | — | IBM Monitoring | 14/3/2018 | 17/6/2026 | IBM Application Performance Management - Response Time Monitoring Agent (IBM Monitoring 8.1.3 and 8.1.4) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within… | |
| Modificada | Alta (8.8) | 0.73% | — | IBM Monitoring | 8/3/2018 | 17/6/2026 | IBM Application Performance Management - Response Time Monitoring Agent (IBM Monitoring 8.1.4) is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 139598. |