Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

358 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)0.84%—Jenkins Dynatrace Application Monitoring23/10/201917/6/2026
A missing permission check in Jenkins Dynatrace Application Monitoring Plugin allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials.
ModificadaAlta (8.1)0.70%—Jenkins Dynatrace Application Monitoring23/10/201917/6/2026
A cross-site request forgery vulnerability in Jenkins Dynatrace Application Monitoring Plugin 2.1.3 and earlier allowed attackers to connect to an attacker-specified URL using attacker-specified credentials.
ModificadaAlta (7.8)0.33%—Jenkins Dynatrace Application Monitoring23/10/201917/6/2026
Jenkins Dynatrace Application Monitoring Plugin 2.1.3 and earlier stored credentials unencrypted in its global configuration file on the Jenkins master where they could be viewed by users with access to the master file system.
ModificadaAlta (7.8)2.1%—Pivotal Cloud Foundry Command Line InterfacePivotal Cloud Foundry Command Line Interface ReleasePivotal Cloud Foundry DeploymentPivotal Cloud Foundry Deployment Concourse Tasks+515/8/201917/6/2026
CF CLI version prior to v6.45.0 (bosh release version 1.16.0) writes the client id and secret to its config file when the user authenticates with --client-credentials flag. A local authenticated malicious user with access to the CF CLI config file can act as that client, who is the owner of the leaked credentials.
ModificadaCrítica (9.8)95%—XstreamOracle Banking PlatformOracle Business Activity MonitoringOracle Communications Billing AND Revenue Management Elastic Charging Engine+623/7/201917/6/2026
It was found that xstream API version 1.4.10 before 1.4.11 introduced a regression for a previous deserialization flaw. If the security framework has not been initialized, it may allow a remote attacker to run arbitrary shell commands when unmarshalling XML or any supported format. e.g. JSON. (regression of…
ModificadaAlta (7.3)0.85%💥 ExploitPronestor Health Monitoring1/4/201917/6/2026
The Pronestor PNHM (aka Health Monitoring or HealthMonitor) add-in before 8.1.13.0 for Outlook has "BUILTIN\Users:(I)(F)" permissions for the "%PROGRAMFILES(X86)%\proNestor\Outlook add-in for Pronestor\PronestorHealthMonitor.exe" file, which allows local users to gain privileges via a Trojan horse…
ModificadaCrítica (9.8)3.2%💥 ExploitSchool Attendance Monitoring System Project School Attendance Monitoring System21/3/201917/6/2026
Attendance Monitoring System 1.0 has SQL Injection via the 'id' parameter to student/index.php?view=view, event/index.php?view=view, and user/index.php?view=view.
ModificadaMedia (6.5)0.73%—Jenkins Monitoring6/2/201917/6/2026
A denial of service vulnerability exists in Jenkins Monitoring Plugin 1.74.0 and earlier in PluginImpl.java that allows attackers to kill threads running on the Jenkins master.
ModificadaMedia (6.1)0.76%—Schneider-electric Ecostruxure Energy ExpertSchneider-electric Ecostruxure Power Monitoring ExpertSchneider-electric Ecostruxure Power Scada Operation17/12/201817/6/2026
A URL redirection vulnerability exists in Power Monitoring Expert, Energy Expert (formerly Power Manager) - EcoStruxure Power Monitoring Expert (PME) v8.2 (all editions), EcoStruxure Energy Expert 1.3 (formerly Power Manager), EcoStruxure Power SCADA Operation (PSO) 8.2 Advanced Reports and Dashboards Module,…
ModificadaAlta (8.1)2.7%—Siemens Simatic IT Line Monitoring SystemSiemens Simatic IT Production SuiteSiemens Simatic IT UA Discrete Manufacturing13/12/201817/6/2026
A vulnerability has been identified in SIMATIC IT LMS (All versions), SIMATIC IT Production Suite (Versions V7.1 < V7.1 Upd3), SIMATIC IT UA Discrete Manufacturing (Versions < V1.2), SIMATIC IT UA Discrete Manufacturing (Versions V1.2), SIMATIC IT UA Discrete Manufacturing (Versions V1.3), SIMATIC IT UA Discrete…
ModificadaCrítica (9.8)1.6%—School Equipment Monitoring System Project School Equipment Monitoring System16/11/201817/6/2026
School Equipment Monitoring System 1.0 allows SQL injection via the login screen, related to include/user.vb.
ModificadaAlta (8.8)2.4%💥 ExploitSchool Attendance Monitoring System Project School Attendance Monitoring System16/11/201817/6/2026
School Attendance Monitoring System 1.0 has CSRF via event/controller.php?action=photos.
ModificadaAlta (8.8)2.4%💥 ExploitSchool Attendance Monitoring System Project School Attendance Monitoring System16/11/201817/6/2026
School Attendance Monitoring System 1.0 has CSRF via /user/user/edit.php.
ModificadaMedia (6.5)2.7%—Serverscheck Monitoring Software24/10/201817/6/2026
ServersCheck Monitoring Software through 14.3.3 allows local users to cause a denial of service (menu functionality loss) by creating an LNK file that points to a second LNK file, if this second LNK file is associated with a Start menu. Ultimately, this behavior comes from a Directory Traversal bug (via the…
ModificadaMedia (6.1)1.1%—Serverscheck Monitoring Software24/10/201817/6/2026
ServersCheck Monitoring Software through 14.3.3 has Persistent and Reflected XSS via the sensors.html status parameter, sensors.html type parameter, sensors.html device parameter, report.html location parameter, group_delete.html group parameter, report_save.html query parameter, sensors.html location parameter, or…
ModificadaAlta (8.8)1.7%—Microfocus Real User Monitoring23/10/201817/6/2026
A potential Remote Arbitrary Code Execution vulnerability has been identified in Micro Focus' Real User Monitoring software, versions 9.26IP, 9.30, 9.40 and 9.50. The vulnerability could be exploited to execute arbitrary code.
ModificadaAlta (7.5)1.2%—IBM Tivoli Monitoring19/9/201817/6/2026
IBM Tivoli Monitoring 6.2.3 through 6.2.3.5 and 6.3.0 through 6.3.0.7 are vulnerable to both TEPS user privilege escalation and possible denial of service due to unconstrained memory growth. IBM X-Force ID: 137039.
ModificadaMedia (5.3)7.1%💥 ExploitPerfsonar Monitoring AND Debugging Dashboard18/6/201817/6/2026
An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2. A direct request to /images/ provides a directory listing.
ModificadaMedia (5.3)7.1%💥 ExploitPerfsonar Monitoring AND Debugging Dashboard18/6/201817/6/2026
An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2. A direct request to /lib/ provides a directory listing.
ModificadaMedia (5.3)7.1%💥 ExploitPerfsonar Monitoring AND Debugging Dashboard18/6/201817/6/2026
An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2. A direct request to /etc/ provides a directory listing.
ModificadaMedia (5.3)7.1%💥 ExploitPerfsonar Monitoring AND Debugging Dashboard18/6/201817/6/2026
An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2. A direct request to /style/ provides a directory listing.
ModificadaCrítica (9.8)3.2%—IBM Tivoli Monitoring22/3/201817/6/2026
IBM Tivoli Monitoring V6 6.2.3 and 6.3.0 could allow an unauthenticated user to remotely execute code through unspecified methods. IBM X-Force ID: 137034.
ModificadaMedia (6.1)1.3%—SAP Process Monitoring Infrastructure14/3/201817/6/2026
Cross-Site Scripting in Process Monitoring Infrastructure, from 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, due to inefficient encoding of user controlled inputs.
ModificadaMedia (6.1)0.88%—IBM Monitoring14/3/201817/6/2026
IBM Application Performance Management - Response Time Monitoring Agent (IBM Monitoring 8.1.3 and 8.1.4) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within…
ModificadaAlta (8.8)0.73%—IBM Monitoring8/3/201817/6/2026
IBM Application Performance Management - Response Time Monitoring Agent (IBM Monitoring 8.1.4) is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 139598.
Orbitaley — Vulnerabilidades