Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
967 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.81% | — | Rems Barangay Population Monitoring System | 14/2/2024 | 17/6/2026 | Barangay Population Monitoring System 1.0 was discovered to contain a SQL injection vulnerability via the resident parameter at /endpoint/delete-resident.php. | |
| Modificada | Alta (7.5) | 0.73% | — | Intel Performance Counter Monitor | 14/2/2024 | 17/6/2026 | Buffer underflow in some Intel(R) PCM software before version 202307 may allow an unauthenticated user to potentially enable denial of service via network access. | |
| Modificada | Media (6.1) | 1.7% | — | Paessler Prtg Network Monitor | 8/2/2024 | 17/6/2026 | Paessler PRTG Network Monitor Cross-Site Scripting Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of Paessler PRTG Network Monitor. User interaction is required to exploit this vulnerability in that the target must visit a malicious… | |
| Modificada | Alta (7.1) | 0.14% | — | Dell Command | Monitor | 6/2/2024 | 17/6/2026 | Dell Command | Monitor, versions prior to 10.9, contain an arbitrary folder deletion vulnerability. A locally authenticated malicious user may exploit this vulnerability in order to perform a privileged arbitrary file delete. | |
| Modificada | Media (5.5) | 0.36% | — | Nsasoft Network Bandwidth Monitor | 2/2/2024 | 17/6/2026 | A vulnerability classified as problematic has been found in Nsasoft NBMonitor Network Bandwidth Monitor 1.6.5.0. This affects an unknown part of the component Registration Handler. The manipulation leads to denial of service. The attack needs to be approached locally. The exploit has been disclosed to the public and… | |
| Modificada | Alta (7.5) | 38% | 💥 Exploit | Wpchill Download Monitor | 8/1/2024 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in WPChill Download Monitor.This issue affects Download Monitor: from n/a through 4.7.60. | |
| Modificada | Alta (7.5) | 2.2% | 💥 Exploit | Swit WP Sessions Time Monitoring Full Automatic | 26/12/2023 | 17/6/2026 | The WP Sessions Time Monitoring Full Automatic WordPress plugin before 1.0.9 does not sanitize the request URL or query parameters before using them in an SQL query, allowing unauthenticated attackers to extract sensitive data from the database via blind time based SQL injection techniques, or in some cases an… | |
| Modificada | Alta (8.8) | 0.91% | — | Wpchill Download Monitor | 20/12/2023 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in WPChill Download Monitor.This issue affects Download Monitor: from n/a through 4.8.3. | |
| Modificada | Alta (8.1) | 0.64% | — | Crawlspider SEO Change Monitor | 20/12/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CrawlSpider SEO Change Monitor – Track Website Changes.This issue affects SEO Change Monitor – Track Website Changes: from n/a through 1.2. | |
| Modificada | Alta (7.5) | 0.73% | — | Bosch Monitor WallBosch Videojet Decoder 7513 FirmwareBosch Videojet Decoder 7523 FirmwareBosch Video Recording Manager+1 | 18/12/2023 | 17/6/2026 | An improper handling of a malformed API request to an API server in Bosch BT software products can allow an unauthenticated attacker to cause a Denial of Service (DoS) situation. | |
| Modificada | Media (4.8) | 0.39% | — | Petersplugins Smart External Link Click Monitor [link Log] | 14/12/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Peter Raschendorfer Smart External Link Click Monitor [Link Log] allows Stored XSS.This issue affects Smart External Link Click Monitor [Link Log]: from n/a through 5.0.2. | |
| Modificada | Alta (7.1) | 0.24% | — | Schneider-electric Easy UPS Online Monitoring Software | 14/12/2023 | 17/6/2026 | A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause arbitrary file deletion upon service restart when accessed by a local and low-privileged attacker. | |
| Modificada | Media (6.1) | 0.41% | — | Campaignmonitor Campaign Monitor | 30/11/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Campaign Monitor Campaign Monitor for WordPress allows Reflected XSS.This issue affects Campaign Monitor for WordPress: from n/a through 2.8.12. | |
| Modificada | Alta (7.8) | 0.20% | — | Dell Command|monitor | 23/11/2023 | 17/6/2026 | Dell Command | Monitor versions prior to 10.10.0, contain an improper access control vulnerability. A local malicious standard user could potentially exploit this vulnerability while repairing/changing installation, leading to privilege escalation. | |
| Modificada | Media (5.5) | 0.69% | — | Zohocorp Manageengine Analytics PlusZohocorp Manageengine AppcreatorZohocorp Manageengine Application Control PlusZohocorp Manageengine Browser Security Plus+35 | 15/11/2023 | 17/6/2026 | An information disclosure vulnerability exists in multiple ManageEngine products that can result in encryption keys being exposed. A low-privileged OS user with access to the host where an affected ManageEngine product is installed can view and use the exposed key to decrypt product database passwords. This allows the… | |
| Modificada | Media (6.1) | 0.41% | — | Schneider-electric Ecostruxure Power Monitoring Expert | 15/11/2023 | 17/6/2026 | A CWE-79 Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) vulnerability that could cause a vulnerability leading to a cross site scripting condition where attackers can have a victim’s browser run arbitrary JavaScript when they visit a page containing the injected payload. | |
| Modificada | Media (6.1) | 0.45% | — | Schneider-electric Ecostruxure Power Monitoring Expert | 15/11/2023 | 17/6/2026 | A CWE-601 URL Redirection to Untrusted Site vulnerability exists that could cause an openredirect vulnerability leading to a cross site scripting attack. By providing a URL-encoded input attackers can cause the software’s web application to redirect to the chosen domain after a successful login is performed. | |
| Modificada | Media (4.9) | 0.65% | — | Wpchill Download Monitor | 13/11/2023 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in WPChill Download Monitor.This issue affects Download Monitor: from n/a through 4.8.1. | |
| Modificada | Crítica (9.8) | 0.86% | — | Lanaccess Onsafe Monitorhm | 8/11/2023 | 17/6/2026 | An improper input validation vulnerability has been found in Lanaccess ONSAFE MonitorHM affecting version 3.7.0. This vulnerability could lead a remote attacker to exploit the checkbox element and perform remote code execution, compromising the entire infrastructure. | |
| Modificada | Alta (8.1) | 0.58% | — | Fatcatapps Campaign Monitor Optin CAT | 31/10/2023 | 17/6/2026 | The Campaign Monitor Forms by Optin Cat WordPress plugin before 2.5.6 does not prevent users with low privileges (like subscribers) from overwriting any options on a site with the string "true", which could lead to a variety of outcomes, including DoS. | |
| Modificada | Crítica (9.8) | 0.68% | — | CTI Monitoring AND Early Warning System Project CTI Monitoring AND Early Warning System | 27/10/2023 | 17/6/2026 | A vulnerability was found in Shanghai CTI Navigation CTI Monitoring and Early Warning System 2.2. It has been classified as critical. This affects an unknown part of the file /Web/SysManage/UserEdit.aspx. The manipulation of the argument ID leads to sql injection. The exploit has been disclosed to the public and may… | |
| Modificada | Alta (7.2) | 0.48% | — | Tenable Nessus Network Monitor | 26/10/2023 | 17/6/2026 | Under certain conditions, Nessus Network Monitor was found to not properly enforce input validation. This could allow an admin user to alter parameters that could potentially allow a blindSQL injection. | |
| Modificada | Alta (7.8) | 0.15% | — | Tenable Nessus Network Monitor | 26/10/2023 | 17/6/2026 | NNM failed to properly set ACLs on its installation directory, which could allow a low privileged user to run arbitrary code with SYSTEM privileges where NNM is installed to a non-standard location | |
| Modificada | Alta (8.8) | 0.47% | — | Tenable Nessus Network Monitor | 26/10/2023 | 17/6/2026 | Under certain conditions, Nessus Network Monitor could allow a low privileged user to escalate privileges to NT AUTHORITY\SYSTEM on Windows hosts by replacing a specially crafted file. | |
| Modificada | Alta (8.8) | 1.1% | — | Esst Monitoring | 17/10/2023 | 17/6/2026 | eSST Monitoring v2.147.1 was discovered to contain a remote code execution (RCE) vulnerability via the file upload function. |