Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

967 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)0.81%—Rems Barangay Population Monitoring System14/2/202417/6/2026
Barangay Population Monitoring System 1.0 was discovered to contain a SQL injection vulnerability via the resident parameter at /endpoint/delete-resident.php.
ModificadaAlta (7.5)0.73%—Intel Performance Counter Monitor14/2/202417/6/2026
Buffer underflow in some Intel(R) PCM software before version 202307 may allow an unauthenticated user to potentially enable denial of service via network access.
ModificadaMedia (6.1)1.7%—Paessler Prtg Network Monitor8/2/202417/6/2026
Paessler PRTG Network Monitor Cross-Site Scripting Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of Paessler PRTG Network Monitor. User interaction is required to exploit this vulnerability in that the target must visit a malicious…
ModificadaAlta (7.1)0.14%—Dell Command | Monitor6/2/202417/6/2026
Dell Command | Monitor, versions prior to 10.9, contain an arbitrary folder deletion vulnerability. A locally authenticated malicious user may exploit this vulnerability in order to perform a privileged arbitrary file delete.
ModificadaMedia (5.5)0.36%—Nsasoft Network Bandwidth Monitor2/2/202417/6/2026
A vulnerability classified as problematic has been found in Nsasoft NBMonitor Network Bandwidth Monitor 1.6.5.0. This affects an unknown part of the component Registration Handler. The manipulation leads to denial of service. The attack needs to be approached locally. The exploit has been disclosed to the public and…
ModificadaAlta (7.5)38%💥 ExploitWpchill Download Monitor8/1/202417/6/2026
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in WPChill Download Monitor.This issue affects Download Monitor: from n/a through 4.7.60.
ModificadaAlta (7.5)2.2%💥 ExploitSwit WP Sessions Time Monitoring Full Automatic26/12/202317/6/2026
The WP Sessions Time Monitoring Full Automatic WordPress plugin before 1.0.9 does not sanitize the request URL or query parameters before using them in an SQL query, allowing unauthenticated attackers to extract sensitive data from the database via blind time based SQL injection techniques, or in some cases an…
ModificadaAlta (8.8)0.91%—Wpchill Download Monitor20/12/202317/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in WPChill Download Monitor.This issue affects Download Monitor: from n/a through 4.8.3.
ModificadaAlta (8.1)0.64%—Crawlspider SEO Change Monitor20/12/202317/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CrawlSpider SEO Change Monitor – Track Website Changes.This issue affects SEO Change Monitor – Track Website Changes: from n/a through 1.2.
ModificadaAlta (7.5)0.73%—Bosch Monitor WallBosch Videojet Decoder 7513 FirmwareBosch Videojet Decoder 7523 FirmwareBosch Video Recording Manager+118/12/202317/6/2026
An improper handling of a malformed API request to an API server in Bosch BT software products can allow an unauthenticated attacker to cause a Denial of Service (DoS) situation.
ModificadaMedia (4.8)0.39%—Petersplugins Smart External Link Click Monitor [link Log]14/12/202317/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Peter Raschendorfer Smart External Link Click Monitor [Link Log] allows Stored XSS.This issue affects Smart External Link Click Monitor [Link Log]: from n/a through 5.0.2.
ModificadaAlta (7.1)0.24%—Schneider-electric Easy UPS Online Monitoring Software14/12/202317/6/2026
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause arbitrary file deletion upon service restart when accessed by a local and low-privileged attacker.
ModificadaMedia (6.1)0.41%—Campaignmonitor Campaign Monitor30/11/202317/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Campaign Monitor Campaign Monitor for WordPress allows Reflected XSS.This issue affects Campaign Monitor for WordPress: from n/a through 2.8.12.
ModificadaAlta (7.8)0.20%—Dell Command|monitor23/11/202317/6/2026
Dell Command | Monitor versions prior to 10.10.0, contain an improper access control vulnerability. A local malicious standard user could potentially exploit this vulnerability while repairing/changing installation, leading to privilege escalation.
ModificadaMedia (5.5)0.69%—Zohocorp Manageengine Analytics PlusZohocorp Manageengine AppcreatorZohocorp Manageengine Application Control PlusZohocorp Manageengine Browser Security Plus+3515/11/202317/6/2026
An information disclosure vulnerability exists in multiple ManageEngine products that can result in encryption keys being exposed. A low-privileged OS user with access to the host where an affected ManageEngine product is installed can view and use the exposed key to decrypt product database passwords. This allows the…
ModificadaMedia (6.1)0.41%—Schneider-electric Ecostruxure Power Monitoring Expert15/11/202317/6/2026
A CWE-79 Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) vulnerability that could cause a vulnerability leading to a cross site scripting condition where attackers can have a victim’s browser run arbitrary JavaScript when they visit a page containing the injected payload.
ModificadaMedia (6.1)0.45%—Schneider-electric Ecostruxure Power Monitoring Expert15/11/202317/6/2026
A CWE-601 URL Redirection to Untrusted Site vulnerability exists that could cause an openredirect vulnerability leading to a cross site scripting attack. By providing a URL-encoded input attackers can cause the software’s web application to redirect to the chosen domain after a successful login is performed.
ModificadaMedia (4.9)0.65%—Wpchill Download Monitor13/11/202317/6/2026
Server-Side Request Forgery (SSRF) vulnerability in WPChill Download Monitor.This issue affects Download Monitor: from n/a through 4.8.1.
ModificadaCrítica (9.8)0.86%—Lanaccess Onsafe Monitorhm8/11/202317/6/2026
An improper input validation vulnerability has been found in Lanaccess ONSAFE MonitorHM affecting version 3.7.0. This vulnerability could lead a remote attacker to exploit the checkbox element and perform remote code execution, compromising the entire infrastructure.
ModificadaAlta (8.1)0.58%—Fatcatapps Campaign Monitor Optin CAT31/10/202317/6/2026
The Campaign Monitor Forms by Optin Cat WordPress plugin before 2.5.6 does not prevent users with low privileges (like subscribers) from overwriting any options on a site with the string "true", which could lead to a variety of outcomes, including DoS.
ModificadaCrítica (9.8)0.68%—CTI Monitoring AND Early Warning System Project CTI Monitoring AND Early Warning System27/10/202317/6/2026
A vulnerability was found in Shanghai CTI Navigation CTI Monitoring and Early Warning System 2.2. It has been classified as critical. This affects an unknown part of the file /Web/SysManage/UserEdit.aspx. The manipulation of the argument ID leads to sql injection. The exploit has been disclosed to the public and may…
ModificadaAlta (7.2)0.48%—Tenable Nessus Network Monitor26/10/202317/6/2026
Under certain conditions, Nessus Network Monitor was found to not properly enforce input validation. This could allow an admin user to alter parameters that could potentially allow a blindSQL injection.
ModificadaAlta (7.8)0.15%—Tenable Nessus Network Monitor26/10/202317/6/2026
NNM failed to properly set ACLs on its installation directory, which could allow a low privileged user to run arbitrary code with SYSTEM privileges where NNM is installed to a non-standard location
ModificadaAlta (8.8)0.47%—Tenable Nessus Network Monitor26/10/202317/6/2026
Under certain conditions, Nessus Network Monitor could allow a low privileged user to escalate privileges to NT AUTHORITY\SYSTEM on Windows hosts by replacing a specially crafted file.
ModificadaAlta (8.8)1.1%—Esst Monitoring17/10/202317/6/2026
eSST Monitoring v2.147.1 was discovered to contain a remote code execution (RCE) vulnerability via the file upload function.
Orbitaley — Vulnerabilidades