Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
358 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.3) | 1.7% | — | IBM Application Performance ManagementIBM Cloud APM Data CollectorIBM Monitoring | 8/3/2018 | 17/6/2026 | IBM Application Performance Management for Monitoring & Diagnostics (IBM Monitoring 8.1.3 and 8.1.4) may release sensitive personal data to the staff who can access to the database of this product. IBM X-Force ID: 138210. | |
| Modificada | Media (5.4) | 0.71% | — | Serverscheck Monitoring Software | 27/12/2017 | 17/6/2026 | ServersCheck Monitoring Software before 14.2.3 is prone to a cross-site scripting vulnerability as user supplied-data is not validated/sanitized when passed in the settings_SMS_ALERT_TYPE parameter, and JavaScript can be executed on settings-save.html (the Settings - SMS Alerts page). | |
| Modificada | Alta (8) | 3.1% | 💥 PoC | IBM Tivoli Monitoring | 13/12/2017 | 17/6/2026 | IBM Tivoli Monitoring V6 6.2.2.x could allow a remote attacker to execute arbitrary code on the system, caused by a use-after-free error. A remote attacker could exploit this vulnerability to execute arbitrary code on the system or cause the application to crash. IBM X-Force ID: 133243. | |
| Modificada | Alta (7.4) | 1.9% | — | Dell EMC M&RDell EMC Storage Monitoring AND ReportingDell EMC Vipr SRMDell EMC VNX Monitoring AND Reporting | 22/9/2017 | 17/6/2026 | In EMC ViPR SRM, Storage M&R, VNX M&R, and M&R (Watch4Net) for SAS Solution Packs, the Java Management Extensions (JMX) protocol used to communicate between components in the Alerting and/or Compliance components can be leveraged to create a denial of service (DoS) condition. Attackers with knowledge of JMX agent user… | |
| Modificada | Alta (8.8) | 3.0% | — | Dell EMC M&RDell EMC Storage Monitoring AND ReportingDell EMC Vipr SRMDell EMC VNX Monitoring AND Reporting | 22/9/2017 | 17/6/2026 | In EMC ViPR SRM, Storage M&R, VNX M&R, and M&R (Watch4Net) for SAS Solution Packs, the Webservice Gateway is affected by a directory traversal vulnerability. Attackers with knowledge of Webservice Gateway credentials could potentially exploit this vulnerability to access unauthorized information, and modify or delete… | |
| Modificada | Crítica (9.8) | 14% | — | Dell EMC M&RDell EMC Storage Monitoring AND ReportingDell EMC Vipr SRMDell EMC VNX Monitoring AND Reporting | 17/7/2017 | 17/6/2026 | EMC ViPR SRM, EMC Storage M&R, EMC VNX M&R, EMC M&R for SAS Solution Packs (EMC ViPR SRM prior to 4.1, EMC Storage M&R prior to 4.1, EMC VNX M&R all versions, EMC M&R (Watch4Net) for SAS Solution Packs all versions) contain undocumented accounts with default passwords for Webservice Gateway and RMI JMX components. A… | |
| Modificada | Alta (7.5) | 0.75% | — | IBM Tivoli Monitoring | 17/7/2017 | 17/6/2026 | IBM Tivoli Monitoring Portal v6 could allow a local (network adjacent) attacker to modify SQL commands to the Portal Server, when default client-server communications, HTTP, are being used. IBM X-Force ID: 123494. | |
| Modificada | Alta (7.5) | 8.5% | 💥 PoC | IBM Tivoli Monitoring | 17/7/2017 | 17/6/2026 | IBM Tivoli Monitoring Portal v6 could allow a local (network adjacent) attacker to execute arbitrary commands on the system, when default client-server default communications, HTTP, are being used. IBM X-Force ID: 123493. | |
| Modificada | Alta (7) | 0.22% | — | IBM Tivoli Monitoring | 17/7/2017 | 17/6/2026 | IBM Tivoli Monitoring Portal V6 client could allow a local attacker to gain elevated privileges for IBM Tivoli Monitoring, caused by the default console connection not being encrypted. IBM X-Force ID: 123487. | |
| Modificada | Media (5.3) | 1.3% | — | IBM Tivoli Monitoring | 27/6/2017 | 17/6/2026 | IBM Tivoli Monitoring V6 could allow an unauthenticated user to access SOAP queries that could contain sensitive information. IBM X-Force ID: 117696. | |
| Modificada | Media (6.1) | 1.1% | — | Clickfraud-monitoring Adsense-click-fraud-monitoringPhpwhois Project Phpwhois | 17/5/2017 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in phpwhois 4.2.5, as used in the adsense-click-fraud-monitoring plugin 1.7.5 for WordPress, allows remote attackers to inject arbitrary web script or HTML via the query parameter to whois.php. | |
| Modificada | Media (4.6) | 0.57% | — | IBM Tivoli Monitoring | 8/3/2017 | 17/6/2026 | IBM Tivoli Monitoring 6.2 and 6.3 is vulnerable to possible host header injection attack that could lead to HTTP cache poisoning or firewall bypass. IBM Reference #: 1997223. | |
| Modificada | Media (5.5) | 0.42% | — | Munin-monitoring MuninDebian Linux | 22/2/2017 | 17/6/2026 | Munin before 2.999.6 has a local file write vulnerability when CGI graphs are enabled. Setting multiple upper_limit GET parameters allows overwriting any file accessible to the www-data user. | |
| Modificada | Alta (7.8) | 0.41% | — | IBM Tivoli Monitoring | 1/12/2016 | 17/6/2026 | Stack-based buffer overflow in the ax Shared Libraries in the Agent in IBM Tivoli Monitoring (ITM) 6.2.2 before FP9, 6.2.3 before FP5, and 6.3.0 before FP2 on Linux and UNIX allows local users to gain privileges via unspecified vectors. | |
| Modificada | Crítica (9.9) | 3.3% | — | IBM Tivoli Monitoring | 12/3/2016 | 17/6/2026 | The portal client in IBM Tivoli Monitoring (ITM) 6.2.2 through FP9, 6.2.3 through FP5, and 6.3.0 through FP6 allows remote authenticated users to gain privileges via unspecified vectors. | |
| Modificada | Alta (8.5) | 3.4% | — | IBM Tivoli Monitoring | 3/1/2016 | 17/6/2026 | The portal in IBM Tivoli Monitoring (ITM) 6.2.2 through FP9, 6.2.3 through FP5, and 6.3.0 before FP7 allows remote authenticated users to execute arbitrary commands by leveraging Take Action view authority and providing crafted input. | |
| Modificada | Alta (8.5) | 1.8% | — | IBM Tivoli Monitoring | 2/2/2015 | 17/6/2026 | IBM Tivoli Monitoring (ITM) 6.2.0 through FP03, 6.2.1 through FP04, 6.2.2 through FP09, 6.2.3 through FP05, and 6.3.0 before FP04 allows remote authenticated users to bypass intended access restrictions and execute arbitrary commands by leveraging Take Action view authority to modify in-progress commands. | |
| Modificada | Media (4.3) | 1.9% | — | Pandorafms Pandora Flexible Monitoring System | 19/11/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Page visualization agents in Pandora FMS 5.1 SP1 and earlier allows remote attackers to inject arbitrary web script or HTML via the refr parameter to index.php. | |
| Modificada | Media (5) | 1.8% | — | Jenkins-ci Monitoring Plugin | 16/10/2014 | 17/6/2026 | The Monitoring plugin before 1.53.0 for Jenkins allows remote attackers to obtain sensitive information by accessing unspecified pages. | |
| Modificada | Media (4.3) | 1.8% | — | Jenkins-ci Monitoring Plugin | 10/10/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Monitoring plugin before 1.53.0 for Jenkins allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | GNU BashArista EOSOracle LinuxQnap QTS+70 | 25/9/2014 | 17/6/2026 | GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown other impact via a crafted environment, as demonstrated by vectors involving the ForceCommand feature… | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | GNU BashArista EOSOracle LinuxQnap QTS+70 | 24/9/2014 | 17/6/2026 | GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the… | |
| Modificada | Alta (7.2) | 0.84% | 💥 Exploit | IBM Monitoring Agent FOR Unix LogsIBM Monitoring Server (ms) AND Shared Libraries (ax) | 29/8/2014 | 16/6/2026 | Monitoring Agent for UNIX Logs 6.2.0 through FP03, 6.2.1 through FP04, 6.2.2 through FP09, and 6.2.3 through FP04 and Monitoring Server (ms) and Shared Libraries (ax) 6.2.0 through FP03, 6.2.1 through FP04, 6.2.2 through FP08, 6.2.3 through FP01, and 6.3.0 through FP01 in IBM Tivoli Monitoring (ITM) on UNIX allow… | |
| Modificada | Media (5) | 1.4% | — | SAP Computing Center Management System Monitoring | 9/6/2014 | 17/6/2026 | SAP CCMS Monitoring (BC-CCM-MON) has hardcoded credentials, which makes it easier for remote attackers to obtain access via unspecified vectors. | |
| Modificada | Media (4.3) | 1.8% | — | Munin-monitoring Munin | 13/12/2013 | 17/6/2026 | Munin::Master::Node in Munin before 2.0.18 allows remote attackers to cause a denial of service (abort data collection for node) via a plugin that uses "multigraph" as a multigraph service name. |