Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
1028 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.5) | 0.38% | — | Fujielectric Monitouch V-sft | 30/5/2024 | 17/6/2026 | Fuji Electric Monitouch V-SFT is vulnerable to an out-of-bounds write because of a type confusion, which could result in arbitrary code execution. | |
| Analizada | Alta (8.5) | 0.56% | — | Fujielectric Monitouch V-sft | 30/5/2024 | 17/6/2026 | Fuji Electric Monitouch V-SFT is vulnerable to a stack-based buffer overflow, which could allow an attacker to execute arbitrary code. | |
| Aplazada | Media (5.4) | 0.30% | — | Download MonitorAI | 30/5/2024 | 17/6/2026 | The Download Monitor plugin for WordPress is vulnerable to unauthorized access to functionality due to a missing capability check on the dlm_uninstall_plugin function in all versions up to, and including, 4.9.13. This makes it possible for authenticated attackers to uninstall the plugin and delete its data. | |
| Aplazada | Media (6.3) | 0.27% | — | PHP Server MonitorAIPhpmailerAI | 24/5/2024 | 17/6/2026 | PHP Server Monitor, version 3.2.0, is vulnerable to an XSS via the /phpservermon-3.2.0/vendor/phpmailer/phpmailer/test_script/index.php page in all visible parameters. An attacker could create a specially crafted URL, send it to a victim and retrieve their session details. | |
| Analizada | Media (5.3) | 0.58% | — | Remyandrade Electricity Consumption Monitoring Tool | 20/5/2024 | 17/6/2026 | A vulnerability was found in SourceCodester Electricity Consumption Monitoring Tool 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /endpoint/delete-bill.php. The manipulation of the argument bill leads to sql injection. The attack can be initiated remotely. The exploit has… | |
| Analizada | Alta (7.8) | 0.49% | — | Microsoft Azure Monitor Agent | 16/5/2024 | 17/6/2026 | Azure Monitor Agent Elevation of Privilege Vulnerability | |
| Aplazada | Alta (7.3) | 0.31% | — | Agasta Sanketlife 2.0 Pocket 12 Lead ECG MonitorAI | 22/4/2024 | 17/6/2026 | Insecure Permission vulnerability in Agasta Sanketlife 2.0 Pocket 12-Lead ECG Monitor FW Version 3.0 allows a local attacker to cause a denial of service via the Bluetooth Low Energy (BLE) component. | |
| Analizada | Media (6.5) | 0.40% | — | Dell Storage Monitoring AND ReportingDell Storage Resource Manager | 12/4/2024 | 17/6/2026 | Dell Storage Resource Manager, 4.9.0.0 and below, contain(s) a Session Fixation Vulnerability in SRM Windows Host Agent. An adjacent network unauthenticated attacker could potentially exploit this vulnerability, leading to the hijack of a targeted user's application session. | |
| Analizada | Alta (8.4) | 0.75% | — | Microsoft Azure Monitor Agent | 9/4/2024 | 17/6/2026 | Azure Monitor Agent Elevation of Privilege Vulnerability | |
| Modificada | Alta (7.2) | 0.61% | — | Wpchill Download Monitor | 29/3/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPChill Download Monitor.This issue affects Download Monitor: from n/a through 4.9.4. | |
| Aplazada | Alta (7.1) | 0.35% | — | Activewebsight SEO Backlink MonitorAI | 27/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Active Websight SEO Backlink Monitor allows Reflected XSS.This issue affects SEO Backlink Monitor: from n/a through 1.5.0. | |
| Aplazada | Crítica (9.8) | 0.74% | — | Vehicle Monitoring Platform Cmsv6AI | 25/3/2024 | 17/6/2026 | Insecure Permissions vulnerability in Vehicle Monitoring platform system CMSV6 v.7.31.0.2 through v.7.32.0.3 allows a remote attacker to escalate privileges via the default password component. | |
| Analizada | Alta (7.8) | 0.99% | — | Microsoft Azure AutomationMicrosoft Azure Automation Update ManagementMicrosoft Azure Security CenterMicrosoft Azure Sentinel+4 | 12/3/2024 | 17/6/2026 | Open Management Infrastructure (OMI) Elevation of Privilege Vulnerability | |
| Analizada | Media (6.1) | 0.67% | 💥 PoC | Badgermeter Monitool | 12/3/2024 | 17/6/2026 | Cross-site scripting vulnerability in Badger Meter Monitool that affects versions up to 4.6.3 and earlier. This vulnerability allows a remote attacker to send a specially crafted javascript payload to an authenticated user and partially hijack their browser session. | |
| Analizada | Media (6.5) | 1.0% | 💥 PoC | Badgermeter Monitool | 12/3/2024 | 17/6/2026 | Incorrectly limiting the path to a restricted directory vulnerability in Badger Meter Monitool that affects versions up to 4.6.3 and earlier. This vulnerability allows an authenticated attacker to retrieve any file from the device using the download-file functionality. | |
| Analizada | Media (5.5) | 0.49% | 💥 PoC | Badgermeter Monitool | 12/3/2024 | 17/6/2026 | Information exposure vulnerability in Badger Meter Monitool affecting versions up to 4.6.3 and earlier. A local attacker could change the application's file parameter to a log file obtaining all sensitive information such as database credentials. | |
| Analizada | Alta (7.5) | 2.2% | 💥 PoC | Badgermeter Monitool | 12/3/2024 | 17/6/2026 | SQL injection vulnerability in Badger Meter Monitool affecting versions 4.6.3 and earlier. A remote attacker could send a specially crafted SQL query to the server via the j_username parameter and retrieve the information stored in the database. | |
| Modificada | Media (5.4) | 79% | — | Jenkins Build Monitor View | 6/3/2024 | 17/6/2026 | Jenkins Build Monitor View Plugin 1.14-860.vd06ef2568b_3f and earlier does not escape Build Monitor View names, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to configure Build Monitor Views. | |
| Analizada | Media (6.1) | 0.41% | — | Remyandrade Barangay Population Monitoring System | 1/3/2024 | 17/6/2026 | A vulnerability was found in SourceCodester Barangay Population Monitoring System up to 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /endpoint/update-resident.php. The manipulation of the argument full_name leads to cross site scripting. The attack may be launched… | |
| Modificada | Crítica (9.8) | 0.81% | — | Rems Barangay Population Monitoring System | 14/2/2024 | 17/6/2026 | Barangay Population Monitoring System 1.0 was discovered to contain a SQL injection vulnerability via the resident parameter at /endpoint/delete-resident.php. | |
| Modificada | Alta (7.5) | 0.73% | — | Intel Performance Counter Monitor | 14/2/2024 | 17/6/2026 | Buffer underflow in some Intel(R) PCM software before version 202307 may allow an unauthenticated user to potentially enable denial of service via network access. | |
| Modificada | Media (6.1) | 1.7% | — | Paessler Prtg Network Monitor | 8/2/2024 | 17/6/2026 | Paessler PRTG Network Monitor Cross-Site Scripting Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of Paessler PRTG Network Monitor. User interaction is required to exploit this vulnerability in that the target must visit a malicious… | |
| Modificada | Alta (7.1) | 0.14% | — | Dell Command | Monitor | 6/2/2024 | 17/6/2026 | Dell Command | Monitor, versions prior to 10.9, contain an arbitrary folder deletion vulnerability. A locally authenticated malicious user may exploit this vulnerability in order to perform a privileged arbitrary file delete. | |
| Modificada | Media (5.5) | 0.36% | — | Nsasoft Network Bandwidth Monitor | 2/2/2024 | 17/6/2026 | A vulnerability classified as problematic has been found in Nsasoft NBMonitor Network Bandwidth Monitor 1.6.5.0. This affects an unknown part of the component Registration Handler. The manipulation leads to denial of service. The attack needs to be approached locally. The exploit has been disclosed to the public and… | |
| Modificada | Alta (7.5) | 38% | 💥 Exploit | Wpchill Download Monitor | 8/1/2024 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in WPChill Download Monitor.This issue affects Download Monitor: from n/a through 4.7.60. |