Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
967 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.2% | — | Esst Monitoring | 17/10/2023 | 17/6/2026 | eSST Monitoring v2.147.1 was discovered to contain a remote code execution (RCE) vulnerability via the Gii code generator component. | |
| Modificada | Alta (7.5) | 0.69% | — | Esst Monitoring | 17/10/2023 | 17/6/2026 | A lack of input sanitizing in the file download feature of eSST Monitoring v2.147.1 allows attackers to execute a path traversal. | |
| Modificada | Crítica (9.8) | 0.92% | — | Schneider-electric Ecostruxure Power Monitoring ExpertSchneider-electric Ecostruxure Power Operation With Advanced ReportsSchneider-electric Ecostruxure Power Scada Operation With Advanced Reports | 4/10/2023 | 17/6/2026 | A CWE-502: Deserialization of untrusted data vulnerability exists that could allow an attacker to execute arbitrary code on the targeted system by sending a specifically crafted packet to the application. | |
| Modificada | Crítica (9.8) | 2.8% | — | DTS Monitoring | 3/10/2023 | 17/6/2026 | An issue was discovered in DTS Monitoring 3.57.0. The parameter url within the WGET check function is vulnerable to OS command injection (blind). | |
| Modificada | Crítica (9.8) | 2.8% | — | DTS Monitoring | 3/10/2023 | 17/6/2026 | An issue was discovered in DTS Monitoring 3.57.0. The parameter ip within the Ping check function is vulnerable to OS command injection (blind). | |
| Modificada | Crítica (9.8) | 1.7% | — | DTS Monitoring | 3/10/2023 | 17/6/2026 | An issue was discovered in DTS Monitoring 3.57.0. The parameter common_name within the SSL Certificate check function is vulnerable to OS command injection (blind). | |
| Modificada | Crítica (9.8) | 2.8% | — | DTS Monitoring | 3/10/2023 | 17/6/2026 | An issue was discovered in DTS Monitoring 3.57.0. The parameter url within the Curl check function is vulnerable to OS command injection (blind). | |
| Modificada | Crítica (9.8) | 2.3% | — | DTS Monitoring | 3/10/2023 | 17/6/2026 | An issue was discovered in DTS Monitoring 3.57.0. The parameter options within the WGET check function is vulnerable to OS command injection (blind). | |
| Modificada | Crítica (9.8) | 1.5% | — | DTS Monitoring | 3/10/2023 | 17/6/2026 | An issue was discovered in DTS Monitoring 3.57.0. The parameter port within the SSL Certificate check function is vulnerable to OS command injection (blind). | |
| Modificada | Media (6.7) | 0.30% | 💥 PoC | AMD Ryzen MasterAMD Ryzen Master Monitoring SDK | 15/8/2023 | 17/6/2026 | Insufficient validation in the IOCTL (Input Output Control) input buffer in AMD Ryzen™ Master may permit a privileged attacker to perform memory reads/writes potentially leading to a loss of confidentiality or arbitrary kernel execution. | |
| Modificada | Media (4.4) | 0.22% | — | AMD Ryzen MasterAMD Ryzen Master Monitoring SDK | 15/8/2023 | 17/6/2026 | Insufficient validation of the IOCTL (Input Output Control) input buffer in AMD Ryzen™ Master may allow a privileged attacker to provide a null value potentially resulting in a Windows crash leading to denial of service. | |
| Modificada | Alta (7.2) | 56% | — | Paessler Prtg Network Monitor | 9/8/2023 | 17/6/2026 | A command injection was identified in PRTG 23.2.84.1566 and earlier versions in the Dicom C-ECHO sensor where an authenticated user with write permissions could abuse the debug option to write new files that could potentially get executed by the EXE/Script sensor. The severity of this vulnerability is high and… | |
| Modificada | Alta (7.2) | 14% | 💥 Exploit | Paessler Prtg Network Monitor | 9/8/2023 | 17/6/2026 | A command injection vulnerability was identified in PRTG 23.2.84.1566 and earlier versions in the HL7 sensor where an authenticated user with write permissions could abuse the debug option to write new files that could potentially get executed by the EXE/Script sensor. The severity of this vulnerability is high and… | |
| Modificada | Alta (8.8) | 0.65% | — | Paessler Prtg Network Monitor | 9/8/2023 | 17/6/2026 | A cross-site request forgery (CSRF) token bypass was identified in PRTG 23.2.84.1566 and earlier versions that allows remote attackers to perform actions with the permissions of a victim user, provided the victim user has an active session and is induced to trigger the malicious request. This could force PRTG to… | |
| Modificada | Media (4.7) | 0.51% | — | Paessler Prtg Network Monitor | 9/8/2023 | 17/6/2026 | A path traversal vulnerability was identified in the SQL v2 sensors in PRTG 23.2.84.1566 and earlier versions where an authenticated user with write permissions could trick the SQL v2 sensors into behaving differently for existing files and non-existing files. This made it possible to traverse paths, allowing the… | |
| Modificada | Media (4.7) | 0.51% | — | Paessler Prtg Network Monitor | 9/8/2023 | 17/6/2026 | A path traversal vulnerability was identified in the WMI Custom sensor in PRTG 23.2.84.1566 and earlier versions where an authenticated user with write permissions could trick the WMI Custom sensor into behaving differently for existing files and non-existing files. This made it possible to traverse paths, allowing… | |
| Modificada | Media (4.7) | 0.51% | — | Paessler Prtg Network Monitor | 9/8/2023 | 17/6/2026 | A path traversal vulnerability was identified in the HL7 sensor in PRTG 23.2.84.1566 and earlier versions where an authenticated user with write permissions could trick the HL7 sensor into behaving differently for existing files and non-existing files. This made it possible to traverse paths, allowing the sensor to… | |
| Modificada | Alta (7.5) | 0.92% | — | Cdwanjiang Flash Flood Disaster Monitoring AND Warning System | 5/8/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in Chengdu Flash Flood Disaster Monitoring and Warning System 2.0. This issue affects some unknown processing of the file \Service\FileHandler.ashx. The manipulation of the argument FileDirectory leads to absolute path traversal. The attack may be… | |
| Modificada | Media (5.3) | 1.1% | — | Cdwanjiang Flash Flood Disaster Monitoring AND Warning System | 5/8/2023 | 17/6/2026 | A vulnerability classified as problematic was found in Chengdu Flash Flood Disaster Monitoring and Warning System 2.0. This vulnerability affects unknown code of the file \Service\FileDownload.ashx. The manipulation of the argument Files leads to path traversal: '../filedir'. The attack can be initiated remotely. The… | |
| Modificada | Alta (7.2) | 3.2% | — | Solarwinds Network Configuration Monitor | 26/7/2023 | 17/6/2026 | The SolarWinds Network Configuration Manager was susceptible to the Directory Traversal Vulnerability. This vulnerability allows users with administrative access to SolarWinds Web Console to execute arbitrary commands. | |
| Modificada | Crítica (9.8) | 0.90% | — | Cdwanjiang Flash Flood Disaster Monitoring AND Warning System | 21/7/2023 | 17/6/2026 | A vulnerability classified as problematic was found in Chengdu Flash Flood Disaster Monitoring and Warning System 2.0. This vulnerability affects unknown code of the file /Service/FileHandler.ashx. The manipulation of the argument userFile leads to unrestricted upload. The exploit has been disclosed to the public and… | |
| Modificada | Baja (3.7) | 0.67% | — | Cdwanjiang Flash Flood Disaster Monitoring AND Warning System | 21/7/2023 | 17/6/2026 | A vulnerability classified as problematic has been found in Chengdu Flash Flood Disaster Monitoring and Warning System 2.0. This affects an unknown part of the file /Service/ImageStationDataService.asmx of the component File Name Handler. The manipulation leads to insufficiently random values. The complexity of an… | |
| Modificada | Crítica (9.8) | 0.95% | — | Cdwanjiang Flash Flood Disaster Monitoring AND Warning System | 21/7/2023 | 17/6/2026 | A vulnerability was found in Chengdu Flash Flood Disaster Monitoring and Warning System 2.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /Controller/Ajaxfileupload.ashx. The manipulation of the argument file leads to unrestricted upload. The exploit has been… | |
| Modificada | Crítica (9.8) | 0.89% | — | Cdwanjiang Flash Flood Disaster Monitoring AND Warning System | 20/7/2023 | 17/6/2026 | A vulnerability has been found in Chengdu Flash Flood Disaster Monitoring and Warning System 2.0 and classified as critical. This vulnerability affects unknown code of the file /App_Resource/UEditor/server/upload.aspx. The manipulation of the argument file leads to unrestricted upload. The exploit has been disclosed… | |
| Modificada | Alta (8.8) | 0.88% | — | Istrong Four Mountain Torrent Disaster Prevention, Control Monitoring AND Early Warning System | 20/7/2023 | 17/6/2026 | A vulnerability, which was classified as critical, was found in Gen Technology Four Mountain Torrent Disaster Prevention and Control of Monitoring and Early Warning System up to 20230712. This affects an unknown part of the file /Duty/AjaxHandle/UploadFloodPlanFileUpdate.ashx. The manipulation of the argument Filedata… |