Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
1028 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 2.2% | 💥 Exploit | Swit WP Sessions Time Monitoring Full Automatic | 26/12/2023 | 17/6/2026 | The WP Sessions Time Monitoring Full Automatic WordPress plugin before 1.0.9 does not sanitize the request URL or query parameters before using them in an SQL query, allowing unauthenticated attackers to extract sensitive data from the database via blind time based SQL injection techniques, or in some cases an… | |
| Modificada | Alta (8.8) | 0.91% | — | Wpchill Download Monitor | 20/12/2023 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in WPChill Download Monitor.This issue affects Download Monitor: from n/a through 4.8.3. | |
| Modificada | Alta (8.1) | 0.64% | — | Crawlspider SEO Change Monitor | 20/12/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CrawlSpider SEO Change Monitor – Track Website Changes.This issue affects SEO Change Monitor – Track Website Changes: from n/a through 1.2. | |
| Modificada | Alta (7.5) | 0.73% | — | Bosch Monitor WallBosch Videojet Decoder 7513 FirmwareBosch Videojet Decoder 7523 FirmwareBosch Video Recording Manager+1 | 18/12/2023 | 17/6/2026 | An improper handling of a malformed API request to an API server in Bosch BT software products can allow an unauthenticated attacker to cause a Denial of Service (DoS) situation. | |
| Modificada | Media (4.8) | 0.39% | — | Petersplugins Smart External Link Click Monitor [link Log] | 14/12/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Peter Raschendorfer Smart External Link Click Monitor [Link Log] allows Stored XSS.This issue affects Smart External Link Click Monitor [Link Log]: from n/a through 5.0.2. | |
| Modificada | Alta (7.1) | 0.24% | — | Schneider-electric Easy UPS Online Monitoring Software | 14/12/2023 | 17/6/2026 | A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause arbitrary file deletion upon service restart when accessed by a local and low-privileged attacker. | |
| Modificada | Media (6.1) | 0.41% | — | Campaignmonitor Campaign Monitor | 30/11/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Campaign Monitor Campaign Monitor for WordPress allows Reflected XSS.This issue affects Campaign Monitor for WordPress: from n/a through 2.8.12. | |
| Modificada | Alta (7.8) | 0.20% | — | Dell Command|monitor | 23/11/2023 | 17/6/2026 | Dell Command | Monitor versions prior to 10.10.0, contain an improper access control vulnerability. A local malicious standard user could potentially exploit this vulnerability while repairing/changing installation, leading to privilege escalation. | |
| Modificada | Media (5.5) | 0.69% | — | Zohocorp Manageengine Analytics PlusZohocorp Manageengine AppcreatorZohocorp Manageengine Application Control PlusZohocorp Manageengine Browser Security Plus+35 | 15/11/2023 | 17/6/2026 | An information disclosure vulnerability exists in multiple ManageEngine products that can result in encryption keys being exposed. A low-privileged OS user with access to the host where an affected ManageEngine product is installed can view and use the exposed key to decrypt product database passwords. This allows the… | |
| Modificada | Media (6.1) | 0.41% | — | Schneider-electric Ecostruxure Power Monitoring Expert | 15/11/2023 | 17/6/2026 | A CWE-79 Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) vulnerability that could cause a vulnerability leading to a cross site scripting condition where attackers can have a victim’s browser run arbitrary JavaScript when they visit a page containing the injected payload. | |
| Modificada | Media (6.1) | 0.45% | — | Schneider-electric Ecostruxure Power Monitoring Expert | 15/11/2023 | 17/6/2026 | A CWE-601 URL Redirection to Untrusted Site vulnerability exists that could cause an openredirect vulnerability leading to a cross site scripting attack. By providing a URL-encoded input attackers can cause the software’s web application to redirect to the chosen domain after a successful login is performed. | |
| Modificada | Media (4.9) | 0.65% | — | Wpchill Download Monitor | 13/11/2023 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in WPChill Download Monitor.This issue affects Download Monitor: from n/a through 4.8.1. | |
| Modificada | Crítica (9.8) | 0.86% | — | Lanaccess Onsafe Monitorhm | 8/11/2023 | 17/6/2026 | An improper input validation vulnerability has been found in Lanaccess ONSAFE MonitorHM affecting version 3.7.0. This vulnerability could lead a remote attacker to exploit the checkbox element and perform remote code execution, compromising the entire infrastructure. | |
| Modificada | Alta (8.1) | 0.58% | — | Fatcatapps Campaign Monitor Optin CAT | 31/10/2023 | 17/6/2026 | The Campaign Monitor Forms by Optin Cat WordPress plugin before 2.5.6 does not prevent users with low privileges (like subscribers) from overwriting any options on a site with the string "true", which could lead to a variety of outcomes, including DoS. | |
| Modificada | Crítica (9.8) | 0.68% | — | CTI Monitoring AND Early Warning System Project CTI Monitoring AND Early Warning System | 27/10/2023 | 17/6/2026 | A vulnerability was found in Shanghai CTI Navigation CTI Monitoring and Early Warning System 2.2. It has been classified as critical. This affects an unknown part of the file /Web/SysManage/UserEdit.aspx. The manipulation of the argument ID leads to sql injection. The exploit has been disclosed to the public and may… | |
| Modificada | Alta (7.2) | 0.48% | — | Tenable Nessus Network Monitor | 26/10/2023 | 17/6/2026 | Under certain conditions, Nessus Network Monitor was found to not properly enforce input validation. This could allow an admin user to alter parameters that could potentially allow a blindSQL injection. | |
| Modificada | Alta (7.8) | 0.15% | — | Tenable Nessus Network Monitor | 26/10/2023 | 17/6/2026 | NNM failed to properly set ACLs on its installation directory, which could allow a low privileged user to run arbitrary code with SYSTEM privileges where NNM is installed to a non-standard location | |
| Modificada | Alta (8.8) | 0.47% | — | Tenable Nessus Network Monitor | 26/10/2023 | 17/6/2026 | Under certain conditions, Nessus Network Monitor could allow a low privileged user to escalate privileges to NT AUTHORITY\SYSTEM on Windows hosts by replacing a specially crafted file. | |
| Modificada | Alta (8.8) | 1.1% | — | Esst Monitoring | 17/10/2023 | 17/6/2026 | eSST Monitoring v2.147.1 was discovered to contain a remote code execution (RCE) vulnerability via the file upload function. | |
| Modificada | Crítica (9.8) | 1.2% | — | Esst Monitoring | 17/10/2023 | 17/6/2026 | eSST Monitoring v2.147.1 was discovered to contain a remote code execution (RCE) vulnerability via the Gii code generator component. | |
| Modificada | Alta (7.5) | 0.69% | — | Esst Monitoring | 17/10/2023 | 17/6/2026 | A lack of input sanitizing in the file download feature of eSST Monitoring v2.147.1 allows attackers to execute a path traversal. | |
| Modificada | Crítica (9.8) | 0.92% | — | Schneider-electric Ecostruxure Power Monitoring ExpertSchneider-electric Ecostruxure Power Operation With Advanced ReportsSchneider-electric Ecostruxure Power Scada Operation With Advanced Reports | 4/10/2023 | 17/6/2026 | A CWE-502: Deserialization of untrusted data vulnerability exists that could allow an attacker to execute arbitrary code on the targeted system by sending a specifically crafted packet to the application. | |
| Modificada | Crítica (9.8) | 2.8% | — | DTS Monitoring | 3/10/2023 | 17/6/2026 | An issue was discovered in DTS Monitoring 3.57.0. The parameter url within the WGET check function is vulnerable to OS command injection (blind). | |
| Modificada | Crítica (9.8) | 2.8% | — | DTS Monitoring | 3/10/2023 | 17/6/2026 | An issue was discovered in DTS Monitoring 3.57.0. The parameter ip within the Ping check function is vulnerable to OS command injection (blind). | |
| Modificada | Crítica (9.8) | 1.7% | — | DTS Monitoring | 3/10/2023 | 17/6/2026 | An issue was discovered in DTS Monitoring 3.57.0. The parameter common_name within the SSL Certificate check function is vulnerable to OS command injection (blind). |