Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

1028 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)2.8%—DTS Monitoring3/10/202317/6/2026
An issue was discovered in DTS Monitoring 3.57.0. The parameter url within the Curl check function is vulnerable to OS command injection (blind).
ModificadaCrítica (9.8)2.3%—DTS Monitoring3/10/202317/6/2026
An issue was discovered in DTS Monitoring 3.57.0. The parameter options within the WGET check function is vulnerable to OS command injection (blind).
ModificadaCrítica (9.8)1.5%—DTS Monitoring3/10/202317/6/2026
An issue was discovered in DTS Monitoring 3.57.0. The parameter port within the SSL Certificate check function is vulnerable to OS command injection (blind).
ModificadaMedia (6.7)0.30%💥 PoCAMD Ryzen MasterAMD Ryzen Master Monitoring SDK15/8/202317/6/2026
Insufficient validation in the IOCTL (Input Output Control) input buffer in AMD Ryzen™ Master may permit a privileged attacker to perform memory reads/writes potentially leading to a loss of confidentiality or arbitrary kernel execution.
ModificadaMedia (4.4)0.22%—AMD Ryzen MasterAMD Ryzen Master Monitoring SDK15/8/202317/6/2026
Insufficient validation of the IOCTL (Input Output Control) input buffer in AMD Ryzen™ Master may allow a privileged attacker to provide a null value potentially resulting in a Windows crash leading to denial of service.
ModificadaAlta (7.2)56%—Paessler Prtg Network Monitor9/8/202317/6/2026
A command injection was identified in PRTG 23.2.84.1566 and earlier versions in the Dicom C-ECHO sensor where an authenticated user with write permissions could abuse the debug option to write new files that could potentially get executed by the EXE/Script sensor. The severity of this vulnerability is high and…
ModificadaAlta (7.2)14%💥 ExploitPaessler Prtg Network Monitor9/8/202317/6/2026
A command injection vulnerability was identified in PRTG 23.2.84.1566 and earlier versions in the HL7 sensor where an authenticated user with write permissions could abuse the debug option to write new files that could potentially get executed by the EXE/Script sensor. The severity of this vulnerability is high and…
ModificadaAlta (8.8)0.65%—Paessler Prtg Network Monitor9/8/202317/6/2026
A cross-site request forgery (CSRF) token bypass was identified in PRTG 23.2.84.1566 and earlier versions that allows remote attackers to perform actions with the permissions of a victim user, provided the victim user has an active session and is induced to trigger the malicious request. This could force PRTG to…
ModificadaMedia (4.7)0.51%—Paessler Prtg Network Monitor9/8/202317/6/2026
A path traversal vulnerability was identified in the SQL v2 sensors in PRTG 23.2.84.1566 and earlier versions where an authenticated user with write permissions could trick the SQL v2 sensors into behaving differently for existing files and non-existing files. This made it possible to traverse paths, allowing the…
ModificadaMedia (4.7)0.51%—Paessler Prtg Network Monitor9/8/202317/6/2026
A path traversal vulnerability was identified in the WMI Custom sensor in PRTG 23.2.84.1566 and earlier versions where an authenticated user with write permissions could trick the WMI Custom sensor into behaving differently for existing files and non-existing files. This made it possible to traverse paths, allowing…
ModificadaMedia (4.7)0.51%—Paessler Prtg Network Monitor9/8/202317/6/2026
A path traversal vulnerability was identified in the HL7 sensor in PRTG 23.2.84.1566 and earlier versions where an authenticated user with write permissions could trick the HL7 sensor into behaving differently for existing files and non-existing files. This made it possible to traverse paths, allowing the sensor to…
ModificadaAlta (7.5)0.92%—Cdwanjiang Flash Flood Disaster Monitoring AND Warning System5/8/202317/6/2026
A vulnerability, which was classified as problematic, has been found in Chengdu Flash Flood Disaster Monitoring and Warning System 2.0. This issue affects some unknown processing of the file \Service\FileHandler.ashx. The manipulation of the argument FileDirectory leads to absolute path traversal. The attack may be…
ModificadaMedia (5.3)1.1%—Cdwanjiang Flash Flood Disaster Monitoring AND Warning System5/8/202317/6/2026
A vulnerability classified as problematic was found in Chengdu Flash Flood Disaster Monitoring and Warning System 2.0. This vulnerability affects unknown code of the file \Service\FileDownload.ashx. The manipulation of the argument Files leads to path traversal: '../filedir'. The attack can be initiated remotely. The…
ModificadaAlta (7.2)3.2%—Solarwinds Network Configuration Monitor26/7/202317/6/2026
The SolarWinds Network Configuration Manager was susceptible to the Directory Traversal Vulnerability. This vulnerability allows users with administrative access to SolarWinds Web Console to execute arbitrary commands.
ModificadaCrítica (9.8)0.90%—Cdwanjiang Flash Flood Disaster Monitoring AND Warning System21/7/202317/6/2026
A vulnerability classified as problematic was found in Chengdu Flash Flood Disaster Monitoring and Warning System 2.0. This vulnerability affects unknown code of the file /Service/FileHandler.ashx. The manipulation of the argument userFile leads to unrestricted upload. The exploit has been disclosed to the public and…
ModificadaBaja (3.7)0.67%—Cdwanjiang Flash Flood Disaster Monitoring AND Warning System21/7/202317/6/2026
A vulnerability classified as problematic has been found in Chengdu Flash Flood Disaster Monitoring and Warning System 2.0. This affects an unknown part of the file /Service/ImageStationDataService.asmx of the component File Name Handler. The manipulation leads to insufficiently random values. The complexity of an…
ModificadaCrítica (9.8)0.95%—Cdwanjiang Flash Flood Disaster Monitoring AND Warning System21/7/202317/6/2026
A vulnerability was found in Chengdu Flash Flood Disaster Monitoring and Warning System 2.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /Controller/Ajaxfileupload.ashx. The manipulation of the argument file leads to unrestricted upload. The exploit has been…
ModificadaCrítica (9.8)0.89%—Cdwanjiang Flash Flood Disaster Monitoring AND Warning System20/7/202317/6/2026
A vulnerability has been found in Chengdu Flash Flood Disaster Monitoring and Warning System 2.0 and classified as critical. This vulnerability affects unknown code of the file /App_Resource/UEditor/server/upload.aspx. The manipulation of the argument file leads to unrestricted upload. The exploit has been disclosed…
ModificadaAlta (8.8)0.88%—Istrong Four Mountain Torrent Disaster Prevention, Control Monitoring AND Early Warning System20/7/202317/6/2026
A vulnerability, which was classified as critical, was found in Gen Technology Four Mountain Torrent Disaster Prevention and Control of Monitoring and Early Warning System up to 20230712. This affects an unknown part of the file /Duty/AjaxHandle/UploadFloodPlanFileUpdate.ashx. The manipulation of the argument Filedata…
ModificadaAlta (8.8)0.89%—Tildeslash Monit18/7/202317/6/2026
An issue was discovered in Tildeslash Monit before 5.31.0, allows remote attackers to gain escilated privlidges due to improper PAM-authorization.
ModificadaMedia (6.5)0.61%—Jenkins External Monitor JOB Type12/7/202317/6/2026
Jenkins External Monitor Job Type Plugin 206.v9a_94ff0b_4a_10 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
ModificadaCrítica (9.8)0.96%—Istrong Mountain Flood Disaster Prevention Monitoring AND Early Warning System11/7/202317/6/2026
A vulnerability, which was classified as critical, has been found in Suncreate Mountain Flood Disaster Prevention Monitoring and Early Warning System up to 20230706. This issue affects some unknown processing of the file /Duty/AjaxHandle/UpLoadFloodPlanFile.ashx of the component UpLoadFloodPlanFile. The manipulation…
ModificadaCrítica (9.8)0.96%—Istrong Mountain Flood Disaster Prevention Monitoring AND Early Warning System11/7/202317/6/2026
A vulnerability classified as critical was found in Suncreate Mountain Flood Disaster Prevention Monitoring and Early Warning System up to 20230706. This vulnerability affects unknown code of the file /Duty/AjaxHandle/Write/UploadFile.ashx of the component Duty Write-UploadFile. The manipulation of the argument…
ModificadaCrítica (9.8)0.91%—Istrong Mountain Flood Disaster Prevention Monitoring AND Early Warning System11/7/202317/6/2026
A vulnerability was found in Suncreate Mountain Flood Disaster Prevention Monitoring and Early Warning System up to 20230704. It has been rated as critical. Affected by this issue is some unknown functionality of the file /Duty/AjaxHandle/UploadHandler.ashx of the component Duty Module. The manipulation of the…
ModificadaAlta (8.8)0.93%—Rockwellautomation Powermonitor 1000 Firmware11/7/202317/6/2026
The Rockwell Automation PowerMonitor 1000 contains stored cross-site scripting vulnerabilities within the web page of the product. The vulnerable pages do not require privileges to access and can be injected with code by an attacker which could be used to leverage an attack on an authenticated user resulting in remote…