Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2736▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
966 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 1.1% | 💥 Exploit | OP5 Monitor | 14/11/2022 | 17/6/2026 | OP5 Monitor 8.3.1, 8.3.2, and OP5 8.3.3 are vulnerable to Cross Site Scripting (XSS). | |
| Modificada | Crítica (9.8) | 0.37% | — | Eaton Foreseer Electrical Power Monitoring System | 28/10/2022 | 17/6/2026 | A security vulnerability was discovered in the Eaton Foreseer EPMS software. Foreseer EPMS connects an operation’s vast array of devices to assist in the reduction of energy consumption and avoid unplanned downtime caused by the failures of critical systems. A threat actor may upload arbitrary files using the file… | |
| Modificada | Media (5.3) | 0.79% | — | Paessler Prtg Network Monitor | 25/10/2022 | 17/6/2026 | PRTG Network Monitor through 22.2.77.2204 does not prevent custom input for a device’s icon, which can be modified to insert arbitrary content into the style tag for that device. When the device page loads, the arbitrary Cascading Style Sheets (CSS) data is inserted into the style tag, loading malicious content. Due… | |
| Modificada | Crítica (9.8) | 2.3% | 💥 PoC | Shinken-monitoring Shinken Monitoring | 20/10/2022 | 17/6/2026 | Shinken Solutions Shinken Monitoring Version 2.4.3 affected is vulnerable to Incorrect Access Control. The SafeUnpickler class found in shinken/safepickle.py implements a weak authentication scheme when unserializing objects passed from monitoring nodes to the Shinken monitoring server. | |
| Modificada | Crítica (9.8) | 0.68% | — | Trumpf JOB Order InterfaceTrumpf OseonTrumpf Trutops BoostTrumpf Trutops FAB+1 | 17/10/2022 | 17/6/2026 | Multiple Trumpf Products in multiple versions use default privileged Windows users and passwords. An adversary may use these accounts to remotely gain full access to the system. | |
| Modificada | Alta (8) | 0.79% | — | Foresightsports GC3 Launch Monitor FirmwareBushnellgolf Launch PRO Firmware | 13/10/2022 | 17/6/2026 | Foresight GC3 Launch Monitor 1.3.15.68 ships with a Target Communication Framework (TCF) service enabled. This service listens on a TCP port on all interfaces and allows for process debugging, file system modification, and terminal access as the root user. In conjunction with a hosted wireless access point and the… | |
| Modificada | Media (4.9) | 1.1% | — | Wpchill Download Monitor | 10/10/2022 | 17/6/2026 | The Download Monitor WordPress plugin before 4.5.98 does not ensure that files to be downloaded are inside the blog folders, and not sensitive, allowing high privilege users such as admin to download the wp-config.php or /etc/passwd even in an hardened environment or multisite setup. | |
| Modificada | Media (4.6) | 0.29% | — | Cisco IOS XE ROM Monitor | 10/10/2022 | 17/6/2026 | A vulnerability in the password-recovery disable feature of Cisco IOS XE ROM Monitor (ROMMON) Software for Cisco Catalyst Switches could allow an unauthenticated, local attacker to recover the configuration or reset the enable password. This vulnerability is due to a problem with the file and boot variable permissions… | |
| Modificada | Media (6.1) | 0.43% | — | Gavazziautomation CPY CAR Park ServerGavazziautomation UWP 3.0 Monitoring Gateway AND Controller Firmware | 28/9/2022 | 17/6/2026 | In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 the Sentilo Proxy is prone to reflected XSS which only affects the Sentilo service. | |
| Modificada | Baja (2.7) | 0.53% | — | Gavazziautomation CPY CAR Park ServerGavazziautomation UWP 3.0 Monitoring Gateway AND Controller Firmware | 28/9/2022 | 17/6/2026 | In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 the Sentilo Proxy server was discovered to contain a SQL injection vulnerability allowing an attacker to query other tables of the Sentilo service. | |
| Modificada | Crítica (9.8) | 1.3% | — | Gavazziautomation CPY CAR Park ServerGavazziautomation UWP 3.0 Monitoring Gateway AND Controller Firmware | 28/9/2022 | 17/6/2026 | Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 was discovered to be vulnerable to a relative path traversal vulnerability which enables remote attackers to read arbitrary files and gain full control of the device. | |
| Modificada | Alta (7.5) | 1.0% | — | Gavazziautomation CPY CAR Park ServerGavazziautomation UWP 3.0 Monitoring Gateway AND Controller Firmware | 28/9/2022 | 17/6/2026 | In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 a remote, unauthenticated attacker could make use of an SQL-injection to gain access to a volatile temporary database with the current states of the device. | |
| Modificada | Crítica (9.8) | 1.0% | — | Gavazziautomation CPY CAR Park ServerGavazziautomation UWP 3.0 Monitoring Gateway AND Controller Firmware | 28/9/2022 | 17/6/2026 | In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 a remote, unauthenticated attacker could make use of hard-coded credentials to gain SuperUser access to the device. | |
| Modificada | Crítica (9.8) | 1.2% | — | Gavazziautomation CPY CAR Park ServerGavazziautomation UWP 3.0 Monitoring Gateway AND Controller Firmware | 28/9/2022 | 17/6/2026 | In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 a remote, unauthenticated attacker could utilize an improper input validation on an API-submitted parameter to execute arbitrary OS commands. | |
| Modificada | Crítica (9.8) | 0.84% | — | Gavazziautomation CPY CAR Park ServerGavazziautomation UWP 3.0 Monitoring Gateway AND Controller Firmware | 28/9/2022 | 17/6/2026 | In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 a missing authentication allows for full access via API. | |
| Modificada | Alta (7.2) | 1.2% | — | Gavazziautomation CPY CAR Park ServerGavazziautomation UWP 3.0 Monitoring Gateway AND Controller Firmware | 28/9/2022 | 17/6/2026 | In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 an remote attacker with admin rights could execute arbitrary commands due to missing input sanitization in the backup restore function | |
| Modificada | Crítica (9.4) | 1.2% | — | Gavazziautomation CPY CAR Park ServerGavazziautomation UWP 3.0 Monitoring Gateway AND Controller Firmware | 28/9/2022 | 17/6/2026 | In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 an unauthenticated remote attacker could utilize a SQL-Injection vulnerability to gain full database access, modify users and stop services . | |
| Modificada | Alta (7.5) | 0.86% | — | Gavazziautomation CPY CAR Park ServerGavazziautomation UWP 3.0 Monitoring Gateway AND Controller Firmware | 28/9/2022 | 17/6/2026 | An improper authentication vulnerability exists in the Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 Web-App which allows an authentication bypass to the context of an unauthorised user if free-access is disabled. | |
| Modificada | Crítica (9.8) | 1.1% | — | Gavazziautomation CPY CAR Park ServerGavazziautomation UWP 3.0 Monitoring Gateway AND Controller Firmware | 28/9/2022 | 17/6/2026 | In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 a remote, unauthenticated attacker could make use of hard-coded credentials to gain full access to the device. | |
| Modificada | Crítica (9.8) | 1.3% | — | Wpwhitesecurity Website File Changes Monitor | 8/8/2022 | 17/6/2026 | The Website File Changes Monitor WordPress plugin before 1.8.3 does not sanitise and escape user input before using it in a SQL statement via an action available to users with the manage_options capability (by default admins), leading to an SQL injection | |
| Modificada | Media (4.3) | 0.40% | — | Jenkins External Monitor JOB Type | 27/7/2022 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins External Monitor Job Type Plugin 191.v363d0d1efdf8 and earlier allows attackers to create runs of an external job. | |
| Modificada | Alta (8.8) | 0.48% | — | Hitachienergy Modular Switchgear Monitoring Firmware | 25/7/2022 | 17/6/2026 | A vulnerability exists in the http web interface where the web interface does not validate data in an HTTP header. This causes a possible HTTP response splitting, which if exploited could lead an attacker to channel down harmful code into the user’s web browser, such as to steal the session cookies. Thus, an attacker… | |
| Modificada | Alta (8.8) | 0.22% | — | Hitachienergy Modular Switchgear Monitoring Firmware | 25/7/2022 | 17/6/2026 | A vulnerability exists in the HTTP web interface where the web interface does not sufficiently verify if a well-formed, valid, consistent request was intentionally provided by the user who submitted the request. This cause a Cross Site Request Forgery (CSRF), which if exploited could lead an attacker to gain… | |
| Modificada | Media (6.5) | 1.3% | — | Monitoringsoft Softguard WEB | 17/7/2022 | 17/6/2026 | The export function in SoftGuard Web (SGW) before 5.1.5 allows directory traversal to read an arbitrary local file via export or man.tcl. | |
| Modificada | Media (5.4) | 0.61% | — | Monitoringsoft Softguard WEB | 17/7/2022 | 17/6/2026 | SoftGuard Web (SGW) before 5.1.5 allows HTML injection. |