Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2722▼ 518 respecto a la semana anterior
Críticas / altas1296▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

966 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.9)1.1%—Wpchill Download Monitor17/7/202217/6/2026
The Download Monitor WordPress plugin before 4.5.91 does not ensure that files to be downloaded are inside the blog folders, and not sensitive, allowing high privilege users such as admin to download the wp-config.php or /etc/passwd even in an hardened environment or multisite setup.
ModificadaAlta (8.1)0.92%—IBM Cloud PAK FOR Multicloud Management Monitoring30/6/202217/6/2026
IBM CloudPak for Multicloud Monitoring 2.0 and 2.3 has a few containers running in privileged mode which is vulnerable to host information leakage or destruction if unauthorized access to these containers could execute arbitrary commands. IBM X-Force ID: 211048.
ModificadaCrítica (9.8)4.5%💥 PoCAntminer Monitor Project Antminer Monitor17/6/202217/6/2026
A vulnerability in Antminer Monitor 0.50.0 exists because of backdoor or misconfiguration inside a settings file in flask server. Settings file has a predefined secret string, which would be randomly generated, however it is static.
ModificadaCrítica (9.8)1.1%—Voipmonitor17/6/202217/6/2026
VoIPmonitor WEB GUI up to version 24.61 is affected by SQL injection through the "api.php" file and "user" parameter.
ModificadaAlta (7.8)0.92%—Microsoft Azure Automation State ConfigurationMicrosoft Azure Automation Update ManagementMicrosoft Azure DiagnosticsMicrosoft Azure Security Center+615/6/202217/6/2026
Open Management Infrastructure (OMI) Elevation of Privilege Vulnerability
ModificadaAlta (8.8)1.5%💥 PoCEmcosoftware MSI Package BuilderEmcosoftware Network InventoryEmcosoftware Network Software ScannerEmcosoftware Ping Monitor+423/5/20229/7/2026
Certain EMCO Software products are affected by: CWE-494: Download of Code Without Integrity Check. This affects MSI Package Builder for Windows 9.1.4 and Remote Installer for Windows 6.0.13 and Ping Monitor for Windows 8.0.18 and Remote Shutdown for Windows 7.2.2 and WakeOnLan 2.0.8 and Network Inventory for Windows…
ModificadaCrítica (9.8)1.5%—Trumpf Trutops BoostTrumpf Trutops FABTrumpf Trutops Monitor2/5/202217/6/2026
Multiple Version of TRUMPF TruTops products expose a service function without necessary authentication. Execution of this function may result in unauthorized access to change of data or disruption of the whole service.
ModificadaMedia (5.5)1.5%—RedisFedoraproject FedoraNetapp Management Services FOR Element SoftwareManagement Services FOR Netapp HCI+127/4/202217/6/2026
Redis is an in-memory database that persists on disk. Prior to versions 6.2.7 and 7.0.0, an attacker attempting to load a specially crafted Lua script can cause NULL pointer dereference which will result with a crash of the redis-server process. The problem is fixed in Redis versions 7.0.0 and 6.2.7. An additional…
ModificadaAlta (7.8)2.3%—RedisFedoraproject FedoraNetapp Management Services FOR Element SoftwareManagement Services FOR Netapp HCI+127/4/202217/6/2026
Redis is an in-memory database that persists on disk. By exploiting weaknesses in the Lua script execution environment, an attacker with access to Redis prior to version 7.0.0 or 6.2.7 can inject Lua code that will execute with the (potentially higher) privileges of another Redis user. The Lua script execution…
ModificadaMedia (6.1)3.2%—Solarwinds Database Performance AnalyzerSolarwinds Database Performance Monitor21/4/202217/6/2026
Cross-site scripting vulnerability is present in Database Performance Monitor 2022.1.7779 and previous versions when using a complex SQL query
ModificadaAlta (7.5)10.0%💥 PoCGolang GOFedoraproject FedoraNetapp Kubernetes Monitoring Operator20/4/202217/6/2026
encoding/pem in Go before 1.17.9 and 1.18.x before 1.18.1 has a Decode stack overflow via a large amount of PEM data.
ModificadaMedia (5.3)5.7%💥 PoCVmware Spring FrameworkNetapp Active IQ Unified ManagerNetapp Cloud Secure AgentNetapp Metrocluster Tiebreaker+314/4/202217/6/2026
In Spring Framework versions 5.3.0 - 5.3.18, 5.2.0 - 5.2.20, and older unsupported versions, the patterns for disallowedFields on a DataBinder are case sensitive which means a field is not effectively protected unless it is listed with both upper and lower case for the first character of the field, including upper and…
ModificadaAlta (8.8)0.99%—Drtrustusa Icheck Connect BP Monitor BP Testing 118 Firmware7/4/20229/7/2026
Dr Trust USA iCheck Connect BP Monitor BP Testing 118 version 1.2.1 is vulnerable to Missing Authentication.
ModificadaMedia (6.5)0.60%—Drtrustusa Icheck Connect BP Monitor BP Testing 118 Firmware7/4/20229/7/2026
Dr Trust USA iCheck Connect BP Monitor BP Testing 118 version 1.2.1 is vulnerable to Transmitting Write Requests and Chars.
ModificadaAlta (7.5)0.80%—Drtrustusa Icheck Connect BP Monitor BP Testing 118 Firmware7/4/20229/7/2026
Dr Trust USA iCheck Connect BP Monitor BP Testing 118 1.2.1 is vulnerable to a Replay Attack to BP Monitoring.
ModificadaAlta (8.8)1.00%—Drtrustusa Icheck Connect BP Monitor BP Testing 118 Firmware7/4/20229/7/2026
Dr Trust USA iCheck Connect BP Monitor BP Testing 118 1.2.1 is vulnerable to Plain text command over BLE.
AnalizadaCrítica (9.8)100%⚠ Explotación activa💥 ExploitVmware Spring FrameworkCisco CX Cloud AgentOracle Communications Cloud Native Core Automated Test SuiteOracle Communications Cloud Native Core Console+341/4/202217/6/2026
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to…
AnalizadaCrítica (9.8)100%⚠ Explotación activa💥 ExploitVmware Spring Cloud FunctionOracle Banking BranchOracle Banking Cash ManagementOracle Banking Corporate Lending Process Management+241/4/202217/6/2026
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and access to local resources.
ModificadaMedia (5.4)0.81%—Jenkins Sitemonitor29/3/202217/6/2026
Jenkins SiteMonitor Plugin 0.6 and earlier does not escape URLs of sites to monitor in tooltips, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
ModificadaMedia (6.5)1.4%—Tipsandtricks-hq Simple Download Monitor14/3/202217/6/2026
The Simple Download Monitor WordPress plugin before 3.9.5 allows users with a role as low as Contributor to download any file on the web server (such as wp-config.php) via a path traversal vector.
ModificadaAlta (7.8)0.21%—Wordline Hidccemonitorsvc3/3/202217/6/2026
Wordline HIDCCEMonitorSVC before v5.2.4.3 contains an unquoted service path which allows attackers to escalate privileges to the system level.
ModificadaAlta (8.2)22%—Nodejs Node.jsOracle Mysql ClusterOracle Mysql ConnectorsOracle Mysql Enterprise Monitor+724/2/202217/6/2026
Due to the formatting logic of the "console.table()" function it was not safe to allow user controlled input to be passed to the "properties" parameter while simultaneously passing a plain object with at least one property as the first parameter, which could be "__proto__". The prototype pollution has very limited…
ModificadaMedia (5.3)9.4%—Nodejs Node.jsOracle GraalvmOracle Mysql ClusterOracle Mysql Connectors+524/2/202217/6/2026
Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 did not handle multi-value Relative Distinguished Names correctly. Attackers could craft certificate subjects containing a single-value Relative Distinguished Name that would be interpreted as a multi-value Relative Distinguished Name, for example, in order to…
ModificadaMedia (5.3)10%—Nodejs Node.jsOracle GraalvmOracle Mysql ClusterOracle Mysql Connectors+524/2/202217/6/2026
Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 converts SANs (Subject Alternative Names) to a string format. It uses this string to check peer certificates against hostnames when validating connections. The string format was subject to an injection vulnerability when name constraints were used within a…
ModificadaAlta (7.4)8.4%—Nodejs Node.jsOracle GraalvmOracle Mysql ConnectorsOracle Mysql Enterprise Monitor+424/2/202217/6/2026
Accepting arbitrary Subject Alternative Name (SAN) types, unless a PKI is specifically defined to use a particular SAN type, can result in bypassing name-constrained intermediates. Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 was accepting URI SAN types, which PKIs are often not defined to use. Additionally,…