Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
1028 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.68% | — | Trumpf JOB Order InterfaceTrumpf OseonTrumpf Trutops BoostTrumpf Trutops FAB+1 | 17/10/2022 | 17/6/2026 | Multiple Trumpf Products in multiple versions use default privileged Windows users and passwords. An adversary may use these accounts to remotely gain full access to the system. | |
| Modificada | Alta (8) | 0.79% | — | Foresightsports GC3 Launch Monitor FirmwareBushnellgolf Launch PRO Firmware | 13/10/2022 | 17/6/2026 | Foresight GC3 Launch Monitor 1.3.15.68 ships with a Target Communication Framework (TCF) service enabled. This service listens on a TCP port on all interfaces and allows for process debugging, file system modification, and terminal access as the root user. In conjunction with a hosted wireless access point and the… | |
| Modificada | Media (4.9) | 1.1% | — | Wpchill Download Monitor | 10/10/2022 | 17/6/2026 | The Download Monitor WordPress plugin before 4.5.98 does not ensure that files to be downloaded are inside the blog folders, and not sensitive, allowing high privilege users such as admin to download the wp-config.php or /etc/passwd even in an hardened environment or multisite setup. | |
| Modificada | Media (4.6) | 0.29% | — | Cisco IOS XE ROM Monitor | 10/10/2022 | 17/6/2026 | A vulnerability in the password-recovery disable feature of Cisco IOS XE ROM Monitor (ROMMON) Software for Cisco Catalyst Switches could allow an unauthenticated, local attacker to recover the configuration or reset the enable password. This vulnerability is due to a problem with the file and boot variable permissions… | |
| Modificada | Media (6.1) | 0.43% | — | Gavazziautomation CPY CAR Park ServerGavazziautomation UWP 3.0 Monitoring Gateway AND Controller Firmware | 28/9/2022 | 17/6/2026 | In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 the Sentilo Proxy is prone to reflected XSS which only affects the Sentilo service. | |
| Modificada | Baja (2.7) | 0.53% | — | Gavazziautomation CPY CAR Park ServerGavazziautomation UWP 3.0 Monitoring Gateway AND Controller Firmware | 28/9/2022 | 17/6/2026 | In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 the Sentilo Proxy server was discovered to contain a SQL injection vulnerability allowing an attacker to query other tables of the Sentilo service. | |
| Modificada | Crítica (9.8) | 1.3% | — | Gavazziautomation CPY CAR Park ServerGavazziautomation UWP 3.0 Monitoring Gateway AND Controller Firmware | 28/9/2022 | 17/6/2026 | Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 was discovered to be vulnerable to a relative path traversal vulnerability which enables remote attackers to read arbitrary files and gain full control of the device. | |
| Modificada | Alta (7.5) | 1.0% | — | Gavazziautomation CPY CAR Park ServerGavazziautomation UWP 3.0 Monitoring Gateway AND Controller Firmware | 28/9/2022 | 17/6/2026 | In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 a remote, unauthenticated attacker could make use of an SQL-injection to gain access to a volatile temporary database with the current states of the device. | |
| Modificada | Crítica (9.8) | 1.0% | — | Gavazziautomation CPY CAR Park ServerGavazziautomation UWP 3.0 Monitoring Gateway AND Controller Firmware | 28/9/2022 | 17/6/2026 | In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 a remote, unauthenticated attacker could make use of hard-coded credentials to gain SuperUser access to the device. | |
| Modificada | Crítica (9.8) | 1.2% | — | Gavazziautomation CPY CAR Park ServerGavazziautomation UWP 3.0 Monitoring Gateway AND Controller Firmware | 28/9/2022 | 17/6/2026 | In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 a remote, unauthenticated attacker could utilize an improper input validation on an API-submitted parameter to execute arbitrary OS commands. | |
| Modificada | Crítica (9.8) | 0.84% | — | Gavazziautomation CPY CAR Park ServerGavazziautomation UWP 3.0 Monitoring Gateway AND Controller Firmware | 28/9/2022 | 17/6/2026 | In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 a missing authentication allows for full access via API. | |
| Modificada | Alta (7.2) | 1.2% | — | Gavazziautomation CPY CAR Park ServerGavazziautomation UWP 3.0 Monitoring Gateway AND Controller Firmware | 28/9/2022 | 17/6/2026 | In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 an remote attacker with admin rights could execute arbitrary commands due to missing input sanitization in the backup restore function | |
| Modificada | Crítica (9.4) | 1.2% | — | Gavazziautomation CPY CAR Park ServerGavazziautomation UWP 3.0 Monitoring Gateway AND Controller Firmware | 28/9/2022 | 17/6/2026 | In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 an unauthenticated remote attacker could utilize a SQL-Injection vulnerability to gain full database access, modify users and stop services . | |
| Modificada | Alta (7.5) | 0.86% | — | Gavazziautomation CPY CAR Park ServerGavazziautomation UWP 3.0 Monitoring Gateway AND Controller Firmware | 28/9/2022 | 17/6/2026 | An improper authentication vulnerability exists in the Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 Web-App which allows an authentication bypass to the context of an unauthorised user if free-access is disabled. | |
| Modificada | Crítica (9.8) | 1.1% | — | Gavazziautomation CPY CAR Park ServerGavazziautomation UWP 3.0 Monitoring Gateway AND Controller Firmware | 28/9/2022 | 17/6/2026 | In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 a remote, unauthenticated attacker could make use of hard-coded credentials to gain full access to the device. | |
| Modificada | Crítica (9.8) | 1.3% | — | Wpwhitesecurity Website File Changes Monitor | 8/8/2022 | 17/6/2026 | The Website File Changes Monitor WordPress plugin before 1.8.3 does not sanitise and escape user input before using it in a SQL statement via an action available to users with the manage_options capability (by default admins), leading to an SQL injection | |
| Modificada | Media (4.3) | 0.40% | — | Jenkins External Monitor JOB Type | 27/7/2022 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins External Monitor Job Type Plugin 191.v363d0d1efdf8 and earlier allows attackers to create runs of an external job. | |
| Modificada | Alta (8.8) | 0.48% | — | Hitachienergy Modular Switchgear Monitoring Firmware | 25/7/2022 | 17/6/2026 | A vulnerability exists in the http web interface where the web interface does not validate data in an HTTP header. This causes a possible HTTP response splitting, which if exploited could lead an attacker to channel down harmful code into the user’s web browser, such as to steal the session cookies. Thus, an attacker… | |
| Modificada | Alta (8.8) | 0.22% | — | Hitachienergy Modular Switchgear Monitoring Firmware | 25/7/2022 | 17/6/2026 | A vulnerability exists in the HTTP web interface where the web interface does not sufficiently verify if a well-formed, valid, consistent request was intentionally provided by the user who submitted the request. This cause a Cross Site Request Forgery (CSRF), which if exploited could lead an attacker to gain… | |
| Modificada | Media (6.5) | 1.3% | — | Monitoringsoft Softguard WEB | 17/7/2022 | 17/6/2026 | The export function in SoftGuard Web (SGW) before 5.1.5 allows directory traversal to read an arbitrary local file via export or man.tcl. | |
| Modificada | Media (5.4) | 0.61% | — | Monitoringsoft Softguard WEB | 17/7/2022 | 17/6/2026 | SoftGuard Web (SGW) before 5.1.5 allows HTML injection. | |
| Modificada | Media (4.9) | 1.1% | — | Wpchill Download Monitor | 17/7/2022 | 17/6/2026 | The Download Monitor WordPress plugin before 4.5.91 does not ensure that files to be downloaded are inside the blog folders, and not sensitive, allowing high privilege users such as admin to download the wp-config.php or /etc/passwd even in an hardened environment or multisite setup. | |
| Modificada | Alta (8.1) | 0.92% | — | IBM Cloud PAK FOR Multicloud Management Monitoring | 30/6/2022 | 17/6/2026 | IBM CloudPak for Multicloud Monitoring 2.0 and 2.3 has a few containers running in privileged mode which is vulnerable to host information leakage or destruction if unauthorized access to these containers could execute arbitrary commands. IBM X-Force ID: 211048. | |
| Modificada | Crítica (9.8) | 4.5% | 💥 PoC | Antminer Monitor Project Antminer Monitor | 17/6/2022 | 17/6/2026 | A vulnerability in Antminer Monitor 0.50.0 exists because of backdoor or misconfiguration inside a settings file in flask server. Settings file has a predefined secret string, which would be randomly generated, however it is static. | |
| Modificada | Crítica (9.8) | 1.1% | — | Voipmonitor | 17/6/2022 | 17/6/2026 | VoIPmonitor WEB GUI up to version 24.61 is affected by SQL injection through the "api.php" file and "user" parameter. |