Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
966 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.41% | — | Trigonesoft Remote System Monitor | 17/2/2022 | 17/6/2026 | TRIGONE Remote System Monitor 3.61 is vulnerable to an unquoted path service allowing local users to launch processes with elevated privileges. | |
| Modificada | Media (4.8) | 0.45% | — | Wocu-monitoring Wocu Monitoring | 11/2/2022 | 17/6/2026 | A stored cross site scripting have been identified at the comments in the report creation due to an obsolote version of tinymce editor. In order to exploit this vulnerability, the attackers needs an account with enough privileges to view and edit reports. | |
| Modificada | Crítica (9.8) | 1.3% | — | Mitsubishielectric C Controller Interface Module UtilityMitsubishielectric C Controller Module Setting AND Monitoring ToolMitsubishielectric Cc-link IE Control Network Data CollectorMitsubishielectric Cc-link IE Field Network Data Collector+42 | 11/2/2022 | 17/6/2026 | Multiple Mitsubishi Electric Factory Automation engineering software products have a malicious code execution vulnerability. A malicious attacker could use this vulnerability to obtain information, modify information, and cause a denial-of-service condition. | |
| Modificada | Crítica (9.1) | 3.1% | — | Golang GONetapp Beegfs CSI DriverNetapp Cloud Insights Telegraf AgentNetapp Kubernetes Monitoring Operator+2 | 11/2/2022 | 17/6/2026 | Curve.IsOnCurve in crypto/elliptic in Go before 1.16.14 and 1.17.x before 1.17.7 can incorrectly return true in situations with a big.Int value that is not a valid field element. | |
| Modificada | Alta (7.5) | 2.7% | 💥 PoC | Golang GONetapp Beegfs CSI DriverNetapp Cloud Insights Telegraf AgentNetapp Kubernetes Monitoring Operator+1 | 11/2/2022 | 17/6/2026 | cmd/go in Go before 1.16.14 and 1.17.x before 1.17.7 can misinterpret branch names that falsely appear to be version tags. This can lead to incorrect access control if an actor is supposed to be able to create branches but not tags. | |
| Modificada | Alta (7.5) | 2.8% | — | Golang GONetapp Beegfs CSI DriverNetapp Cloud Insights Telegraf AgentNetapp Kubernetes Monitoring Operator+2 | 11/2/2022 | 17/6/2026 | Rat.SetString in math/big in Go before 1.16.14 and 1.17.x before 1.17.7 has an overflow that can lead to Uncontrolled Memory Consumption. | |
| Modificada | Media (5.4) | 0.45% | — | Schneider-electric Ecostruxure Power Monitoring Expert | 4/2/2022 | 17/6/2026 | A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could allow an authenticated attacker to view data, change settings, or impact availability of the software when the user visits a page containing the injected payload. Affected Product: EcoStruxure… | |
| Modificada | Alta (8.8) | 1.2% | — | Schneider-electric Ecostruxure Power Monitoring Expert | 4/2/2022 | 17/6/2026 | A CWE-20: Improper Input Validation vulnerability exists that could allow an unauthenticated attacker to view data, change settings, impact availability of the software, or potentially impact a user�s local machine when the user clicks a specially crafted link. Affected Product: EcoStruxure Power Monitoring Expert… | |
| Modificada | Media (6.5) | 0.77% | — | Schneider-electric Ecostruxure Power Monitoring Expert | 4/2/2022 | 17/6/2026 | A CWE-20: Improper Input Validation vulnerability exists that could allow arbitrary files on the server to be read by authenticated users through a limited operating system service account. Affected Product: EcoStruxure Power Monitoring Expert (Versions 2020 and prior) | |
| Modificada | Alta (8.8) | 1.8% | — | Voipmonitor | 4/2/2022 | 17/6/2026 | The config restore function of Voipmonitor GUI before v24.96 does not properly check files sent as restore archives, allowing remote attackers to execute arbitrary commands via a crafted file in the web root. | |
| Modificada | Crítica (9.8) | 50% | 💥 Exploit | Voipmonitor | 4/2/2022 | 17/6/2026 | A SQL injection vulnerability in Voipmonitor GUI before v24.96 allows attackers to escalate privileges to the Administrator level. | |
| Modificada | Crítica (9.8) | 2.0% | — | Voipmonitor | 4/2/2022 | 17/6/2026 | An incorrect check in the component cdr.php of Voipmonitor GUI before v24.96 allows unauthenticated attackers to escalate privileges via a crafted request. | |
| Modificada | Media (6.8) | 1.4% | — | Wpchill Download Monitor | 28/1/2022 | 17/6/2026 | Authenticated (admin+) Arbitrary File Download vulnerability discovered in Download Monitor WordPress plugin (versions <= 4.4.6). The plugin allows arbitrary files, including sensitive configuration files such as wp-config.php, to be downloaded via the &downloadable_file_urls[0] parameter data. It's also possible to… | |
| Modificada | Media (4.8) | 84% | — | Wpchill Download Monitor | 28/1/2022 | 17/6/2026 | Authenticated (admin+) Persistent Cross-Site Scripting (XSS) vulnerability discovered in Download Monitor WordPress plugin (versions <= 4.4.6) Vulnerable parameters: &post_title, &downloadable_file_version[0]. | |
| Modificada | Alta (8.8) | 1.2% | — | Schneider-electric Ecostruxure Power Monitoring Expert | 28/1/2022 | 17/6/2026 | A CWE-20: Improper Input Validation vulnerability exists that could cause arbitrary code execution when the user visits a page containing the injected payload. This CVE is unique from CVE-2021-22826. Affected Product: EcoStruxure� Power Monitoring Expert 9.0 and prior versions | |
| Modificada | Alta (8.8) | 1.2% | — | Schneider-electric Ecostruxure Power Monitoring Expert | 28/1/2022 | 17/6/2026 | A CWE-20: Improper Input Validation vulnerability exists that could cause arbitrary code execution when the user visits a page containing the injected payload. This CVE is unique from CVE-2021-22827. Affected Product: EcoStruxure� Power Monitoring Expert 9.0 and prior versions | |
| Modificada | Alta (7) | 0.69% | — | Apache TomcatOracle Agile Engineering Data ManagementOracle Communications Cloud Native Core PolicyOracle Financial Services Crime AND Compliance Management Studio+3 | 27/1/2022 | 17/6/2026 | The fix for bug CVE-2020-9484 introduced a time of check, time of use vulnerability into Apache Tomcat 10.1.0-M1 to 10.1.0-M8, 10.0.0-M5 to 10.0.14, 9.0.35 to 9.0.56 and 8.5.55 to 8.5.73 that allowed a local attacker to perform actions with the privileges of the user that the Tomcat process is using. This issue is… | |
| Modificada | Alta (8.8) | 0.63% | — | Tipsandtricks-hq Simple Download Monitor | 24/1/2022 | 17/6/2026 | The Simple Download Monitor WordPress plugin before 3.9.9 does not enforce nonce checks, which could allow attackers to perform CSRF attacks to 1) make admins export logs to exploit a separate log disclosure vulnerability (fixed in 3.9.6), 2) delete logs (fixed in 3.9.9), 3) remove thumbnail image from downloads | |
| Modificada | Media (5.4) | 0.61% | — | Tipsandtricks-hq Simple Download Monitor | 24/1/2022 | 17/6/2026 | The Simple Download Monitor WordPress plugin before 3.9.11 could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attack via 1) "color" or "css_class" argument of sdm_download shortcode, 2) "class" or "placeholder" argument of sdm_search_form shortcode. | |
| Modificada | Media (6.6) | 0.67% | — | Oracle Communications Operations Monitor | 19/1/2022 | 17/6/2026 | Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (component: Mediation Engine). Supported versions that are affected are 3.4, 4.2, 4.3, 4.4 and 5.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle… | |
| Modificada | Media (4.8) | 0.53% | — | Oracle Communications Operations Monitor | 19/1/2022 | 17/6/2026 | Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (component: Mediation Engine). Supported versions that are affected are 3.4, 4.2, 4.3, 4.4 and 5.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle… | |
| Modificada | Media (6.6) | 0.67% | — | Oracle Communications Operations Monitor | 19/1/2022 | 17/6/2026 | Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (component: Mediation Engine). Supported versions that are affected are 3.4, 4.2, 4.3, 4.4 and 5.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle… | |
| Modificada | Media (5.4) | 0.52% | — | Oracle Communications Operations Monitor | 19/1/2022 | 17/6/2026 | Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (component: Mediation Engine). Supported versions that are affected are 3.4, 4.2, 4.3, 4.4 and 5.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle… | |
| Modificada | Media (6.6) | 0.67% | — | Oracle Communications Operations Monitor | 19/1/2022 | 17/6/2026 | Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (component: Mediation Engine). Supported versions that are affected are 3.4, 4.2, 4.3, 4.4 and 5.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle… | |
| Modificada | Media (5.4) | 0.52% | — | Oracle Communications Operations Monitor | 19/1/2022 | 17/6/2026 | Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (component: Mediation Engine). Supported versions that are affected are 3.4, 4.2, 4.3, 4.4 and 5.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle… |