Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2619▼ 461 respecto a la semana anterior
Críticas / altas1277▼ 72 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)235▼ 274 respecto a la semana anterior
–

967 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.4)0.12%—Intel Performance Counter Monitor11/8/20262/10/2026
Untrusted search path for some Intel(R) Performance Counter Monitor (Intel(R) PCM) before version tag 202604 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable escalation of privilege. This…
AplazadaMedia (5.3)0.30%—Download MonitorAI8/8/202626/8/2026
The Download Monitor WordPress plugin before 5.2.6 does not perform authorization checks on one of its download-logging AJAX actions, and exposes the nonce protecting it to unauthenticated visitors, allowing unauthenticated users to inject arbitrary download log entries and inflate a site's download statistics.
AnalizadaAlta (7.8)0.16%—Dell Monitor Driver3/8/20267/8/2026
Dell Monitor driver, version 1.0.0.0, contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.
AplazadaCrítica (9.8)0.50%—ShopmonitorAI31/7/202626/8/2026
The ShopMonitor.io WordPress plugin before 1.2.0 does not properly restrict its email-rerouting test mode, gating it behind a trusted-source check that is satisfiable with client-supplied request headers, allowing unauthenticated attackers to redirect outgoing emails, including the WordPress administrator…
Pendiente de análisisAlta (8.3)0.42%—Linuxfabrik Monitoring-pluginsAIIcingaAINagiosAI29/7/202630/7/2026
Linuxfabrik monitoring-plugins provides Python monitoring plugins for Icinga, Nagios, and related monitoring systems. In 6.0.0 and earlier, the redfish-* plugins built request URLs by concatenating an operator-supplied base URL with response-supplied @odata.id links, allowing a malicious or compromised BMC to redirect…
Pendiente de análisisMedia (5.8)0.10%—Linuxfabrik Monitoring-pluginsAIPython Sqlite3AI29/7/202630/7/2026
Linuxfabrik monitoring-plugins provides Python monitoring plugins for Icinga, Nagios, and related monitoring systems. In version 6.0.0, the logfile check legacy database migration moved a predictable path from /tmp with os.rename() and allowed a local user controlling the plugin account to place a symlink that would…
AplazadaCrítica (9.3)0.56%—Tycon Systems Tpdin Monitor Web2AI24/7/20264/9/2026
The Tycon Systems TPDIN-Monitor-WEB2 ships without HTTP credentials configured, intended for an installer to set them on first use. On firmware 2.4.4 and earlier, a unit left in this unconfigured state serves the web management interface without requiring any login. An attacker with network access to such a unit can…
AplazadaMedia (5.3)0.19%—Tycon Systems Tpdin-monitor-web2AI24/7/20264/9/2026
The web management interface in Tycon Systems TPDIN-Monitor-WEB2 stores and displays system credentials in cleartext on a certain configuration page accessible to authenticated users. Any party with access to the administrative dashboard can immediately read these credentials, which may be used to compromise other…
AplazadaAlta (7.1)0.25%—Wpforms Download MonitorAI23/7/202623/7/2026
Unauthenticated Cross Site Scripting (XSS) in Download Monitor - WPForms Lock <= 1.0.4 versions.
Pendiente de análisisCrítica (9.6)0.84%—Centreon-open-ticketsAICentreon Infra MonitoringAI13/7/202613/7/2026
This vulnerability is a critical Server-Side Template Injection (SSTI) in Centreon's centreon-open-tickets module that leads to Remote Code Execution. The message_confirm field is stored without sanitization and rendered via Smarty with no security policy enabled, allowing any authenticated user, to inject and execute…
AplazadaMedia (6.9)0.48%—Nezha MonitoringAI10/7/202613/7/2026
Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. Prior to 2.2.5, the GET /api/v1/ddns and GET /api/v1/notification endpoints return full resource objects including plaintext third-party API credentials, including Cloudflare API tokens, TencentCloud SecretKeys, Slack,…
AplazadaBaja (2.1)0.29%—Flask-dashboard Flask-monitoringdashboardAI8/7/20268/7/2026
A vulnerability has been found in flask-dashboard Flask-MonitoringDashboard up to 5.0.2. Affected by this issue is some unknown functionality. Such manipulation leads to cross-site request forgery. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The project was…
AplazadaMedia (5.1)0.34%—Ricoh WEB Image MonitorAI30/6/202631/8/2026
Multiple laser printers and MFPs (multifunction printers) which implement Ricoh Web Image Monitor contain a reflected cross-site scripting vulnerability. An arbitrary script may be executed on the web browser of the user who accesses a crafted URL.
AnalizadaMedia (4.4)0.14%—Fortra File Integrity Monitoring23/6/202629/6/2026
Fortra File Integrity Monitoring (FIM), formerly Tripwire Enterprise, versions prior to 9.4.0 may assign incorrect or elevated effective permissions to users created by the tetool import command while FIM is running, particularly when the import also creates or changes roles or role-permission relationships.
AnalizadaMedia (4.8)0.24%—Fortra File Integrity Monitoring23/6/202628/6/2026
Fortra File Integrity Monitoring (FIM), formerly Tripwire Enterprise, versions prior to 9.4.0.1 contain a stored cross-site scripting (XSS) vulnerability in the Asset View UI component. An authenticated user with sufficient privileges to create or modify affected node or database configuration fields could store…
AplazadaAlta (8.5)0.36%—Swit WP Sessions Time Monitoring Full AutomaticAI16/6/202617/6/2026
Subscriber SQL Injection in WP Sessions Time Monitoring Full Automatic <= 1.1.4 versions.
AplazadaMedia (4.4)0.37%—Download MonitorAI15/6/202617/6/2026
Author Arbitrary File Download in Download Monitor <= 5.1.9 versions.
AplazadaMedia (6.8)0.32%—Nezha MonitoringAI12/6/202617/6/2026
Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 1.0.0 to before version 2.2.0, the getRedirectURL function in oauth2.go:22-29 constructs the OAuth2 callback URL by concatenating the request's Host header with a fixed path, with zero validation of the Host…
AplazadaMedia (6.5)0.41%—Nezha MonitoringAI12/6/202617/6/2026
Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 1.0.0 to before version 2.2.0, the Nezha dashboard exposes two endpoints that create long-lived WebSocket streams to monitored agents: POST /api/v1/terminal → createTerminal() (terminal.go:27-67) and POST…
AplazadaMedia (6.4)0.31%—Nezha MonitoringAI12/6/202617/6/2026
Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 2.0.14 to before version 2.1.0, PATCH /server/{id} accepts and persists nonexistent ddns_profiles IDs for a member-owned server. If another user later creates a DDNS profile with one of those IDs, the DDNS…
AplazadaMedia (6.5)0.40%—Nezha MonitoringAI12/6/202617/6/2026
Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 2.0.14 to before version 2.1.0, authenticated users can claim the dashboard Host through NAT and preempt all dashboard routing. This issue has been patched in version 2.1.0.
AplazadaCrítica (9.1)2.3%—Nezha MonitoringAI12/6/202617/6/2026
Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. Prior to version 2.0.13, fallbackToFrontend in the dashboard's NoRoute handler treats any URL whose raw string starts with /dashboard as an admin-frontend asset request. The check uses strings.HasPrefix, not a path-segment…
AplazadaMedia (5.3)0.34%—Nezha MonitoringAI12/6/202617/6/2026
Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 2.0.0 to before version 2.0.14, private services (`EnableShowInService: false`) are enumerable via per-server endpoints, leaking name and timing data. This issue has been patched in version 2.0.14.
AplazadaAlta (7.1)0.17%—Nezha MonitoringAI12/6/202617/6/2026
Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 1.0.0 to before version 2.0.14, cross-site GET request can trigger stored cron commands on a victim's agents. This issue has been patched in version 2.0.14.
AplazadaAlta (7.1)0.37%—Nezha MonitoringAI12/6/202617/6/2026
Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 0.20.0 to before version 2.0.12, authenticated agents can forge service-monitor results for other users' services. This issue has been patched in version 2.0.12.