Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3017▼ 66 respecto a la semana anterior
Críticas / altas1412▲ 56 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)381▼ 129 respecto a la semana anterior
358 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.37% | — | Nezha MonitoringAI | 12/6/2026 | 17/6/2026 | Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 1.4.0 to before version 2.0.8, a RoleMember can fire other users' cron tasks via AlertRule.FailTriggerTasks (no ownership check). This issue has been patched in version 2.0.8. | |
| Aplazada | Alta (7.7) | 0.37% | — | Nezha MonitoringAI | 12/6/2026 | 17/6/2026 | Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 1.4.0 to before version 2.0.8, nezha's dashboard supports two user roles: RoleAdmin (Role==0) and RoleMember (Role==1). The notification routes POST /api/v1/notification and PATCH /api/v1/notification/:id are… | |
| Aplazada | Crítica (9.9) | 0.49% | — | Nezha MonitoringAI | 12/6/2026 | 17/6/2026 | Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 1.4.0 to before version 2.0.8, a RoleMember user can create a scheduled cron task with Cover=CronCoverAll, Servers=[] and an arbitrary Command. At every tick of the scheduler, the dashboard pushes that command… | |
| Aplazada | Baja (2.1) | 0.41% | — | Vps-inventory-monitoringAI | 23/5/2026 | 23/7/2026 | A vulnerability was determined in 546669204 vps-inventory-monitoring up to 98c00b370668c96ae75e91c15548d9ea113652d9. This issue affects the function eval of the file app/index/command/VpsTest.php of the component VpsTest Console. Executing a manipulation of the argument vf can lead to code injection. The attack may be… | |
| Pendiente de análisis | Media (6.1) | 0.20% | — | Thruk MonitoringAI | 8/5/2026 | 17/6/2026 | In Thruk Monitoring through 2.46.3, the login field of the login form is vulnerable to reflected XSS. This vulnerability can be exploited by unauthenticated remote attackers to target users of the monitoring interface. | |
| Analizada | Alta (8.6) | 0.60% | — | Openvehicles Open Vehicle Monitoring System Firmware | 1/5/2026 | 17/6/2026 | Buffer overflow vulnerability in Open Vehicle Monitoring System 3 (OVMS3) 3.3.005. In canformat_canswitch.cpp the parser does not properly validate a CANswitch DLC value, allowing remote attackers to cause a denial of service or possibly execute arbitrary code via crafted CANswitch frames. | |
| Analizada | Alta (8.8) | 0.70% | — | Openvehicles Open Vehicle Monitoring System Firmware | 1/5/2026 | 17/6/2026 | Buffer overflow vulnerability in Open Vehicle Monitoring System 3 (OVMS3) 3.3.005. In canformat_pcap.cpp , the parser's phdr.len field is not properly validated, allowing remote attackers to cause a denial of service or possibly execute arbitrary code via crafted PCAP input. | |
| Analizada | Crítica (10) | 1.1% | — | Openvehicles Open Vehicle Monitoring System Firmware | 1/5/2026 | 17/6/2026 | Buffer overflow vulnerability in Open Vehicle Monitoring System 3 (OVMS3) 3.3.005. In canformat_gvret.cpp, the length field in GVRET binary data is not properly validated, allowing remote attackers to cause a denial of service or possibly execute arbitrary code via crafted GVRET frames. | |
| Analizada | Crítica (9.9) | 0.29% | — | Percona Monitoring AND Management | 2/4/2026 | 24/7/2026 | An issue was discovered in Percona PMM before 3.7. Because an internal database user retains specific superuser privileges, an attacker with pmm-admin rights can abuse the "Add data source" feature to break out of the database context and execute shell commands on the underlying operating system. | |
| Analizada | Media (6.9) | 0.16% | — | Hhdsoftware Device Monitoring Studio | 30/3/2026 | 17/6/2026 | Device Monitoring Studio 8.10.00.8925 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string to the server connection dialog. Attackers can trigger the crash by entering a malformed server name or address containing repeated characters… | |
| Aplazada | Alta (8.5) | 0.15% | — | Ratoc Raid Monitoring ManagerAI | 26/3/2026 | 17/6/2026 | The installer of RATOC RAID Monitoring Manager for Windows allows to customize the installation folder. If the installation folder is customized to some non-default one, the folder may be left with un-secure ACLs and non-administrative users can alter contents of that folder. It may allow a non-administrative user to… | |
| Aplazada | Alta (8.4) | 0.18% | — | Ratoc Raid Monitoring ManagerAI | 26/3/2026 | 17/6/2026 | The installer of RATOC RAID Monitoring Manager for Windows searches the current directory to load certain DLLs. If a user is directed to place a crafted DLL with the installer, an arbitrary code may be executed with the administrator privilege. | |
| Aplazada | Media (5.5) | 0.47% | — | Acrel Environmental Monitoring Cloud PlatformAI | 22/3/2026 | 17/6/2026 | A vulnerability was found in Acrel Environmental Monitoring Cloud Platform 1.1.0. This issue affects some unknown processing. Performing a manipulation results in unrestricted upload. The attack may be initiated remotely. The exploit has been made public and could be used. The vendor was contacted early about this… | |
| Analizada | Alta (8.8) | 0.71% | — | Ctfer Monitoring | 20/3/2026 | 17/6/2026 | The CTFer.io Monitoring component is in charge of the collection, process and storage of various signals (i.e. logs, metrics and distributed traces). In versions prior to 0.2.2, the sanitizeArchivePath function in pkg/extract/extract.go (lines 248–254) is vulnerable to Path Traversal due to a missing trailing path… | |
| Aplazada | Alta (7.1) | 0.41% | — | Ctfer.io MonitoringAI | 16/3/2026 | 17/6/2026 | The CTFer.io Monitoring component is in charge of the collection, process and storage of various signals (i.e. logs, metrics and distributed traces). Prior to 0.2.1, due to a mis-written NetworkPolicy, a malicious actor can pivot from a component to any other namespace. This breaks the security-by-default property… | |
| Aplazada | Media (5.3) | 0.29% | — | Swit WP Sessions Time Monitoring Full AutomaticAI | 13/3/2026 | 17/6/2026 | Missing Authorization vulnerability in activity-log.com WP Sessions Time Monitoring Full Automatic activitytime allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Sessions Time Monitoring Full Automatic: from n/a through <= 1.1.3. | |
| Analizada | Alta (8.5) | 0.19% | — | Schneider-electric Ecostruxure Power Monitoring ExpertSchneider-electric Ecostruxure Power Operation | 10/3/2026 | 24/6/2026 | CWE‑502: Deserialization of Untrusted Data vulnerability exists that could cause arbitrary code execution with administrative privileges when a locally authenticated attacker sends a crafted data stream, triggering unsafe deserialization. | |
| Analizada | Media (5.5) | 0.59% | — | Emiloi E-logbook With Health Monitoring System FOR Covid-19 | 24/2/2026 | 17/6/2026 | A security vulnerability has been detected in itsourcecode E-Logbook with Health Monitoring System for COVID-19 1.0. This vulnerability affects unknown code of the file /check_profile_old.php. The manipulation of the argument profile_id leads to sql injection. Remote exploitation of the attack is possible. The exploit… | |
| Aplazada | Media (5.5) | 0.44% | — | Huace Monitoring AND Early Warning SystemAI | 17/2/2026 | 17/6/2026 | A weakness has been identified in Huace Monitoring and Early Warning System 2.2. Affected by this issue is some unknown functionality of the file /Web/SysManage/ProjectRole.aspx. Executing a manipulation of the argument ID can lead to sql injection. It is possible to launch the attack remotely. The exploit has been… | |
| Analizada | Alta (7.5) | 0.40% | — | Dwyeromega Isensix Advanced Remote Monitoring System Firmware | 6/1/2026 | 17/6/2026 | DwyerOmega Isensix Advanced Remote Monitoring System (ARMS) 1.5.7 allows an attacker to retrieve sensitive information from the underlying SQL database via Blind SQL Injection through the user parameter in the login page. This allows an attacker to steal credentials, which may be cleartext, from existing users (and… | |
| Analizada | Media (4.8) | 0.17% | — | Solaredge Monitoring Platform | 12/12/2025 | 17/6/2026 | SolarEdge monitoring platform contains a Cross‑Site Scripting (XSS) flaw that allows an authenticated user to inject payloads into report names, which may execute in a victim’s browser during a deletion attempt. | |
| Analizada | Crítica (9.8) | 0.42% | — | IBM Tivoli Monitoring | 30/10/2025 | 17/6/2026 | IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 21 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view, overwrite, or append to arbitrary files on the system. | |
| Analizada | Alta (7.5) | 0.53% | — | IBM Tivoli Monitoring | 30/10/2025 | 17/6/2026 | IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 21 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. | |
| Aplazada | Alta (8.4) | 0.43% | — | Centreon Infra MonitoringAI | 27/10/2025 | 17/6/2026 | Incorrect Default Permissions vulnerability in Centreon Infra Monitoring (MBI modules) allows Embedding Scripts within Scripts by CentreonBI user account on the MBI server This issue affects Infra Monitoring: from 24.10.0 before 24.10.6, from 24.04.0 before 24.04.9, from 23.10.0 before 23.10.15. | |
| Aplazada | Crítica (9.8) | 0.29% | — | TM2 MonitoringAI | 22/10/2025 | 5/7/2026 | TM2 Monitoring v3.04 contains an authentication bypass and plaintext credential disclosure. |