Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2619▼ 461 respecto a la semana anterior
Críticas / altas1277▼ 72 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)235▼ 274 respecto a la semana anterior
–

66 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.4)50%—OpensslDebian LinuxNetapp Clustered Data OntapNetapp Clustered Data Ontap Antivirus Connector+2824/8/202117/6/2026
ASN.1 strings are represented internally within OpenSSL as an ASN1_STRING structure which contains a buffer holding the string data and a field holding the buffer length. This contrasts with normal C strings which are repesented as a buffer for the string data which is terminated with a NUL (0) byte. Although not a…
ModificadaCrítica (9.8)88%—OpensslDebian LinuxNetapp Active IQ Unified ManagerNetapp Clustered Data Ontap+2724/8/202117/6/2026
In order to decrypt SM2 encrypted data an application is expected to call the API function EVP_PKEY_decrypt(). Typically an application will call this function twice. The first time, on entry, the "out" parameter can be NULL and, on exit, the "outlen" parameter is populated with the buffer size required to hold the…
ModificadaMedia (4.3)0.45%—Paessler Prtg Network Monitor10/6/202117/6/2026
PRTG Network Monitor 20.1.55.1775 allows /editsettings CSRF for user account creation.
ModificadaMedia (5.3)1.8%—Paessler Prtg Network Monitor31/3/202117/6/2026
An issue was discovered in PRTG Network Monitor before 21.1.66.1623. By invoking the screenshot functionality with prepared context paths, an attacker is able to verify the existence of certain files on the filesystem of the PRTG's Web server.
ModificadaAlta (7.4)18%—OpensslFreebsdNetapp Santricity Smi-s Provider FirmwareNetapp Storagegrid Firmware+2925/3/202117/6/2026
The X509_V_FLAG_X509_STRICT flag enables additional security checks of the certificates present in a certificate chain. It is not set by default. Starting from OpenSSL version 1.1.1h a check to disallow certificates in the chain that have explicitly encoded elliptic curve parameters was added as an additional strict…
ModificadaMedia (5.9)64%—OpensslDebian LinuxFreebsdNetapp Active IQ Unified Manager+10225/3/202117/6/2026
An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension (where it was present in the initial ClientHello), but includes a signature_algorithms_cert extension then a NULL pointer…
ModificadaMedia (5.9)7.4%—OpensslDebian LinuxTenable Nessus Network MonitorTenable.sc+1916/2/202117/6/2026
The OpenSSL public API function X509_issuer_and_serial_hash() attempts to create a unique hash value based on the issuer and serial number data contained within an X509 certificate. However it fails to correctly handle any errors that may occur while parsing the issuer field (which might occur if the issuer field is…
ModificadaAlta (7.5)51%—OpensslDebian LinuxTenable LOG Correlation EngineTenable Nessus Network Monitor+1716/2/202117/6/2026
Calls to EVP_CipherUpdate, EVP_EncryptUpdate and EVP_DecryptUpdate may overflow the output length argument in some cases where the input length is close to the maximum permissable length for an integer on the platform. In such cases the return value from the function call will be 1 (indicating success), but the output…
ModificadaMedia (5.9)7.1%—OpensslDebian LinuxFedoraproject FedoraOracle API Gateway+408/12/202017/6/2026
The X.509 GeneralName type is a generic type for representing different types of names. One of those name types is known as EDIPartyName. OpenSSL provides a function GENERAL_NAME_cmp which compares different instances of a GENERAL_NAME to see if they are equal or not. This function behaves incorrectly when both…
ModificadaAlta (7.8)0.37%—Tenable Nessus Network Monitor6/11/202017/6/2026
A vulnerability in Nessus Network Monitor versions 5.11.0, 5.11.1, and 5.12.0 for Windows could allow an authenticated local attacker to execute arbitrary code by copying user-supplied files to a specially constructed path in a specifically named user directory. The attacker needs valid credentials on the Windows…
ModificadaMedia (5.4)2.9%—Paessler Prtg Network Monitor23/6/202017/6/2026
XSS exists in PRTG Network Monitor 20.1.56.1574 via crafted map properties. An attacker with Read/Write privileges can create a map, and then use the Map Designer Properties screen to insert JavaScript code. This can be exploited against any user with View Maps or Edit Maps access.
ModificadaMedia (5.3)52%—Paessler Prtg Network Monitor5/4/202017/6/2026
PRTG Network Monitor before 20.1.57.1745 allows remote unauthenticated attackers to obtain information about probes running or the server itself (CPU usage, memory, Windows version, and internal statistics) via an HTTP request, as demonstrated by type=probes to login.htm or index.htm.
ModificadaCrítica (9.8)4.7%—Paessler Prtg Network Monitor30/3/202017/6/2026
A webserver component in Paessler PRTG Network Monitor 19.2.50 to PRTG 20.1.56 allows unauthenticated remote command execution via a crafted POST request or the what parameter of the screenshot function in the Contact Support form.
ModificadaAlta (7.2)4.5%—Paessler Prtg Network Monitor17/3/202017/6/2026
A Write to Arbitrary Location in Disk vulnerability exists in PRTG Network Monitor 19.1.49 and below that allows attackers to place files in arbitrary locations with SYSTEM privileges (although not controlling the contents of such files) due to insufficient sanitisation when passing arguments to the phantomjs.exe…
ModificadaAlta (7.2)6.3%—Paessler Prtg Network Monitor16/3/202017/6/2026
A Remote Code Execution vulnerability exists in PRTG Network Monitor before 19.4.54.1506 that allows attackers to execute code due to insufficient sanitization when passing arguments to the HttpTransactionSensor.exe binary. In order to exploit the vulnerability, remote authenticated administrators need to create a new…
ModificadaMedia (5.5)0.27%—Paessler Prtg Network Monitor3/2/202017/6/2026
An issue was discovered in PRTG 7.x through 19.4.53. Due to insufficient access control on local registry keys for the Core Server Service, a non-administrative user on the local machine is able to access administrative credentials.
ModificadaCrítica (9.8)4.4%—Akips Network Monitor6/1/202017/6/2026
The application login page in AKIPS Network Monitor 15.37 through 16.5 allows a remote unauthenticated attacker to execute arbitrary OS commands via shell metacharacters in the username parameter (a failed login attempt returns the command-injection output to a limited login failure field). This is fixed in 16.6.
ModificadaMedia (6.1)1.2%—Paessler Prtg Network Monitor31/12/201917/6/2026
PRTG Network Monitor v7.1.3.3378 allows XSS via the /search.htm searchtext parameter. NOTE: This product is discontinued.
ModificadaMedia (6.1)1.2%—Paessler Prtg Network Monitor31/12/201917/6/2026
PRTG Network Monitor v7.1.3.3378 allows XSS via the /public/login.htm errormsg or loginurl parameter. NOTE: This product is discontinued.
ModificadaMedia (6.1)0.65%—Paessler Prtg Network Monitor10/4/201917/6/2026
PRTG before 19.1.49.1966 has Cross Site Scripting (XSS) in the WEBGUI.
ModificadaAlta (8.8)0.87%—Paessler Prtg Network Monitor21/11/201817/6/2026
PRTG Network Monitor before 18.2.40.1683 allows an authenticated user with a read-only account to create another user with a read-write account (including administrator) via an HTTP request because /api/addusers doesn't check, or doesn't properly check, user rights.
AnalizadaCrítica (9.8)98%⚠ Explotación activaPaessler Prtg Network Monitor21/11/201817/6/2026
PRTG Network Monitor before 18.2.40.1683 allows remote unauthenticated attackers to create users with read-write privileges (including administrator). A remote unauthenticated user can craft an HTTP request and override attributes of the 'include' directive in /public/login.htm and perform a Local File Inclusion…
ModificadaAlta (8.8)4.6%—Paessler Prtg Network Monitor12/11/201817/6/2026
PRTG Network Monitor before 18.3.44.2054 allows a remote authenticated attacker (with read-write privileges) to execute arbitrary code and OS commands with system privileges. When creating an HTTP Advanced Sensor, the user's input in the POST parameter 'proxyport_' is mishandled. The attacker can craft an HTTP request…
ModificadaAlta (7.5)2.8%—Paessler Prtg Network Monitor12/11/201817/6/2026
PRTG Network Monitor before 18.2.41.1652 allows remote unauthenticated attackers to terminate the PRTG Core Server Service via a special HTTP request.
AnalizadaAlta (7.2)87%⚠ Explotación activaPaessler Prtg Network Monitor2/7/201817/6/2026
An issue was discovered in PRTG Network Monitor before 18.2.39. An attacker who has access to the PRTG System Administrator web console with administrative privileges can exploit an OS command injection vulnerability (both on the server and on devices) by sending malformed parameters in sensor or notification…