Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2882▼ 181 respecto a la semana anterior
Críticas / altas1279▼ 60 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)487▼ 22 respecto a la semana anterior
–

967 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.4)0.25%—Nezha MonitoringAI12/6/202617/6/2026
Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 0.20.0 to before version 2.0.10, an authenticated Nezha dashboard user can create or update a DDNS profile with provider webhook and configure an arbitrary webhook_url, HTTP method, request body, and headers.…
AplazadaAlta (7.1)0.37%—Nezha MonitoringAI12/6/202617/6/2026
Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 1.4.0 to before version 2.0.8, a RoleMember can fire other users' cron tasks via AlertRule.FailTriggerTasks (no ownership check). This issue has been patched in version 2.0.8.
AplazadaAlta (7.7)0.37%—Nezha MonitoringAI12/6/202617/6/2026
Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 1.4.0 to before version 2.0.8, nezha's dashboard supports two user roles: RoleAdmin (Role==0) and RoleMember (Role==1). The notification routes POST /api/v1/notification and PATCH /api/v1/notification/:id are…
AplazadaCrítica (9.9)0.49%—Nezha MonitoringAI12/6/202617/6/2026
Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 1.4.0 to before version 2.0.8, a RoleMember user can create a scheduled cron task with Cover=CronCoverAll, Servers=[] and an arbitrary Command. At every tick of the scheduler, the dashboard pushes that command…
AplazadaCrítica (9.3)0.42%—Sysinternals Process MonitorAI9/6/202623/7/2026
A Stored Cross-Site Scripting vulnerability in Vinna Process Monitor Version 4.0 Service Pack 1 (Build 63255) allows an authenticated remote attacker with low privileges to inject malicious JavaScript code into the application. This enables attackers to steal administrative access tokens and session credentials.
AplazadaAlta (8.2)0.60%—Usagi-org Ai-goofish-monitorAI28/5/202621/7/2026
Usagi-org ai-goofish-monitor contains an unauthenticated arbitrary file read vulnerability in the GET /api/prompts/{filename} endpoint on Windows deployments that allows unauthenticated remote attackers to read arbitrary files by supplying absolute Windows paths or backslash-based traversal sequences. Attackers can…
AplazadaBaja (2.1)0.41%—Vps-inventory-monitoringAI23/5/202623/7/2026
A vulnerability was determined in 546669204 vps-inventory-monitoring up to 98c00b370668c96ae75e91c15548d9ea113652d9. This issue affects the function eval of the file app/index/command/VpsTest.php of the component VpsTest Console. Executing a manipulation of the argument vf can lead to code injection. The attack may be…
AnalizadaMedia (6.5)0.64%—Microsoft Azure Monitor Agent12/5/202617/6/2026
Untrusted search path in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.
AnalizadaAlta (7.8)0.36%—Microsoft Azure Monitor Agent12/5/202618/6/2026
External control of file name or path in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.
Pendiente de análisisMedia (6.1)0.20%—Thruk MonitoringAI8/5/202617/6/2026
In Thruk Monitoring through 2.46.3, the login field of the login form is vulnerable to reflected XSS. This vulnerability can be exploited by unauthenticated remote attackers to target users of the monitoring interface.
AnalizadaAlta (8.1)0.69%—Microsoft Azure Monitor Action Group Notification System7/5/202617/6/2026
Server-side request forgery (ssrf) in Azure Notification Service allows an authorized attacker to elevate privileges over a network.
Pendiente de análisisMedia (6.8)0.13%—Medtronic Mycarelinkpatient MonitorAI7/5/202617/6/2026
Medtronic MyCareLink Patient Monitor uses per-product credentials that are stored in a recoverable format. An attacker can use these credentials to modify encrypted drive data.
Pendiente de análisisMedia (6.8)0.16%—Medtronic Myarelink Patient MonitorAI7/5/202617/6/2026
Medtronic MyCareLink Patient Monitor has an internal serial interface, which allows an attacker with physical access to access a login prompt via a UART terminal.​
AnalizadaAlta (8.6)0.60%—Openvehicles Open Vehicle Monitoring System Firmware1/5/202617/6/2026
Buffer overflow vulnerability in Open Vehicle Monitoring System 3 (OVMS3) 3.3.005. In canformat_canswitch.cpp the parser does not properly validate a CANswitch DLC value, allowing remote attackers to cause a denial of service or possibly execute arbitrary code via crafted CANswitch frames.
AnalizadaAlta (8.8)0.70%—Openvehicles Open Vehicle Monitoring System Firmware1/5/202617/6/2026
Buffer overflow vulnerability in Open Vehicle Monitoring System 3 (OVMS3) 3.3.005. In canformat_pcap.cpp , the parser's phdr.len field is not properly validated, allowing remote attackers to cause a denial of service or possibly execute arbitrary code via crafted PCAP input.
AnalizadaCrítica (10)1.1%—Openvehicles Open Vehicle Monitoring System Firmware1/5/202617/6/2026
Buffer overflow vulnerability in Open Vehicle Monitoring System 3 (OVMS3) 3.3.005. In canformat_gvret.cpp, the length field in GVRET binary data is not properly validated, allowing remote attackers to cause a denial of service or possibly execute arbitrary code via crafted GVRET frames.
Pendiente de análisisMedia (5.1)0.38%—Ricoh WEB Image MonitorAI30/4/202631/8/2026
Open redirect vulnerability exists in Multiple laser printers and MFPs which implement Ricoh Web Image Monitor. When accessing a specially crafted URL, the user may be redirected to an arbitrary website. As a result, the user may become a victim of a phishing attack.
Pendiente de análisisMedia (5.5)0.20%—Safetica StprocessmonitorAI17/4/202617/6/2026
STProcessMonitor 11.11.4.0, part of the Safetica Application suite, allows an admin-privileged user to send crafted IOCTL requests to terminate processes that are protected through a third-party implementation. This is caused by insufficient caller validation in the driver's IOCTL handler, enabling unauthorized…
AnalizadaAlta (7.8)2.5%—Microsoft Azure Monitor Agent14/4/202617/6/2026
Deserialization of untrusted data in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.
AnalizadaAlta (7.8)0.33%—Microsoft Azure Monitor Agent14/4/202617/6/2026
Improper input validation in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.
AplazadaAlta (8.5)0.36%—Download MonitorAI8/4/202624/7/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Chill Download Monitor download-monitor allows Blind SQL Injection.This issue affects Download Monitor: from n/a through <= 5.1.8.
AplazadaMedia (5.4)0.19%—Download MonitorAI8/4/202624/7/2026
The Download Monitor plugin for WordPress is vulnerable to Cross-Site Request Forgery in the `actions_handler()` and `bulk_actions_handler()` methods in `class-dlm-downloads-path.php` in all versions up to, and including, 5.1.10. This is due to missing nonce verification on these functions. This makes it possible for…
AnalizadaCrítica (9.9)0.29%—Percona Monitoring AND Management2/4/202624/7/2026
An issue was discovered in Percona PMM before 3.7. Because an internal database user retains specific superuser privileges, an attacker with pmm-admin rights can abuse the "Add data source" feature to break out of the database context and execute shell commands on the underlying operating system.
Pendiente de análisisCrítica (9.3)0.58%—Remote Spectrum Monitor Ms27102aAI31/3/202624/7/2026
The MS27102A Remote Spectrum Monitor is vulnerable to an authentication bypass that allows unauthorized users to access and manipulate its management interface. Because the device provides no mechanism to enable or configure authentication, the issue is inherent to its design rather than a deployment error.
AplazadaAlta (7.2)0.40%—Querymonitor Query MonitorAI31/3/202624/7/2026
The Query Monitor – The developer tools panel for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘$_SERVER['REQUEST_URI']’ parameter in all versions up to, and including, 3.20.3 due to insufficient input sanitization and output escaping. This makes it possible for…