Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3028▼ 62 respecto a la semana anterior
Críticas / altas1422▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
358 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.5) | 0.42% | — | Fabian Project Monitoring System | 10/10/2025 | 17/6/2026 | A vulnerability was found in code-projects Project Monitoring System 1.0. The impacted element is an unknown function of the file /useredit.php. The manipulation of the argument uid results in sql injection. The attack can be executed remotely. The exploit has been made public and could be used. | |
| Analizada | Baja (2) | 0.29% | — | Fabian Project Monitoring System | 28/9/2025 | 17/6/2026 | A vulnerability has been found in code-projects Project Monitoring System 1.0. Affected is an unknown function of the file /onlineJobSearchEngine/postjob.php. Such manipulation of the argument txtapplyto leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public… | |
| Analizada | Media (5.5) | 0.48% | — | Fabian Project Monitoring System | 27/9/2025 | 17/6/2026 | A flaw has been found in code-projects Project Monitoring System 1.0. The impacted element is an unknown function of the file /login.php. This manipulation of the argument username/password causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used. | |
| Analizada | Media (5.5) | 0.42% | — | Emiloi E-logbook With Health Monitoring System FOR Covid-19 | 18/9/2025 | 17/6/2026 | A flaw has been found in itsourcecode E-Logbook with Health Monitoring System for COVID-19 1.0. This issue affects some unknown processing of the file /check_profile.php. Executing manipulation of the argument profile_id can lead to sql injection. It is possible to launch the attack remotely. The exploit has been… | |
| Analizada | Baja (2.1) | 0.35% | — | Emiloi E-logbook With Health Monitoring System FOR Covid-19 | 17/9/2025 | 25/9/2026 | A vulnerability was determined in itsourcecode E-Logbook with Health Monitoring System for COVID-19 1.0 on COVID. This affects an unknown function of the file /print_reports_prev.php. Executing manipulation of the argument profile_id can lead to cross site scripting. It is possible to launch the attack remotely. The… | |
| Analizada | Baja (2.1) | 0.36% | — | Emiloi E-logbook With Health Monitoring System FOR Covid-19 | 14/9/2025 | 17/6/2026 | A vulnerability was detected in itsourcecode E-Logbook with Health Monitoring System for COVID-19 1.0. This issue affects some unknown processing of the file /stc-log-keeper/check_profile.php of the component POST Request Handler. The manipulation of the argument profile_id results in cross site scripting. The attack… | |
| Analizada | Media (5.5) | 0.53% | — | Emiloi E-logbook With Health Monitoring System FOR Covid-19 | 9/9/2025 | 17/6/2026 | A security vulnerability has been detected in itsourcecode E-Logbook with Health Monitoring System for COVID-19 1.0. The affected element is an unknown function of the file /login.php. The manipulation of the argument Username leads to sql injection. The attack is possible to be carried out remotely. The exploit has… | |
| Aplazada | Alta (7.1) | 0.13% | — | Wordpress Error Monitoring BY BugsnagAI | 5/9/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Tom Longridge WordPress Error Monitoring by Bugsnag bugsnag allows Stored XSS.This issue affects WordPress Error Monitoring by Bugsnag: from n/a through <= 1.6.3. | |
| Aplazada | Alta (8.4) | 0.17% | — | Ratoc Systems Raid Monitoring ManagerAI | 5/9/2025 | 17/6/2026 | RATOC RAID Monitoring Manager for Windows provided by RATOC Systems, Inc. registers a Windows service with an unquoted file path. A user with the write permission on the root directory of the system drive may execute arbitrary code with SYSTEM privilege. | |
| Analizada | Media (6.9) | 0.11% | — | Oetiker BGP Monitoring | 28/8/2025 | 25/9/2026 | Improper Certificate Validation in Checkmk Exchange plugin BGP Monitoring allows attackers in MitM position to intercept traffic. | |
| Aplazada | Baja (2.1) | 0.34% | — | Acrel Environmental Monitoring Cloud PlatformAI | 18/8/2025 | 17/6/2026 | A vulnerability was identified in Acrel Environmental Monitoring Cloud Platform up to 20250804. This affects an unknown part of the file /NewsManage/UploadNewsImg. The manipulation of the argument File leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the… | |
| Analizada | Media (5.5) | 0.63% | — | Dahuatech Monitoring Platform | 9/8/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in Dinstar Monitoring Platform 甘肃省危险品库监控平台 1.0. Affected is an unknown function of the file /itc/$%7BappPath%7D/login_getPasswordErrorNum.action. The manipulation of the argument userBean.loginName leads to sql injection. It is possible to launch the attack… | |
| Aplazada | Alta (8.6) | 0.21% | — | EG4 Monitoring CenterAI | 8/8/2025 | 17/6/2026 | The affected product allows firmware updates to be downloaded from EG4's website, transferred via USB dongles, or installed through EG4's Monitoring Center (remote, cloud-connected interface) or via a serial connection, and can install these files without integrity checks. The TTComp archive format used for the… | |
| Analizada | Crítica (9.8) | 0.50% | — | IBM Tivoli Monitoring | 6/8/2025 | 17/6/2026 | IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 20 is vulnerable to a heap-based buffer overflow, caused by improper bounds checking. A remote attacker could overflow a buffer and execute arbitrary code on the system or cause the server to crash. | |
| Analizada | Crítica (9.8) | 0.50% | — | IBM Tivoli Monitoring | 6/8/2025 | 17/6/2026 | IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 20 is vulnerable to a heap-based buffer overflow, caused by improper bounds checking. A remote attacker could overflow a buffer and execute arbitrary code on the system or cause the server to crash. | |
| Aplazada | Alta (7.1) | 0.28% | — | Roche Diagnostics Navify MonitoringAI | 5/8/2025 | 17/6/2026 | Improper Input Validation vulnerability in Roche Diagnostics navify Monitoring allows an attacker to manipulate input data, which may lead to a denial of service (DoS) due to negatively impacting the server's performance. This vulnerability has no impact on data confidentiality or integrity. This issue affects navify… | |
| Analizada | Baja (2.1) | 0.45% | — | Phpgurukul BP Monitoring Management System | 25/7/2025 | 17/6/2026 | A vulnerability classified as critical was found in PHPGurukul BP Monitoring Management System 1.0. This vulnerability affects unknown code of the file /bwdates-report-result.php. The manipulation of the argument fromdate/todate leads to sql injection. The attack can be initiated remotely. The exploit has been… | |
| Aplazada | Alta (7.1) | 0.29% | — | Turpak Automatic Station Monitoring SystemAI | 21/7/2025 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Turpak Automatic Station Monitoring System allows Privilege Escalation. This issue affects Automatic Station Monitoring System: before 5.0.6.51. | |
| Aplazada | Alta (8.7) | 0.34% | — | Leviton AcquisuiteAILeviton Energy Monitoring HUBAI | 18/7/2025 | 17/6/2026 | Leviton AcquiSuite and Energy Monitoring Hub are susceptible to a cross-site scripting vulnerability, allowing an attacker to craft a malicious payload in URL parameters, which would execute in a client browser when accessed by a user, steal session tokens, and control the service. | |
| Aplazada | Crítica (9.3) | 2.6% | — | Idera Up.time Monitoring StationAI | 16/7/2025 | 17/6/2026 | An unauthenticated arbitrary file upload vulnerability exists in Idera Up.Time Monitoring Station versions up to and including 7.2. The `wizards/post2file.php` script accepts arbitrary POST parameters, allowing attackers to upload crafted PHP files to the webroot. Successful exploitation results in remote code… | |
| Analizada | Media (5.5) | 0.55% | — | Phpgurukul BP Monitoring Management System | 9/6/2025 | 17/6/2026 | A vulnerability has been found in PHPGurukul BP Monitoring Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /registration.php. The manipulation of the argument emailid leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to… | |
| Analizada | Baja (2.1) | 0.42% | — | Phpgurukul BP Monitoring Management System | 6/6/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in PHPGurukul BP Monitoring Management System 1.0. This issue affects some unknown processing of the file /edit-family-member.php. The manipulation of the argument memberage leads to sql injection. The attack may be initiated remotely. The exploit has… | |
| Analizada | Crítica (9.8) | 1.0% | — | IBM Tivoli Monitoring | 28/5/2025 | 17/6/2026 | IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 19 could allow a remote attacker to execute arbitrary code due to improper validation of an index value of a dynamically allocated array. | |
| Aplazada | Media (6.1) | 0.14% | — | ALT MonitoringAI | 17/5/2025 | 17/6/2026 | The AlT Monitoring plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.3. This is due to missing or incorrect nonce validation on the 'ALT_Monitoring_edit' page. This makes it possible for unauthenticated attackers to update settings and inject malicious web… | |
| Aplazada | Media (5.3) | 0.39% | — | Fitstats Technologies AthletemonitoringAI | 3/3/2025 | 17/6/2026 | A vulnerability classified as problematic was found in FITSTATS Technologies AthleteMonitoring up to 20250302. This vulnerability affects unknown code of the file /login.php. The manipulation of the argument username leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to… |