Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3005▼ 85 respecto a la semana anterior
Críticas / altas1403▲ 41 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

66 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)7.2%—Paessler Prtg Network Monitor21/4/201817/6/2026
Paessler PRTG Network Monitor before 18.1.39.1648 mishandles stack memory during unspecified API calls.
ModificadaAlta (7.8)0.34%—10-strike Network Monitor12/3/201817/6/2026
Unquoted Windows search path vulnerability in the srvInventoryWebServer service in 10-Strike Network Monitor 5.4 allows local users to gain privileges via a malicious artefact.
ModificadaMedia (6.5)0.70%—Paessler Prtg Network Monitor26/10/201717/6/2026
In Paessler PRTG Network Monitor 17.3.33.2830, it's possible to create a Map as a read-only user, by forging a request and sending it to the server.
ModificadaMedia (6.7)1.4%—Paessler Prtg Network Monitor20/10/201717/6/2026
PRTG Network Monitor 17.3.33.2830 allows remote authenticated administrators to execute arbitrary code by uploading a .exe file and then proceeding in spite of the error message.
ModificadaMedia (5.4)0.53%—Paessler Prtg Network Monitor15/10/201717/6/2026
PRTG Network Monitor version 17.3.33.2830 is vulnerable to stored Cross-Site Scripting on all group names created, related to incorrect error handling for an HTML encoded script.
ModificadaMedia (6.1)0.67%—Paessler Prtg Network Monitor4/10/201717/6/2026
PRTG Network Monitor version 17.3.33.2830 is vulnerable to reflected Cross-Site Scripting on error.htm (the error page), via the errormsg parameter.
ModificadaMedia (4.8)0.53%—Paessler Prtg Network Monitor4/10/201717/6/2026
PRTG Network Monitor version 17.3.33.2830 is vulnerable to stored Cross-Site Scripting on all sensor titles, related to incorrect error handling for a %00 in the SRC attribute of an IMG element.
ModificadaMedia (5.4)1.1%—Paessler Prtg Network Monitor24/8/201717/6/2026
Cross-site scripting (XSS-STORED) vulnerability in the DEVICES OR SENSORS functionality in Paessler PRTG Network Monitor before 17.3.33.2654 allows authenticated remote attackers to inject arbitrary web script or HTML.
ModificadaMedia (6.1)0.76%—Paessler Prtg Network Monitor18/8/201717/6/2026
Cross-site scripting (XSS) vulnerability in Paessler PRTG Network Monitor before 17.2.32.2279 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (6.1)0.66%—Paessler Prtg Network Monitor10/4/201717/6/2026
Paessler PRTG before 16.2.24.4045 has XSS via SNMP.
ModificadaMedia (6.5)1.3%—Paessler Prtg Network Monitor23/1/201717/6/2026
XML external entity vulnerability in PRTG Network Monitor before 16.2.23.3077/3078 allows remote authenticated users to read arbitrary files by creating a new HTTP XML/REST Value sensor that accesses a crafted XML file.
ModificadaAlta (7.5)3.0%—Alchemy LAB Alchemy EYEDEK Software Alchemy Network Monitor21/12/200116/6/2026
Directory traversal vulnerability in HTTP server for Alchemy Eye and Alchemy Network Monitor allows remote attackers to execute arbitrary commands via an HTTP request containing (1) a .. in versions 2.0 through 2.6.18, or (2) a DOS device name followed by a .. in versions 2.6.19 through 3.0.10.
ModificadaMedia (5)2.4%—Alchemy LAB Alchemy EYEDEK Software Alchemy Network Monitor21/12/200116/6/2026
HTTP server in Alchemy Eye and Alchemy Network Monitor 1.9x through 2.6.18 is enabled without authentication by default, which allows remote attackers to obtain network monitoring logs with potentially sensitive information by directly requesting the eye.ini file.
ModificadaMedia (5)8.0%—BB4 BIG Brother Network Monitor9/1/200116/6/2026
bb-hist.sh, bb-histlog.sh, bb-hostsvc.sh, bb-rep.sh, bb-replog.sh, and bb-ack.sh in Big Brother (BB) before 1.5d3 allows remote attackers to determine the existence of files and user ID's by specifying the target file in the HISTFILE parameter.
ModificadaAlta (7.5)3.3%—BB4 BIG Brother Network Monitor19/12/200023/9/2026
bbd server in Big Brother System and Network Monitor before 1.5c2 allows remote attackers to execute arbitrary commands via the "&" shell metacharacter.
ModificadaAlta (7.5)15%—Microsoft Network Monitor19/12/200023/9/2026
Buffer overflow in the HTTP protocol parser for Microsoft Network Monitor (Netmon) allows remote attackers to execute arbitrary commands via malformed data, aka the "Netmon Protocol Parsing" vulnerability.