Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3005▼ 85 respecto a la semana anterior
Críticas / altas1403▲ 41 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
66 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 7.2% | — | Paessler Prtg Network Monitor | 21/4/2018 | 17/6/2026 | Paessler PRTG Network Monitor before 18.1.39.1648 mishandles stack memory during unspecified API calls. | |
| Modificada | Alta (7.8) | 0.34% | — | 10-strike Network Monitor | 12/3/2018 | 17/6/2026 | Unquoted Windows search path vulnerability in the srvInventoryWebServer service in 10-Strike Network Monitor 5.4 allows local users to gain privileges via a malicious artefact. | |
| Modificada | Media (6.5) | 0.70% | — | Paessler Prtg Network Monitor | 26/10/2017 | 17/6/2026 | In Paessler PRTG Network Monitor 17.3.33.2830, it's possible to create a Map as a read-only user, by forging a request and sending it to the server. | |
| Modificada | Media (6.7) | 1.4% | — | Paessler Prtg Network Monitor | 20/10/2017 | 17/6/2026 | PRTG Network Monitor 17.3.33.2830 allows remote authenticated administrators to execute arbitrary code by uploading a .exe file and then proceeding in spite of the error message. | |
| Modificada | Media (5.4) | 0.53% | — | Paessler Prtg Network Monitor | 15/10/2017 | 17/6/2026 | PRTG Network Monitor version 17.3.33.2830 is vulnerable to stored Cross-Site Scripting on all group names created, related to incorrect error handling for an HTML encoded script. | |
| Modificada | Media (6.1) | 0.67% | — | Paessler Prtg Network Monitor | 4/10/2017 | 17/6/2026 | PRTG Network Monitor version 17.3.33.2830 is vulnerable to reflected Cross-Site Scripting on error.htm (the error page), via the errormsg parameter. | |
| Modificada | Media (4.8) | 0.53% | — | Paessler Prtg Network Monitor | 4/10/2017 | 17/6/2026 | PRTG Network Monitor version 17.3.33.2830 is vulnerable to stored Cross-Site Scripting on all sensor titles, related to incorrect error handling for a %00 in the SRC attribute of an IMG element. | |
| Modificada | Media (5.4) | 1.1% | — | Paessler Prtg Network Monitor | 24/8/2017 | 17/6/2026 | Cross-site scripting (XSS-STORED) vulnerability in the DEVICES OR SENSORS functionality in Paessler PRTG Network Monitor before 17.3.33.2654 allows authenticated remote attackers to inject arbitrary web script or HTML. | |
| Modificada | Media (6.1) | 0.76% | — | Paessler Prtg Network Monitor | 18/8/2017 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Paessler PRTG Network Monitor before 17.2.32.2279 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (6.1) | 0.66% | — | Paessler Prtg Network Monitor | 10/4/2017 | 17/6/2026 | Paessler PRTG before 16.2.24.4045 has XSS via SNMP. | |
| Modificada | Media (6.5) | 1.3% | — | Paessler Prtg Network Monitor | 23/1/2017 | 17/6/2026 | XML external entity vulnerability in PRTG Network Monitor before 16.2.23.3077/3078 allows remote authenticated users to read arbitrary files by creating a new HTTP XML/REST Value sensor that accesses a crafted XML file. | |
| Modificada | Alta (7.5) | 3.0% | — | Alchemy LAB Alchemy EYEDEK Software Alchemy Network Monitor | 21/12/2001 | 16/6/2026 | Directory traversal vulnerability in HTTP server for Alchemy Eye and Alchemy Network Monitor allows remote attackers to execute arbitrary commands via an HTTP request containing (1) a .. in versions 2.0 through 2.6.18, or (2) a DOS device name followed by a .. in versions 2.6.19 through 3.0.10. | |
| Modificada | Media (5) | 2.4% | — | Alchemy LAB Alchemy EYEDEK Software Alchemy Network Monitor | 21/12/2001 | 16/6/2026 | HTTP server in Alchemy Eye and Alchemy Network Monitor 1.9x through 2.6.18 is enabled without authentication by default, which allows remote attackers to obtain network monitoring logs with potentially sensitive information by directly requesting the eye.ini file. | |
| Modificada | Media (5) | 8.0% | — | BB4 BIG Brother Network Monitor | 9/1/2001 | 16/6/2026 | bb-hist.sh, bb-histlog.sh, bb-hostsvc.sh, bb-rep.sh, bb-replog.sh, and bb-ack.sh in Big Brother (BB) before 1.5d3 allows remote attackers to determine the existence of files and user ID's by specifying the target file in the HISTFILE parameter. | |
| Modificada | Alta (7.5) | 3.3% | — | BB4 BIG Brother Network Monitor | 19/12/2000 | 23/9/2026 | bbd server in Big Brother System and Network Monitor before 1.5c2 allows remote attackers to execute arbitrary commands via the "&" shell metacharacter. | |
| Modificada | Alta (7.5) | 15% | — | Microsoft Network Monitor | 19/12/2000 | 23/9/2026 | Buffer overflow in the HTTP protocol parser for Microsoft Network Monitor (Netmon) allows remote attackers to execute arbitrary commands via malformed data, aka the "Netmon Protocol Parsing" vulnerability. |