Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
1029 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.8) | 0.32% | — | Performance MonitorAI | 31/3/2026 | 17/6/2026 | The Performance Monitor WordPress plugin through 1.0.6 does not validate a parameter before making a request to it, which could allow unauthenticated users to perform SSRF attacks | |
| Analizada | Media (6.9) | 0.16% | — | Hhdsoftware Device Monitoring Studio | 30/3/2026 | 17/6/2026 | Device Monitoring Studio 8.10.00.8925 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string to the server connection dialog. Attackers can trigger the crash by entering a malformed server name or address containing repeated characters… | |
| Aplazada | Alta (7.5) | 0.36% | — | Ironistic Download MonitorAI | 30/3/2026 | 17/6/2026 | The Download Monitor plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.1.7 via the executePayment() function due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to complete arbitrary pending orders by… | |
| Aplazada | Alta (8.5) | 0.15% | — | Ratoc Raid Monitoring ManagerAI | 26/3/2026 | 17/6/2026 | The installer of RATOC RAID Monitoring Manager for Windows allows to customize the installation folder. If the installation folder is customized to some non-default one, the folder may be left with un-secure ACLs and non-administrative users can alter contents of that folder. It may allow a non-administrative user to… | |
| Aplazada | Alta (8.4) | 0.18% | — | Ratoc Raid Monitoring ManagerAI | 26/3/2026 | 17/6/2026 | The installer of RATOC RAID Monitoring Manager for Windows searches the current directory to load certain DLLs. If a user is directed to place a crafted DLL with the installer, an arbitrary code may be executed with the administrator privilege. | |
| Aplazada | Media (5.5) | 0.47% | — | Acrel Environmental Monitoring Cloud PlatformAI | 22/3/2026 | 17/6/2026 | A vulnerability was found in Acrel Environmental Monitoring Cloud Platform 1.1.0. This issue affects some unknown processing. Performing a manipulation results in unrestricted upload. The attack may be initiated remotely. The exploit has been made public and could be used. The vendor was contacted early about this… | |
| Aplazada | Alta (7.2) | 0.37% | — | Performance MonitorAI | 21/3/2026 | 17/6/2026 | The Performance Monitor plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.0.6. This is due to insufficient validation of the 'url' parameter in the '/wp-json/performance-monitor/v1/curl_data' REST API endpoint. This makes it possible for unauthenticated attackers… | |
| Analizada | Alta (8.8) | 0.71% | — | Ctfer Monitoring | 20/3/2026 | 17/6/2026 | The CTFer.io Monitoring component is in charge of the collection, process and storage of various signals (i.e. logs, metrics and distributed traces). In versions prior to 0.2.2, the sanitizeArchivePath function in pkg/extract/extract.go (lines 248–254) is vulnerable to Path Traversal due to a missing trailing path… | |
| Aplazada | Alta (7.1) | 0.41% | — | Ctfer.io MonitoringAI | 16/3/2026 | 17/6/2026 | The CTFer.io Monitoring component is in charge of the collection, process and storage of various signals (i.e. logs, metrics and distributed traces). Prior to 0.2.1, due to a mis-written NetworkPolicy, a malicious actor can pivot from a component to any other namespace. This breaks the security-by-default property… | |
| Aplazada | Media (5.3) | 0.26% | — | Studio99 WP MonitorAI | 13/3/2026 | 17/6/2026 | Missing Authorization vulnerability in Studio99 Studio99 WP Monitor studio99-wp-monitor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Studio99 WP Monitor: from n/a through <= 1.0.3. | |
| Aplazada | Media (5.3) | 0.29% | — | Swit WP Sessions Time Monitoring Full AutomaticAI | 13/3/2026 | 17/6/2026 | Missing Authorization vulnerability in activity-log.com WP Sessions Time Monitoring Full Automatic activitytime allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Sessions Time Monitoring Full Automatic: from n/a through <= 1.1.3. | |
| Analizada | Media (5.3) | 0.28% | — | Siemens Sinec Security Monitor | 10/3/2026 | 17/6/2026 | A vulnerability has been identified in SINEC Security Monitor (All versions < V4.9.0). The affected application leaks confidential information in metadata, and files such as information on contributors and email address, on `SSM Server`. | |
| Analizada | Alta (8.5) | 0.19% | — | Schneider-electric Ecostruxure Power Monitoring ExpertSchneider-electric Ecostruxure Power Operation | 10/3/2026 | 24/6/2026 | CWE‑502: Deserialization of Untrusted Data vulnerability exists that could cause arbitrary code execution with administrative privileges when a locally authenticated attacker sends a crafted data stream, triggering unsafe deserialization. | |
| Aplazada | Media (6.4) | 0.20% | — | Simple Download MonitorAI | 27/2/2026 | 17/6/2026 | The Simple Download Monitor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom field in all versions up to, and including, 4.0.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject… | |
| Analizada | Media (5.5) | 0.59% | — | Emiloi E-logbook With Health Monitoring System FOR Covid-19 | 24/2/2026 | 17/6/2026 | A security vulnerability has been detected in itsourcecode E-Logbook with Health Monitoring System for COVID-19 1.0. This vulnerability affects unknown code of the file /check_profile_old.php. The manipulation of the argument profile_id leads to sql injection. Remote exploitation of the attack is possible. The exploit… | |
| Aplazada | Media (5.5) | 0.44% | — | Huace Monitoring AND Early Warning SystemAI | 17/2/2026 | 17/6/2026 | A weakness has been identified in Huace Monitoring and Early Warning System 2.2. Affected by this issue is some unknown functionality of the file /Web/SysManage/ProjectRole.aspx. Executing a manipulation of the argument ID can lead to sql injection. It is possible to launch the attack remotely. The exploit has been… | |
| Aplazada | Media (5.1) | 0.23% | — | Ricoh WEB Image MonitorAI | 12/2/2026 | 17/6/2026 | RICOH Web Image Monitor 1.09 contains an HTML injection vulnerability in the address configuration CGI script that allows attackers to inject malicious HTML code. Attackers can exploit the entryNameIn and entryDisplayNameIn parameters to insert arbitrary HTML content, potentially enabling cross-site scripting attacks. | |
| Aplazada | Media (5.1) | 0.23% | — | Heatmiser NetmonitorAI | 12/2/2026 | 17/6/2026 | Heatmiser Netmonitor v3.03 contains an HTML injection vulnerability in the outputSetup.htm page that allows attackers to inject malicious HTML code through the outputtitle parameter. Attackers can craft specially formatted POST requests to the outputtitle parameter to execute arbitrary HTML and potentially manipulate… | |
| Aplazada | Crítica (9.3) | 0.29% | — | Heatmiser NetmonitorAI | 12/2/2026 | 17/6/2026 | Heatmiser Netmonitor 3.03 contains a hardcoded credentials vulnerability in the networkSetup.htm page with predictable admin login credentials. Attackers can access the device by using the hard-coded username 'admin' and password 'admin' in the hidden form input fields. | |
| Analizada | Media (4.6) | 0.47% | — | Nsasoft Nbmonitor | 11/2/2026 | 29/6/2026 | NBMonitor 1.6.6.0 contains a denial of service vulnerability in its registration key input that allows attackers to crash the application. Attackers can generate a 1000-character buffer payload and paste it into the 'Key' field to trigger an application crash. | |
| Aplazada | Alta (8.5) | 0.18% | — | Alps HID Monitor ServiceAI | 6/2/2026 | 17/6/2026 | Alps HID Monitor Service 8.1.0.10 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code with elevated privileges. Attackers can exploit the unquoted path in C:\Program Files\Apoint2K\HidMonitorSvc.exe to inject malicious executables and gain system-level… | |
| Aplazada | Alta (7.1) | 0.80% | — | 10-strike Bandwidth MonitorAI | 30/1/2026 | 17/6/2026 | 10-Strike Bandwidth Monitor 3.9 contains a buffer overflow vulnerability that allows attackers to bypass SafeSEH, ASLR, and DEP protections through carefully crafted input. Attackers can exploit the vulnerability by sending a malicious payload to the application's registration key input, enabling remote code execution… | |
| Aplazada | Alta (8.5) | 0.13% | — | 10-strike Bandwidth MonitorAI | 29/1/2026 | 17/6/2026 | 10-Strike Bandwidth Monitor 3.9 contains an unquoted service path vulnerability in multiple services that allows local attackers to escalate privileges. Attackers can place a malicious executable in specific file path locations to achieve privilege escalation to SYSTEM during service startup. | |
| Analizada | Alta (8.7) | 0.49% | — | Tildeslash M/monit | 28/1/2026 | 17/6/2026 | M/Monit 3.7.4 contains a privilege escalation vulnerability that allows authenticated users to modify user permissions by manipulating the admin parameter. Attackers can send a POST request to the /api/1/admin/users/update endpoint with a crafted payload to grant administrative access to a standard user account. | |
| Analizada | Alta (7.1) | 0.49% | — | Tildeslash M/monit | 28/1/2026 | 17/6/2026 | M/Monit 3.7.4 contains an authentication vulnerability that allows authenticated attackers to retrieve user password hashes through an administrative API endpoint. Attackers can send requests to the /api/1/admin/users/list and /api/1/admin/users/get endpoints to extract MD5 password hashes for all users. |