Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
358 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (10) | 0.51% | — | BSS Software Mobuy Online Machinery Monitoring PanelAI | 14/2/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in BSS Software Mobuy Online Machinery Monitoring Panel allows SQL Injection. This issue affects Mobuy Online Machinery Monitoring Panel: before 2.0. | |
| Aplazada | Alta (7.1) | 0.26% | — | Swit WP Sessions Time Monitoring Full AutomaticAI | 31/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in activity-log.com WP Sessions Time Monitoring Full Automatic activitytime allows Reflected XSS.This issue affects WP Sessions Time Monitoring Full Automatic: from n/a through <= 1.1.1. | |
| Analizada | Media (6.1) | 0.38% | — | Syedfakharabbas Backlink Monitoring Manager | 9/1/2025 | 17/6/2026 | The Backlink Monitoring Manager WordPress plugin through 0.1.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin. | |
| Aplazada | Media (6.1) | 0.36% | — | Pingmeter Uptime MonitoringAI | 21/12/2024 | 17/6/2026 | The Pingmeter Uptime Monitoring plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the '_wpnonce' parameter in all versions up to, and including, 1.0.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts… | |
| Aplazada | Crítica (9.8) | 23% | 💥 Exploit | WP Umbrella Update Backup Restore AND MonitoringAI | 8/12/2024 | 17/6/2026 | The WP Umbrella: Update Backup Restore & Monitoring plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.17.0 via the 'filename' parameter of the 'umbrella-restore' action. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the… | |
| Analizada | Alta (7.3) | 0.24% | — | AMD Ryzen Master Monitoring Software Development KIT | 12/11/2024 | 17/6/2026 | Incorrect default permissions in the AMD RyzenTM Master monitoring SDK installation directory could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution. | |
| Aplazada | Crítica (9.3) | 1.1% | 💥 PoC | Swit WP Sessions Time Monitoring Full AutomaticAI | 24/10/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in activity-log.com WP Sessions Time Monitoring Full Automatic activitytime allows SQL Injection.This issue affects WP Sessions Time Monitoring Full Automatic: from n/a through <= 1.0.9. | |
| Aplazada | Crítica (9.3) | 0.59% | — | Omntec Proteus Tank Monitoring Oel8000iii SeriesAI | 27/9/2024 | 17/6/2026 | OMNTEC Proteus Tank Monitoring OEL8000III Series could allow an attacker to perform administrative actions without proper authentication. | |
| Analizada | Alta (8.8) | 0.84% | — | IBM Cloud PAK FOR Multicloud Management Monitoring | 26/9/2024 | 17/6/2026 | IBM ManageIQ could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted yaml file request. | |
| Analizada | Media (4.9) | 0.34% | — | IBM Cloud PAK FOR Multicloud Management Monitoring | 26/9/2024 | 17/6/2026 | IBM Cloud Pak for Multicloud Management 2.3 through 2.3 FP8 stores user credentials in a log file plain clear text which can be read by a privileged user. | |
| Modificada | Media (6.5) | 0.27% | — | Eaton Foreseer Electrical Power Monitoring System | 13/9/2024 | 17/6/2026 | The Eaton Foreseer software provides multiple customizable input fields for the users to configure parameters in the tool like alarms, reports, etc. Some of these input fields were not checking the length and bounds of the entered value. The exploit of this security flaw by a bad actor may result in excessive memory… | |
| Modificada | Alta (8.1) | 0.12% | — | Eaton Foreseer Electrical Power Monitoring System | 13/9/2024 | 17/6/2026 | The Eaton Foreseer software provides the feasibility for the user to configure external servers for multiple purposes such as network management, user management, etc. The software uses encryption to store these configurations securely on the host machine. However, the keys used for this encryption were insecurely… | |
| Analizada | Media (6.1) | 0.29% | — | Eaton Foreseer Electrical Power Monitoring System | 13/9/2024 | 17/6/2026 | The Eaton Foreseer software provides users the capability to customize the dashboard in WebView pages. However, the input fields for this feature in the Eaton Foreseer software lacked proper input sanitization on the server-side, which could lead to injection and execution of malicious scripts when abused by bad… | |
| Aplazada | Media (5.3) | 0.39% | — | Shandong Star Measurement AND Control Equipment Heating Network Wireless Monitoring SystemAI | 11/9/2024 | 17/6/2026 | A vulnerability was found in Shandong Star Measurement and Control Equipment Heating Network Wireless Monitoring System 5.6.2 and classified as critical. Affected by this issue is the function GetDataKindByType of the file /DataSrvs/UCCGSrv.asmx. The manipulation leads to sql injection. The attack may be launched… | |
| Analizada | Media (5.3) | 0.42% | — | Rems Daily Calories Monitoring Tool | 25/8/2024 | 17/6/2026 | A vulnerability was found in SourceCodester Daily Calories Monitoring Tool 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /endpoint/delete-calorie.php. The manipulation of the argument calorie leads to cross site scripting. The attack can be initiated remotely. The… | |
| Analizada | Media (5.3) | 0.41% | — | Rems Daily Calories Monitoring Tool | 25/8/2024 | 17/6/2026 | A vulnerability was found in SourceCodester Daily Calories Monitoring Tool 1.0. It has been classified as problematic. This affects an unknown part of the file /endpoint/add-calorie.php. The manipulation of the argument calorie_date/calorie_name leads to cross site scripting. It is possible to initiate the attack… | |
| Analizada | Alta (8.8) | 7.0% | — | Zohocorp Manageengine OpmanagerZohocorp Manageengine Opmanager MSPZohocorp Manageengine Opmanager PlusZohocorp Manageengine Remote Monitoring AND Management Central | 23/8/2024 | 17/6/2026 | Zohocorp ManageEngine OpManager and Remote Monitoring and Management versions 128329 and below are vulnerable to the authenticated remote code execution in the deploy agent option. | |
| Analizada | Media (5.3) | 0.61% | — | Project Expense Monitoring System Project Project Expense Monitoring System | 20/8/2024 | 17/6/2026 | A vulnerability classified as critical was found in itsourcecode Project Expense Monitoring System 1.0. This vulnerability affects unknown code of the file printtransfer.php. The manipulation of the argument transfer_id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the… | |
| Analizada | Media (5.3) | 0.61% | — | Project Expense Monitoring System Project Project Expense Monitoring System | 20/8/2024 | 17/6/2026 | A vulnerability classified as critical has been found in itsourcecode Project Expense Monitoring System 1.0. This affects an unknown part of the file transferred_report.php. The manipulation of the argument start/end/employee leads to sql injection. It is possible to initiate the attack remotely. The exploit has been… | |
| Analizada | Media (5.3) | 0.48% | — | Project Expense Monitoring System Project Project Expense Monitoring System | 19/8/2024 | 17/6/2026 | A vulnerability was found in itsourcecode Project Expense Monitoring System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file print.php. The manipulation of the argument map_id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed… | |
| Analizada | Media (5.3) | 0.48% | — | Project Expense Monitoring System Project Project Expense Monitoring System | 19/8/2024 | 17/6/2026 | A vulnerability was found in itsourcecode Project Expense Monitoring System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file execute.php. The manipulation of the argument code leads to sql injection. The attack can be launched remotely. The exploit has been… | |
| Analizada | Media (6.9) | 0.58% | — | Project Expense Monitoring System Project Project Expense Monitoring System | 19/8/2024 | 17/6/2026 | A vulnerability was found in itsourcecode Project Expense Monitoring System 1.0. It has been classified as critical. Affected is an unknown function of the file login1.php of the component Backend Login. The manipulation of the argument user leads to sql injection. It is possible to launch the attack remotely. The… | |
| Analizada | Media (5.3) | 0.61% | — | Rems Daily Expenses Monitoring APP | 15/8/2024 | 17/6/2026 | A vulnerability classified as critical has been found in SourceCodester Daily Expenses Monitoring App 1.0. This affects an unknown part of the file /endpoint/delete-expense.php. The manipulation of the argument expense leads to sql injection. It is possible to initiate the attack remotely. The exploit has been… | |
| Analizada | Crítica (9.8) | 0.66% | — | Rems Daily Calories Monitoring Tool | 12/8/2024 | 17/6/2026 | Sourcecodester Daily Calories Monitoring Tool v1.0 is vulnerable to SQL Injection via "delete-calorie.php." | |
| Analizada | Media (6.1) | 0.31% | — | Janobe School Attendence Monitoring SystemJanobe School Event Management System | 6/8/2024 | 17/6/2026 | Cross-Site Scripting (XSS) vulnerability in School Attendance Monitoring System and School Event Management System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain details of their session cookie via the 'Attendance', 'attenddate' and 'YearLevel' parameters in… |