Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
–

143 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.5)0.32%—Monostream Tifig16/8/202217/6/2026
tifig v0.2.2 was discovered to contain a heap-use-after-free via temInfoEntry().
ModificadaCrítica (9.8)1.3%—Monorepo-build Project Monorepo-build2/8/202217/6/2026
This affects all versions of package monorepo-build.
ModificadaCrítica (9.3)1.3%—Monorepo Project Monorepo11/7/202217/6/2026
The cinemaproject/monorepo repository through 2021-03-03 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
ModificadaCrítica (9.8)3.3%—Microsoft .netMicrosoft .net CoreMicrosoft MonoMicrosoft Visual Studio 201925/2/202117/6/2026
.NET Core Remote Code Execution Vulnerability
ModificadaCrítica (9.8)6.9%—Mitsubishielectric C Controller Module Setting AND Monitoring ToolMitsubishielectric CPU Module Logging Configuration ToolMitsubishielectric CW ConfiguratorMitsubishielectric Data Transfer+3719/2/202117/6/2026
Improper Handling of Length Parameter Inconsistency vulnerability in Mitsubishi Electric FA Engineering Software (CPU Module Logging Configuration Tool versions 1.112R and prior, CW Configurator versions 1.011M and prior, Data Transfer versions 3.44W and prior, EZSocket versions 5.4 and prior, FR Configurator all…
ModificadaCrítica (9.8)3.9%—Mitsubishielectric C Controller Module Setting AND Monitoring ToolMitsubishielectric CPU Module Logging Configuration ToolMitsubishielectric CW ConfiguratorMitsubishielectric Data Transfer+3719/2/202117/6/2026
Heap-based buffer overflow vulnerability in Mitsubishi Electric FA Engineering Software (CPU Module Logging Configuration Tool versions 1.112R and prior, CW Configurator versions 1.011M and prior, Data Transfer versions 3.44W and prior, EZSocket versions 5.4 and prior, FR Configurator all versions, FR Configurator SW3…
ModificadaCrítica (9.1)10%💥 ExploitSAP Scimono9/2/202117/6/2026
In SCIMono before 0.0.19, it is possible for an attacker to inject and execute java expression compromising the availability and integrity of the system.
ModificadaAlta (7.2)12%—Monocms7/1/202117/6/2026
MonoCMS Blog 1.0 is affected by incorrect access control that can lead to remote arbitrary code execution. At monofiles/category.php:27, user input can be saved to category/[foldername]/index.php causing RCE.
ModificadaAlta (8.1)1.7%—Monocms7/10/202017/6/2026
MonoCMS Blog 1.0 is affected by: Arbitrary File Deletion. Any authenticated user can delete files on and off the webserver (php files can be unlinked and not deleted).
ModificadaAlta (7.5)1.6%—Monocms6/10/202017/6/2026
MonoCMS Blog 1.0 stores hard-coded admin hashes in the log.xml file in the source files for MonoCMS Blog. Hash type is bcrypt and hashcat mode 3200 can be used to crack the hash.
ModificadaMedia (6.5)0.57%—Monocms6/10/202017/6/2026
A Cross Site Request Forgery (CSRF) vulnerability in MonoCMS Blog 1.0 allows attackers to change the password of a user.
ModificadaMedia (6.1)1.0%—Cmonos6/10/202017/6/2026
Stored cross-site scripting vulnerability in CMONOS.JP ver2.0.20191009 and earlier allows remote attackers to inject arbitrary script via unspecified vectors.
ModificadaCrítica (9.8)2.6%—Daemonology Bsdiff16/9/202017/6/2026
A memory corruption vulnerability is present in bspatch as shipped in Colin Percival’s bsdiff tools version 4.3. Insufficient checks when handling external inputs allows an attacker to bypass the sanity checks in place and write out of a dynamically allocated buffer boundaries.
ModificadaCrítica (9.8)2.8%—Monox29/4/202017/6/2026
MonoX through 5.1.40.5152 allows remote code execution via HTML5Upload.ashx or Pages/SocialNetworking/lng/en-US/PhotoGallery.aspx because of deserialization in ModuleGallery.HTML5Upload, ModuleGallery.SilverLightUploadModule, HTML5Upload, and SilverLightUploadHandler.
ModificadaAlta (7.2)1.7%—Monox29/4/202017/6/2026
MonoX through 5.1.40.5152 allows administrators to execute arbitrary code by modifying an ASPX template.
ModificadaAlta (7.2)1.4%—Monox29/4/202017/6/2026
MonoX through 5.1.40.5152 allows admins to execute arbitrary programs by reconfiguring the Converter Executable setting from ffmpeg.exe to a different program.
ModificadaMedia (5.4)0.53%—Monox29/4/202017/6/2026
MonoX through 5.1.40.5152 allows stored XSS via User Status, Blog Comments, or Blog Description.
ModificadaAlta (7.5)0.51%—Appinghouse Memono16/4/202017/6/2026
Users can lock their notes with a password in Memono version 3.8. Thus, users needs to know a password to read notes. However, these notes are stored in a database without encryption and an attacker can read the password-protected notes without having the password. Notes are stored in the ZENTITY table in the…
ModificadaAlta (7.5)2.2%—Monopd Project Monopd9/12/201917/6/2026
Off-by-one error in the readBuf function in listener.cpp in libcapsinetwork and monopd before 0.9.8, allows remote attackers to cause a denial of service (crash) via a long line.
ModificadaAlta (7.5)2.6%—Mono-project MonoCanonical Ubuntu LinuxDebian Linux21/11/201916/6/2026
mono 2.10.x ASP.NET Web Form Hash collision DoS
ModificadaMedia (6.5)2.7%—Microsoft Visual Studio 2017Microsoft NugetMono-project Mono FrameworkMicrosoft .net Core SDK+49/4/201917/6/2026
A tampering vulnerability exists in the NuGet Package Manager for Linux and Mac that could allow an authenticated attacker to modify a NuGet package's folder structure, aka 'NuGet Package Manager Tampering Vulnerability'.
ModificadaMedia (5.3)0.35%—Google Monorail20/11/201817/6/2026
Google Monorail before 2018-06-07 has a Cross-Site Search (XS-Search) vulnerability because CSV downloads are affected by CSRF, and calculations of download times (for requests with a crafted groupby value) can be used to obtain sensitive information about the content of bug reports.
ModificadaMedia (5.3)0.34%—Google Monorail20/11/201817/6/2026
Google Monorail before 2018-05-04 has a Cross-Site Search (XS-Search) vulnerability because CSV downloads are affected by CSRF, and calculations of download times (for requests with an unsupported axis) can be used to obtain sensitive information about the content of bug reports.
ModificadaMedia (5.3)0.34%—Google Monorail20/11/201817/6/2026
Google Monorail before 2018-04-04 has a Cross-Site Search (XS-Search) vulnerability because CSV downloads are affected by CSRF, and calculations of download times (for requests with duplicated columns) can be used to obtain sensitive information about the content of bug reports.
ModificadaAlta (8.8)4.3%—Dell Idrac6 ModularDell Idrac6 Monolithic2/7/201817/6/2026
The web-based diagnostics console in Dell EMC iDRAC6 (Monolithic versions prior to 2.91 and Modular all versions) contains a command injection vulnerability. A remote authenticated malicious iDRAC user with access to the diagnostics console could potentially exploit this vulnerability to execute arbitrary commands as…
Orbitaley — Vulnerabilidades