Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
143 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.32% | — | Monostream Tifig | 16/8/2022 | 17/6/2026 | tifig v0.2.2 was discovered to contain a heap-use-after-free via temInfoEntry(). | |
| Modificada | Crítica (9.8) | 1.3% | — | Monorepo-build Project Monorepo-build | 2/8/2022 | 17/6/2026 | This affects all versions of package monorepo-build. | |
| Modificada | Crítica (9.3) | 1.3% | — | Monorepo Project Monorepo | 11/7/2022 | 17/6/2026 | The cinemaproject/monorepo repository through 2021-03-03 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | |
| Modificada | Crítica (9.8) | 3.3% | — | Microsoft .netMicrosoft .net CoreMicrosoft MonoMicrosoft Visual Studio 2019 | 25/2/2021 | 17/6/2026 | .NET Core Remote Code Execution Vulnerability | |
| Modificada | Crítica (9.8) | 6.9% | — | Mitsubishielectric C Controller Module Setting AND Monitoring ToolMitsubishielectric CPU Module Logging Configuration ToolMitsubishielectric CW ConfiguratorMitsubishielectric Data Transfer+37 | 19/2/2021 | 17/6/2026 | Improper Handling of Length Parameter Inconsistency vulnerability in Mitsubishi Electric FA Engineering Software (CPU Module Logging Configuration Tool versions 1.112R and prior, CW Configurator versions 1.011M and prior, Data Transfer versions 3.44W and prior, EZSocket versions 5.4 and prior, FR Configurator all… | |
| Modificada | Crítica (9.8) | 3.9% | — | Mitsubishielectric C Controller Module Setting AND Monitoring ToolMitsubishielectric CPU Module Logging Configuration ToolMitsubishielectric CW ConfiguratorMitsubishielectric Data Transfer+37 | 19/2/2021 | 17/6/2026 | Heap-based buffer overflow vulnerability in Mitsubishi Electric FA Engineering Software (CPU Module Logging Configuration Tool versions 1.112R and prior, CW Configurator versions 1.011M and prior, Data Transfer versions 3.44W and prior, EZSocket versions 5.4 and prior, FR Configurator all versions, FR Configurator SW3… | |
| Modificada | Crítica (9.1) | 10% | 💥 Exploit | SAP Scimono | 9/2/2021 | 17/6/2026 | In SCIMono before 0.0.19, it is possible for an attacker to inject and execute java expression compromising the availability and integrity of the system. | |
| Modificada | Alta (7.2) | 12% | — | Monocms | 7/1/2021 | 17/6/2026 | MonoCMS Blog 1.0 is affected by incorrect access control that can lead to remote arbitrary code execution. At monofiles/category.php:27, user input can be saved to category/[foldername]/index.php causing RCE. | |
| Modificada | Alta (8.1) | 1.7% | — | Monocms | 7/10/2020 | 17/6/2026 | MonoCMS Blog 1.0 is affected by: Arbitrary File Deletion. Any authenticated user can delete files on and off the webserver (php files can be unlinked and not deleted). | |
| Modificada | Alta (7.5) | 1.6% | — | Monocms | 6/10/2020 | 17/6/2026 | MonoCMS Blog 1.0 stores hard-coded admin hashes in the log.xml file in the source files for MonoCMS Blog. Hash type is bcrypt and hashcat mode 3200 can be used to crack the hash. | |
| Modificada | Media (6.5) | 0.57% | — | Monocms | 6/10/2020 | 17/6/2026 | A Cross Site Request Forgery (CSRF) vulnerability in MonoCMS Blog 1.0 allows attackers to change the password of a user. | |
| Modificada | Media (6.1) | 1.0% | — | Cmonos | 6/10/2020 | 17/6/2026 | Stored cross-site scripting vulnerability in CMONOS.JP ver2.0.20191009 and earlier allows remote attackers to inject arbitrary script via unspecified vectors. | |
| Modificada | Crítica (9.8) | 2.6% | — | Daemonology Bsdiff | 16/9/2020 | 17/6/2026 | A memory corruption vulnerability is present in bspatch as shipped in Colin Percival’s bsdiff tools version 4.3. Insufficient checks when handling external inputs allows an attacker to bypass the sanity checks in place and write out of a dynamically allocated buffer boundaries. | |
| Modificada | Crítica (9.8) | 2.8% | — | Monox | 29/4/2020 | 17/6/2026 | MonoX through 5.1.40.5152 allows remote code execution via HTML5Upload.ashx or Pages/SocialNetworking/lng/en-US/PhotoGallery.aspx because of deserialization in ModuleGallery.HTML5Upload, ModuleGallery.SilverLightUploadModule, HTML5Upload, and SilverLightUploadHandler. | |
| Modificada | Alta (7.2) | 1.7% | — | Monox | 29/4/2020 | 17/6/2026 | MonoX through 5.1.40.5152 allows administrators to execute arbitrary code by modifying an ASPX template. | |
| Modificada | Alta (7.2) | 1.4% | — | Monox | 29/4/2020 | 17/6/2026 | MonoX through 5.1.40.5152 allows admins to execute arbitrary programs by reconfiguring the Converter Executable setting from ffmpeg.exe to a different program. | |
| Modificada | Media (5.4) | 0.53% | — | Monox | 29/4/2020 | 17/6/2026 | MonoX through 5.1.40.5152 allows stored XSS via User Status, Blog Comments, or Blog Description. | |
| Modificada | Alta (7.5) | 0.51% | — | Appinghouse Memono | 16/4/2020 | 17/6/2026 | Users can lock their notes with a password in Memono version 3.8. Thus, users needs to know a password to read notes. However, these notes are stored in a database without encryption and an attacker can read the password-protected notes without having the password. Notes are stored in the ZENTITY table in the… | |
| Modificada | Alta (7.5) | 2.2% | — | Monopd Project Monopd | 9/12/2019 | 17/6/2026 | Off-by-one error in the readBuf function in listener.cpp in libcapsinetwork and monopd before 0.9.8, allows remote attackers to cause a denial of service (crash) via a long line. | |
| Modificada | Alta (7.5) | 2.6% | — | Mono-project MonoCanonical Ubuntu LinuxDebian Linux | 21/11/2019 | 16/6/2026 | mono 2.10.x ASP.NET Web Form Hash collision DoS | |
| Modificada | Media (6.5) | 2.7% | — | Microsoft Visual Studio 2017Microsoft NugetMono-project Mono FrameworkMicrosoft .net Core SDK+4 | 9/4/2019 | 17/6/2026 | A tampering vulnerability exists in the NuGet Package Manager for Linux and Mac that could allow an authenticated attacker to modify a NuGet package's folder structure, aka 'NuGet Package Manager Tampering Vulnerability'. | |
| Modificada | Media (5.3) | 0.35% | — | Google Monorail | 20/11/2018 | 17/6/2026 | Google Monorail before 2018-06-07 has a Cross-Site Search (XS-Search) vulnerability because CSV downloads are affected by CSRF, and calculations of download times (for requests with a crafted groupby value) can be used to obtain sensitive information about the content of bug reports. | |
| Modificada | Media (5.3) | 0.34% | — | Google Monorail | 20/11/2018 | 17/6/2026 | Google Monorail before 2018-05-04 has a Cross-Site Search (XS-Search) vulnerability because CSV downloads are affected by CSRF, and calculations of download times (for requests with an unsupported axis) can be used to obtain sensitive information about the content of bug reports. | |
| Modificada | Media (5.3) | 0.34% | — | Google Monorail | 20/11/2018 | 17/6/2026 | Google Monorail before 2018-04-04 has a Cross-Site Search (XS-Search) vulnerability because CSV downloads are affected by CSRF, and calculations of download times (for requests with duplicated columns) can be used to obtain sensitive information about the content of bug reports. | |
| Modificada | Alta (8.8) | 4.3% | — | Dell Idrac6 ModularDell Idrac6 Monolithic | 2/7/2018 | 17/6/2026 | The web-based diagnostics console in Dell EMC iDRAC6 (Monolithic versions prior to 2.91 and Modular all versions) contains a command injection vulnerability. A remote authenticated malicious iDRAC user with access to the diagnostics console could potentially exploit this vulnerability to execute arbitrary commands as… |