Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
1029 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.5) | 0.18% | — | Epson Status MonitorAI | 28/1/2026 | 17/6/2026 | EPSON 1.124 contains an unquoted service path vulnerability in the SENADB service that allows local attackers to execute code with elevated system privileges. Attackers can exploit the unquoted path in C:\Program Files (x86)\EPSON_P2B\Printer Software\Status Monitor\ to inject malicious executables that will run with… | |
| Aplazada | Alta (8.5) | 0.18% | — | Epson Status Monitor 3AI | 27/1/2026 | 17/6/2026 | EPSON Status Monitor 3 version 8.0 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code by exploiting the service binary path. Attackers can leverage the unquoted path in 'C:\Program Files\Common Files\EPSON\EPW!3SSRP\E_S60RPB.EXE' to inject malicious… | |
| Analizada | Media (6.7) | 0.42% | — | Nsasoft Nbmonitor | 16/1/2026 | 29/6/2026 | NBMonitor 1.6.8 contains a denial of service vulnerability that allows attackers to crash the application by overflowing the registration code input field. Attackers can paste a 256-character buffer into the registration key field to trigger an application crash and potential system instability. | |
| Analizada | Media (6.5) | 0.40% | — | Paessler Prtg Network Monitor | 14/1/2026 | 17/6/2026 | Paessler PRTG Network Monitor before 25.4.114 allows Denial-of-Service (DoS) by an authenticated attacker via the Notification Contacts functionality. | |
| Analizada | Media (5.4) | 0.26% | — | Paessler Prtg Network Monitor | 14/1/2026 | 17/6/2026 | Paessler PRTG Network Monitor before 25.4.114 allows XSS by an unauthenticated attacker via the filter parameter. | |
| Analizada | Media (6.1) | 0.26% | — | Paessler Prtg Network Monitor | 14/1/2026 | 17/6/2026 | Paessler PRTG Network Monitor before 25.4.114 allows XSS by an unauthenticated attacker via the tag parameter. | |
| Modificada | Media (4.6) | 0.17% | 💥 PoC | Airth Smart Home AQI Monitor Bootloader | 14/1/2026 | 5/7/2026 | An issue in AIRTH SMART HOME AQI MONITOR Bootloader v.1.005 allows a physically proximate attacker to obtain sensitive information via the UART port of the BK7231N controller (Wi-Fi and BLE module) on the device is open to access | |
| Aplazada | Media (4.3) | 0.22% | — | Campaignmonitor Campaign Monitor FOR WordpressAI | 8/1/2026 | 17/6/2026 | Missing Authorization vulnerability in Campaign Monitor Campaign Monitor for WordPress allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Campaign Monitor for WordPress: from n/a through 2.9.1. | |
| Analizada | Alta (7.5) | 0.40% | — | Dwyeromega Isensix Advanced Remote Monitoring System Firmware | 6/1/2026 | 17/6/2026 | DwyerOmega Isensix Advanced Remote Monitoring System (ARMS) 1.5.7 allows an attacker to retrieve sensitive information from the underlying SQL database via Blind SQL Injection through the user parameter in the login page. This allows an attacker to steal credentials, which may be cleartext, from existing users (and… | |
| Aplazada | Alta (8.4) | 0.26% | — | Fujielectric Monitouch V-sft-6AI | 17/12/2025 | 17/6/2026 | Fuji Electric Monitouch V-SFT-6 is vulnerable to an out-of-bounds write while processing a specially crafted project file, which may allow an attacker to execute arbitrary code. | |
| Analizada | Media (4.8) | 0.17% | — | Solaredge Monitoring Platform | 12/12/2025 | 17/6/2026 | SolarEdge monitoring platform contains a Cross‑Site Scripting (XSS) flaw that allows an authenticated user to inject payloads into report names, which may execute in a victim’s browser during a deletion attempt. | |
| Analizada | Alta (8.8) | 0.74% | — | Microsoft Azure Monitor Agent | 9/12/2025 | 17/6/2026 | Out-of-bounds write in Azure Monitor Agent allows an authorized attacker to execute code over a network. | |
| Analizada | Alta (7.1) | 0.39% | — | Siemens Sinec Security Monitor | 9/12/2025 | 17/6/2026 | A vulnerability has been identified in SINEC Security Monitor (All versions < V4.10.0). The affected application lacks input validation of date parameter in report generation functionality. This could allow an authenticated, lowly privileged attacker to cause denial of service condition of the report functionality. | |
| Analizada | Alta (8.4) | 0.16% | — | Siemens Sinec Security Monitor | 9/12/2025 | 17/6/2026 | A vulnerability has been identified in SINEC Security Monitor (All versions < V4.10.0). The affected application does not have proper authorization checks for the file_transfer feature in ssmctl-client command. This could allow an authenticated, lowly privileged local attacker to read or write to any file on server or… | |
| Analizada | Crítica (9.8) | 0.71% | — | Microsoft Azure Monitor | 20/11/2025 | 17/6/2026 | Azure Monitor Elevation of Privilege Vulnerability | |
| Analizada | Alta (7.3) | 0.33% | — | Microsoft Azure Monitor Agent | 11/11/2025 | 17/6/2026 | Heap-based buffer overflow in Azure Monitor Agent allows an unauthorized attacker to execute code locally. | |
| Aplazada | Crítica (10) | 0.69% | — | SAP SQL Anywhere MonitorAI | 11/11/2025 | 17/6/2026 | SQL Anywhere Monitor (Non-GUI) baked credentials into the code,exposing the resources or functionality to unintended users and providing attackers with the possibility of arbitrary code execution.This could cause high impact on confidentiality integrity and availability of the system. | |
| Analizada | Alta (7.8) | 0.14% | 💥 PoC | Dell Command Monitor | 5/11/2025 | 17/6/2026 | Dell Command Monitor (DCM), versions prior to 10.12.3.28, contains an Execution with Unnecessary Privileges vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges. | |
| Analizada | Alta (8.4) | 0.19% | — | Fujielectric Monitouch V-sft | 4/11/2025 | 17/6/2026 | Fuji Electric Monitouch V-SFT-6 is vulnerable to a stack-based buffer overflow while processing a specially crafted project file, which may allow an attacker to execute arbitrary code. | |
| Analizada | Alta (8.4) | 0.19% | — | Fujielectric Monitouch V-sft | 4/11/2025 | 17/6/2026 | A maliciously crafted project file may cause a heap-based buffer overflow in Fuji Electric Monitouch V-SFT-6, which may allow the attacker to execute arbitrary code. | |
| Analizada | Crítica (9.8) | 0.42% | — | IBM Tivoli Monitoring | 30/10/2025 | 17/6/2026 | IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 21 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view, overwrite, or append to arbitrary files on the system. | |
| Analizada | Alta (7.5) | 0.53% | — | IBM Tivoli Monitoring | 30/10/2025 | 17/6/2026 | IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 21 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. | |
| Aplazada | Alta (7.8) | 0.14% | 💥 PoC | Threatfire System MonitorAI | 29/10/2025 | 17/6/2026 | Incorrect access control in the kernel driver of ThreatFire System Monitor v4.7.0.53 allows attackers to escalate privileges and execute arbitrary commands via an insecure IOCTL. | |
| Aplazada | Alta (8.4) | 0.43% | — | Centreon Infra MonitoringAI | 27/10/2025 | 17/6/2026 | Incorrect Default Permissions vulnerability in Centreon Infra Monitoring (MBI modules) allows Embedding Scripts within Scripts by CentreonBI user account on the MBI server This issue affects Infra Monitoring: from 24.10.0 before 24.10.6, from 24.04.0 before 24.04.9, from 23.10.0 before 23.10.15. | |
| Analizada | Alta (7.5) | 0.61% | — | Openenergymonitor Emoncms | 24/10/2025 | 17/6/2026 | Emoncms 11.7.3 has a remote code execution vulnerability in the firmware upload feature that allows authenticated users to execute arbitrary commands on the target system. The vulnerability stems from insufficient input validation of user-controlled parameters including filename, port, baud_rate, core, and autoreset… |