Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

967 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.7)0.42%—Nsasoft Nbmonitor16/1/202629/6/2026
NBMonitor 1.6.8 contains a denial of service vulnerability that allows attackers to crash the application by overflowing the registration code input field. Attackers can paste a 256-character buffer into the registration key field to trigger an application crash and potential system instability.
AnalizadaMedia (6.5)0.40%—Paessler Prtg Network Monitor14/1/202617/6/2026
Paessler PRTG Network Monitor before 25.4.114 allows Denial-of-Service (DoS) by an authenticated attacker via the Notification Contacts functionality.
AnalizadaMedia (5.4)0.26%—Paessler Prtg Network Monitor14/1/202617/6/2026
Paessler PRTG Network Monitor before 25.4.114 allows XSS by an unauthenticated attacker via the filter parameter.
AnalizadaMedia (6.1)0.26%—Paessler Prtg Network Monitor14/1/202617/6/2026
Paessler PRTG Network Monitor before 25.4.114 allows XSS by an unauthenticated attacker via the tag parameter.
ModificadaMedia (4.6)0.17%💥 PoCAirth Smart Home AQI Monitor Bootloader14/1/20265/7/2026
An issue in AIRTH SMART HOME AQI MONITOR Bootloader v.1.005 allows a physically proximate attacker to obtain sensitive information via the UART port of the BK7231N controller (Wi-Fi and BLE module) on the device is open to access
AplazadaMedia (4.3)0.22%—Campaignmonitor Campaign Monitor FOR WordpressAI8/1/202617/6/2026
Missing Authorization vulnerability in Campaign Monitor Campaign Monitor for WordPress allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Campaign Monitor for WordPress: from n/a through 2.9.1.
AnalizadaAlta (7.5)0.40%—Dwyeromega Isensix Advanced Remote Monitoring System Firmware6/1/202617/6/2026
DwyerOmega Isensix Advanced Remote Monitoring System (ARMS) 1.5.7 allows an attacker to retrieve sensitive information from the underlying SQL database via Blind SQL Injection through the user parameter in the login page. This allows an attacker to steal credentials, which may be cleartext, from existing users (and…
AnalizadaMedia (4.8)0.17%—Solaredge Monitoring Platform12/12/202517/6/2026
SolarEdge monitoring platform contains a Cross‑Site Scripting (XSS) flaw that allows an authenticated user to inject payloads into report names, which may execute in a victim’s browser during a deletion attempt.
AnalizadaAlta (8.8)0.74%—Microsoft Azure Monitor Agent9/12/202517/6/2026
Out-of-bounds write in Azure Monitor Agent allows an authorized attacker to execute code over a network.
AnalizadaAlta (7.1)0.39%—Siemens Sinec Security Monitor9/12/202517/6/2026
A vulnerability has been identified in SINEC Security Monitor (All versions < V4.10.0). The affected application lacks input validation of date parameter in report generation functionality. This could allow an authenticated, lowly privileged attacker to cause denial of service condition of the report functionality.
AnalizadaAlta (8.4)0.16%—Siemens Sinec Security Monitor9/12/202517/6/2026
A vulnerability has been identified in SINEC Security Monitor (All versions < V4.10.0). The affected application does not have proper authorization checks for the file_transfer feature in ssmctl-client command. This could allow an authenticated, lowly privileged local attacker to read or write to any file on server or…
AnalizadaCrítica (9.8)0.71%—Microsoft Azure Monitor20/11/202517/6/2026
Azure Monitor Elevation of Privilege Vulnerability
AnalizadaAlta (7.3)0.33%—Microsoft Azure Monitor Agent11/11/202517/6/2026
Heap-based buffer overflow in Azure Monitor Agent allows an unauthorized attacker to execute code locally.
AplazadaCrítica (10)0.69%—SAP SQL Anywhere MonitorAI11/11/202517/6/2026
SQL Anywhere Monitor (Non-GUI) baked credentials into the code,exposing the resources or functionality to unintended users and providing attackers with the possibility of arbitrary code execution.This could cause high impact on confidentiality integrity and availability of the system.
AnalizadaAlta (7.8)0.14%💥 PoCDell Command Monitor5/11/202517/6/2026
Dell Command Monitor (DCM), versions prior to 10.12.3.28, contains an Execution with Unnecessary Privileges vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.
AnalizadaCrítica (9.8)0.42%—IBM Tivoli Monitoring30/10/202517/6/2026
IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 21 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view, overwrite, or append to arbitrary files on the system.
AnalizadaAlta (7.5)0.53%—IBM Tivoli Monitoring30/10/202517/6/2026
IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 21 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.
AplazadaAlta (7.8)0.14%💥 PoCThreatfire System MonitorAI29/10/202517/6/2026
Incorrect access control in the kernel driver of ThreatFire System Monitor v4.7.0.53 allows attackers to escalate privileges and execute arbitrary commands via an insecure IOCTL.
AplazadaAlta (8.4)0.43%—Centreon Infra MonitoringAI27/10/202517/6/2026
Incorrect Default Permissions vulnerability in Centreon Infra Monitoring (MBI modules) allows Embedding Scripts within Scripts by CentreonBI user account on the MBI server This issue affects Infra Monitoring: from 24.10.0 before 24.10.6, from 24.04.0 before 24.04.9, from 23.10.0 before 23.10.15.
AnalizadaAlta (7.5)0.61%—Openenergymonitor Emoncms24/10/202517/6/2026
Emoncms 11.7.3 has a remote code execution vulnerability in the firmware upload feature that allows authenticated users to execute arbitrary commands on the target system. The vulnerability stems from insufficient input validation of user-controlled parameters including filename, port, baud_rate, core, and autoreset…
AnalizadaMedia (6.1)0.19%—Openenergymonitor Emoncms24/10/202517/6/2026
Emoncms 11.7.3 is vulnerable to Cross Site in the input handling mechanism. This vulnerability allows authenticated attackers with API access to inject malicious JavaScript code that executes when administrators view the application logs.
AplazadaCrítica (9.8)0.29%—TM2 MonitoringAI22/10/20255/7/2026
TM2 Monitoring v3.04 contains an authentication bypass and plaintext credential disclosure.
AnalizadaAlta (7.8)0.64%—Microsoft Azure Monitor Agent14/10/202517/6/2026
Improper access control in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.
AnalizadaAlta (7)0.78%—Microsoft Azure Monitor Agent14/10/202517/6/2026
Deserialization of untrusted data in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.
AnalizadaMedia (5.5)0.42%—Fabian Project Monitoring System10/10/202517/6/2026
A vulnerability was found in code-projects Project Monitoring System 1.0. The impacted element is an unknown function of the file /useredit.php. The manipulation of the argument uid results in sql injection. The attack can be executed remotely. The exploit has been made public and could be used.
Orbitaley — Vulnerabilidades