Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
967 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.7) | 0.42% | — | Nsasoft Nbmonitor | 16/1/2026 | 29/6/2026 | NBMonitor 1.6.8 contains a denial of service vulnerability that allows attackers to crash the application by overflowing the registration code input field. Attackers can paste a 256-character buffer into the registration key field to trigger an application crash and potential system instability. | |
| Analizada | Media (6.5) | 0.40% | — | Paessler Prtg Network Monitor | 14/1/2026 | 17/6/2026 | Paessler PRTG Network Monitor before 25.4.114 allows Denial-of-Service (DoS) by an authenticated attacker via the Notification Contacts functionality. | |
| Analizada | Media (5.4) | 0.26% | — | Paessler Prtg Network Monitor | 14/1/2026 | 17/6/2026 | Paessler PRTG Network Monitor before 25.4.114 allows XSS by an unauthenticated attacker via the filter parameter. | |
| Analizada | Media (6.1) | 0.26% | — | Paessler Prtg Network Monitor | 14/1/2026 | 17/6/2026 | Paessler PRTG Network Monitor before 25.4.114 allows XSS by an unauthenticated attacker via the tag parameter. | |
| Modificada | Media (4.6) | 0.17% | 💥 PoC | Airth Smart Home AQI Monitor Bootloader | 14/1/2026 | 5/7/2026 | An issue in AIRTH SMART HOME AQI MONITOR Bootloader v.1.005 allows a physically proximate attacker to obtain sensitive information via the UART port of the BK7231N controller (Wi-Fi and BLE module) on the device is open to access | |
| Aplazada | Media (4.3) | 0.22% | — | Campaignmonitor Campaign Monitor FOR WordpressAI | 8/1/2026 | 17/6/2026 | Missing Authorization vulnerability in Campaign Monitor Campaign Monitor for WordPress allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Campaign Monitor for WordPress: from n/a through 2.9.1. | |
| Analizada | Alta (7.5) | 0.40% | — | Dwyeromega Isensix Advanced Remote Monitoring System Firmware | 6/1/2026 | 17/6/2026 | DwyerOmega Isensix Advanced Remote Monitoring System (ARMS) 1.5.7 allows an attacker to retrieve sensitive information from the underlying SQL database via Blind SQL Injection through the user parameter in the login page. This allows an attacker to steal credentials, which may be cleartext, from existing users (and… | |
| Analizada | Media (4.8) | 0.17% | — | Solaredge Monitoring Platform | 12/12/2025 | 17/6/2026 | SolarEdge monitoring platform contains a Cross‑Site Scripting (XSS) flaw that allows an authenticated user to inject payloads into report names, which may execute in a victim’s browser during a deletion attempt. | |
| Analizada | Alta (8.8) | 0.74% | — | Microsoft Azure Monitor Agent | 9/12/2025 | 17/6/2026 | Out-of-bounds write in Azure Monitor Agent allows an authorized attacker to execute code over a network. | |
| Analizada | Alta (7.1) | 0.39% | — | Siemens Sinec Security Monitor | 9/12/2025 | 17/6/2026 | A vulnerability has been identified in SINEC Security Monitor (All versions < V4.10.0). The affected application lacks input validation of date parameter in report generation functionality. This could allow an authenticated, lowly privileged attacker to cause denial of service condition of the report functionality. | |
| Analizada | Alta (8.4) | 0.16% | — | Siemens Sinec Security Monitor | 9/12/2025 | 17/6/2026 | A vulnerability has been identified in SINEC Security Monitor (All versions < V4.10.0). The affected application does not have proper authorization checks for the file_transfer feature in ssmctl-client command. This could allow an authenticated, lowly privileged local attacker to read or write to any file on server or… | |
| Analizada | Crítica (9.8) | 0.71% | — | Microsoft Azure Monitor | 20/11/2025 | 17/6/2026 | Azure Monitor Elevation of Privilege Vulnerability | |
| Analizada | Alta (7.3) | 0.33% | — | Microsoft Azure Monitor Agent | 11/11/2025 | 17/6/2026 | Heap-based buffer overflow in Azure Monitor Agent allows an unauthorized attacker to execute code locally. | |
| Aplazada | Crítica (10) | 0.69% | — | SAP SQL Anywhere MonitorAI | 11/11/2025 | 17/6/2026 | SQL Anywhere Monitor (Non-GUI) baked credentials into the code,exposing the resources or functionality to unintended users and providing attackers with the possibility of arbitrary code execution.This could cause high impact on confidentiality integrity and availability of the system. | |
| Analizada | Alta (7.8) | 0.14% | 💥 PoC | Dell Command Monitor | 5/11/2025 | 17/6/2026 | Dell Command Monitor (DCM), versions prior to 10.12.3.28, contains an Execution with Unnecessary Privileges vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges. | |
| Analizada | Crítica (9.8) | 0.42% | — | IBM Tivoli Monitoring | 30/10/2025 | 17/6/2026 | IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 21 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view, overwrite, or append to arbitrary files on the system. | |
| Analizada | Alta (7.5) | 0.53% | — | IBM Tivoli Monitoring | 30/10/2025 | 17/6/2026 | IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 21 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. | |
| Aplazada | Alta (7.8) | 0.14% | 💥 PoC | Threatfire System MonitorAI | 29/10/2025 | 17/6/2026 | Incorrect access control in the kernel driver of ThreatFire System Monitor v4.7.0.53 allows attackers to escalate privileges and execute arbitrary commands via an insecure IOCTL. | |
| Aplazada | Alta (8.4) | 0.43% | — | Centreon Infra MonitoringAI | 27/10/2025 | 17/6/2026 | Incorrect Default Permissions vulnerability in Centreon Infra Monitoring (MBI modules) allows Embedding Scripts within Scripts by CentreonBI user account on the MBI server This issue affects Infra Monitoring: from 24.10.0 before 24.10.6, from 24.04.0 before 24.04.9, from 23.10.0 before 23.10.15. | |
| Analizada | Alta (7.5) | 0.61% | — | Openenergymonitor Emoncms | 24/10/2025 | 17/6/2026 | Emoncms 11.7.3 has a remote code execution vulnerability in the firmware upload feature that allows authenticated users to execute arbitrary commands on the target system. The vulnerability stems from insufficient input validation of user-controlled parameters including filename, port, baud_rate, core, and autoreset… | |
| Analizada | Media (6.1) | 0.19% | — | Openenergymonitor Emoncms | 24/10/2025 | 17/6/2026 | Emoncms 11.7.3 is vulnerable to Cross Site in the input handling mechanism. This vulnerability allows authenticated attackers with API access to inject malicious JavaScript code that executes when administrators view the application logs. | |
| Aplazada | Crítica (9.8) | 0.29% | — | TM2 MonitoringAI | 22/10/2025 | 5/7/2026 | TM2 Monitoring v3.04 contains an authentication bypass and plaintext credential disclosure. | |
| Analizada | Alta (7.8) | 0.64% | — | Microsoft Azure Monitor Agent | 14/10/2025 | 17/6/2026 | Improper access control in Azure Monitor Agent allows an authorized attacker to elevate privileges locally. | |
| Analizada | Alta (7) | 0.78% | — | Microsoft Azure Monitor Agent | 14/10/2025 | 17/6/2026 | Deserialization of untrusted data in Azure Monitor Agent allows an authorized attacker to elevate privileges locally. | |
| Analizada | Media (5.5) | 0.42% | — | Fabian Project Monitoring System | 10/10/2025 | 17/6/2026 | A vulnerability was found in code-projects Project Monitoring System 1.0. The impacted element is an unknown function of the file /useredit.php. The manipulation of the argument uid results in sql injection. The attack can be executed remotely. The exploit has been made public and could be used. |