Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
1029 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.1) | 0.19% | — | Openenergymonitor Emoncms | 24/10/2025 | 17/6/2026 | Emoncms 11.7.3 is vulnerable to Cross Site in the input handling mechanism. This vulnerability allows authenticated attackers with API access to inject malicious JavaScript code that executes when administrators view the application logs. | |
| Aplazada | Crítica (9.8) | 0.29% | — | TM2 MonitoringAI | 22/10/2025 | 5/7/2026 | TM2 Monitoring v3.04 contains an authentication bypass and plaintext credential disclosure. | |
| Analizada | Alta (7.8) | 0.64% | — | Microsoft Azure Monitor Agent | 14/10/2025 | 17/6/2026 | Improper access control in Azure Monitor Agent allows an authorized attacker to elevate privileges locally. | |
| Analizada | Alta (7) | 0.78% | — | Microsoft Azure Monitor Agent | 14/10/2025 | 17/6/2026 | Deserialization of untrusted data in Azure Monitor Agent allows an authorized attacker to elevate privileges locally. | |
| Analizada | Media (5.5) | 0.42% | — | Fabian Project Monitoring System | 10/10/2025 | 17/6/2026 | A vulnerability was found in code-projects Project Monitoring System 1.0. The impacted element is an unknown function of the file /useredit.php. The manipulation of the argument uid results in sql injection. The attack can be executed remotely. The exploit has been made public and could be used. | |
| Analizada | Alta (8.4) | 0.17% | — | Fujielectric Monitouch V-sft | 10/10/2025 | 17/6/2026 | A use after free vulnerability exists in VS6ComFile!load_link_inf of V-SFT v6.2.7.0 and earlier. Opening specially crafted V-SFT files may lead to information disclosure, affected system's abnormal end (ABEND), and arbitrary code execution. | |
| Analizada | Alta (8.4) | 0.17% | — | Fujielectric Monitouch V-sft | 10/10/2025 | 17/6/2026 | An out-of-bounds read vulnerability exists in VS6ComFile!CSaveData::delete_mem of V-SFT v6.2.7.0 and earlier. Opening specially crafted V-SFT files may lead to information disclosure, affected system's abnormal end (ABEND), and arbitrary code execution. | |
| Analizada | Alta (8.4) | 0.17% | — | Fujielectric Monitouch V-sft | 10/10/2025 | 17/6/2026 | An out-of-bounds read vulnerability exists in VS6ComFile!get_ovlp_element_size of V-SFT v6.2.7.0 and earlier. Opening specially crafted V-SFT files may lead to information disclosure, affected system's abnormal end (ABEND), and arbitrary code execution. | |
| Analizada | Alta (8.4) | 0.17% | — | Fujielectric Monitouch V-sft | 10/10/2025 | 17/6/2026 | An out-of-bounds read vulnerability exists in VS6ComFile!load_link_inf of V-SFT v6.2.7.0 and earlier. Opening specially crafted V-SFT files may lead to information disclosure, affected system's abnormal end (ABEND), and arbitrary code execution. | |
| Analizada | Alta (8.4) | 0.18% | — | Fujielectric Monitouch V-sft | 10/10/2025 | 17/6/2026 | An out-of-bounds read vulnerability exists in VS6MemInIF!set_temp_type_default of V-SFT v6.2.7.0 and earlier. Opening specially crafted V-SFT files may lead to information disclosure, affected system's abnormal end (ABEND), and arbitrary code execution. | |
| Analizada | Alta (8.4) | 0.18% | — | Fujielectric Monitouch V-sft | 10/10/2025 | 17/6/2026 | An out-of-bounds write vulnerability exists in VS6ComFile!CItemDraw::is_motion_tween of V-SFT v6.2.7.0 and earlier. Opening specially crafted V-SFT files may lead to information disclosure, affected system's abnormal end (ABEND), and arbitrary code execution. | |
| Analizada | Alta (8.4) | 0.18% | — | Fujielectric Monitouch V-sft | 10/10/2025 | 17/6/2026 | An out-of-bounds write vulnerability exists in VS6ComFile!set_AnimationItem of V-SFT v6.2.7.0 and earlier. Opening specially crafted V-SFT files may lead to information disclosure, affected system's abnormal end (ABEND), and arbitrary code execution. | |
| Analizada | Alta (8.4) | 0.18% | — | Fujielectric Monitouch V-sft | 10/10/2025 | 17/6/2026 | An out-of-bounds write vulnerability exists in VS6ComFile!CItemExChange::WinFontDynStrCheck of V-SFT v6.2.7.0 and earlier. Opening specially crafted V-SFT files may lead to information disclosure, affected system's abnormal end (ABEND), and arbitrary code execution. | |
| Analizada | Alta (8.4) | 0.20% | — | Fujielectric Monitouch V-sft | 10/10/2025 | 17/6/2026 | A stack-based buffer overflow vulnerability exists in VS6ComFile!CV7BaseMap::WriteV7DataToRom of V-SFT v6.2.7.0 and earlier. Opening specially crafted V-SFT files may lead to information disclosure, affected system's abnormal end (ABEND), and arbitrary code execution. | |
| Modificada | Media (5.4) | 0.44% | — | Microsoft Azure Monitor | 9/10/2025 | 17/6/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Azure Monitor allows an unauthorized attacker to perform spoofing over a network. | |
| Aplazada | Alta (8.7) | 0.48% | — | Central Monitor Cns-6201AI | 30/9/2025 | 17/6/2026 | Multiple versions of Central Monitor CNS-6201 contain a NULL pointer dereference vulnerability. When processing a crafted certain UDP packet, the affected device may abnormally terminate. | |
| Analizada | Baja (2) | 0.29% | — | Fabian Project Monitoring System | 28/9/2025 | 17/6/2026 | A vulnerability has been found in code-projects Project Monitoring System 1.0. Affected is an unknown function of the file /onlineJobSearchEngine/postjob.php. Such manipulation of the argument txtapplyto leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public… | |
| Analizada | Media (5.5) | 0.48% | — | Fabian Project Monitoring System | 27/9/2025 | 17/6/2026 | A flaw has been found in code-projects Project Monitoring System 1.0. The impacted element is an unknown function of the file /login.php. This manipulation of the argument username/password causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used. | |
| Aplazada | Crítica (9.8) | 0.72% | — | Imonitor EAMAI | 25/9/2025 | 17/6/2026 | iMonitor EAM 9.6394 ships with default administrative credentials that are also displayed within the management client’s connection dialog. If the administrator does not change these defaults, a remote attacker can authenticate to the EAM server and gain full control over monitored agents and data. This enables… | |
| Aplazada | Media (6.5) | 0.13% | — | Imonitor EAMAI | 25/9/2025 | 17/6/2026 | iMonitor EAM 9.6394 transmits communication between the EAM client agent and the EAM server, as well as between the EAM monitor management software and the server, in plaintext without authentication or encryption. An attacker with network access can intercept sensitive information (such as credentials, keylogger… | |
| Aplazada | Alta (7.8) | 0.23% | — | Imonitor EAMAI | 25/9/2025 | 1/10/2026 | iMonitor EAM 9.6394 installs a system service (eamusbsrv64.exe) that runs with NT AUTHORITY\SYSTEM privileges. This service includes an insecure update mechanism that automatically loads files placed in the C:\sysupdate\ directory during startup. Because any local user can create and write to this directory, an… | |
| Aplazada | Media (4.4) | 0.28% | — | Activewebsight SEO Backlink MonitorAI | 22/9/2025 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in activewebsight SEO Backlink Monitor seo-backlink-monitor allows Server Side Request Forgery.This issue affects SEO Backlink Monitor: from n/a through <= 1.8.0. | |
| Aplazada | Media (4.3) | 0.17% | — | Activewebsight SEO Backlink MonitorAI | 22/9/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in activewebsight SEO Backlink Monitor seo-backlink-monitor allows Cross Site Request Forgery.This issue affects SEO Backlink Monitor: from n/a through <= 1.8.0. | |
| Analizada | Media (5.5) | 0.42% | — | Emiloi E-logbook With Health Monitoring System FOR Covid-19 | 18/9/2025 | 17/6/2026 | A flaw has been found in itsourcecode E-Logbook with Health Monitoring System for COVID-19 1.0. This issue affects some unknown processing of the file /check_profile.php. Executing manipulation of the argument profile_id can lead to sql injection. It is possible to launch the attack remotely. The exploit has been… | |
| Analizada | Baja (2.1) | 0.35% | — | Emiloi E-logbook With Health Monitoring System FOR Covid-19 | 17/9/2025 | 25/9/2026 | A vulnerability was determined in itsourcecode E-Logbook with Health Monitoring System for COVID-19 1.0 on COVID. This affects an unknown function of the file /print_reports_prev.php. Executing manipulation of the argument profile_id can lead to cross site scripting. It is possible to launch the attack remotely. The… |