Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
–

1029 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.1)0.19%—Openenergymonitor Emoncms24/10/202517/6/2026
Emoncms 11.7.3 is vulnerable to Cross Site in the input handling mechanism. This vulnerability allows authenticated attackers with API access to inject malicious JavaScript code that executes when administrators view the application logs.
AplazadaCrítica (9.8)0.29%—TM2 MonitoringAI22/10/20255/7/2026
TM2 Monitoring v3.04 contains an authentication bypass and plaintext credential disclosure.
AnalizadaAlta (7.8)0.64%—Microsoft Azure Monitor Agent14/10/202517/6/2026
Improper access control in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.
AnalizadaAlta (7)0.78%—Microsoft Azure Monitor Agent14/10/202517/6/2026
Deserialization of untrusted data in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.
AnalizadaMedia (5.5)0.42%—Fabian Project Monitoring System10/10/202517/6/2026
A vulnerability was found in code-projects Project Monitoring System 1.0. The impacted element is an unknown function of the file /useredit.php. The manipulation of the argument uid results in sql injection. The attack can be executed remotely. The exploit has been made public and could be used.
AnalizadaAlta (8.4)0.17%—Fujielectric Monitouch V-sft10/10/202517/6/2026
A use after free vulnerability exists in VS6ComFile!load_link_inf of V-SFT v6.2.7.0 and earlier. Opening specially crafted V-SFT files may lead to information disclosure, affected system's abnormal end (ABEND), and arbitrary code execution.
AnalizadaAlta (8.4)0.17%—Fujielectric Monitouch V-sft10/10/202517/6/2026
An out-of-bounds read vulnerability exists in VS6ComFile!CSaveData::delete_mem of V-SFT v6.2.7.0 and earlier. Opening specially crafted V-SFT files may lead to information disclosure, affected system's abnormal end (ABEND), and arbitrary code execution.
AnalizadaAlta (8.4)0.17%—Fujielectric Monitouch V-sft10/10/202517/6/2026
An out-of-bounds read vulnerability exists in VS6ComFile!get_ovlp_element_size of V-SFT v6.2.7.0 and earlier. Opening specially crafted V-SFT files may lead to information disclosure, affected system's abnormal end (ABEND), and arbitrary code execution.
AnalizadaAlta (8.4)0.17%—Fujielectric Monitouch V-sft10/10/202517/6/2026
An out-of-bounds read vulnerability exists in VS6ComFile!load_link_inf of V-SFT v6.2.7.0 and earlier. Opening specially crafted V-SFT files may lead to information disclosure, affected system's abnormal end (ABEND), and arbitrary code execution.
AnalizadaAlta (8.4)0.18%—Fujielectric Monitouch V-sft10/10/202517/6/2026
An out-of-bounds read vulnerability exists in VS6MemInIF!set_temp_type_default of V-SFT v6.2.7.0 and earlier. Opening specially crafted V-SFT files may lead to information disclosure, affected system's abnormal end (ABEND), and arbitrary code execution.
AnalizadaAlta (8.4)0.18%—Fujielectric Monitouch V-sft10/10/202517/6/2026
An out-of-bounds write vulnerability exists in VS6ComFile!CItemDraw::is_motion_tween of V-SFT v6.2.7.0 and earlier. Opening specially crafted V-SFT files may lead to information disclosure, affected system's abnormal end (ABEND), and arbitrary code execution.
AnalizadaAlta (8.4)0.18%—Fujielectric Monitouch V-sft10/10/202517/6/2026
An out-of-bounds write vulnerability exists in VS6ComFile!set_AnimationItem of V-SFT v6.2.7.0 and earlier. Opening specially crafted V-SFT files may lead to information disclosure, affected system's abnormal end (ABEND), and arbitrary code execution.
AnalizadaAlta (8.4)0.18%—Fujielectric Monitouch V-sft10/10/202517/6/2026
An out-of-bounds write vulnerability exists in VS6ComFile!CItemExChange::WinFontDynStrCheck of V-SFT v6.2.7.0 and earlier. Opening specially crafted V-SFT files may lead to information disclosure, affected system's abnormal end (ABEND), and arbitrary code execution.
AnalizadaAlta (8.4)0.20%—Fujielectric Monitouch V-sft10/10/202517/6/2026
A stack-based buffer overflow vulnerability exists in VS6ComFile!CV7BaseMap::WriteV7DataToRom of V-SFT v6.2.7.0 and earlier. Opening specially crafted V-SFT files may lead to information disclosure, affected system's abnormal end (ABEND), and arbitrary code execution.
ModificadaMedia (5.4)0.44%—Microsoft Azure Monitor9/10/202517/6/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Azure Monitor allows an unauthorized attacker to perform spoofing over a network.
AplazadaAlta (8.7)0.48%—Central Monitor Cns-6201AI30/9/202517/6/2026
Multiple versions of Central Monitor CNS-6201 contain a NULL pointer dereference vulnerability. When processing a crafted certain UDP packet, the affected device may abnormally terminate.
AnalizadaBaja (2)0.29%—Fabian Project Monitoring System28/9/202517/6/2026
A vulnerability has been found in code-projects Project Monitoring System 1.0. Affected is an unknown function of the file /onlineJobSearchEngine/postjob.php. Such manipulation of the argument txtapplyto leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public…
AnalizadaMedia (5.5)0.48%—Fabian Project Monitoring System27/9/202517/6/2026
A flaw has been found in code-projects Project Monitoring System 1.0. The impacted element is an unknown function of the file /login.php. This manipulation of the argument username/password causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used.
AplazadaCrítica (9.8)0.72%—Imonitor EAMAI25/9/202517/6/2026
iMonitor EAM 9.6394 ships with default administrative credentials that are also displayed within the management client’s connection dialog. If the administrator does not change these defaults, a remote attacker can authenticate to the EAM server and gain full control over monitored agents and data. This enables…
AplazadaMedia (6.5)0.13%—Imonitor EAMAI25/9/202517/6/2026
iMonitor EAM 9.6394 transmits communication between the EAM client agent and the EAM server, as well as between the EAM monitor management software and the server, in plaintext without authentication or encryption. An attacker with network access can intercept sensitive information (such as credentials, keylogger…
AplazadaAlta (7.8)0.23%—Imonitor EAMAI25/9/20251/10/2026
iMonitor EAM 9.6394 installs a system service (eamusbsrv64.exe) that runs with NT AUTHORITY\SYSTEM privileges. This service includes an insecure update mechanism that automatically loads files placed in the C:\sysupdate\ directory during startup. Because any local user can create and write to this directory, an…
AplazadaMedia (4.4)0.28%—Activewebsight SEO Backlink MonitorAI22/9/202517/6/2026
Server-Side Request Forgery (SSRF) vulnerability in activewebsight SEO Backlink Monitor seo-backlink-monitor allows Server Side Request Forgery.This issue affects SEO Backlink Monitor: from n/a through <= 1.8.0.
AplazadaMedia (4.3)0.17%—Activewebsight SEO Backlink MonitorAI22/9/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in activewebsight SEO Backlink Monitor seo-backlink-monitor allows Cross Site Request Forgery.This issue affects SEO Backlink Monitor: from n/a through <= 1.8.0.
AnalizadaMedia (5.5)0.42%—Emiloi E-logbook With Health Monitoring System FOR Covid-1918/9/202517/6/2026
A flaw has been found in itsourcecode E-Logbook with Health Monitoring System for COVID-19 1.0. This issue affects some unknown processing of the file /check_profile.php. Executing manipulation of the argument profile_id can lead to sql injection. It is possible to launch the attack remotely. The exploit has been…
AnalizadaBaja (2.1)0.35%—Emiloi E-logbook With Health Monitoring System FOR Covid-1917/9/202525/9/2026
A vulnerability was determined in itsourcecode E-Logbook with Health Monitoring System for COVID-19 1.0 on COVID. This affects an unknown function of the file /print_reports_prev.php. Executing manipulation of the argument profile_id can lead to cross site scripting. It is possible to launch the attack remotely. The…