Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
358 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.3) | 0.55% | — | Oretnom23 Tracking Monitoring Management System | 1/8/2024 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in SourceCodester Tracking Monitoring Management System 1.0. This issue affects some unknown processing of the file /manage_user.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been… | |
| Analizada | Media (5.3) | 0.54% | — | Oretnom23 Tracking Monitoring Management System | 1/8/2024 | 17/6/2026 | A vulnerability classified as critical was found in SourceCodester Tracking Monitoring Management System 1.0. This vulnerability affects unknown code of the file /ajax.php?action=save_establishment. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been… | |
| Analizada | Media (6.9) | 0.37% | — | Oretnom23 Tracking Monitoring Management System | 1/8/2024 | 17/6/2026 | A vulnerability classified as problematic has been found in SourceCodester Tracking Monitoring Management System 1.0. This affects an unknown part of the file /ajax.php. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public… | |
| Analizada | Media (5.3) | 0.45% | — | Oretnom23 Tracking Monitoring Management System | 1/8/2024 | 17/6/2026 | A vulnerability was found in SourceCodester Tracking Monitoring Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /ajax.php?action=save_establishment. The manipulation of the argument name leads to cross site scripting. The attack may be launched… | |
| Analizada | Media (5.3) | 0.58% | — | Remyandrade Electricity Consumption Monitoring Tool | 20/5/2024 | 17/6/2026 | A vulnerability was found in SourceCodester Electricity Consumption Monitoring Tool 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /endpoint/delete-bill.php. The manipulation of the argument bill leads to sql injection. The attack can be initiated remotely. The exploit has… | |
| Analizada | Media (6.5) | 0.40% | — | Dell Storage Monitoring AND ReportingDell Storage Resource Manager | 12/4/2024 | 17/6/2026 | Dell Storage Resource Manager, 4.9.0.0 and below, contain(s) a Session Fixation Vulnerability in SRM Windows Host Agent. An adjacent network unauthenticated attacker could potentially exploit this vulnerability, leading to the hijack of a targeted user's application session. | |
| Aplazada | Crítica (9.8) | 0.74% | — | Vehicle Monitoring Platform Cmsv6AI | 25/3/2024 | 17/6/2026 | Insecure Permissions vulnerability in Vehicle Monitoring platform system CMSV6 v.7.31.0.2 through v.7.32.0.3 allows a remote attacker to escalate privileges via the default password component. | |
| Analizada | Alta (7.8) | 0.99% | — | Microsoft Azure AutomationMicrosoft Azure Automation Update ManagementMicrosoft Azure Security CenterMicrosoft Azure Sentinel+4 | 12/3/2024 | 17/6/2026 | Open Management Infrastructure (OMI) Elevation of Privilege Vulnerability | |
| Analizada | Media (6.1) | 0.41% | — | Remyandrade Barangay Population Monitoring System | 1/3/2024 | 17/6/2026 | A vulnerability was found in SourceCodester Barangay Population Monitoring System up to 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /endpoint/update-resident.php. The manipulation of the argument full_name leads to cross site scripting. The attack may be launched… | |
| Modificada | Crítica (9.8) | 0.81% | — | Rems Barangay Population Monitoring System | 14/2/2024 | 17/6/2026 | Barangay Population Monitoring System 1.0 was discovered to contain a SQL injection vulnerability via the resident parameter at /endpoint/delete-resident.php. | |
| Modificada | Alta (7.5) | 2.2% | 💥 Exploit | Swit WP Sessions Time Monitoring Full Automatic | 26/12/2023 | 17/6/2026 | The WP Sessions Time Monitoring Full Automatic WordPress plugin before 1.0.9 does not sanitize the request URL or query parameters before using them in an SQL query, allowing unauthenticated attackers to extract sensitive data from the database via blind time based SQL injection techniques, or in some cases an… | |
| Modificada | Alta (7.1) | 0.24% | — | Schneider-electric Easy UPS Online Monitoring Software | 14/12/2023 | 17/6/2026 | A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause arbitrary file deletion upon service restart when accessed by a local and low-privileged attacker. | |
| Modificada | Media (5.5) | 0.69% | — | Zohocorp Manageengine Analytics PlusZohocorp Manageengine AppcreatorZohocorp Manageengine Application Control PlusZohocorp Manageengine Browser Security Plus+35 | 15/11/2023 | 17/6/2026 | An information disclosure vulnerability exists in multiple ManageEngine products that can result in encryption keys being exposed. A low-privileged OS user with access to the host where an affected ManageEngine product is installed can view and use the exposed key to decrypt product database passwords. This allows the… | |
| Modificada | Media (6.1) | 0.41% | — | Schneider-electric Ecostruxure Power Monitoring Expert | 15/11/2023 | 17/6/2026 | A CWE-79 Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) vulnerability that could cause a vulnerability leading to a cross site scripting condition where attackers can have a victim’s browser run arbitrary JavaScript when they visit a page containing the injected payload. | |
| Modificada | Media (6.1) | 0.45% | — | Schneider-electric Ecostruxure Power Monitoring Expert | 15/11/2023 | 17/6/2026 | A CWE-601 URL Redirection to Untrusted Site vulnerability exists that could cause an openredirect vulnerability leading to a cross site scripting attack. By providing a URL-encoded input attackers can cause the software’s web application to redirect to the chosen domain after a successful login is performed. | |
| Modificada | Crítica (9.8) | 0.68% | — | CTI Monitoring AND Early Warning System Project CTI Monitoring AND Early Warning System | 27/10/2023 | 17/6/2026 | A vulnerability was found in Shanghai CTI Navigation CTI Monitoring and Early Warning System 2.2. It has been classified as critical. This affects an unknown part of the file /Web/SysManage/UserEdit.aspx. The manipulation of the argument ID leads to sql injection. The exploit has been disclosed to the public and may… | |
| Modificada | Alta (8.8) | 1.1% | — | Esst Monitoring | 17/10/2023 | 17/6/2026 | eSST Monitoring v2.147.1 was discovered to contain a remote code execution (RCE) vulnerability via the file upload function. | |
| Modificada | Crítica (9.8) | 1.2% | — | Esst Monitoring | 17/10/2023 | 17/6/2026 | eSST Monitoring v2.147.1 was discovered to contain a remote code execution (RCE) vulnerability via the Gii code generator component. | |
| Modificada | Alta (7.5) | 0.69% | — | Esst Monitoring | 17/10/2023 | 17/6/2026 | A lack of input sanitizing in the file download feature of eSST Monitoring v2.147.1 allows attackers to execute a path traversal. | |
| Modificada | Crítica (9.8) | 0.92% | — | Schneider-electric Ecostruxure Power Monitoring ExpertSchneider-electric Ecostruxure Power Operation With Advanced ReportsSchneider-electric Ecostruxure Power Scada Operation With Advanced Reports | 4/10/2023 | 17/6/2026 | A CWE-502: Deserialization of untrusted data vulnerability exists that could allow an attacker to execute arbitrary code on the targeted system by sending a specifically crafted packet to the application. | |
| Modificada | Crítica (9.8) | 2.8% | — | DTS Monitoring | 3/10/2023 | 17/6/2026 | An issue was discovered in DTS Monitoring 3.57.0. The parameter url within the WGET check function is vulnerable to OS command injection (blind). | |
| Modificada | Crítica (9.8) | 2.8% | — | DTS Monitoring | 3/10/2023 | 17/6/2026 | An issue was discovered in DTS Monitoring 3.57.0. The parameter ip within the Ping check function is vulnerable to OS command injection (blind). | |
| Modificada | Crítica (9.8) | 1.7% | — | DTS Monitoring | 3/10/2023 | 17/6/2026 | An issue was discovered in DTS Monitoring 3.57.0. The parameter common_name within the SSL Certificate check function is vulnerable to OS command injection (blind). | |
| Modificada | Crítica (9.8) | 2.8% | — | DTS Monitoring | 3/10/2023 | 17/6/2026 | An issue was discovered in DTS Monitoring 3.57.0. The parameter url within the Curl check function is vulnerable to OS command injection (blind). | |
| Modificada | Crítica (9.8) | 2.3% | — | DTS Monitoring | 3/10/2023 | 17/6/2026 | An issue was discovered in DTS Monitoring 3.57.0. The parameter options within the WGET check function is vulnerable to OS command injection (blind). |