Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
1029 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (2.1) | 0.36% | — | Emiloi E-logbook With Health Monitoring System FOR Covid-19 | 14/9/2025 | 17/6/2026 | A vulnerability was detected in itsourcecode E-Logbook with Health Monitoring System for COVID-19 1.0. This issue affects some unknown processing of the file /stc-log-keeper/check_profile.php of the component POST Request Handler. The manipulation of the argument profile_id results in cross site scripting. The attack… | |
| Analizada | Media (5.5) | 0.53% | — | Emiloi E-logbook With Health Monitoring System FOR Covid-19 | 9/9/2025 | 17/6/2026 | A security vulnerability has been detected in itsourcecode E-Logbook with Health Monitoring System for COVID-19 1.0. The affected element is an unknown function of the file /login.php. The manipulation of the argument Username leads to sql injection. The attack is possible to be carried out remotely. The exploit has… | |
| Aplazada | Alta (7.1) | 0.13% | — | Wordpress Error Monitoring BY BugsnagAI | 5/9/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Tom Longridge WordPress Error Monitoring by Bugsnag bugsnag allows Stored XSS.This issue affects WordPress Error Monitoring by Bugsnag: from n/a through <= 1.6.3. | |
| Aplazada | Alta (8.4) | 0.17% | — | Ratoc Systems Raid Monitoring ManagerAI | 5/9/2025 | 17/6/2026 | RATOC RAID Monitoring Manager for Windows provided by RATOC Systems, Inc. registers a Windows service with an unquoted file path. A user with the write permission on the root directory of the system drive may execute arbitrary code with SYSTEM privilege. | |
| Analizada | Media (6.9) | 0.11% | — | Oetiker BGP Monitoring | 28/8/2025 | 25/9/2026 | Improper Certificate Validation in Checkmk Exchange plugin BGP Monitoring allows attackers in MitM position to intercept traffic. | |
| Aplazada | Media (6.5) | 0.32% | — | Simple Download MonitorAI | 28/8/2025 | 17/6/2026 | The Simple Download Monitor plugin for WordPress is vulnerable to time-based SQL Injection via the order parameter in all versions up to, and including, 3.9.33 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for… | |
| Aplazada | Media (6.5) | 0.17% | — | Mra13 Simple Download MonitorAI | 27/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mra13 Simple Download Monitor simple-download-monitor allows Stored XSS.This issue affects Simple Download Monitor: from n/a through <= 3.9.34. | |
| Aplazada | Baja (2.1) | 0.34% | — | Acrel Environmental Monitoring Cloud PlatformAI | 18/8/2025 | 17/6/2026 | A vulnerability was identified in Acrel Environmental Monitoring Cloud Platform up to 20250804. This affects an unknown part of the file /NewsManage/UploadNewsImg. The manipulation of the argument File leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the… | |
| Analizada | Media (5.5) | 0.63% | — | Dahuatech Monitoring Platform | 9/8/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in Dinstar Monitoring Platform 甘肃省危险品库监控平台 1.0. Affected is an unknown function of the file /itc/$%7BappPath%7D/login_getPasswordErrorNum.action. The manipulation of the argument userBean.loginName leads to sql injection. It is possible to launch the attack… | |
| Aplazada | Alta (8.6) | 0.21% | — | EG4 Monitoring CenterAI | 8/8/2025 | 17/6/2026 | The affected product allows firmware updates to be downloaded from EG4's website, transferred via USB dongles, or installed through EG4's Monitoring Center (remote, cloud-connected interface) or via a serial connection, and can install these files without integrity checks. The TTComp archive format used for the… | |
| Analizada | Crítica (9.8) | 0.50% | — | IBM Tivoli Monitoring | 6/8/2025 | 17/6/2026 | IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 20 is vulnerable to a heap-based buffer overflow, caused by improper bounds checking. A remote attacker could overflow a buffer and execute arbitrary code on the system or cause the server to crash. | |
| Analizada | Crítica (9.8) | 0.50% | — | IBM Tivoli Monitoring | 6/8/2025 | 17/6/2026 | IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 20 is vulnerable to a heap-based buffer overflow, caused by improper bounds checking. A remote attacker could overflow a buffer and execute arbitrary code on the system or cause the server to crash. | |
| Aplazada | Alta (8.6) | 3.6% | 💥 Exploit | Nagios XI Network MonitorAI | 5/8/2025 | 16/6/2026 | Nagios XI Network Monitor prior to Graph Explorer component version 1.3 contains a command injection vulnerability in `visApi.php`. An authenticated user can inject system commands via unsanitized parameters such as `host`, resulting in remote code execution. | |
| Aplazada | Alta (7.1) | 0.28% | — | Roche Diagnostics Navify MonitoringAI | 5/8/2025 | 17/6/2026 | Improper Input Validation vulnerability in Roche Diagnostics navify Monitoring allows an attacker to manipulate input data, which may lead to a denial of service (DoS) due to negatively impacting the server's performance. This vulnerability has no impact on data confidentiality or integrity. This issue affects navify… | |
| Analizada | Baja (2.1) | 0.45% | — | Phpgurukul BP Monitoring Management System | 25/7/2025 | 17/6/2026 | A vulnerability classified as critical was found in PHPGurukul BP Monitoring Management System 1.0. This vulnerability affects unknown code of the file /bwdates-report-result.php. The manipulation of the argument fromdate/todate leads to sql injection. The attack can be initiated remotely. The exploit has been… | |
| Analizada | Media (6.5) | 0.24% | — | Softperfect Connection Quality Monitor | 24/7/2025 | 17/6/2026 | SoftPerfect Pty Ltd Connection Quality Monitor v1.1 was discovered to store all credentials in plaintext. | |
| Aplazada | Media (6.8) | 0.27% | — | Medtronic Mycareelink Patient MonitorAI | 24/7/2025 | 17/6/2026 | Medtronic MyCareLink Patient Monitor has a built-in user account with an empty password, which allows an attacker with physical access to log in with no password and access modify system functionality. This issue affects MyCareLink Patient Monitor models 24950 and 24952: before June 25, 2025 | |
| Aplazada | Media (6.8) | 0.19% | — | Medtronic Mycarelink Patient MonitorAI | 24/7/2025 | 17/6/2026 | Medtronic MyCareLink Patient Monitor uses an unencrypted filesystem on internal storage, which allows an attacker with physical access to read and modify files. This issue affects MyCareLink Patient Monitor models 24950 and 24952: before June 25, 2025 | |
| Aplazada | Media (6.5) | 0.17% | — | Medtronic Mycarelink Patient MonitorAI | 24/7/2025 | 17/6/2026 | Medtronic MyCareLink Patient Monitor has an internal service that deserializes data, which allows a local attacker to interact with the service by crafting a binary payload to crash the service or elevate privileges. This issue affects MyCareLink Patient Monitor models 24950 and 24952: before June 25, 2025 | |
| Aplazada | Alta (7.1) | 0.29% | — | Turpak Automatic Station Monitoring SystemAI | 21/7/2025 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Turpak Automatic Station Monitoring System allows Privilege Escalation. This issue affects Automatic Station Monitoring System: before 5.0.6.51. | |
| Aplazada | Alta (8.7) | 0.36% | — | Leviton AcquisuiteAILeviton Energy Monitoring HUBAI | 18/7/2025 | 17/6/2026 | Leviton AcquiSuite and Energy Monitoring Hub are susceptible to a cross-site scripting vulnerability, allowing an attacker to craft a malicious payload in URL parameters, which would execute in a client browser when accessed by a user, steal session tokens, and control the service. | |
| Aplazada | Crítica (9.3) | 2.6% | 💥 Exploit | Idera Up.time Monitoring StationAI | 16/7/2025 | 17/6/2026 | An unauthenticated arbitrary file upload vulnerability exists in Idera Up.Time Monitoring Station versions up to and including 7.2. The `wizards/post2file.php` script accepts arbitrary POST parameters, allowing attackers to upload crafted PHP files to the webroot. Successful exploitation results in remote code… | |
| Aplazada | Alta (8.7) | 3.5% | 💥 Exploit | OP5 MonitorAI | 15/7/2025 | 8/9/2026 | An authenticated command injection vulnerability exists in OP5 Monitor through version 7.1.9 via the 'cmd_str' parameter in the command_test.php endpoint. A user with access to the web interface can exploit the 'Test this command' feature to execute arbitrary shell commands as the unprivileged web application user.… | |
| Analizada | Alta (7.5) | 0.96% | — | Microsoft Azure Monitor Agent | 8/7/2025 | 17/6/2026 | Improper control of generation of code ('code injection') in Azure Monitor Agent allows an unauthorized attacker to execute code over an adjacent network. | |
| Analizada | Baja (1.2) | 0.52% | — | Monitorr | 4/7/2025 | 17/6/2026 | A vulnerability was found in Monitorr up to 1.7.6m. It has been classified as problematic. This affects an unknown part of the file assets/config/_installation/mkdbajax.php of the component Installer. The manipulation of the argument datadir leads to improper input validation. It is possible to initiate the attack… |