Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
–

967 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaBaja (2.1)0.45%—Phpgurukul BP Monitoring Management System25/7/202517/6/2026
A vulnerability classified as critical was found in PHPGurukul BP Monitoring Management System 1.0. This vulnerability affects unknown code of the file /bwdates-report-result.php. The manipulation of the argument fromdate/todate leads to sql injection. The attack can be initiated remotely. The exploit has been…
AnalizadaMedia (6.5)0.24%—Softperfect Connection Quality Monitor24/7/202517/6/2026
SoftPerfect Pty Ltd Connection Quality Monitor v1.1 was discovered to store all credentials in plaintext.
AplazadaMedia (6.8)0.27%—Medtronic Mycareelink Patient MonitorAI24/7/202517/6/2026
Medtronic MyCareLink Patient Monitor has a built-in user account with an empty password, which allows an attacker with physical access to log in with no password and access modify system functionality. This issue affects MyCareLink Patient Monitor models 24950 and 24952: before June 25, 2025
AplazadaMedia (6.8)0.19%—Medtronic Mycarelink Patient MonitorAI24/7/202517/6/2026
Medtronic MyCareLink Patient Monitor uses an unencrypted filesystem on internal storage, which allows an attacker with physical access to read and modify files. This issue affects MyCareLink Patient Monitor models 24950 and 24952: before June 25, 2025
AplazadaMedia (6.5)0.17%—Medtronic Mycarelink Patient MonitorAI24/7/202517/6/2026
Medtronic MyCareLink Patient Monitor has an internal service that deserializes data, which allows a local attacker to interact with the service by crafting a binary payload to crash the service or elevate privileges. This issue affects MyCareLink Patient Monitor models 24950 and 24952: before June 25, 2025
AplazadaAlta (7.1)0.29%—Turpak Automatic Station Monitoring SystemAI21/7/202517/6/2026
Authorization Bypass Through User-Controlled Key vulnerability in Turpak Automatic Station Monitoring System allows Privilege Escalation. This issue affects Automatic Station Monitoring System: before 5.0.6.51.
AplazadaAlta (8.7)0.36%—Leviton AcquisuiteAILeviton Energy Monitoring HUBAI18/7/202517/6/2026
Leviton AcquiSuite and Energy Monitoring Hub are susceptible to a cross-site scripting vulnerability, allowing an attacker to craft a malicious payload in URL parameters, which would execute in a client browser when accessed by a user, steal session tokens, and control the service.
AplazadaCrítica (9.3)2.6%💥 ExploitIdera Up.time Monitoring StationAI16/7/202517/6/2026
An unauthenticated arbitrary file upload vulnerability exists in Idera Up.Time Monitoring Station versions up to and including 7.2. The `wizards/post2file.php` script accepts arbitrary POST parameters, allowing attackers to upload crafted PHP files to the webroot. Successful exploitation results in remote code…
AplazadaAlta (8.7)3.5%💥 ExploitOP5 MonitorAI15/7/20258/9/2026
An authenticated command injection vulnerability exists in OP5 Monitor through version 7.1.9 via the 'cmd_str' parameter in the command_test.php endpoint. A user with access to the web interface can exploit the 'Test this command' feature to execute arbitrary shell commands as the unprivileged web application user.…
AnalizadaAlta (7.5)0.96%—Microsoft Azure Monitor Agent8/7/202517/6/2026
Improper control of generation of code ('code injection') in Azure Monitor Agent allows an unauthorized attacker to execute code over an adjacent network.
AnalizadaBaja (1.2)0.52%—Monitorr4/7/202517/6/2026
A vulnerability was found in Monitorr up to 1.7.6m. It has been classified as problematic. This affects an unknown part of the file assets/config/_installation/mkdbajax.php of the component Installer. The manipulation of the argument datadir leads to improper input validation. It is possible to initiate the attack…
AplazadaMedia (6.5)0.45%—Asna RegistrarAIAsna Datagate FOR SQL ServerAIAsna Datagate Component SuiteAIAsna Datagate MonitorAI+133/7/202517/6/2026
ASNA Assist and ASNA Registrar before 2025-03-31 allow deserialization attacks against .NET remoting. These are Windows system services that support license key management and deprecated Windows network authentication. The services are implemented with .NET remoting and can be exploited via well-known deserialization…
ModificadaMedia (5.4)0.27%—Melapress File Monitor3/7/202517/6/2026
Missing Authorization vulnerability in Melapress Melapress File Monitor website-file-changes-monitor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Melapress File Monitor: from n/a through < 2.2.0.
AplazadaMedia (5.3)0.46%💥 PoCTraffic MonitorAI13/6/202517/6/2026
The Traffic Monitor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the tfcm_maybe_set_bot_flags() function in all versions up to, and including, 3.2.2. This makes it possible for unauthenticated attackers to disabled bot logging.
AplazadaMedia (5.5)0.47%—Egauge Eg3000 Energy MonitorAI9/6/202517/6/2026
A vulnerability was found in eGauge EG3000 Energy Monitor 3.6.3. It has been classified as problematic. This affects an unknown part of the component Setting Handler. The manipulation leads to missing authentication. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may…
AnalizadaMedia (5.5)0.55%—Phpgurukul BP Monitoring Management System9/6/202517/6/2026
A vulnerability has been found in PHPGurukul BP Monitoring Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /registration.php. The manipulation of the argument emailid leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to…
AnalizadaBaja (2.1)0.42%—Phpgurukul BP Monitoring Management System6/6/202517/6/2026
A vulnerability, which was classified as critical, has been found in PHPGurukul BP Monitoring Management System 1.0. This issue affects some unknown processing of the file /edit-family-member.php. The manipulation of the argument memberage leads to sql injection. The attack may be initiated remotely. The exploit has…
AnalizadaCrítica (9.8)1.0%—IBM Tivoli Monitoring28/5/202517/6/2026
IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 19 could allow a remote attacker to execute arbitrary code due to improper validation of an index value of a dynamically allocated array.
AnalizadaAlta (7.8)0.16%—Tenable Nessus Network Monitor23/5/202517/6/2026
In Tenable Network Monitor versions prior to 6.5.1 on a Windows host, it was found that a non-administrative user could stage files in a local directory to run arbitrary code with SYSTEM privileges, potentially leading to local privilege escalation.
AnalizadaAlta (7.8)0.15%—Tenable Nessus Network Monitor23/5/202517/6/2026
When installing Tenable Network Monitor to a non-default location on a Windows host, Tenable Network Monitor versions prior to 6.5.1 did not enforce secure permissions for sub-directories. This could allow for local privilege escalation if users had not secured the directories in the non-default installation location.
AplazadaMedia (6.1)0.14%—ALT MonitoringAI17/5/202517/6/2026
The AlT Monitoring plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.3. This is due to missing or incorrect nonce validation on the 'ALT_Monitoring_edit' page. This makes it possible for unauthenticated attackers to update settings and inject malicious web…
AnalizadaMedia (5.4)0.33%—Melapress File Monitor15/5/202517/6/2026
The Melapress File Monitor WordPress plugin before 2.1.1 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks
AnalizadaMedia (4.1)0.40%—Melapress File Monitor15/5/202517/6/2026
The Melapress File Monitor WordPress plugin before 2.1.0 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks
AplazadaMedia (5.1)0.69%💥 ExploitRicoh WEB Image MonitorAI12/5/202517/6/2026
Reflected cross-site scripting vulnerability exists in the laser printers and MFPs (multifunction printers) which implement Ricoh Web Image Monitor. If exploited, an arbitrary script may be executed on the web browser of the user who accessed Web Image Monitor. As for the details of affected product names and…
AplazadaAlta (7.5)0.80%—Wpchill Download MonitorAI7/5/202517/6/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WP Chill Download Monitor download-monitor allows PHP Local File Inclusion.This issue affects Download Monitor: from n/a through <= 5.0.22.
Orbitaley — Vulnerabilidades