Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
967 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (2.1) | 0.45% | — | Phpgurukul BP Monitoring Management System | 25/7/2025 | 17/6/2026 | A vulnerability classified as critical was found in PHPGurukul BP Monitoring Management System 1.0. This vulnerability affects unknown code of the file /bwdates-report-result.php. The manipulation of the argument fromdate/todate leads to sql injection. The attack can be initiated remotely. The exploit has been… | |
| Analizada | Media (6.5) | 0.24% | — | Softperfect Connection Quality Monitor | 24/7/2025 | 17/6/2026 | SoftPerfect Pty Ltd Connection Quality Monitor v1.1 was discovered to store all credentials in plaintext. | |
| Aplazada | Media (6.8) | 0.27% | — | Medtronic Mycareelink Patient MonitorAI | 24/7/2025 | 17/6/2026 | Medtronic MyCareLink Patient Monitor has a built-in user account with an empty password, which allows an attacker with physical access to log in with no password and access modify system functionality. This issue affects MyCareLink Patient Monitor models 24950 and 24952: before June 25, 2025 | |
| Aplazada | Media (6.8) | 0.19% | — | Medtronic Mycarelink Patient MonitorAI | 24/7/2025 | 17/6/2026 | Medtronic MyCareLink Patient Monitor uses an unencrypted filesystem on internal storage, which allows an attacker with physical access to read and modify files. This issue affects MyCareLink Patient Monitor models 24950 and 24952: before June 25, 2025 | |
| Aplazada | Media (6.5) | 0.17% | — | Medtronic Mycarelink Patient MonitorAI | 24/7/2025 | 17/6/2026 | Medtronic MyCareLink Patient Monitor has an internal service that deserializes data, which allows a local attacker to interact with the service by crafting a binary payload to crash the service or elevate privileges. This issue affects MyCareLink Patient Monitor models 24950 and 24952: before June 25, 2025 | |
| Aplazada | Alta (7.1) | 0.29% | — | Turpak Automatic Station Monitoring SystemAI | 21/7/2025 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Turpak Automatic Station Monitoring System allows Privilege Escalation. This issue affects Automatic Station Monitoring System: before 5.0.6.51. | |
| Aplazada | Alta (8.7) | 0.36% | — | Leviton AcquisuiteAILeviton Energy Monitoring HUBAI | 18/7/2025 | 17/6/2026 | Leviton AcquiSuite and Energy Monitoring Hub are susceptible to a cross-site scripting vulnerability, allowing an attacker to craft a malicious payload in URL parameters, which would execute in a client browser when accessed by a user, steal session tokens, and control the service. | |
| Aplazada | Crítica (9.3) | 2.6% | 💥 Exploit | Idera Up.time Monitoring StationAI | 16/7/2025 | 17/6/2026 | An unauthenticated arbitrary file upload vulnerability exists in Idera Up.Time Monitoring Station versions up to and including 7.2. The `wizards/post2file.php` script accepts arbitrary POST parameters, allowing attackers to upload crafted PHP files to the webroot. Successful exploitation results in remote code… | |
| Aplazada | Alta (8.7) | 3.5% | 💥 Exploit | OP5 MonitorAI | 15/7/2025 | 8/9/2026 | An authenticated command injection vulnerability exists in OP5 Monitor through version 7.1.9 via the 'cmd_str' parameter in the command_test.php endpoint. A user with access to the web interface can exploit the 'Test this command' feature to execute arbitrary shell commands as the unprivileged web application user.… | |
| Analizada | Alta (7.5) | 0.96% | — | Microsoft Azure Monitor Agent | 8/7/2025 | 17/6/2026 | Improper control of generation of code ('code injection') in Azure Monitor Agent allows an unauthorized attacker to execute code over an adjacent network. | |
| Analizada | Baja (1.2) | 0.52% | — | Monitorr | 4/7/2025 | 17/6/2026 | A vulnerability was found in Monitorr up to 1.7.6m. It has been classified as problematic. This affects an unknown part of the file assets/config/_installation/mkdbajax.php of the component Installer. The manipulation of the argument datadir leads to improper input validation. It is possible to initiate the attack… | |
| Aplazada | Media (6.5) | 0.45% | — | Asna RegistrarAIAsna Datagate FOR SQL ServerAIAsna Datagate Component SuiteAIAsna Datagate MonitorAI+13 | 3/7/2025 | 17/6/2026 | ASNA Assist and ASNA Registrar before 2025-03-31 allow deserialization attacks against .NET remoting. These are Windows system services that support license key management and deprecated Windows network authentication. The services are implemented with .NET remoting and can be exploited via well-known deserialization… | |
| Modificada | Media (5.4) | 0.27% | — | Melapress File Monitor | 3/7/2025 | 17/6/2026 | Missing Authorization vulnerability in Melapress Melapress File Monitor website-file-changes-monitor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Melapress File Monitor: from n/a through < 2.2.0. | |
| Aplazada | Media (5.3) | 0.46% | 💥 PoC | Traffic MonitorAI | 13/6/2025 | 17/6/2026 | The Traffic Monitor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the tfcm_maybe_set_bot_flags() function in all versions up to, and including, 3.2.2. This makes it possible for unauthenticated attackers to disabled bot logging. | |
| Aplazada | Media (5.5) | 0.47% | — | Egauge Eg3000 Energy MonitorAI | 9/6/2025 | 17/6/2026 | A vulnerability was found in eGauge EG3000 Energy Monitor 3.6.3. It has been classified as problematic. This affects an unknown part of the component Setting Handler. The manipulation leads to missing authentication. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may… | |
| Analizada | Media (5.5) | 0.55% | — | Phpgurukul BP Monitoring Management System | 9/6/2025 | 17/6/2026 | A vulnerability has been found in PHPGurukul BP Monitoring Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /registration.php. The manipulation of the argument emailid leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to… | |
| Analizada | Baja (2.1) | 0.42% | — | Phpgurukul BP Monitoring Management System | 6/6/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in PHPGurukul BP Monitoring Management System 1.0. This issue affects some unknown processing of the file /edit-family-member.php. The manipulation of the argument memberage leads to sql injection. The attack may be initiated remotely. The exploit has… | |
| Analizada | Crítica (9.8) | 1.0% | — | IBM Tivoli Monitoring | 28/5/2025 | 17/6/2026 | IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 19 could allow a remote attacker to execute arbitrary code due to improper validation of an index value of a dynamically allocated array. | |
| Analizada | Alta (7.8) | 0.16% | — | Tenable Nessus Network Monitor | 23/5/2025 | 17/6/2026 | In Tenable Network Monitor versions prior to 6.5.1 on a Windows host, it was found that a non-administrative user could stage files in a local directory to run arbitrary code with SYSTEM privileges, potentially leading to local privilege escalation. | |
| Analizada | Alta (7.8) | 0.15% | — | Tenable Nessus Network Monitor | 23/5/2025 | 17/6/2026 | When installing Tenable Network Monitor to a non-default location on a Windows host, Tenable Network Monitor versions prior to 6.5.1 did not enforce secure permissions for sub-directories. This could allow for local privilege escalation if users had not secured the directories in the non-default installation location. | |
| Aplazada | Media (6.1) | 0.14% | — | ALT MonitoringAI | 17/5/2025 | 17/6/2026 | The AlT Monitoring plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.3. This is due to missing or incorrect nonce validation on the 'ALT_Monitoring_edit' page. This makes it possible for unauthenticated attackers to update settings and inject malicious web… | |
| Analizada | Media (5.4) | 0.33% | — | Melapress File Monitor | 15/5/2025 | 17/6/2026 | The Melapress File Monitor WordPress plugin before 2.1.1 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks | |
| Analizada | Media (4.1) | 0.40% | — | Melapress File Monitor | 15/5/2025 | 17/6/2026 | The Melapress File Monitor WordPress plugin before 2.1.0 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks | |
| Aplazada | Media (5.1) | 0.69% | 💥 Exploit | Ricoh WEB Image MonitorAI | 12/5/2025 | 17/6/2026 | Reflected cross-site scripting vulnerability exists in the laser printers and MFPs (multifunction printers) which implement Ricoh Web Image Monitor. If exploited, an arbitrary script may be executed on the web browser of the user who accessed Web Image Monitor. As for the details of affected product names and… | |
| Aplazada | Alta (7.5) | 0.80% | — | Wpchill Download MonitorAI | 7/5/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WP Chill Download Monitor download-monitor allows PHP Local File Inclusion.This issue affects Download Monitor: from n/a through <= 5.0.22. |