Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

358 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)1.5%—DTS Monitoring3/10/202317/6/2026
An issue was discovered in DTS Monitoring 3.57.0. The parameter port within the SSL Certificate check function is vulnerable to OS command injection (blind).
ModificadaMedia (6.7)0.30%💥 PoCAMD Ryzen MasterAMD Ryzen Master Monitoring SDK15/8/202317/6/2026
Insufficient validation in the IOCTL (Input Output Control) input buffer in AMD Ryzen™ Master may permit a privileged attacker to perform memory reads/writes potentially leading to a loss of confidentiality or arbitrary kernel execution.
ModificadaMedia (4.4)0.22%—AMD Ryzen MasterAMD Ryzen Master Monitoring SDK15/8/202317/6/2026
Insufficient validation of the IOCTL (Input Output Control) input buffer in AMD Ryzen™ Master may allow a privileged attacker to provide a null value potentially resulting in a Windows crash leading to denial of service.
ModificadaAlta (7.5)0.92%—Cdwanjiang Flash Flood Disaster Monitoring AND Warning System5/8/202317/6/2026
A vulnerability, which was classified as problematic, has been found in Chengdu Flash Flood Disaster Monitoring and Warning System 2.0. This issue affects some unknown processing of the file \Service\FileHandler.ashx. The manipulation of the argument FileDirectory leads to absolute path traversal. The attack may be…
ModificadaMedia (5.3)1.1%—Cdwanjiang Flash Flood Disaster Monitoring AND Warning System5/8/202317/6/2026
A vulnerability classified as problematic was found in Chengdu Flash Flood Disaster Monitoring and Warning System 2.0. This vulnerability affects unknown code of the file \Service\FileDownload.ashx. The manipulation of the argument Files leads to path traversal: '../filedir'. The attack can be initiated remotely. The…
ModificadaCrítica (9.8)0.90%—Cdwanjiang Flash Flood Disaster Monitoring AND Warning System21/7/202317/6/2026
A vulnerability classified as problematic was found in Chengdu Flash Flood Disaster Monitoring and Warning System 2.0. This vulnerability affects unknown code of the file /Service/FileHandler.ashx. The manipulation of the argument userFile leads to unrestricted upload. The exploit has been disclosed to the public and…
ModificadaBaja (3.7)0.67%—Cdwanjiang Flash Flood Disaster Monitoring AND Warning System21/7/202317/6/2026
A vulnerability classified as problematic has been found in Chengdu Flash Flood Disaster Monitoring and Warning System 2.0. This affects an unknown part of the file /Service/ImageStationDataService.asmx of the component File Name Handler. The manipulation leads to insufficiently random values. The complexity of an…
ModificadaCrítica (9.8)0.95%—Cdwanjiang Flash Flood Disaster Monitoring AND Warning System21/7/202317/6/2026
A vulnerability was found in Chengdu Flash Flood Disaster Monitoring and Warning System 2.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /Controller/Ajaxfileupload.ashx. The manipulation of the argument file leads to unrestricted upload. The exploit has been…
ModificadaCrítica (9.8)0.89%—Cdwanjiang Flash Flood Disaster Monitoring AND Warning System20/7/202317/6/2026
A vulnerability has been found in Chengdu Flash Flood Disaster Monitoring and Warning System 2.0 and classified as critical. This vulnerability affects unknown code of the file /App_Resource/UEditor/server/upload.aspx. The manipulation of the argument file leads to unrestricted upload. The exploit has been disclosed…
ModificadaAlta (8.8)0.88%—Istrong Four Mountain Torrent Disaster Prevention, Control Monitoring AND Early Warning System20/7/202317/6/2026
A vulnerability, which was classified as critical, was found in Gen Technology Four Mountain Torrent Disaster Prevention and Control of Monitoring and Early Warning System up to 20230712. This affects an unknown part of the file /Duty/AjaxHandle/UploadFloodPlanFileUpdate.ashx. The manipulation of the argument Filedata…
ModificadaCrítica (9.8)0.96%—Istrong Mountain Flood Disaster Prevention Monitoring AND Early Warning System11/7/202317/6/2026
A vulnerability, which was classified as critical, has been found in Suncreate Mountain Flood Disaster Prevention Monitoring and Early Warning System up to 20230706. This issue affects some unknown processing of the file /Duty/AjaxHandle/UpLoadFloodPlanFile.ashx of the component UpLoadFloodPlanFile. The manipulation…
ModificadaCrítica (9.8)0.96%—Istrong Mountain Flood Disaster Prevention Monitoring AND Early Warning System11/7/202317/6/2026
A vulnerability classified as critical was found in Suncreate Mountain Flood Disaster Prevention Monitoring and Early Warning System up to 20230706. This vulnerability affects unknown code of the file /Duty/AjaxHandle/Write/UploadFile.ashx of the component Duty Write-UploadFile. The manipulation of the argument…
ModificadaCrítica (9.8)0.91%—Istrong Mountain Flood Disaster Prevention Monitoring AND Early Warning System11/7/202317/6/2026
A vulnerability was found in Suncreate Mountain Flood Disaster Prevention Monitoring and Early Warning System up to 20230704. It has been rated as critical. Affected by this issue is some unknown functionality of the file /Duty/AjaxHandle/UploadHandler.ashx of the component Duty Module. The manipulation of the…
ModificadaCrítica (9.8)1.3%—Percona Monitoring AND Management6/6/202317/6/2026
In Percona Monitoring and Management (PMM) server 2.x before 2.37.1, the authenticate function in auth_server.go does not properly formalize and sanitize URL paths to reject path traversal attempts. This allows an unauthenticated remote user, when a crafted POST request is made against unauthenticated API routes, to…
ModificadaCrítica (9.8)0.80%—Erikogluteknoloji Energy Monitoring2/6/202317/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Erikoglu Technology ErMon allows Command Line Execution through SQL Injection, Authentication Bypass. This issue affects ErMon: before 230602.
AnalizadaAlta (7.1)0.17%—F5 Nginx API Connectivity ManagerF5 Nginx Instance ManagerF5 Nginx Security Monitoring3/5/202317/6/2026
NGINX Management Suite default file permissions are set such that an authenticated attacker may be able to modify sensitive files on NGINX Instance Manager and NGINX API Connectivity Manager. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
AnalizadaAlta (8.1)0.53%—Netapp Cloud BackupNetapp Ontap Select DeployF5 Nginx API Connectivity ManagerF5 Nginx Instance Manager+13/5/202317/6/2026
NGINX Management Suite may allow an authenticated attacker to gain access to configuration objects outside of their assigned environment. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
ModificadaAlta (7.5)0.71%—Schneider-electric APC Easy UPS Online Monitoring SoftwareSchneider-electric Easy UPS Online Monitoring Software18/4/202317/6/2026
A CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause Denial-of-Service when accessed by an unauthenticated user on the Schneider UPS Monitor service.
ModificadaCrítica (9.8)1.2%—Schneider-electric APC Easy UPS Online Monitoring SoftwareSchneider-electric Easy UPS Online Monitoring Software18/4/202317/6/2026
CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause remote code execution when manipulating internal methods through Java RMI interface.
ModificadaCrítica (9.8)1.3%—Schneider-electric APC Easy UPS Online Monitoring SoftwareSchneider-electric Easy UPS Online Monitoring Software18/4/202317/6/2026
A CWE-306: Missing Authentication for Critical Function vulnerability exists that could allow changes to administrative credentials, leading to potential remote code execution without requiring prior authentication on the Java RMI interface.
ModificadaAlta (8.8)0.32%—Schneider-electric Ecostruxure Power Monitoring Expert18/4/202317/6/2026
A CWE-613: Insufficient Session Expiration vulnerability exists that could allow an attacker to maintain unauthorized access over a hijacked session in PME after the legitimate user has signed out of their account.
ModificadaCrítica (9.8)0.74%—Phpgurukul BP Monitoring Management System8/4/202317/6/2026
A vulnerability has been found in PHPGurukul BP Monitoring Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file password-recovery.php of the component Password Recovery. The manipulation of the argument emailid/contactno leads to sql injection. The…
ModificadaCrítica (9.8)0.71%—Phpgurukul BP Monitoring Management System8/4/202317/6/2026
A vulnerability, which was classified as critical, was found in PHPGurukul BP Monitoring Management System 1.0. Affected is an unknown function of the file change-password.php of the component Change Password Handler. The manipulation of the argument password leads to sql injection. It is possible to launch the attack…
ModificadaMedia (6.1)0.56%—Phpgurukul BP Monitoring Management System8/4/202317/6/2026
A vulnerability, which was classified as problematic, has been found in PHPGurukul BP Monitoring Management System 1.0. This issue affects some unknown processing of the file add-family-member.php of the component Add New Family Member Handler. The manipulation of the argument Member Name leads to cross site…
ModificadaMedia (6.5)0.63%—Phpgurukul BP Monitoring Management System7/4/202317/6/2026
A vulnerability, which was classified as critical, was found in PHPGurukul BP Monitoring Management System 1.0. Affected is an unknown function of the file profile.php of the component User Profile Update Handler. The manipulation of the argument name/mobno leads to sql injection. It is possible to launch the attack…