Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
1029 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.45% | — | Asna RegistrarAIAsna Datagate FOR SQL ServerAIAsna Datagate Component SuiteAIAsna Datagate MonitorAI+13 | 3/7/2025 | 17/6/2026 | ASNA Assist and ASNA Registrar before 2025-03-31 allow deserialization attacks against .NET remoting. These are Windows system services that support license key management and deprecated Windows network authentication. The services are implemented with .NET remoting and can be exploited via well-known deserialization… | |
| Modificada | Media (5.4) | 0.27% | — | Melapress File Monitor | 3/7/2025 | 17/6/2026 | Missing Authorization vulnerability in Melapress Melapress File Monitor website-file-changes-monitor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Melapress File Monitor: from n/a through < 2.2.0. | |
| Aplazada | Media (5.3) | 0.46% | 💥 PoC | Traffic MonitorAI | 13/6/2025 | 17/6/2026 | The Traffic Monitor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the tfcm_maybe_set_bot_flags() function in all versions up to, and including, 3.2.2. This makes it possible for unauthenticated attackers to disabled bot logging. | |
| Aplazada | Media (5.5) | 0.47% | — | Egauge Eg3000 Energy MonitorAI | 9/6/2025 | 17/6/2026 | A vulnerability was found in eGauge EG3000 Energy Monitor 3.6.3. It has been classified as problematic. This affects an unknown part of the component Setting Handler. The manipulation leads to missing authentication. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may… | |
| Analizada | Media (5.5) | 0.55% | — | Phpgurukul BP Monitoring Management System | 9/6/2025 | 17/6/2026 | A vulnerability has been found in PHPGurukul BP Monitoring Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /registration.php. The manipulation of the argument emailid leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to… | |
| Analizada | Baja (2.1) | 0.42% | — | Phpgurukul BP Monitoring Management System | 6/6/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in PHPGurukul BP Monitoring Management System 1.0. This issue affects some unknown processing of the file /edit-family-member.php. The manipulation of the argument memberage leads to sql injection. The attack may be initiated remotely. The exploit has… | |
| Analizada | Crítica (9.8) | 1.0% | — | IBM Tivoli Monitoring | 28/5/2025 | 17/6/2026 | IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 19 could allow a remote attacker to execute arbitrary code due to improper validation of an index value of a dynamically allocated array. | |
| Analizada | Alta (7.8) | 0.16% | — | Tenable Nessus Network Monitor | 23/5/2025 | 17/6/2026 | In Tenable Network Monitor versions prior to 6.5.1 on a Windows host, it was found that a non-administrative user could stage files in a local directory to run arbitrary code with SYSTEM privileges, potentially leading to local privilege escalation. | |
| Analizada | Alta (7.8) | 0.15% | — | Tenable Nessus Network Monitor | 23/5/2025 | 17/6/2026 | When installing Tenable Network Monitor to a non-default location on a Windows host, Tenable Network Monitor versions prior to 6.5.1 did not enforce secure permissions for sub-directories. This could allow for local privilege escalation if users had not secured the directories in the non-default installation location. | |
| Analizada | Alta (8.4) | 0.24% | — | Fujielectric Monitouch V-sft | 19/5/2025 | 17/6/2026 | V-SFT v6.2.5.0 and earlier contains an issue with stack-based buffer overflow in VS6MemInIF!set_temp_type_default function. Opening specially crafted V7 or V8 files may lead to crash, information disclosure, and arbitrary code execution. | |
| Analizada | Alta (8.4) | 0.24% | — | Fujielectric Monitouch V-sft | 19/5/2025 | 17/6/2026 | V-SFT v6.2.5.0 and earlier contains an issue with stack-based buffer overflow in VS6ComFile!CV7BaseMap::WriteV7DataToRom function. Opening specially crafted V7 or V8 files may lead to crash, information disclosure, and arbitrary code execution. | |
| Analizada | Alta (8.4) | 0.24% | — | Fujielectric Monitouch V-sft | 19/5/2025 | 17/6/2026 | V-SFT v6.2.5.0 and earlier contains an issue with stack-based buffer overflow in VS6File!CTxSubFile::get_ProgramFile_name function. Opening specially crafted V7 or V8 files may lead to crash, information disclosure, and arbitrary code execution. | |
| Analizada | Alta (8.4) | 0.22% | — | Fujielectric Monitouch V-sft | 19/5/2025 | 17/6/2026 | V-SFT v6.2.5.0 and earlier contains an issue with out-of-bounds read in VS6MemInIF.dll!set_plc_type_default function. Opening specially crafted V7 or V8 files may lead to crash, information disclosure, and arbitrary code execution. | |
| Analizada | Alta (8.4) | 0.22% | — | Fujielectric Monitouch V-sft | 19/5/2025 | 17/6/2026 | V-SFT v6.2.5.0 and earlier contains an issue with out-of-bounds read in VS6EditData!CGamenDataRom::set_mr400_strc function. Opening specially crafted V7 or V8 files may lead to crash, information disclosure, and arbitrary code execution. | |
| Analizada | Alta (8.4) | 0.22% | — | Fujielectric Monitouch V-sft | 19/5/2025 | 17/6/2026 | V-SFT v6.2.5.0 and earlier contains an issue with out-of-bounds read in VS6EditData!VS4_SaveEnvFile function. Opening specially crafted V7 or V8 files may lead to crash, information disclosure, and arbitrary code execution. | |
| Analizada | Alta (8.4) | 0.22% | — | Fujielectric Monitouch V-sft | 19/5/2025 | 17/6/2026 | V-SFT v6.2.5.0 and earlier contains an issue with out-of-bounds read in VS6EditData!Conv_Macro_Data function. Opening specially crafted V7 or V8 files may lead to crash, information disclosure, and arbitrary code execution. | |
| Analizada | Alta (8.4) | 0.22% | — | Fujielectric Monitouch V-sft | 19/5/2025 | 17/6/2026 | V-SFT v6.2.5.0 and earlier contains an issue with out-of-bounds read in VS6EditData!CDrawSLine::GetRectArea function. Opening specially crafted V7 or V8 files may lead to crash, information disclosure, and arbitrary code execution. | |
| Analizada | Alta (8.4) | 0.22% | — | Fujielectric Monitouch V-sft | 19/5/2025 | 17/6/2026 | V-SFT v6.2.5.0 and earlier contains an issue with out-of-bounds write in VS6ComFile!MakeItemGlidZahyou function. Opening specially crafted V7 or V8 files may lead to crash, information disclosure, and arbitrary code execution. | |
| Analizada | Alta (8.4) | 0.22% | — | Fujielectric Monitouch V-sft | 19/5/2025 | 17/6/2026 | V-SFT v6.2.5.0 and earlier contains an issue with out-of-bounds write in VS6EditData!CDataRomErrorCheck::MacroCommandCheck function. Opening specially crafted V7 or V8 files may lead to crash, information disclosure, and arbitrary code execution. | |
| Analizada | Alta (8.4) | 0.22% | — | Fujielectric Monitouch V-sft | 19/5/2025 | 17/6/2026 | V-SFT v6.2.5.0 and earlier contains an issue with out-of-bounds write in VS6MemInIF!set_temp_type_default function. Opening specially crafted V7 or V8 files may lead to crash, information disclosure, and arbitrary code execution. | |
| Analizada | Alta (8.4) | 0.22% | — | Fujielectric Monitouch V-sft | 19/5/2025 | 17/6/2026 | V-SFT v6.2.5.0 and earlier contains an issue with free of pointer not at start of buffer in VS6EditData.dll!CWinFontInf::WinFontMsgCheck function. Opening specially crafted V7 or V8 files may lead to crash, information disclosure, and arbitrary code execution. | |
| Aplazada | Media (6.1) | 0.14% | — | ALT MonitoringAI | 17/5/2025 | 17/6/2026 | The AlT Monitoring plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.3. This is due to missing or incorrect nonce validation on the 'ALT_Monitoring_edit' page. This makes it possible for unauthenticated attackers to update settings and inject malicious web… | |
| Analizada | Media (5.4) | 0.33% | — | Melapress File Monitor | 15/5/2025 | 17/6/2026 | The Melapress File Monitor WordPress plugin before 2.1.1 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks | |
| Analizada | Media (4.1) | 0.40% | — | Melapress File Monitor | 15/5/2025 | 17/6/2026 | The Melapress File Monitor WordPress plugin before 2.1.0 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks | |
| Aplazada | Media (5.1) | 0.69% | 💥 Exploit | Ricoh WEB Image MonitorAI | 12/5/2025 | 17/6/2026 | Reflected cross-site scripting vulnerability exists in the laser printers and MFPs (multifunction printers) which implement Ricoh Web Image Monitor. If exploited, an arbitrary script may be executed on the web browser of the user who accessed Web Image Monitor. As for the details of affected product names and… |