Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2783▼ 434 respecto a la semana anterior
Críticas / altas1335▼ 118 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
358 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.56% | — | Monitoring OF Students Cyber Accounts System Project Monitoring OF Students Cyber Accounts System | 18/3/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in SourceCodester Monitoring of Students Cyber Accounts System 1.0. Affected by this issue is some unknown functionality of the file modules/balance/index.php?view=balancelist of the component POST Parameter Handler. The manipulation of the argument… | |
| Modificada | Crítica (9.8) | 0.74% | — | Monitoring OF Students Cyber Accounts System Project Monitoring OF Students Cyber Accounts System | 18/3/2023 | 17/6/2026 | A vulnerability classified as critical was found in SourceCodester Monitoring of Students Cyber Accounts System 1.0. Affected by this vulnerability is an unknown functionality of the file login.php of the component POST Parameter Handler. The manipulation of the argument un leads to sql injection. The attack can be… | |
| Modificada | Crítica (9.8) | 0.62% | — | Phpgurukul BP Monitoring Management System | 14/3/2023 | 17/6/2026 | BP Monitoring Management System v1.0 was discovered to contain a SQL injection vulnerability via the emailid parameter in the login page. | |
| Modificada | Alta (7.5) | 1.1% | — | Hitachienergy Sys600 FirmwareHitachienergy Rtu500 FirmwareHitachienergy Reb500 FirmwareHitachienergy Pwc600 Firmware+9 | 21/2/2023 | 17/6/2026 | A vulnerability exists in the IEC 61850 communication stack that affects multiple Hitachi Energy products. An attacker could exploit the vulnerability by using a specially crafted message sequence, to force the IEC 61850 MMS-server communication stack, to stop accepting new MMS-client connections. Already… | |
| Modificada | Alta (8.8) | 0.53% | — | IBM Cloud PAK FOR Multicloud Management Monitoring | 8/2/2023 | 17/6/2026 | IBM Cloud Pak for Multicloud Management Monitoring 2.0 and 2.3 allows users without admin roles access to admin functions by specifying direct URL paths. IBM X-Force ID: 238210. | |
| Modificada | Alta (7.8) | 0.16% | — | Schneider-electric APC Easy UPS Online Monitoring SoftwareSchneider-electric Easy UPS Online Monitoring Software | 1/2/2023 | 17/6/2026 | A CWE-798: Use of Hard-coded Credentials vulnerability exists that could cause local privilege escalation when local attacker connects to the database. Affected Products: APC Easy UPS Online Monitoring Software (Windows 7, 10, 11 & Windows Server 2016, 2019, 2022 - Versions prior to V2.5-GA), APC Easy UPS Online… | |
| Modificada | Alta (7.8) | 0.18% | — | Schneider-electric APC Easy UPS Online Monitoring SoftwareSchneider-electric Easy UPS Online Monitoring Software | 1/2/2023 | 17/6/2026 | A CWE-732: Incorrect Permission Assignment for Critical Resource vulnerability exists that could cause local privilege escalation when a local attacker modifies the webroot directory. Affected Products: APC Easy UPS Online Monitoring Software (Windows 7, 10, 11 & Windows Server 2016, 2019, 2022 - Versions prior to… | |
| Modificada | Crítica (9.8) | 1.1% | — | Schneider-electric APC Easy UPS Online Monitoring SoftwareSchneider-electric Easy UPS Online Monitoring Software | 1/2/2023 | 17/6/2026 | A CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists that could cause remote code execution when the attacker uploads a malicious JSP file. Affected Products: APC Easy UPS Online Monitoring Software (Windows 7, 10, 11 & Windows Server 2016, 2019, 2022 - Versions prior to V2.5-GA), APC Easy… | |
| Modificada | Crítica (9.8) | 0.71% | — | Schneider-electric APC Easy UPS Online Monitoring SoftwareSchneider-electric Easy UPS Online Monitoring Software | 1/2/2023 | 17/6/2026 | A CWE-306: Missing Authentication for Critical Function The software does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources. Affected Products: APC Easy UPS Online Monitoring Software (Windows 7, 10, 11 & Windows Server 2016, 2019,… | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Zohocorp Manageengine Access Manager PlusZohocorp Manageengine Ad360Zohocorp Manageengine Adaudit PlusZohocorp Manageengine Admanager Plus+18 | 18/1/2023 | 31/7/2026 | Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache Santuario xmlsec (aka XML Security for Java) 1.4.1, because the xmlsec XSLT features, by design in that version, make the application responsible for certain security protections,… | |
| Modificada | Baja (3.3) | 0.51% | — | Grafana Synthetic Monitoring Agent | 30/11/2022 | 17/6/2026 | The Synthetic Monitoring Agent for Grafana's Synthetic Monitoring application provides probe functionality and executes network checks for monitoring remote targets. Users running the Synthetic Monitoring agent prior to version 0.12.0 in their local network are impacted. The authentication token used to communicate… | |
| Modificada | Crítica (9.8) | 0.37% | — | Eaton Foreseer Electrical Power Monitoring System | 28/10/2022 | 17/6/2026 | A security vulnerability was discovered in the Eaton Foreseer EPMS software. Foreseer EPMS connects an operation’s vast array of devices to assist in the reduction of energy consumption and avoid unplanned downtime caused by the failures of critical systems. A threat actor may upload arbitrary files using the file… | |
| Modificada | Crítica (9.8) | 2.3% | 💥 PoC | Shinken-monitoring Shinken Monitoring | 20/10/2022 | 17/6/2026 | Shinken Solutions Shinken Monitoring Version 2.4.3 affected is vulnerable to Incorrect Access Control. The SafeUnpickler class found in shinken/safepickle.py implements a weak authentication scheme when unserializing objects passed from monitoring nodes to the Shinken monitoring server. | |
| Modificada | Media (6.1) | 0.43% | — | Gavazziautomation CPY CAR Park ServerGavazziautomation UWP 3.0 Monitoring Gateway AND Controller Firmware | 28/9/2022 | 17/6/2026 | In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 the Sentilo Proxy is prone to reflected XSS which only affects the Sentilo service. | |
| Modificada | Baja (2.7) | 0.53% | — | Gavazziautomation CPY CAR Park ServerGavazziautomation UWP 3.0 Monitoring Gateway AND Controller Firmware | 28/9/2022 | 17/6/2026 | In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 the Sentilo Proxy server was discovered to contain a SQL injection vulnerability allowing an attacker to query other tables of the Sentilo service. | |
| Modificada | Crítica (9.8) | 1.3% | — | Gavazziautomation CPY CAR Park ServerGavazziautomation UWP 3.0 Monitoring Gateway AND Controller Firmware | 28/9/2022 | 17/6/2026 | Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 was discovered to be vulnerable to a relative path traversal vulnerability which enables remote attackers to read arbitrary files and gain full control of the device. | |
| Modificada | Alta (7.5) | 1.0% | — | Gavazziautomation CPY CAR Park ServerGavazziautomation UWP 3.0 Monitoring Gateway AND Controller Firmware | 28/9/2022 | 17/6/2026 | In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 a remote, unauthenticated attacker could make use of an SQL-injection to gain access to a volatile temporary database with the current states of the device. | |
| Modificada | Crítica (9.8) | 1.0% | — | Gavazziautomation CPY CAR Park ServerGavazziautomation UWP 3.0 Monitoring Gateway AND Controller Firmware | 28/9/2022 | 17/6/2026 | In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 a remote, unauthenticated attacker could make use of hard-coded credentials to gain SuperUser access to the device. | |
| Modificada | Crítica (9.8) | 1.2% | — | Gavazziautomation CPY CAR Park ServerGavazziautomation UWP 3.0 Monitoring Gateway AND Controller Firmware | 28/9/2022 | 17/6/2026 | In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 a remote, unauthenticated attacker could utilize an improper input validation on an API-submitted parameter to execute arbitrary OS commands. | |
| Modificada | Crítica (9.8) | 0.84% | — | Gavazziautomation CPY CAR Park ServerGavazziautomation UWP 3.0 Monitoring Gateway AND Controller Firmware | 28/9/2022 | 17/6/2026 | In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 a missing authentication allows for full access via API. | |
| Modificada | Alta (7.2) | 1.2% | — | Gavazziautomation CPY CAR Park ServerGavazziautomation UWP 3.0 Monitoring Gateway AND Controller Firmware | 28/9/2022 | 17/6/2026 | In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 an remote attacker with admin rights could execute arbitrary commands due to missing input sanitization in the backup restore function | |
| Modificada | Crítica (9.4) | 1.2% | — | Gavazziautomation CPY CAR Park ServerGavazziautomation UWP 3.0 Monitoring Gateway AND Controller Firmware | 28/9/2022 | 17/6/2026 | In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 an unauthenticated remote attacker could utilize a SQL-Injection vulnerability to gain full database access, modify users and stop services . | |
| Modificada | Alta (7.5) | 0.86% | — | Gavazziautomation CPY CAR Park ServerGavazziautomation UWP 3.0 Monitoring Gateway AND Controller Firmware | 28/9/2022 | 17/6/2026 | An improper authentication vulnerability exists in the Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 Web-App which allows an authentication bypass to the context of an unauthorised user if free-access is disabled. | |
| Modificada | Crítica (9.8) | 1.1% | — | Gavazziautomation CPY CAR Park ServerGavazziautomation UWP 3.0 Monitoring Gateway AND Controller Firmware | 28/9/2022 | 17/6/2026 | In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 a remote, unauthenticated attacker could make use of hard-coded credentials to gain full access to the device. | |
| Modificada | Alta (8.8) | 0.48% | — | Hitachienergy Modular Switchgear Monitoring Firmware | 25/7/2022 | 17/6/2026 | A vulnerability exists in the http web interface where the web interface does not validate data in an HTTP header. This causes a possible HTTP response splitting, which if exploited could lead an attacker to channel down harmful code into the user’s web browser, such as to steal the session cookies. Thus, an attacker… |