Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
967 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.3) | 0.55% | — | Rockwellautomation Power Monitor 1000AI | 18/12/2024 | 17/6/2026 | A device takeover vulnerability exists in the Rockwell Automation Power Monitor 1000. This vulnerability allows configuration of a new Policyholder user without any authentication via API. Policyholder user is the most privileged user that can perform edit operations, creating admin users and performing factory reset. | |
| Aplazada | Crítica (9.8) | 23% | 💥 Exploit | WP Umbrella Update Backup Restore AND MonitoringAI | 8/12/2024 | 17/6/2026 | The WP Umbrella: Update Backup Restore & Monitoring plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.17.0 via the 'filename' parameter of the 'umbrella-restore' action. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the… | |
| Aplazada | Media (6.1) | 0.35% | — | Campaign Monitor Forms BY Optin CATAI | 3/12/2024 | 17/6/2026 | The Campaign Monitor Forms by Optin Cat plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.5.7. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages… | |
| Aplazada | Media (5.3) | 0.28% | — | 404 Error MonitorAI | 16/11/2024 | 17/6/2026 | The 404 Error Monitor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1. This is due to missing or incorrect nonce validation on the updatePluginSettings() function. This makes it possible for unauthenticated attackers to make changes to plugin settings and… | |
| Analizada | Alta (7.3) | 0.24% | — | AMD Ryzen Master Monitoring Software Development KIT | 12/11/2024 | 17/6/2026 | Incorrect default permissions in the AMD RyzenTM Master monitoring SDK installation directory could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution. | |
| Modificada | Crítica (9.8) | 0.39% | — | Renzojohnson Contact Form 7 Campaign Monitor Extension | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in Renzo Johnson Contact Form 7 Campaign Monitor Extension contact-form-7-campaign-monitor-extension.This issue affects Contact Form 7 Campaign Monitor Extension: from n/a through <= 0.4.67. | |
| Aplazada | Alta (7.7) | 0.70% | — | Ricoh WEB Image MonitorAI | 1/11/2024 | 17/6/2026 | Stack-based buffer overflow vulnerability exists in multiple laser printers and MFPs which implement Ricoh Web Image Monitor. If this vulnerability is exploited, receiving a specially crafted request created and sent by an attacker may lead to arbitrary code execution and/or a denial-of-service (DoS) condition. As for… | |
| Aplazada | Media (4.3) | 0.41% | — | Download MonitorAI | 30/10/2024 | 17/6/2026 | The Download Monitor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_search_users function in all versions up to, and including, 5.0.13. This makes it possible for authenticated attackers, with Subscriber-level access and above, to obtain usernames… | |
| Modificada | Media (6.1) | 0.29% | — | Edwardstoever Monitor.chat | 29/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Edward Stoever Monitor.chat monitor-chat allows Reflected XSS.This issue affects Monitor.chat: from n/a through <= 1.1.1. | |
| Aplazada | Media (4.3) | 0.45% | — | Ironikus Download MonitorAI | 26/10/2024 | 17/6/2026 | The Download Monitor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_handle_api_key_actions function in all versions up to, and including, 5.0.12. This makes it possible for authenticated attackers, with Subscriber-level access and above, to revoke… | |
| Aplazada | Crítica (9.3) | 1.1% | 💥 PoC | Swit WP Sessions Time Monitoring Full AutomaticAI | 24/10/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in activity-log.com WP Sessions Time Monitoring Full Automatic activitytime allows SQL Injection.This issue affects WP Sessions Time Monitoring Full Automatic: from n/a through <= 1.0.9. | |
| Analizada | Alta (7.5) | 0.47% | — | Wpchill Download Monitor | 16/10/2024 | 17/6/2026 | The Download Monitor plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several REST-API routes related to reporting in versions up to, and including, 4.7.51. This makes it possible for unauthenticated attackers to view user data and other sensitive information intended for… | |
| Analizada | Alta (7.1) | 0.65% | — | Microsoft Azure Monitor Agent | 8/10/2024 | 17/6/2026 | Azure Monitor Agent Elevation of Privilege Vulnerability | |
| Modificada | Media (5.3) | 0.38% | — | Siemens Sinec Security Monitor | 8/10/2024 | 17/6/2026 | A vulnerability has been identified in SINEC Security Monitor (All versions < V4.9.0). The affected application does not properly validate that user input complies with a list of allowed values. This could allow an authenticated remote attacker to compromise the integrity of the configuration of the affected… | |
| Modificada | Media (6.9) | 0.55% | — | Siemens Sinec Security Monitor | 8/10/2024 | 17/6/2026 | A vulnerability has been identified in SINEC Security Monitor (All versions < V4.9.0). The affected application does not properly validate a file path that is supplied to an endpoint intended to create CSR files. This could allow an unauthenticated remote attacker to create files in writable directories outside the… | |
| Modificada | Crítica (9.3) | 0.27% | — | Siemens Sinec Security Monitor | 8/10/2024 | 17/6/2026 | A vulnerability has been identified in SINEC Security Monitor (All versions < V4.9.0). The affected application does not properly neutralize special elements in user input to the ```ssmctl-client``` command. This could allow an authenticated, lowly privileged local attacker to execute privileged commands in the… | |
| Modificada | Crítica (9.4) | 0.85% | — | Siemens Sinec Security Monitor | 8/10/2024 | 17/6/2026 | A vulnerability has been identified in SINEC Security Monitor (All versions < V4.9.0). The affected application does not properly validate user input to the ```ssmctl-client``` command. This could allow an authenticated, lowly privileged remote attacker to execute arbitrary code with root privileges on the underlying… | |
| Analizada | Media (4.6) | 0.32% | — | Tenable Nessus Network Monitor | 30/9/2024 | 17/6/2026 | A stored cross site scripting vulnerability exists in Nessus Network Monitor where an authenticated, privileged local attacker could inject arbitrary code into the NNM UI via the local CLI. | |
| Aplazada | Crítica (9.3) | 0.59% | — | Omntec Proteus Tank Monitoring Oel8000iii SeriesAI | 27/9/2024 | 17/6/2026 | OMNTEC Proteus Tank Monitoring OEL8000III Series could allow an attacker to perform administrative actions without proper authentication. | |
| Analizada | Alta (8.8) | 0.84% | — | IBM Cloud PAK FOR Multicloud Management Monitoring | 26/9/2024 | 17/6/2026 | IBM ManageIQ could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted yaml file request. | |
| Analizada | Media (4.9) | 0.34% | — | IBM Cloud PAK FOR Multicloud Management Monitoring | 26/9/2024 | 17/6/2026 | IBM Cloud Pak for Multicloud Management 2.3 through 2.3 FP8 stores user credentials in a log file plain clear text which can be read by a privileged user. | |
| Analizada | Media (4.3) | 0.37% | — | Wpchill Download Monitor | 26/9/2024 | 17/6/2026 | The Download Monitor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the enable_shop() function in all versions up to, and including, 5.0.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to enable shop… | |
| Aplazada | Media (6.5) | 0.23% | — | Runofast Indoor Security Camera FOR Baby MonitorAI | 18/9/2024 | 17/6/2026 | runofast Indoor Security Camera for Baby Monitor has a default password of password for the root account. This allows access to the /stream1 URI via the rtsp:// protocol to receive the video and audio stream. | |
| Modificada | Media (6.5) | 0.27% | — | Eaton Foreseer Electrical Power Monitoring System | 13/9/2024 | 17/6/2026 | The Eaton Foreseer software provides multiple customizable input fields for the users to configure parameters in the tool like alarms, reports, etc. Some of these input fields were not checking the length and bounds of the entered value. The exploit of this security flaw by a bad actor may result in excessive memory… | |
| Modificada | Alta (8.1) | 0.12% | — | Eaton Foreseer Electrical Power Monitoring System | 13/9/2024 | 17/6/2026 | The Eaton Foreseer software provides the feasibility for the user to configure external servers for multiple purposes such as network management, user management, etc. The software uses encryption to store these configurations securely on the host machine. However, the keys used for this encryption were insecurely… |