Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
–

967 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.3)0.55%—Rockwellautomation Power Monitor 1000AI18/12/202417/6/2026
A device takeover vulnerability exists in the Rockwell Automation Power Monitor 1000. This vulnerability allows configuration of a new Policyholder user without any authentication via API. Policyholder user is the most privileged user that can perform edit operations, creating admin users and performing factory reset.
AplazadaCrítica (9.8)23%💥 ExploitWP Umbrella Update Backup Restore AND MonitoringAI8/12/202417/6/2026
The WP Umbrella: Update Backup Restore & Monitoring plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.17.0 via the 'filename' parameter of the 'umbrella-restore' action. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the…
AplazadaMedia (6.1)0.35%—Campaign Monitor Forms BY Optin CATAI3/12/202417/6/2026
The Campaign Monitor Forms by Optin Cat plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.5.7. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages…
AplazadaMedia (5.3)0.28%—404 Error MonitorAI16/11/202417/6/2026
The 404 Error Monitor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1. This is due to missing or incorrect nonce validation on the updatePluginSettings() function. This makes it possible for unauthenticated attackers to make changes to plugin settings and…
AnalizadaAlta (7.3)0.24%—AMD Ryzen Master Monitoring Software Development KIT12/11/202417/6/2026
Incorrect default permissions in the AMD RyzenTM Master monitoring SDK installation directory could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution.
ModificadaCrítica (9.8)0.39%—Renzojohnson Contact Form 7 Campaign Monitor Extension1/11/202417/6/2026
Missing Authorization vulnerability in Renzo Johnson Contact Form 7 Campaign Monitor Extension contact-form-7-campaign-monitor-extension.This issue affects Contact Form 7 Campaign Monitor Extension: from n/a through <= 0.4.67.
AplazadaAlta (7.7)0.70%—Ricoh WEB Image MonitorAI1/11/202417/6/2026
Stack-based buffer overflow vulnerability exists in multiple laser printers and MFPs which implement Ricoh Web Image Monitor. If this vulnerability is exploited, receiving a specially crafted request created and sent by an attacker may lead to arbitrary code execution and/or a denial-of-service (DoS) condition. As for…
AplazadaMedia (4.3)0.41%—Download MonitorAI30/10/202417/6/2026
The Download Monitor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_search_users function in all versions up to, and including, 5.0.13. This makes it possible for authenticated attackers, with Subscriber-level access and above, to obtain usernames…
ModificadaMedia (6.1)0.29%—Edwardstoever Monitor.chat29/10/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Edward Stoever Monitor.chat monitor-chat allows Reflected XSS.This issue affects Monitor.chat: from n/a through <= 1.1.1.
AplazadaMedia (4.3)0.45%—Ironikus Download MonitorAI26/10/202417/6/2026
The Download Monitor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_handle_api_key_actions function in all versions up to, and including, 5.0.12. This makes it possible for authenticated attackers, with Subscriber-level access and above, to revoke…
AplazadaCrítica (9.3)1.1%💥 PoCSwit WP Sessions Time Monitoring Full AutomaticAI24/10/202417/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in activity-log.com WP Sessions Time Monitoring Full Automatic activitytime allows SQL Injection.This issue affects WP Sessions Time Monitoring Full Automatic: from n/a through <= 1.0.9.
AnalizadaAlta (7.5)0.47%—Wpchill Download Monitor16/10/202417/6/2026
The Download Monitor plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several REST-API routes related to reporting in versions up to, and including, 4.7.51. This makes it possible for unauthenticated attackers to view user data and other sensitive information intended for…
AnalizadaAlta (7.1)0.65%—Microsoft Azure Monitor Agent8/10/202417/6/2026
Azure Monitor Agent Elevation of Privilege Vulnerability
ModificadaMedia (5.3)0.38%—Siemens Sinec Security Monitor8/10/202417/6/2026
A vulnerability has been identified in SINEC Security Monitor (All versions < V4.9.0). The affected application does not properly validate that user input complies with a list of allowed values. This could allow an authenticated remote attacker to compromise the integrity of the configuration of the affected…
ModificadaMedia (6.9)0.55%—Siemens Sinec Security Monitor8/10/202417/6/2026
A vulnerability has been identified in SINEC Security Monitor (All versions < V4.9.0). The affected application does not properly validate a file path that is supplied to an endpoint intended to create CSR files. This could allow an unauthenticated remote attacker to create files in writable directories outside the…
ModificadaCrítica (9.3)0.27%—Siemens Sinec Security Monitor8/10/202417/6/2026
A vulnerability has been identified in SINEC Security Monitor (All versions < V4.9.0). The affected application does not properly neutralize special elements in user input to the ```ssmctl-client``` command. This could allow an authenticated, lowly privileged local attacker to execute privileged commands in the…
ModificadaCrítica (9.4)0.85%—Siemens Sinec Security Monitor8/10/202417/6/2026
A vulnerability has been identified in SINEC Security Monitor (All versions < V4.9.0). The affected application does not properly validate user input to the ```ssmctl-client``` command. This could allow an authenticated, lowly privileged remote attacker to execute arbitrary code with root privileges on the underlying…
AnalizadaMedia (4.6)0.32%—Tenable Nessus Network Monitor30/9/202417/6/2026
A stored cross site scripting vulnerability exists in Nessus Network Monitor where an authenticated, privileged local attacker could inject arbitrary code into the NNM UI via the local CLI.
AplazadaCrítica (9.3)0.59%—Omntec Proteus Tank Monitoring Oel8000iii SeriesAI27/9/202417/6/2026
OMNTEC Proteus Tank Monitoring OEL8000III Series could allow an attacker to perform administrative actions without proper authentication.
AnalizadaAlta (8.8)0.84%—IBM Cloud PAK FOR Multicloud Management Monitoring26/9/202417/6/2026
IBM ManageIQ could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted yaml file request.
AnalizadaMedia (4.9)0.34%—IBM Cloud PAK FOR Multicloud Management Monitoring26/9/202417/6/2026
IBM Cloud Pak for Multicloud Management 2.3 through 2.3 FP8 stores user credentials in a log file plain clear text which can be read by a privileged user.
AnalizadaMedia (4.3)0.37%—Wpchill Download Monitor26/9/202417/6/2026
The Download Monitor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the enable_shop() function in all versions up to, and including, 5.0.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to enable shop…
AplazadaMedia (6.5)0.23%—Runofast Indoor Security Camera FOR Baby MonitorAI18/9/202417/6/2026
runofast Indoor Security Camera for Baby Monitor has a default password of password for the root account. This allows access to the /stream1 URI via the rtsp:// protocol to receive the video and audio stream.
ModificadaMedia (6.5)0.27%—Eaton Foreseer Electrical Power Monitoring System13/9/202417/6/2026
The Eaton Foreseer software provides multiple customizable input fields for the users to configure parameters in the tool like alarms, reports, etc. Some of these input fields were not checking the length and bounds of the entered value. The exploit of this security flaw by a bad actor may result in excessive memory…
ModificadaAlta (8.1)0.12%—Eaton Foreseer Electrical Power Monitoring System13/9/202417/6/2026
The Eaton Foreseer software provides the feasibility for the user to configure external servers for multiple purposes such as network management, user management, etc. The software uses encryption to store these configurations securely on the host machine. However, the keys used for this encryption were insecurely…