Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2778▼ 418 respecto a la semana anterior
Críticas / altas1332▼ 108 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

358 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)0.22%—Hitachienergy Modular Switchgear Monitoring Firmware25/7/202217/6/2026
A vulnerability exists in the HTTP web interface where the web interface does not sufficiently verify if a well-formed, valid, consistent request was intentionally provided by the user who submitted the request. This cause a Cross Site Request Forgery (CSRF), which if exploited could lead an attacker to gain…
ModificadaMedia (6.5)1.3%—Monitoringsoft Softguard WEB17/7/202217/6/2026
The export function in SoftGuard Web (SGW) before 5.1.5 allows directory traversal to read an arbitrary local file via export or man.tcl.
ModificadaMedia (5.4)0.61%—Monitoringsoft Softguard WEB17/7/202217/6/2026
SoftGuard Web (SGW) before 5.1.5 allows HTML injection.
ModificadaAlta (8.1)0.92%—IBM Cloud PAK FOR Multicloud Management Monitoring30/6/202217/6/2026
IBM CloudPak for Multicloud Monitoring 2.0 and 2.3 has a few containers running in privileged mode which is vulnerable to host information leakage or destruction if unauthorized access to these containers could execute arbitrary commands. IBM X-Force ID: 211048.
ModificadaAlta (7.8)0.92%—Microsoft Azure Automation State ConfigurationMicrosoft Azure Automation Update ManagementMicrosoft Azure DiagnosticsMicrosoft Azure Security Center+615/6/202217/6/2026
Open Management Infrastructure (OMI) Elevation of Privilege Vulnerability
ModificadaAlta (7.5)10.0%💥 PoCGolang GOFedoraproject FedoraNetapp Kubernetes Monitoring Operator20/4/202217/6/2026
encoding/pem in Go before 1.17.9 and 1.18.x before 1.18.1 has a Decode stack overflow via a large amount of PEM data.
ModificadaMedia (4.8)0.45%—Wocu-monitoring Wocu Monitoring11/2/202217/6/2026
A stored cross site scripting have been identified at the comments in the report creation due to an obsolote version of tinymce editor. In order to exploit this vulnerability, the attackers needs an account with enough privileges to view and edit reports.
ModificadaCrítica (9.8)1.3%—Mitsubishielectric C Controller Interface Module UtilityMitsubishielectric C Controller Module Setting AND Monitoring ToolMitsubishielectric Cc-link IE Control Network Data CollectorMitsubishielectric Cc-link IE Field Network Data Collector+4211/2/202217/6/2026
Multiple Mitsubishi Electric Factory Automation engineering software products have a malicious code execution vulnerability. A malicious attacker could use this vulnerability to obtain information, modify information, and cause a denial-of-service condition.
ModificadaCrítica (9.1)3.1%—Golang GONetapp Beegfs CSI DriverNetapp Cloud Insights Telegraf AgentNetapp Kubernetes Monitoring Operator+211/2/202217/6/2026
Curve.IsOnCurve in crypto/elliptic in Go before 1.16.14 and 1.17.x before 1.17.7 can incorrectly return true in situations with a big.Int value that is not a valid field element.
ModificadaAlta (7.5)2.7%💥 PoCGolang GONetapp Beegfs CSI DriverNetapp Cloud Insights Telegraf AgentNetapp Kubernetes Monitoring Operator+111/2/202217/6/2026
cmd/go in Go before 1.16.14 and 1.17.x before 1.17.7 can misinterpret branch names that falsely appear to be version tags. This can lead to incorrect access control if an actor is supposed to be able to create branches but not tags.
ModificadaAlta (7.5)2.8%—Golang GONetapp Beegfs CSI DriverNetapp Cloud Insights Telegraf AgentNetapp Kubernetes Monitoring Operator+211/2/202217/6/2026
Rat.SetString in math/big in Go before 1.16.14 and 1.17.x before 1.17.7 has an overflow that can lead to Uncontrolled Memory Consumption.
ModificadaMedia (5.4)0.45%—Schneider-electric Ecostruxure Power Monitoring Expert4/2/202217/6/2026
A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could allow an authenticated attacker to view data, change settings, or impact availability of the software when the user visits a page containing the injected payload. Affected Product: EcoStruxure…
ModificadaAlta (8.8)1.2%—Schneider-electric Ecostruxure Power Monitoring Expert4/2/202217/6/2026
A CWE-20: Improper Input Validation vulnerability exists that could allow an unauthenticated attacker to view data, change settings, impact availability of the software, or potentially impact a user�s local machine when the user clicks a specially crafted link. Affected Product: EcoStruxure Power Monitoring Expert…
ModificadaMedia (6.5)0.77%—Schneider-electric Ecostruxure Power Monitoring Expert4/2/202217/6/2026
A CWE-20: Improper Input Validation vulnerability exists that could allow arbitrary files on the server to be read by authenticated users through a limited operating system service account. Affected Product: EcoStruxure Power Monitoring Expert (Versions 2020 and prior)
ModificadaAlta (8.8)1.2%—Schneider-electric Ecostruxure Power Monitoring Expert28/1/202217/6/2026
A CWE-20: Improper Input Validation vulnerability exists that could cause arbitrary code execution when the user visits a page containing the injected payload. This CVE is unique from CVE-2021-22826. Affected Product: EcoStruxure� Power Monitoring Expert 9.0 and prior versions
ModificadaAlta (8.8)1.2%—Schneider-electric Ecostruxure Power Monitoring Expert28/1/202217/6/2026
A CWE-20: Improper Input Validation vulnerability exists that could cause arbitrary code execution when the user visits a page containing the injected payload. This CVE is unique from CVE-2021-22827. Affected Product: EcoStruxure� Power Monitoring Expert 9.0 and prior versions
ModificadaAlta (7.5)33%💥 ExploitHd-network Real-time Monitoring System Project Hd-network Real-time Monitoring System15/12/202117/6/2026
HD-Network Real-time Monitoring System 2.0 allows ../ directory traversal to read /etc/shadow via the /language/lang s_Language parameter.
AnalizadaAlta (7.8)2.9%⚠ Explotación activaMicrosoft Azure Automation State ConfigurationMicrosoft Azure Automation Update ManagementMicrosoft Azure Diagnostics (lad)Microsoft Azure Open Management Infrastructure+715/9/202110/8/2026
Open Management Infrastructure Elevation of Privilege Vulnerability
AnalizadaAlta (7.8)11%⚠ Explotación activa💥 ExploitMicrosoft Azure Automation State ConfigurationMicrosoft Azure Automation Update ManagementMicrosoft Azure Diagnostics (lad)Microsoft Azure Open Management Infrastructure+715/9/202110/8/2026
Open Management Infrastructure Elevation of Privilege Vulnerability
AnalizadaCrítica (9.8)100%⚠ Explotación activa💥 ExploitMicrosoft Azure Automation State ConfigurationMicrosoft Azure Automation Update ManagementMicrosoft Azure Diagnostics (lad)Microsoft Azure Security Center+615/9/202110/8/2026
Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
AnalizadaAlta (7.8)2.7%⚠ Explotación activaMicrosoft Azure Automation State ConfigurationMicrosoft Azure Automation Update ManagementMicrosoft Azure Diagnostics (lad)Microsoft Azure Security Center+615/9/202110/8/2026
Open Management Infrastructure Elevation of Privilege Vulnerability
AnalizadaAlta (8.5)11%💥 ExploitXstreamFedoraproject FedoraDebian LinuxNetapp Snapmanager+1123/8/202117/6/2026
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to request data from internal resources that are not publicly available only by manipulating the processed input stream with a Java runtime version 14 to 8. No user is affected,…
AnalizadaAlta (8.5)3.4%—XstreamFedoraproject FedoraDebian LinuxNetapp Snapmanager+1123/8/202117/6/2026
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to request data from internal resources that are not publicly available only by manipulating the processed input stream with a Java runtime version 14 to 8. No user is affected,…
AnalizadaMedia (6.3)5.9%—XstreamDebian LinuxFedoraproject FedoraNetapp Snapmanager+1123/8/202117/6/2026
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to allocate 100% CPU time on the target system depending on CPU type or parallel execution of such a payload resulting in a denial of service only by manipulating the processed…
AnalizadaAlta (8.5)4.7%—XstreamFedoraproject FedoraDebian LinuxNetapp Snapmanager+1123/8/202117/6/2026
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's…