Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2676▼ 422 respecto a la semana anterior
Críticas / altas1295▼ 73 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 274 respecto a la semana anterior
–

18 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.1)0.76%—Snstheme AvazAI9/6/202517/6/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in snstheme Avaz snsavaz allows PHP Local File Inclusion.This issue affects Avaz: from n/a through <= 2.8.
ModificadaAlta (7.5)2.8%—Gavazzionline Powersoft4/5/202317/6/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Carlo Gavazzi Powersoft up to version 2.1.1.1 allows an unauthenticated, remote attacker to download any file from the affected device.
ModificadaMedia (6.1)0.43%—Gavazziautomation CPY CAR Park ServerGavazziautomation UWP 3.0 Monitoring Gateway AND Controller Firmware28/9/202217/6/2026
In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 the Sentilo Proxy is prone to reflected XSS which only affects the Sentilo service.
ModificadaBaja (2.7)0.53%—Gavazziautomation CPY CAR Park ServerGavazziautomation UWP 3.0 Monitoring Gateway AND Controller Firmware28/9/202217/6/2026
In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 the Sentilo Proxy server was discovered to contain a SQL injection vulnerability allowing an attacker to query other tables of the Sentilo service.
ModificadaCrítica (9.8)1.3%—Gavazziautomation CPY CAR Park ServerGavazziautomation UWP 3.0 Monitoring Gateway AND Controller Firmware28/9/202217/6/2026
Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 was discovered to be vulnerable to a relative path traversal vulnerability which enables remote attackers to read arbitrary files and gain full control of the device.
ModificadaAlta (7.5)1.0%—Gavazziautomation CPY CAR Park ServerGavazziautomation UWP 3.0 Monitoring Gateway AND Controller Firmware28/9/202217/6/2026
In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 a remote, unauthenticated attacker could make use of an SQL-injection to gain access to a volatile temporary database with the current states of the device.
ModificadaCrítica (9.8)1.0%—Gavazziautomation CPY CAR Park ServerGavazziautomation UWP 3.0 Monitoring Gateway AND Controller Firmware28/9/202217/6/2026
In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 a remote, unauthenticated attacker could make use of hard-coded credentials to gain SuperUser access to the device.
ModificadaCrítica (9.8)1.2%—Gavazziautomation CPY CAR Park ServerGavazziautomation UWP 3.0 Monitoring Gateway AND Controller Firmware28/9/202217/6/2026
In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 a remote, unauthenticated attacker could utilize an improper input validation on an API-submitted parameter to execute arbitrary OS commands.
ModificadaCrítica (9.8)0.84%—Gavazziautomation CPY CAR Park ServerGavazziautomation UWP 3.0 Monitoring Gateway AND Controller Firmware28/9/202217/6/2026
In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 a missing authentication allows for full access via API.
ModificadaAlta (7.2)1.2%—Gavazziautomation CPY CAR Park ServerGavazziautomation UWP 3.0 Monitoring Gateway AND Controller Firmware28/9/202217/6/2026
In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 an remote attacker with admin rights could execute arbitrary commands due to missing input sanitization in the backup restore function
ModificadaCrítica (9.4)1.2%—Gavazziautomation CPY CAR Park ServerGavazziautomation UWP 3.0 Monitoring Gateway AND Controller Firmware28/9/202217/6/2026
In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 an unauthenticated remote attacker could utilize a SQL-Injection vulnerability to gain full database access, modify users and stop services .
ModificadaAlta (7.5)0.86%—Gavazziautomation CPY CAR Park ServerGavazziautomation UWP 3.0 Monitoring Gateway AND Controller Firmware28/9/202217/6/2026
An improper authentication vulnerability exists in the Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 Web-App which allows an authentication bypass to the context of an unauthorised user if free-access is disabled.
ModificadaCrítica (9.8)1.1%—Gavazziautomation CPY CAR Park ServerGavazziautomation UWP 3.0 Monitoring Gateway AND Controller Firmware28/9/202217/6/2026
In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 a remote, unauthenticated attacker could make use of hard-coded credentials to gain full access to the device.
ModificadaAlta (7.5)9.3%—Carlosgavazzi Vmu-c EM FirmwareCarlosgavazzi Vmu-c PV Firmware13/2/201717/6/2026
An issue was discovered in Carlo Gavazzi VMU-C EM prior to firmware Version A11_U05, and VMU-C PV prior to firmware Version A17. Sensitive information is stored in clear-text.
ModificadaCrítica (10)1.2%—Carlosgavazzi Vmu-c EM FirmwareCarlosgavazzi Vmu-c PV Firmware13/2/201717/6/2026
An issue was discovered in Carlo Gavazzi VMU-C EM prior to firmware Version A11_U05, and VMU-C PV prior to firmware Version A17. Successful exploitation of this CROSS-SITE REQUEST FORGERY (CSRF) vulnerability can allow execution of unauthorized actions on the device such as configuration parameter changes, and saving…
ModificadaCrítica (9.8)2.4%—Carlosgavazzi Vmu-c EM FirmwareCarlosgavazzi Vmu-c PV Firmware13/2/201717/6/2026
An issue was discovered in Carlo Gavazzi VMU-C EM prior to firmware Version A11_U05, and VMU-C PV prior to firmware Version A17. The access control flaw allows access to most application functions without authentication.
ModificadaAlta (10)1.5%—Carlosgavazzi Eos-box Photovoltaic Monitoring System FirmwareCarlosgavazzi Eos-box Photovoltaic Monitoring System23/12/201216/6/2026
The Carlo Gavazzi EOS-Box stores hard-coded passwords in the PHP file of the device. By using the hard-coded passwords, attackers can log into the device with administrative privileges. This could allow the attacker to have unauthorized access.
ModificadaAlta (7.5)1.3%—Carlosgavazzi Eos-box Photovoltaic Monitoring System FirmwareCarlosgavazzi Eos-box Photovoltaic Monitoring System23/12/201216/6/2026
The Carlo Gavazzi EOS-Box does not check the validity of the data before executing queries. By accessing the SQL table of certain pages that do not require authentication, attackers can leak information from the device. This could allow the attacker to compromise confidentiality.