Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3081▲ 625 respecto a la semana anterior
Críticas / altas1483▲ 317 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)393▲ 186 respecto a la semana anterior
8 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.61% | — | Openenergymonitor Emoncms | 24/10/2025 | 17/6/2026 | Emoncms 11.7.3 has a remote code execution vulnerability in the firmware upload feature that allows authenticated users to execute arbitrary commands on the target system. The vulnerability stems from insufficient input validation of user-controlled parameters including filename, port, baud_rate, core, and autoreset… | |
| Analizada | Media (6.1) | 0.19% | — | Openenergymonitor Emoncms | 24/10/2025 | 17/6/2026 | Emoncms 11.7.3 is vulnerable to Cross Site in the input handling mechanism. This vulnerability allows authenticated attackers with API access to inject malicious JavaScript code that executes when administrators view the application logs. | |
| Analizada | Crítica (9.8) | 0.53% | — | Openenergymonitor Emoncms | 6/2/2025 | 17/6/2026 | A SQL Injection vulnerability exists in the /feed/insert.json endpoint of the Emoncms project >= 11.6.9. The vulnerability is caused by improper handling of user-supplied input in the data query parameter, allowing attackers to execute arbitrary SQL commands under specific conditions. | |
| Modificada | Media (5.3) | 0.46% | — | Emoncms | 5/6/2023 | 17/6/2026 | emoncms v11 and later was discovered to contain an information disclosure vulnerability which allows attackers to obtain the web directory path and other information leaked by the server via a crafted web request. | |
| Modificada | Media (6.1) | 0.79% | — | Openenergymonitor Emoncms | 21/2/2021 | 17/6/2026 | Modules/input/Views/schedule.php in Emoncms through 10.2.7 allows XSS via the node parameter. | |
| Modificada | Media (5.4) | 0.90% | — | Openenergymonitor Emoncms | 15/7/2019 | 17/6/2026 | OpenEnergyMonitor Project Emoncms 9.8.8 is affected by: Cross Site Scripting (XSS). The impact is: Theoretically low, but might potentially enable persistent XSS (user could embed mal. code). The component is: Javascript code execution in "Name", "Location", "Bio" and "Starting Page" fields in the "My Account" page.… | |
| Modificada | Media (6.1) | 0.92% | — | Openenergymonitor Emoncms | 12/2/2017 | 17/6/2026 | An issue was discovered in Emoncms through 9.8.0. The vulnerability exists due to insufficient filtration of user-supplied data in multiple HTTP GET parameters passed to the "emoncms-master/Modules/vis/visualisations/compare.php" URL. An attacker could execute arbitrary HTML and script code in a browser in the context… | |
| Modificada | Media (6.8) | 1.9% | — | Lemoncms Lemon CMS | 25/7/2008 | 16/6/2026 | Directory traversal vulnerability in lemon_includes/FCKeditor/editor/filemanager/browser/browser.php in Lemon CMS 1.10 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the dir parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from… |