Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2517▼ 423 respecto a la semana anterior
Críticas / altas1296▲ 12 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)57▼ 471 respecto a la semana anterior
–

21 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.4)0.22%—Cgauge YamlAI20/8/202624/9/2026
@cgauge/yaml npm package contains an arbitrary code execution vulnerability that allows attackers to execute arbitrary JavaScript by embedding a custom !js YAML tag whose construct callback unconditionally calls eval() on attacker-supplied string values during document parsing. Any application parsing untrusted YAML…
AplazadaMedia (6.9)0.12%—Flexense SysgaugeAI29/4/202617/6/2026
SysGauge 4.5.18 contains a buffer overflow vulnerability in the proxy configuration handler that allows local attackers to cause a denial of service by supplying an oversized string. Attackers can inject a large payload through the Proxy Server Host Name field in the Options menu to crash the application.
AplazadaAlta (8.6)0.15%—Sysgauge PROAI29/4/202617/6/2026
SysGauge Pro 4.6.12 contains a local buffer overflow vulnerability in the Register function that allows local attackers to overwrite the structured exception handler by supplying a crafted unlock key. Attackers can inject shellcode through the Unlock Key field during registration to execute arbitrary code with…
AplazadaAlta (7.5)0.25%—Ghostpool GaugeAI20/2/202617/6/2026
Missing Authorization vulnerability in GhostPool Gauge gauge allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Gauge: from n/a through <= 6.56.4.
AnalizadaAlta (8.5)0.24%—Flexense Sysgauge16/1/202617/6/2026
SysGauge Server 7.9.18 contains an unquoted service path vulnerability in its binary path configuration that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in 'C:\Program Files\SysGauge Server\bin\sysgaus.exe' to inject malicious executables and escalate…
AplazadaAlta (8.8)0.39%—Doverfuelingsolutions Progauge Maglink LX4AI18/9/202517/6/2026
Dover Fueling Solutions ProGauge MagLink LX4 Devices fail to handle Unix time values beyond a certain point. An attacker can manually change the system time to exploit this limitation, potentially causing errors in authentication and leading to a denial-of-service condition.
AplazadaCrítica (9.3)0.44%—Doverfuelingsolutions Progauge Maglink LX4AI18/9/202517/6/2026
Dover Fueling Solutions ProGauge MagLink LX4 Devices have default root credentials that cannot be changed through standard administrative means. An attacker with network access to the device can gain administrative access to the system.
AplazadaCrítica (9.3)0.82%—Doverfuelingsolutions Progauge Maglink LXAI27/6/202517/6/2026
Dover Fueling Solutions ProGauge MagLink LX Consoles expose an undocumented and unauthenticated target communication framework (TCF) interface on a specific port. Files can be created, deleted, or modified, potentially leading to remote code execution.
AplazadaMedia (5.5)0.47%—Egauge Eg3000 Energy MonitorAI9/6/202517/6/2026
A vulnerability was found in eGauge EG3000 Energy Monitor 3.6.3. It has been classified as problematic. This affects an unknown part of the component Setting Handler. The manipulation leads to missing authentication. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may…
AnalizadaAlta (8.7)0.45%—Doverfuelingsolutions Progauge Maglink LX Console FirmwareDoverfuelingsolutions Progauge Maglink LX4 Console Firmware25/9/202417/6/2026
Once logged in to ProGauge MAGLINK LX4 CONSOLE, a valid user can change their privileges to administrator.
AnalizadaCrítica (10)0.79%—Doverfuelingsolutions Progauge Maglink LX Console FirmwareDoverfuelingsolutions Progauge Maglink LX4 Console Firmware25/9/202417/6/2026
A specially crafted POST request to the ProGauge MAGLINK LX CONSOLE IP sub-menu can allow a remote attacker to inject arbitrary commands.
AnalizadaCrítica (10)0.79%—Doverfuelingsolutions Progauge Maglink LX Console FirmwareDoverfuelingsolutions Progauge Maglink LX4 Console Firmware25/9/202417/6/2026
A specially crafted POST request to the ProGauge MAGLINK LX CONSOLE UTILITY sub-menu can allow a remote attacker to inject arbitrary commands.
AnalizadaCrítica (9.3)0.51%—Doverfuelingsolutions Progauge Maglink LX Console FirmwareDoverfuelingsolutions Progauge Maglink LX4 Console Firmware25/9/202417/6/2026
An attacker can directly request the ProGauge MAGLINK LX CONSOLE resource sub page with full privileges by requesting the URL directly.
AnalizadaCrítica (9.3)0.68%—Doverfuelingsolutions Progauge Maglink LX Console FirmwareDoverfuelingsolutions Progauge Maglink LX4 Console Firmware25/9/202417/6/2026
The web application for ProGauge MAGLINK LX4 CONSOLE contains an administrative-level user account with a password that cannot be changed.
AnalizadaAlta (8.7)0.36%—Doverfuelingsolutions Progauge Maglink LX Console FirmwareDoverfuelingsolutions Progauge Maglink LX4 Console Firmware25/9/202417/6/2026
ProGauge MAGLINK LX CONSOLE does not have sufficient filtering on input fields that are used to render pages which may allow cross site scripting.
ModificadaAlta (7.5)1.4%—Electroind Gaugetech Nexus Firmware28/6/201817/6/2026
Electro Industries GaugeTech Nexus devices allow remote attackers to obtain potentially sensitive information via a direct request for the meter_information.htm, diag_system.htm, or diag_dnp_lan_wan.htm URI.
ModificadaAlta (8.1)9.0%—Flexense Sysgauge23/1/201817/6/2026
The server in Flexense SysGauge 3.6.18 operating on port 9221 can be exploited remotely with the attacker gaining system-level access because of a Buffer Overflow.
ModificadaAlta (7.5)3.8%—Flexense Sysgauge28/12/201717/6/2026
In Flexense SysGauge Server 3.6.18, the Control Protocol suffers from a denial of service. The attack vector is a crafted SERVER_GET_INFO packet sent to control port 9221.
ModificadaCrítica (9.8)11%—Flexense Sysgauge6/3/201717/6/2026
An issue was discovered in SysGauge 1.5.18. A buffer overflow vulnerability in SMTP connection verification leads to arbitrary code execution. The attack vector is a crafted SMTP daemon that sends a long 220 (aka "Service ready") string.
ModificadaBaja (2.1)0.53%—HP Array Configuration UtilityHP Array Diagnostics UtilityHP Proliant Array DiagnosticsHP Smartssd Wear Gauge Utility12/4/201417/6/2026
Unspecified vulnerability in HP Array Configuration Utility, Array Diagnostics Utility, ProLiant Array Diagnostics, and SmartSSD Wear Gauge Utility 9.40 and earlier allows local users to gain privileges via unknown vectors.
ModificadaAlta (7.8)3.8%—Hammer-software Metagauge7/10/200816/6/2026
Directory traversal vulnerability in MetaGauge 1.0.0.17, and probably other versions before 1.0.3.38, allows remote attackers to read arbitrary files via a "..\" (dot dot backslash) in the URL.