Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2517▼ 423 respecto a la semana anterior
Críticas / altas1296▲ 12 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)57▼ 471 respecto a la semana anterior
21 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.4) | 0.22% | — | Cgauge YamlAI | 20/8/2026 | 24/9/2026 | @cgauge/yaml npm package contains an arbitrary code execution vulnerability that allows attackers to execute arbitrary JavaScript by embedding a custom !js YAML tag whose construct callback unconditionally calls eval() on attacker-supplied string values during document parsing. Any application parsing untrusted YAML… | |
| Aplazada | Media (6.9) | 0.12% | — | Flexense SysgaugeAI | 29/4/2026 | 17/6/2026 | SysGauge 4.5.18 contains a buffer overflow vulnerability in the proxy configuration handler that allows local attackers to cause a denial of service by supplying an oversized string. Attackers can inject a large payload through the Proxy Server Host Name field in the Options menu to crash the application. | |
| Aplazada | Alta (8.6) | 0.15% | — | Sysgauge PROAI | 29/4/2026 | 17/6/2026 | SysGauge Pro 4.6.12 contains a local buffer overflow vulnerability in the Register function that allows local attackers to overwrite the structured exception handler by supplying a crafted unlock key. Attackers can inject shellcode through the Unlock Key field during registration to execute arbitrary code with… | |
| Aplazada | Alta (7.5) | 0.25% | — | Ghostpool GaugeAI | 20/2/2026 | 17/6/2026 | Missing Authorization vulnerability in GhostPool Gauge gauge allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Gauge: from n/a through <= 6.56.4. | |
| Analizada | Alta (8.5) | 0.24% | — | Flexense Sysgauge | 16/1/2026 | 17/6/2026 | SysGauge Server 7.9.18 contains an unquoted service path vulnerability in its binary path configuration that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in 'C:\Program Files\SysGauge Server\bin\sysgaus.exe' to inject malicious executables and escalate… | |
| Aplazada | Alta (8.8) | 0.39% | — | Doverfuelingsolutions Progauge Maglink LX4AI | 18/9/2025 | 17/6/2026 | Dover Fueling Solutions ProGauge MagLink LX4 Devices fail to handle Unix time values beyond a certain point. An attacker can manually change the system time to exploit this limitation, potentially causing errors in authentication and leading to a denial-of-service condition. | |
| Aplazada | Crítica (9.3) | 0.44% | — | Doverfuelingsolutions Progauge Maglink LX4AI | 18/9/2025 | 17/6/2026 | Dover Fueling Solutions ProGauge MagLink LX4 Devices have default root credentials that cannot be changed through standard administrative means. An attacker with network access to the device can gain administrative access to the system. | |
| Aplazada | Crítica (9.3) | 0.82% | — | Doverfuelingsolutions Progauge Maglink LXAI | 27/6/2025 | 17/6/2026 | Dover Fueling Solutions ProGauge MagLink LX Consoles expose an undocumented and unauthenticated target communication framework (TCF) interface on a specific port. Files can be created, deleted, or modified, potentially leading to remote code execution. | |
| Aplazada | Media (5.5) | 0.47% | — | Egauge Eg3000 Energy MonitorAI | 9/6/2025 | 17/6/2026 | A vulnerability was found in eGauge EG3000 Energy Monitor 3.6.3. It has been classified as problematic. This affects an unknown part of the component Setting Handler. The manipulation leads to missing authentication. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may… | |
| Analizada | Alta (8.7) | 0.45% | — | Doverfuelingsolutions Progauge Maglink LX Console FirmwareDoverfuelingsolutions Progauge Maglink LX4 Console Firmware | 25/9/2024 | 17/6/2026 | Once logged in to ProGauge MAGLINK LX4 CONSOLE, a valid user can change their privileges to administrator. | |
| Analizada | Crítica (10) | 0.79% | — | Doverfuelingsolutions Progauge Maglink LX Console FirmwareDoverfuelingsolutions Progauge Maglink LX4 Console Firmware | 25/9/2024 | 17/6/2026 | A specially crafted POST request to the ProGauge MAGLINK LX CONSOLE IP sub-menu can allow a remote attacker to inject arbitrary commands. | |
| Analizada | Crítica (10) | 0.79% | — | Doverfuelingsolutions Progauge Maglink LX Console FirmwareDoverfuelingsolutions Progauge Maglink LX4 Console Firmware | 25/9/2024 | 17/6/2026 | A specially crafted POST request to the ProGauge MAGLINK LX CONSOLE UTILITY sub-menu can allow a remote attacker to inject arbitrary commands. | |
| Analizada | Crítica (9.3) | 0.51% | — | Doverfuelingsolutions Progauge Maglink LX Console FirmwareDoverfuelingsolutions Progauge Maglink LX4 Console Firmware | 25/9/2024 | 17/6/2026 | An attacker can directly request the ProGauge MAGLINK LX CONSOLE resource sub page with full privileges by requesting the URL directly. | |
| Analizada | Crítica (9.3) | 0.68% | — | Doverfuelingsolutions Progauge Maglink LX Console FirmwareDoverfuelingsolutions Progauge Maglink LX4 Console Firmware | 25/9/2024 | 17/6/2026 | The web application for ProGauge MAGLINK LX4 CONSOLE contains an administrative-level user account with a password that cannot be changed. | |
| Analizada | Alta (8.7) | 0.36% | — | Doverfuelingsolutions Progauge Maglink LX Console FirmwareDoverfuelingsolutions Progauge Maglink LX4 Console Firmware | 25/9/2024 | 17/6/2026 | ProGauge MAGLINK LX CONSOLE does not have sufficient filtering on input fields that are used to render pages which may allow cross site scripting. | |
| Modificada | Alta (7.5) | 1.4% | — | Electroind Gaugetech Nexus Firmware | 28/6/2018 | 17/6/2026 | Electro Industries GaugeTech Nexus devices allow remote attackers to obtain potentially sensitive information via a direct request for the meter_information.htm, diag_system.htm, or diag_dnp_lan_wan.htm URI. | |
| Modificada | Alta (8.1) | 9.0% | — | Flexense Sysgauge | 23/1/2018 | 17/6/2026 | The server in Flexense SysGauge 3.6.18 operating on port 9221 can be exploited remotely with the attacker gaining system-level access because of a Buffer Overflow. | |
| Modificada | Alta (7.5) | 3.8% | — | Flexense Sysgauge | 28/12/2017 | 17/6/2026 | In Flexense SysGauge Server 3.6.18, the Control Protocol suffers from a denial of service. The attack vector is a crafted SERVER_GET_INFO packet sent to control port 9221. | |
| Modificada | Crítica (9.8) | 11% | — | Flexense Sysgauge | 6/3/2017 | 17/6/2026 | An issue was discovered in SysGauge 1.5.18. A buffer overflow vulnerability in SMTP connection verification leads to arbitrary code execution. The attack vector is a crafted SMTP daemon that sends a long 220 (aka "Service ready") string. | |
| Modificada | Baja (2.1) | 0.53% | — | HP Array Configuration UtilityHP Array Diagnostics UtilityHP Proliant Array DiagnosticsHP Smartssd Wear Gauge Utility | 12/4/2014 | 17/6/2026 | Unspecified vulnerability in HP Array Configuration Utility, Array Diagnostics Utility, ProLiant Array Diagnostics, and SmartSSD Wear Gauge Utility 9.40 and earlier allows local users to gain privileges via unknown vectors. | |
| Modificada | Alta (7.8) | 3.8% | — | Hammer-software Metagauge | 7/10/2008 | 16/6/2026 | Directory traversal vulnerability in MetaGauge 1.0.0.17, and probably other versions before 1.0.3.38, allows remote attackers to read arbitrary files via a "..\" (dot dot backslash) in the URL. |