Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 82 respecto a la semana anterior
Críticas / altas1416▲ 189 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)100▼ 400 respecto a la semana anterior
–

967 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
RecibidaAlta (7.2)——Download MonitorAI2/10/20262/10/2026
The Download Monitor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Cross-Origin postMessage to Admin Editor in all versions up to, and including, 5.2.10 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…
AplazadaMedia (5.3)0.26%—Argotronic ArgusmonitorAI29/9/202630/9/2026
Improper Access Control in ArgusMonitor.sys in Argotronic eGbR ArgusMonitor 7.4.02 and earlier allows local, low-privileged users to bypass device handle access restrictions via a TOCTOU condition in IRP_MJ_CREATE and send a crafted IOCTL 0x9C4024A8 request, causing denial-of-service.
Pendiente de análisisMedia (4.7)0.14%—Microsoft Network MonitorAI29/9/202629/9/2026
Microsoft Network Monitor file parser large loop in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
AplazadaAlta (7.1)0.27%—Paessler Prtg Network MonitorAI24/9/202624/9/2026
PRTG Network Monitor before version 26.2.120.1449 ships a demo EXE/Script sensor that multiplies two integer parameters using cscript.exe. If a non-numeric value is passed instead, cscript.exe raises a 'Type mismatch' runtime error that includes the offending parameter value in plaintext. PRTG provides a documented…
AplazadaMedia (5.1)0.55%—Paessler Prtg Network MonitorAI24/9/202624/9/2026
Paessler PRTG Network Monitor before version 26.2.120.1449 is affected by a reflected Cross-Site Scripting (XSS) vulnerability. When a request is made for a non-existent resource ending in \".htm\", the web interface returns an HTTP 403 \"Forbidden Path\" error page that echoes the requested URL path into the HTML…
Pendiente de análisisAlta (8.4)0.14%—Dell Command MonitorAI21/9/202622/9/2026
Dell Command | Monitor (DCM), versions prior to 10.13.2, contain an Incorrect Permission Assignment for Critical Resource vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.
AplazadaAlta (8.5)0.18%—Biostar Temperature Monitor UtilityAI21/9/202621/9/2026
A security vulnerability has been detected in BioStar Temperature Monitor Utility 1.2.1806.2200. Affected by this vulnerability is the function sub_1105C of the file BS_HWMIO64_W10.sys of the component IOCTL Handler. Such manipulation of the argument PhysicalAddress leads to write-what-where condition. The attack…
AplazadaMedia (5.5)0.43%—Sourcecodester Inventory AND Monitoring SystemAI16/9/202616/9/2026
A vulnerability was detected in SourceCodester Inventory and Monitoring System 1.0. The impacted element is an unknown function of the file /admins/assessments/databank/btn_functions.php?action=add. Performing a manipulation of the argument difficulty_id results in sql injection. Remote exploitation of the attack is…
AplazadaMedia (5.5)0.43%—Sourcecodester Inventory AND Monitoring SystemAI16/9/202616/9/2026
A security vulnerability has been detected in SourceCodester Inventory and Monitoring System 1.0. The affected element is an unknown function of the file /index.php. Such manipulation of the argument Username leads to sql injection. The attack may be launched remotely. The exploit has been disclosed publicly and may…
AplazadaAlta (7)0.09%—Duoxme ApplicationAIVEO Wifi MonitorAIVEO XS Wifi MonitorAI16/9/202618/9/2026
Transmission of the home Wi-Fi credentials without encryption during the pairing process between the DuoxMe application and VEO and VEO-XS Wi-Fi monitors, in versions prior to 4.3.4 of the application and 01.50.001 of the monitor firmware, allows an attacker on the Wi-Fi Direct network to intercept the network…
Pendiente de análisisBaja (2.7)0.22%—Paessler Prtg Network MonitorAI14/9/202622/9/2026
PRTG Network Monitor before 23.1.82 allows remote attackers to write to files via the FTP Server Count Sensor.
AplazadaBaja (2.7)0.22%—Paessler Prtg Network MonitorAI14/9/202622/9/2026
PRTG Network Monitor before 23.1.82 allows remote attackers to write to files via the HTTP XML/REST Sensor.
Pendiente de análisisCrítica (9.8)0.52%—Fortinet FortimonitoronsightAI11/9/202611/9/2026
A inclusion of sensitive information in source code vulnerability in Fortinet FortiMonitorOnSight 7.2.4 through 7.2.7, FortiMonitorOnSight 7.2.0 through 7.2.2 may allow attacker to improper access control via <insert attack vector here>
Pendiente de análisisAlta (8.6)0.46%—Tycon Systems Tpdin-monitor-web3AI4/9/20268/9/2026
Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a Missing Authorization vulnerability. This could allow an attacker to extract system credentials, configurations, or flash contents.
Pendiente de análisisAlta (8.6)0.25%—Tycon Systems Tpdin-monitor-web3AI4/9/20268/9/2026
Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a cross-site request forgery vulnerability. This could allow an attacker to perform state changing operations on the device.
Pendiente de análisisAlta (7.1)0.33%—Tycon Systems Tpdin-monitor-web3AI4/9/20269/9/2026
Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a use of hard-coded credential vulnerability. This could allow an attacker to intercept sensitive information or credentials.
AplazadaMedia (5.5)0.41%—Shenzhen Gongji Technology Xbrother Dynamic Environment Monitoring SystemAI24/8/202624/8/2026
A security vulnerability has been detected in Shenzhen Gongji Technology XBROTHER Dynamic Environment Monitoring System up to 300R004C00B300. The affected element is the function PlanController.getImmediatePlans of the file /xbreport/api/v1/plamange/plansImmediate. The manipulation of the argument order/sort leads to…
AplazadaCrítica (9.9)0.55%—Nezha Monitoring NezhaAI21/8/20269/9/2026
Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. Nezha versions 1.14.13 through 1.14.14 and 2.0.0 through 2.0.9 do not bind stream identifiers created by CreateStream in service/rpc/io_stream.go to their creating user, and `GET /ws/terminal/:id` and `GET /ws/file/:id`…
AplazadaMedia (5.5)0.17%—Linuxfabrik-libAILinuxfabrik Monitoring PluginsAI18/8/20269/9/2026
linuxfabrik-lib provides Python modules for database access, caching, shell execution, and API integrations, and Linuxfabrik Monitoring Plugins uses its shared testing helper across check plugins. Prior to linuxfabrik-lib 6.1.0 and Linuxfabrik Monitoring Plugins 7.0.0, lib.lftest.test() treated the first or second…
AplazadaMedia (5.5)0.29%—Linuxfabrik Monitoring PluginsAI18/8/20269/9/2026
Linuxfabrik Monitoring Plugins provides monitoring plugins for Icinga, Nagios, and related systems. Prior to version 7.0.0, check-plugins/logfile/logfile accepted a free-form --filename path and opened it as root when invoked through the shipped nagios or icinga sudoers allowlist, without confining the resolved path…
AplazadaAlta (7.8)0.21%—Linuxfabrik-libAILinuxfabrik Monitoring PluginsAI18/8/20269/9/2026
linuxfabrik-lib provides Python modules for database access, caching, shell execution, and API integrations, and Linuxfabrik Monitoring Plugins uses those modules to run external monitoring commands. From the earliest affected releases until linuxfabrik-lib 5.0.0 and Linuxfabrik Monitoring Plugins 6.0.0, check plugins…
AplazadaAlta (7)0.18%—Linuxfabrik Monitoring PluginsAIDebian Apt-getAI18/8/20269/9/2026
Linuxfabrik Monitoring Plugins provides monitoring plugins for Icinga, Nagios, and related systems. Prior to version 5.1.0, the shipped assets/sudoers/Debian.sudoers policy allowed the nagios or icinga account to execute /usr/bin/apt-get as root without restricting its arguments. An attacker who already controls that…
Pendiente de análisisAlta (8.7)0.40%—Mira Hormone MonitorAI11/8/20263/9/2026
In the Mira hormone monitor device firmware v1.7.1.47 build 01070147, a remote unauthenticated attacker within BLE range (approximately 10–30 meters) can silently rebind the device to an attacker-controlled account, extract stored hormone measurements in cleartext, cause a denial-of-service via malformed or…
Pendiente de análisisAlta (7.1)0.32%—Mira Hormone MonitorAI11/8/20263/9/2026
The Mira hormone monitor device firmware accepts a 0x01 write from any BLE central without authentication, causing the device to reboot into bootloader mode. An attacker could cause a denial-of-service condition or disrupt ovulation tracking and fertility monitoring workflow.
AnalizadaAlta (7.2)1.0%—Microsoft Azure Monitor Agent11/8/202613/8/2026
Improper neutralization of special elements used in a command ('command injection') in Azure Monitor Agent allows an authorized attacker to elevate privileges over a network.