Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2676▼ 422 respecto a la semana anterior
Críticas / altas1295▼ 73 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 274 respecto a la semana anterior
–

11 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.9)0.26%—Nagvis3/12/202517/6/2026
User enumeration in Nagvis' Checkmk MultisiteAuth before version 1.9.48 allows an unauthenticated attacker to enumerate Checkmk usernames.
ModificadaMedia (5.1)0.22%—Nagvis27/5/202517/6/2026
Improper neutralization of input in Nagvis before version 1.9.47 which can lead to XSS
ModificadaMedia (5.3)0.39%—Nagvis27/5/202517/6/2026
Improper neutralization of input in Nagvis before version 1.9.47 which can lead to livestatus injection
AplazadaAlta (7.2)1.3%—CheckmkAINagvisAI4/2/202517/6/2026
The "NagVis" component within Checkmk is vulnerable to remote code execution. An authenticated attacker with administrative level privileges is able to upload a malicious PHP file and modify specific settings to execute the contents of the file as PHP.
AplazadaMedia (5.4)0.58%—Checkmk NagvisAI4/2/202517/6/2026
The "NagVis" component within Checkmk is vulnerable to reflected cross-site scripting. An attacker can craft a malicious link that will execute arbitrary JavaScript in the context of the browser once clicked. The attack can be performed on both authenticated and unauthenticated users.
ModificadaMedia (6.1)0.53%—Nagvis19/12/202417/6/2026
Improper neutralization of input in Nagvis before version 1.9.42 which can lead to XSS
ModificadaMedia (6.1)0.50%—Nagvis20/10/202317/6/2026
XSS exists in NagVis before 1.9.38 via the select function in share/server/core/functions/html.php.
ModificadaMedia (6.5)4.1%—Nagvis26/5/202317/6/2026
Nagvis before 1.9.34 was discovered to contain an arbitrary file read vulnerability via the component /core/classes/NagVisHoverUrl.php.
ModificadaAlta (8.1)1.1%—Nagvis13/11/202217/6/2026
A vulnerability was found in NagVis up to 1.9.33 and classified as problematic. This issue affects the function checkAuthCookie of the file share/server/core/classes/CoreLogonMultisite.php. The manipulation of the argument hash leads to incorrect type conversion. The attack may be initiated remotely. The complexity of…
ModificadaMedia (6.5)1.9%—Nagvis14/10/202117/6/2026
The Manage Backgrounds functionality within NagVis versions prior to 1.9.29 is vulnerable to an authenticated path traversal vulnerability. Exploitation of this results in a malicious actor having the ability to arbitrarily delete files on the local system.
ModificadaMedia (6.1)0.96%—Nagvis2/3/201717/6/2026
An issue was discovered in NagVis 1.9b12. The vulnerability exists due to insufficient filtration of user-supplied data passed to the "nagvis-master/share/userfiles/gadgets/std_table.php" URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.