Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2676▼ 422 respecto a la semana anterior
Críticas / altas1295▼ 73 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 274 respecto a la semana anterior
11 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.9) | 0.26% | — | Nagvis | 3/12/2025 | 17/6/2026 | User enumeration in Nagvis' Checkmk MultisiteAuth before version 1.9.48 allows an unauthenticated attacker to enumerate Checkmk usernames. | |
| Modificada | Media (5.1) | 0.22% | — | Nagvis | 27/5/2025 | 17/6/2026 | Improper neutralization of input in Nagvis before version 1.9.47 which can lead to XSS | |
| Modificada | Media (5.3) | 0.39% | — | Nagvis | 27/5/2025 | 17/6/2026 | Improper neutralization of input in Nagvis before version 1.9.47 which can lead to livestatus injection | |
| Aplazada | Alta (7.2) | 1.3% | — | CheckmkAINagvisAI | 4/2/2025 | 17/6/2026 | The "NagVis" component within Checkmk is vulnerable to remote code execution. An authenticated attacker with administrative level privileges is able to upload a malicious PHP file and modify specific settings to execute the contents of the file as PHP. | |
| Aplazada | Media (5.4) | 0.58% | — | Checkmk NagvisAI | 4/2/2025 | 17/6/2026 | The "NagVis" component within Checkmk is vulnerable to reflected cross-site scripting. An attacker can craft a malicious link that will execute arbitrary JavaScript in the context of the browser once clicked. The attack can be performed on both authenticated and unauthenticated users. | |
| Modificada | Media (6.1) | 0.53% | — | Nagvis | 19/12/2024 | 17/6/2026 | Improper neutralization of input in Nagvis before version 1.9.42 which can lead to XSS | |
| Modificada | Media (6.1) | 0.50% | — | Nagvis | 20/10/2023 | 17/6/2026 | XSS exists in NagVis before 1.9.38 via the select function in share/server/core/functions/html.php. | |
| Modificada | Media (6.5) | 4.1% | — | Nagvis | 26/5/2023 | 17/6/2026 | Nagvis before 1.9.34 was discovered to contain an arbitrary file read vulnerability via the component /core/classes/NagVisHoverUrl.php. | |
| Modificada | Alta (8.1) | 1.1% | — | Nagvis | 13/11/2022 | 17/6/2026 | A vulnerability was found in NagVis up to 1.9.33 and classified as problematic. This issue affects the function checkAuthCookie of the file share/server/core/classes/CoreLogonMultisite.php. The manipulation of the argument hash leads to incorrect type conversion. The attack may be initiated remotely. The complexity of… | |
| Modificada | Media (6.5) | 1.9% | — | Nagvis | 14/10/2021 | 17/6/2026 | The Manage Backgrounds functionality within NagVis versions prior to 1.9.29 is vulnerable to an authenticated path traversal vulnerability. Exploitation of this results in a malicious actor having the ability to arbitrarily delete files on the local system. | |
| Modificada | Media (6.1) | 0.96% | — | Nagvis | 2/3/2017 | 17/6/2026 | An issue was discovered in NagVis 1.9b12. The vulnerability exists due to insufficient filtration of user-supplied data passed to the "nagvis-master/share/userfiles/gadgets/std_table.php" URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website. |