Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3043▲ 582 respecto a la semana anterior
Críticas / altas1452▲ 283 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)393▲ 186 respecto a la semana anterior
15 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.3) | 0.27% | — | PHP Server MonitorAIPhpmailerAI | 24/5/2024 | 17/6/2026 | PHP Server Monitor, version 3.2.0, is vulnerable to an XSS via the /phpservermon-3.2.0/vendor/phpmailer/phpmailer/test_script/index.php page in all visible parameters. An attacker could create a specially crafted URL, send it to a victim and retrieve their session details. | |
| Modificada | Media (5.3) | 0.82% | — | Phpservermonitor PHP Server Monitor | 15/11/2022 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in phpservermon. Affected is the function setUserLoggedIn of the file src/psm/Service/User.php. The manipulation leads to use of predictable algorithm in random number generator. The exploit has been disclosed to the public and may be used. The name of… | |
| Modificada | Media (5.3) | 0.86% | — | Phpservermonitor PHP Server Monitor | 15/11/2022 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in phpservermon. This affects the function generatePasswordResetToken of the file src/psm/Service/User.php. The manipulation leads to use of predictable algorithm in random number generator. The exploit has been disclosed to the public and may be used.… | |
| Modificada | Media (5.4) | 0.84% | — | Phpservermonitor PHP Server Monitor | 12/12/2021 | 17/6/2026 | phpservermon is vulnerable to Improper Neutralization of CRLF Sequences | |
| Modificada | Media (5.4) | 0.69% | — | Poweradmin PA Server Monitor | 5/11/2021 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in Power Admin PA Server Monitor 8.2.1.1 allows remote attackers to inject arbitrary web script or HTML via Console.exe. | |
| Modificada | Alta (7.8) | 0.42% | — | Motex Lanscope ANMotex Lanscope CAT Client ProgramMotex Lanscope CAT Detection AgentMotex Lanscope CAT Server Monitoring Agent | 26/12/2019 | 17/6/2026 | Privilege escalation vulnerability in Multiple MOTEX products (LanScope Cat client program (MR) and LanScope Cat client program (MR)LanScope Cat detection agent (DA) prior to Ver.9.2.1.0, LanScope Cat server monitoring agent (SA, SAE) prior to Ver.9.2.2.0, LanScope An prior to Ver 2.7.7.0 (LanScope An 2 series), and… | |
| Modificada | Media (6.5) | 0.61% | — | Phpservermonitor PHP Server Monitor | 18/12/2018 | 17/6/2026 | PHP Server Monitor before 3.3.2 has CSRF, as demonstrated by a Delete action. | |
| Modificada | Media (6.1) | 1.3% | — | Microfocus Directory ServerMicrofocus Enterprise DeveloperMicrofocus Enterprise ServerMicrofocus Enterprise Server Monitor AND Control | 21/8/2017 | 17/6/2026 | Reflected and stored Cross-Site Scripting (XSS, CWE-79) vulnerabilities in Directory Server (aka Enterprise Server Administration web UI) and ESMAC (aka Enterprise Server Monitor and Control) in Micro Focus Enterprise Developer and Enterprise Server 2.3 and earlier, 2.3 Update 1 before Hotfix 8, and 2.3 Update 2… | |
| Modificada | Crítica (9.8) | 2.4% | — | Microfocus Enterprise DeveloperMicrofocus Enterprise ServerMicrofocus Enterprise Server Monitor AND Control | 21/8/2017 | 17/6/2026 | An Authentication Bypass (CWE-287) vulnerability in ESMAC (aka Enterprise Server Monitor and Control) in Micro Focus Enterprise Developer and Enterprise Server 2.3 and earlier, 2.3 Update 1 before Hotfix 8, and 2.3 Update 2 before Hotfix 9 allows remote unauthenticated attackers to view and alter configuration… | |
| Modificada | Alta (8.8) | 0.75% | — | Microfocus Directory ServerMicrofocus Enterprise DeveloperMicrofocus Enterprise ServerMicrofocus Enterprise Server Monitor AND Control | 21/8/2017 | 17/6/2026 | A Cross-Site Request Forgery (CWE-352) vulnerability in Directory Server (aka Enterprise Server Administration web UI) in Micro Focus Enterprise Developer and Enterprise Server 2.3 and earlier, 2.3 Update 1 before Hotfix 8, and 2.3 Update 2 before Hotfix 9 allows remote unauthenticated attackers to view and alter… | |
| Modificada | Baja (1.9) | 0.28% | — | Tembria Server Monitor | 27/9/2011 | 16/6/2026 | Tembria Server Monitor before 6.0.5 Build 2252 uses a substitution cipher to encrypt application credentials, which allows local users to obtain sensitive information by leveraging read access to (1) authentication.dat or (2) XML files in the Exports directory. | |
| Modificada | Media (4.3) | 1.3% | — | Tembria Server Monitor | 27/9/2011 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Tembria Server Monitor before 6.0.5 Build 2252 allow remote attackers to inject arbitrary web script or HTML via (1) the siteid parameter to logbook.asp, (2) the siteid parameter to monitor-events.asp, (3) the siteid parameter to reports-config-by-device.asp, (4)… | |
| Modificada | Media (5) | 9.7% | — | Tembria Server Monitor | 14/4/2010 | 16/6/2026 | Multiple stack-based buffer overflows in Tembria Server Monitor before 5.6.1 allow remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a crafted (1) GET, (2) PUT, or (3) HEAD request, as demonstrated by a malformed GET request containing a long PATH_INFO to index.asp. | |
| Modificada | Alta (10) | 1.4% | — | Paessler Ipcheck Server Monitor | 31/8/2006 | 16/6/2026 | Paessler IPCheck Server Monitor before 5.3.3.639/640 does not properly implement a "list of acceptable host IP addresses in the probe settings," which has unknown impact and attack vectors. | |
| Modificada | Media (5) | 4.4% | — | Ipcheck Server Monitor | 14/8/2006 | 16/6/2026 | Directory traversal vulnerability in IPCheck Server Monitor before 5.3.3.639/640 allows remote attackers to read arbitrary files via modified .. (dot dot) sequences in the URL, including (1) "..%2f" (encoded "/" slash), "..../" (multiple dot), and "..%255c../" (double-encoded "\" backslash). |