Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3026▼ 51 respecto a la semana anterior
Críticas / altas1412▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)385▼ 125 respecto a la semana anterior
–

8 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)13%—Idera Uptime Infrastructure Monitor27/8/201817/6/2026
An issue was discovered in post2file.php in Up.Time Monitoring Station 7.5.0 (build 16) and 7.4.0 (build 13). It allows an attacker to upload an arbitrary file, such as a .php file that can execute arbitrary OS commands.
ModificadaCrítica (9.8)1.5%—Idera Uptime Infrastructure Monitor20/7/201717/6/2026
IDERA Uptime Monitor 7.8 has SQL injection in /gadgets/definitions/uptime.CapacityWhatIfGadget/getmetrics.php via the element parameter.
ModificadaCrítica (9.8)1.5%—Idera Uptime Infrastructure Monitor20/7/201717/6/2026
IDERA Uptime Monitor 7.8 has SQL injection in /gadgets/definitions/uptime.CapacityWhatifGadget/getxenmetrics.php via the element parameter.
ModificadaAlta (7.5)4.9%—Idera Uptime Infrastructure Monitor20/7/201717/6/2026
get2post.php in IDERA Uptime Monitor 7.8 has directory traversal in the file_name parameter.
ModificadaAlta (7.5)3.0%—Idera Uptime Infrastructure Monitor10/6/201617/6/2026
The up.time agent in Idera Uptime Infrastructure Monitor 7.5 and 7.6 on Linux allows remote attackers to read arbitrary files via unspecified vectors.
ModificadaMedia (5.3)1.2%—Idera Uptime Infrastructure Monitor31/12/201517/6/2026
The up.time client in Idera Uptime Infrastructure Monitor through 7.6 allows remote attackers to obtain potentially sensitive version, OS, process, and event-log information via a command.
ModificadaAlta (7.3)1.9%—Idera Uptime Infrastructure Monitor31/12/201517/6/2026
Buffer overflow in the up.time client in Idera Uptime Infrastructure Monitor 7.4 might allow remote attackers to execute arbitrary code via long command input.
ModificadaMedia (5.3)1.4%—Idera Uptime Infrastructure Monitor31/12/201517/6/2026
Format string vulnerability in the up.time client in Idera Uptime Infrastructure Monitor 6.0 and 7.2 allows remote attackers to cause a denial of service (application crash) via format string specifiers.