Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2532▼ 363 respecto a la semana anterior
Críticas / altas1340▲ 76 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
23 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.4) | 0.54% | — | Openstack AodhAIOpenstack WatcherAI | 19/8/2026 | 9/9/2026 | In OpenStack Aodh before 22.0.1, the alarm list API bypasses project scoping when the all_projects query parameter is set to false. The API checks for the presence of the all_projects key rather than its value; a true value enforces the administrator-only policy, but a false value removes the key and skips the branch… | |
| Aplazada | Alta (8.6) | 0.15% | — | Nsasoft NetsharewatcherAI | 4/6/2026 | 22/7/2026 | NetShareWatcher 1.5.8.0 contains a structured exception handler buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying malicious input. Attackers can craft a payload with overwritten SEH and NSEH pointers through the Restrictions custom filter field to trigger code execution… | |
| Analizada | Media (4.6) | 0.37% | — | Nsasoft Netsharewatcher | 11/2/2026 | 29/6/2026 | NetShareWatcher 1.5.8.0 contains a buffer overflow vulnerability in the registration name input that allows attackers to crash the application. Attackers can generate a 1000-character payload and paste it into the 'Name' field to trigger an application crash. | |
| Analizada | Media (4.6) | 0.37% | — | Nsasoft Netsharewatcher | 11/2/2026 | 29/6/2026 | NetShareWatcher 1.5.8.0 contains a buffer overflow vulnerability in the registration key input that allows attackers to crash the application by supplying oversized input. Attackers can generate a 1000-character payload and paste it into the registration key field to trigger an application crash. | |
| Aplazada | Alta (8.5) | 0.18% | — | IP WatcherAI | 28/1/2026 | 17/6/2026 | IP Watcher 3.0.0.30 contains an unquoted service path vulnerability in its Windows service configuration that allows local attackers to execute arbitrary code. Attackers can exploit the unquoted binary path to inject malicious executables that will be launched with elevated LocalSystem privileges during service… | |
| Aplazada | Media (5.4) | 0.24% | — | Merkulove Watcher FOR ElementorAI | 31/12/2025 | 23/9/2026 | Missing Authorization vulnerability in merkulove Watcher for Elementor watcher-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Watcher for Elementor: from n/a through <= 1.0.9. | |
| Aplazada | Crítica (9.8) | 1.1% | — | Choco TEI Watcher MiniAI | 31/3/2025 | 17/6/2026 | Direct request ('Forced Browsing') issue exists in CHOCO TEI WATCHER mini (IB-MCT001) all versions. If a remote attacker sends a specially crafted HTTP request to the product, the product data may be obtained or deleted, and/or the product settings may be altered. | |
| Aplazada | Crítica (9.8) | 0.85% | — | Choco TEI Watcher MiniAI | 31/3/2025 | 17/6/2026 | Weak password requirements issue exists in CHOCO TEI WATCHER mini (IB-MCT001) all versions. If this issue is exploited, a brute-force attack may allow an attacker unauthorized access and login. | |
| Aplazada | Media (4.6) | 0.31% | — | Choco TEI Watcher MiniAI | 31/3/2025 | 17/6/2026 | Storing passwords in a recoverable format issue exists in CHOCO TEI WATCHER mini (IB-MCT001) all versions. If this issue is exploited, an attacker who can access the microSD card used on the product may obtain the product login password. | |
| Aplazada | Alta (7.5) | 0.80% | — | Choco TEI Watcher MiniAI | 31/3/2025 | 17/6/2026 | Use of client-side authentication issue exists in CHOCO TEI WATCHER mini (IB-MCT001) all versions. If this issue is exploited, a remote attacker may obtain the product login password without authentication. | |
| Analizada | Media (6) | 0.71% | — | Microsoft Azure Network Watcher | 11/2/2025 | 17/6/2026 | Azure Network Watcher VM Extension Elevation of Privilege Vulnerability | |
| Analizada | Alta (7.3) | 0.85% | — | Microsoft Azure Network Watcher Agent | 10/9/2024 | 10/8/2026 | Azure Network Watcher VM Agent Elevation of Privilege Vulnerability | |
| Analizada | Alta (7.1) | 0.58% | — | Microsoft Azure Network Watcher Agent | 10/9/2024 | 10/8/2026 | Azure Network Watcher VM Agent Elevation of Privilege Vulnerability | |
| Modificada | Alta (7.8) | 0.71% | — | Microsoft Azure Network Watcher Agent | 9/7/2024 | 17/6/2026 | Azure Network Watcher VM Extension Elevation of Privilege Vulnerability | |
| Aplazada | Media (4.4) | 0.17% | — | Panasonic KW WatcherAI | 8/5/2024 | 17/6/2026 | A buffer error in Panasonic KW Watcher versions 1.00 through 2.83 may allow attackers malicious read access to memory. | |
| Modificada | Alta (7.8) | 0.56% | — | Microsoft Azure Network Watcher | 10/10/2023 | 17/6/2026 | Azure Network Watcher VM Agent Elevation of Privilege Vulnerability | |
| Modificada | Alta (7.8) | 0.25% | — | Panasonic KW Watcher | 6/9/2023 | 17/6/2026 | Use after free vulnerability in Panasonic KW Watcher versions 1.00 through 2.82 may allow attackers to execute arbitrary code. | |
| Modificada | Alta (7.8) | 0.46% | — | Panasonic KW Watcher | 6/9/2023 | 17/6/2026 | Buffer overflow vulnerability in Panasonic KW Watcher versions 1.00 through 2.82 may allow attackers to execute arbitrary code. | |
| Modificada | Media (5.5) | 0.46% | — | Microsoft Azure Network Watcher Agent | 13/12/2022 | 17/6/2026 | Azure Network Watcher Agent Security Feature Bypass Vulnerability | |
| Modificada | Alta (7.8) | 0.98% | — | Microsoft Network Watcher Agent | 16/10/2020 | 17/6/2026 | <p>An elevation of privilege vulnerability exists in Network Watcher Agent virtual machine extension for Linux. An attacker who successfully exploited this vulnerability could execute code with elevated privileges.</p> <p>To exploit this vulnerability, an attacker would have to be present as a user on the affected… | |
| Modificada | Media (6.8) | 0.64% | — | LOG Watcher Project LOG Watcher | 21/4/2015 | 17/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in the Log Watcher module before 6.x-1.2 for Drupal allow remote attackers to hijack the authentication of administrators for requests that (1) enable, (2) disable, or (3) delete a report via unspecified vectors. | |
| Modificada | Alta (7.5) | 1.9% | — | Bidwatcher | 2/5/2005 | 16/6/2026 | Format string vulnerability in bidwatcher before 1.3.17 allows remote malicious web servers from eBay, or a spoofed eBay server, to cause a denial of service and possibly execute arbitrary code via certain responses. | |
| Modificada | Alta (7.5) | 2.6% | — | BTT Software Snmp Trap Watcher | 31/8/2001 | 16/6/2026 | Buffer overflow in BTT Software SNMP Trap Watcher 1.16 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long string trap. |