Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2632▼ 455 respecto a la semana anterior
Críticas / altas1285▼ 65 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)235▼ 275 respecto a la semana anterior
1029 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.4) | 0.12% | — | Intel Performance Counter Monitor | 11/8/2026 | 2/10/2026 | Untrusted search path for some Intel(R) Performance Counter Monitor (Intel(R) PCM) before version tag 202604 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable escalation of privilege. This… | |
| Aplazada | Media (5.3) | 0.30% | — | Download MonitorAI | 8/8/2026 | 26/8/2026 | The Download Monitor WordPress plugin before 5.2.6 does not perform authorization checks on one of its download-logging AJAX actions, and exposes the nonce protecting it to unauthenticated visitors, allowing unauthenticated users to inject arbitrary download log entries and inflate a site's download statistics. | |
| Analizada | Alta (7.8) | 0.16% | — | Dell Monitor Driver | 3/8/2026 | 7/8/2026 | Dell Monitor driver, version 1.0.0.0, contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges. | |
| Aplazada | Crítica (9.8) | 0.50% | — | ShopmonitorAI | 31/7/2026 | 26/8/2026 | The ShopMonitor.io WordPress plugin before 1.2.0 does not properly restrict its email-rerouting test mode, gating it behind a trusted-source check that is satisfiable with client-supplied request headers, allowing unauthenticated attackers to redirect outgoing emails, including the WordPress administrator… | |
| Pendiente de análisis | Alta (8.3) | 0.42% | — | Linuxfabrik Monitoring-pluginsAIIcingaAINagiosAI | 29/7/2026 | 30/7/2026 | Linuxfabrik monitoring-plugins provides Python monitoring plugins for Icinga, Nagios, and related monitoring systems. In 6.0.0 and earlier, the redfish-* plugins built request URLs by concatenating an operator-supplied base URL with response-supplied @odata.id links, allowing a malicious or compromised BMC to redirect… | |
| Pendiente de análisis | Media (5.8) | 0.10% | — | Linuxfabrik Monitoring-pluginsAIPython Sqlite3AI | 29/7/2026 | 30/7/2026 | Linuxfabrik monitoring-plugins provides Python monitoring plugins for Icinga, Nagios, and related monitoring systems. In version 6.0.0, the logfile check legacy database migration moved a predictable path from /tmp with os.rename() and allowed a local user controlling the plugin account to place a symlink that would… | |
| Aplazada | Crítica (9.3) | 0.56% | — | Tycon Systems Tpdin Monitor Web2AI | 24/7/2026 | 4/9/2026 | The Tycon Systems TPDIN-Monitor-WEB2 ships without HTTP credentials configured, intended for an installer to set them on first use. On firmware 2.4.4 and earlier, a unit left in this unconfigured state serves the web management interface without requiring any login. An attacker with network access to such a unit can… | |
| Aplazada | Media (5.3) | 0.19% | — | Tycon Systems Tpdin-monitor-web2AI | 24/7/2026 | 4/9/2026 | The web management interface in Tycon Systems TPDIN-Monitor-WEB2 stores and displays system credentials in cleartext on a certain configuration page accessible to authenticated users. Any party with access to the administrative dashboard can immediately read these credentials, which may be used to compromise other… | |
| Aplazada | Alta (7.1) | 0.25% | — | Wpforms Download MonitorAI | 23/7/2026 | 23/7/2026 | Unauthenticated Cross Site Scripting (XSS) in Download Monitor - WPForms Lock <= 1.0.4 versions. | |
| Pendiente de análisis | Crítica (9.6) | 0.84% | — | Centreon-open-ticketsAICentreon Infra MonitoringAI | 13/7/2026 | 13/7/2026 | This vulnerability is a critical Server-Side Template Injection (SSTI) in Centreon's centreon-open-tickets module that leads to Remote Code Execution. The message_confirm field is stored without sanitization and rendered via Smarty with no security policy enabled, allowing any authenticated user, to inject and execute… | |
| Aplazada | Media (6.9) | 0.48% | — | Nezha MonitoringAI | 10/7/2026 | 13/7/2026 | Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. Prior to 2.2.5, the GET /api/v1/ddns and GET /api/v1/notification endpoints return full resource objects including plaintext third-party API credentials, including Cloudflare API tokens, TencentCloud SecretKeys, Slack,… | |
| Aplazada | Baja (2.1) | 0.29% | — | Flask-dashboard Flask-monitoringdashboardAI | 8/7/2026 | 8/7/2026 | A vulnerability has been found in flask-dashboard Flask-MonitoringDashboard up to 5.0.2. Affected by this issue is some unknown functionality. Such manipulation leads to cross-site request forgery. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The project was… | |
| Aplazada | Media (5.1) | 0.34% | — | Ricoh WEB Image MonitorAI | 30/6/2026 | 31/8/2026 | Multiple laser printers and MFPs (multifunction printers) which implement Ricoh Web Image Monitor contain a reflected cross-site scripting vulnerability. An arbitrary script may be executed on the web browser of the user who accesses a crafted URL. | |
| Analizada | Media (4.4) | 0.14% | — | Fortra File Integrity Monitoring | 23/6/2026 | 29/6/2026 | Fortra File Integrity Monitoring (FIM), formerly Tripwire Enterprise, versions prior to 9.4.0 may assign incorrect or elevated effective permissions to users created by the tetool import command while FIM is running, particularly when the import also creates or changes roles or role-permission relationships. | |
| Analizada | Media (4.8) | 0.24% | — | Fortra File Integrity Monitoring | 23/6/2026 | 28/6/2026 | Fortra File Integrity Monitoring (FIM), formerly Tripwire Enterprise, versions prior to 9.4.0.1 contain a stored cross-site scripting (XSS) vulnerability in the Asset View UI component. An authenticated user with sufficient privileges to create or modify affected node or database configuration fields could store… | |
| Aplazada | Alta (8.5) | 0.36% | — | Swit WP Sessions Time Monitoring Full AutomaticAI | 16/6/2026 | 17/6/2026 | Subscriber SQL Injection in WP Sessions Time Monitoring Full Automatic <= 1.1.4 versions. | |
| Aplazada | Media (4.4) | 0.37% | — | Download MonitorAI | 15/6/2026 | 17/6/2026 | Author Arbitrary File Download in Download Monitor <= 5.1.9 versions. | |
| Aplazada | Media (6.8) | 0.32% | — | Nezha MonitoringAI | 12/6/2026 | 17/6/2026 | Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 1.0.0 to before version 2.2.0, the getRedirectURL function in oauth2.go:22-29 constructs the OAuth2 callback URL by concatenating the request's Host header with a fixed path, with zero validation of the Host… | |
| Aplazada | Media (6.5) | 0.41% | — | Nezha MonitoringAI | 12/6/2026 | 17/6/2026 | Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 1.0.0 to before version 2.2.0, the Nezha dashboard exposes two endpoints that create long-lived WebSocket streams to monitored agents: POST /api/v1/terminal → createTerminal() (terminal.go:27-67) and POST… | |
| Aplazada | Media (6.4) | 0.31% | — | Nezha MonitoringAI | 12/6/2026 | 17/6/2026 | Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 2.0.14 to before version 2.1.0, PATCH /server/{id} accepts and persists nonexistent ddns_profiles IDs for a member-owned server. If another user later creates a DDNS profile with one of those IDs, the DDNS… | |
| Aplazada | Media (6.5) | 0.40% | — | Nezha MonitoringAI | 12/6/2026 | 17/6/2026 | Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 2.0.14 to before version 2.1.0, authenticated users can claim the dashboard Host through NAT and preempt all dashboard routing. This issue has been patched in version 2.1.0. | |
| Aplazada | Crítica (9.1) | 2.3% | — | Nezha MonitoringAI | 12/6/2026 | 17/6/2026 | Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. Prior to version 2.0.13, fallbackToFrontend in the dashboard's NoRoute handler treats any URL whose raw string starts with /dashboard as an admin-frontend asset request. The check uses strings.HasPrefix, not a path-segment… | |
| Aplazada | Media (5.3) | 0.34% | — | Nezha MonitoringAI | 12/6/2026 | 17/6/2026 | Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 2.0.0 to before version 2.0.14, private services (`EnableShowInService: false`) are enumerable via per-server endpoints, leaking name and timing data. This issue has been patched in version 2.0.14. | |
| Aplazada | Alta (7.1) | 0.17% | — | Nezha MonitoringAI | 12/6/2026 | 17/6/2026 | Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 1.0.0 to before version 2.0.14, cross-site GET request can trigger stored cron commands on a victim's agents. This issue has been patched in version 2.0.14. | |
| Aplazada | Alta (7.1) | 0.37% | — | Nezha MonitoringAI | 12/6/2026 | 17/6/2026 | Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 0.20.0 to before version 2.0.12, authenticated agents can forge service-monitor results for other users' services. This issue has been patched in version 2.0.12. |