Vulnerabilities

Summary — last 7 days

New vulnerabilities3,037▲ 502 vs. last week
Critical / high1,448▲ 249 vs. last week
New active exploitation (KEV)8▼ 2 vs. last week
Unscored (no CVSS)365▲ 158 vs. last week
–

1,028 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
DeferredMedium (5.3)0.26%—Argotronic ArgusmonitorAI9/29/20269/30/2026
Improper Access Control in ArgusMonitor.sys in Argotronic eGbR ArgusMonitor 7.4.02 and earlier allows local, low-privileged users to bypass device handle access restrictions via a TOCTOU condition in IRP_MJ_CREATE and send a crafted IOCTL 0x9C4024A8 request, causing denial-of-service.
Awaiting AnalysisMedium (4.7)0.14%—Microsoft Network MonitorAI9/29/20269/29/2026
Microsoft Network Monitor file parser large loop in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
DeferredHigh (7.1)0.27%—Paessler Prtg Network MonitorAI9/24/20269/24/2026
PRTG Network Monitor before version 26.2.120.1449 ships a demo EXE/Script sensor that multiplies two integer parameters using cscript.exe. If a non-numeric value is passed instead, cscript.exe raises a 'Type mismatch' runtime error that includes the offending parameter value in plaintext. PRTG provides a documented…
DeferredMedium (5.1)0.55%—Paessler Prtg Network MonitorAI9/24/20269/24/2026
Paessler PRTG Network Monitor before version 26.2.120.1449 is affected by a reflected Cross-Site Scripting (XSS) vulnerability. When a request is made for a non-existent resource ending in \".htm\", the web interface returns an HTTP 403 \"Forbidden Path\" error page that echoes the requested URL path into the HTML…
Awaiting AnalysisHigh (8.4)0.14%—Dell Command MonitorAI9/21/20269/22/2026
Dell Command | Monitor (DCM), versions prior to 10.13.2, contain an Incorrect Permission Assignment for Critical Resource vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.
DeferredHigh (8.5)0.18%—Biostar Temperature Monitor UtilityAI9/21/20269/21/2026
A security vulnerability has been detected in BioStar Temperature Monitor Utility 1.2.1806.2200. Affected by this vulnerability is the function sub_1105C of the file BS_HWMIO64_W10.sys of the component IOCTL Handler. Such manipulation of the argument PhysicalAddress leads to write-what-where condition. The attack…
DeferredMedium (5.5)0.43%—Sourcecodester Inventory AND Monitoring SystemAI9/16/20269/16/2026
A vulnerability was detected in SourceCodester Inventory and Monitoring System 1.0. The impacted element is an unknown function of the file /admins/assessments/databank/btn_functions.php?action=add. Performing a manipulation of the argument difficulty_id results in sql injection. Remote exploitation of the attack is…
DeferredMedium (5.5)0.43%—Sourcecodester Inventory AND Monitoring SystemAI9/16/20269/16/2026
A security vulnerability has been detected in SourceCodester Inventory and Monitoring System 1.0. The affected element is an unknown function of the file /index.php. Such manipulation of the argument Username leads to sql injection. The attack may be launched remotely. The exploit has been disclosed publicly and may…
DeferredHigh (7)0.09%—Duoxme ApplicationAIVEO Wifi MonitorAIVEO XS Wifi MonitorAI9/16/20269/18/2026
Transmission of the home Wi-Fi credentials without encryption during the pairing process between the DuoxMe application and VEO and VEO-XS Wi-Fi monitors, in versions prior to 4.3.4 of the application and 01.50.001 of the monitor firmware, allows an attacker on the Wi-Fi Direct network to intercept the network…
Awaiting AnalysisLow (2.7)0.22%—Paessler Prtg Network MonitorAI9/14/20269/22/2026
PRTG Network Monitor before 23.1.82 allows remote attackers to write to files via the FTP Server Count Sensor.
DeferredLow (2.7)0.22%—Paessler Prtg Network MonitorAI9/14/20269/22/2026
PRTG Network Monitor before 23.1.82 allows remote attackers to write to files via the HTTP XML/REST Sensor.
Awaiting AnalysisCritical (9.8)0.52%—Fortinet FortimonitoronsightAI9/11/20269/11/2026
A inclusion of sensitive information in source code vulnerability in Fortinet FortiMonitorOnSight 7.2.4 through 7.2.7, FortiMonitorOnSight 7.2.0 through 7.2.2 may allow attacker to improper access control via <insert attack vector here>
Awaiting AnalysisHigh (8.6)0.46%—Tycon Systems Tpdin-monitor-web3AI9/4/20269/8/2026
Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a Missing Authorization vulnerability. This could allow an attacker to extract system credentials, configurations, or flash contents.
Awaiting AnalysisHigh (8.6)0.25%—Tycon Systems Tpdin-monitor-web3AI9/4/20269/8/2026
Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a cross-site request forgery vulnerability. This could allow an attacker to perform state changing operations on the device.
Awaiting AnalysisHigh (7.1)0.33%—Tycon Systems Tpdin-monitor-web3AI9/4/20269/9/2026
Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a use of hard-coded credential vulnerability. This could allow an attacker to intercept sensitive information or credentials.
DeferredMedium (5.5)0.41%—Shenzhen Gongji Technology Xbrother Dynamic Environment Monitoring SystemAI8/24/20268/24/2026
A security vulnerability has been detected in Shenzhen Gongji Technology XBROTHER Dynamic Environment Monitoring System up to 300R004C00B300. The affected element is the function PlanController.getImmediatePlans of the file /xbreport/api/v1/plamange/plansImmediate. The manipulation of the argument order/sort leads to…
DeferredCritical (9.9)0.55%—Nezha Monitoring NezhaAI8/21/20269/9/2026
Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. Nezha versions 1.14.13 through 1.14.14 and 2.0.0 through 2.0.9 do not bind stream identifiers created by CreateStream in service/rpc/io_stream.go to their creating user, and `GET /ws/terminal/:id` and `GET /ws/file/:id`…
DeferredMedium (5.5)0.17%—Linuxfabrik-libAILinuxfabrik Monitoring PluginsAI8/18/20269/9/2026
linuxfabrik-lib provides Python modules for database access, caching, shell execution, and API integrations, and Linuxfabrik Monitoring Plugins uses its shared testing helper across check plugins. Prior to linuxfabrik-lib 6.1.0 and Linuxfabrik Monitoring Plugins 7.0.0, lib.lftest.test() treated the first or second…
DeferredMedium (5.5)0.29%—Linuxfabrik Monitoring PluginsAI8/18/20269/9/2026
Linuxfabrik Monitoring Plugins provides monitoring plugins for Icinga, Nagios, and related systems. Prior to version 7.0.0, check-plugins/logfile/logfile accepted a free-form --filename path and opened it as root when invoked through the shipped nagios or icinga sudoers allowlist, without confining the resolved path…
DeferredHigh (7.8)0.21%—Linuxfabrik-libAILinuxfabrik Monitoring PluginsAI8/18/20269/9/2026
linuxfabrik-lib provides Python modules for database access, caching, shell execution, and API integrations, and Linuxfabrik Monitoring Plugins uses those modules to run external monitoring commands. From the earliest affected releases until linuxfabrik-lib 5.0.0 and Linuxfabrik Monitoring Plugins 6.0.0, check plugins…
DeferredHigh (7)0.18%—Linuxfabrik Monitoring PluginsAIDebian Apt-getAI8/18/20269/9/2026
Linuxfabrik Monitoring Plugins provides monitoring plugins for Icinga, Nagios, and related systems. Prior to version 5.1.0, the shipped assets/sudoers/Debian.sudoers policy allowed the nagios or icinga account to execute /usr/bin/apt-get as root without restricting its arguments. An attacker who already controls that…
Awaiting AnalysisHigh (8.7)0.40%—Mira Hormone MonitorAI8/11/20269/3/2026
In the Mira hormone monitor device firmware v1.7.1.47 build 01070147, a remote unauthenticated attacker within BLE range (approximately 10–30 meters) can silently rebind the device to an attacker-controlled account, extract stored hormone measurements in cleartext, cause a denial-of-service via malformed or…
Awaiting AnalysisHigh (7.1)0.32%—Mira Hormone MonitorAI8/11/20269/3/2026
The Mira hormone monitor device firmware accepts a 0x01 write from any BLE central without authentication, causing the device to reboot into bootloader mode. An attacker could cause a denial-of-service condition or disrupt ovulation tracking and fertility monitoring workflow.
AnalyzedHigh (7.2)1.0%—Microsoft Azure Monitor Agent8/11/20268/13/2026
Improper neutralization of special elements used in a command ('command injection') in Azure Monitor Agent allows an authorized attacker to elevate privileges over a network.
Undergoing AnalysisMedium (5.4)0.12%—Intel Performance Counter MonitorAI8/11/20268/12/2026
Untrusted search path for some Intel(R) Performance Counter Monitor (Intel(R) PCM) before version tag 202604 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable escalation of privilege. This…