Vulnerabilities
Summary — last 7 days
New vulnerabilities3,037▲ 502 vs. last week
Critical / high1,448▲ 249 vs. last week
New active exploitation (KEV)8▼ 2 vs. last week
Unscored (no CVSS)365▲ 158 vs. last week
1,028 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | Medium (5.3) | 0.26% | — | Argotronic ArgusmonitorAI | 9/29/2026 | 9/30/2026 | Improper Access Control in ArgusMonitor.sys in Argotronic eGbR ArgusMonitor 7.4.02 and earlier allows local, low-privileged users to bypass device handle access restrictions via a TOCTOU condition in IRP_MJ_CREATE and send a crafted IOCTL 0x9C4024A8 request, causing denial-of-service. | |
| Awaiting Analysis | Medium (4.7) | 0.14% | — | Microsoft Network MonitorAI | 9/29/2026 | 9/29/2026 | Microsoft Network Monitor file parser large loop in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service | |
| Deferred | High (7.1) | 0.27% | — | Paessler Prtg Network MonitorAI | 9/24/2026 | 9/24/2026 | PRTG Network Monitor before version 26.2.120.1449 ships a demo EXE/Script sensor that multiplies two integer parameters using cscript.exe. If a non-numeric value is passed instead, cscript.exe raises a 'Type mismatch' runtime error that includes the offending parameter value in plaintext. PRTG provides a documented… | |
| Deferred | Medium (5.1) | 0.55% | — | Paessler Prtg Network MonitorAI | 9/24/2026 | 9/24/2026 | Paessler PRTG Network Monitor before version 26.2.120.1449 is affected by a reflected Cross-Site Scripting (XSS) vulnerability. When a request is made for a non-existent resource ending in \".htm\", the web interface returns an HTTP 403 \"Forbidden Path\" error page that echoes the requested URL path into the HTML… | |
| Awaiting Analysis | High (8.4) | 0.14% | — | Dell Command MonitorAI | 9/21/2026 | 9/22/2026 | Dell Command | Monitor (DCM), versions prior to 10.13.2, contain an Incorrect Permission Assignment for Critical Resource vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges. | |
| Deferred | High (8.5) | 0.18% | — | Biostar Temperature Monitor UtilityAI | 9/21/2026 | 9/21/2026 | A security vulnerability has been detected in BioStar Temperature Monitor Utility 1.2.1806.2200. Affected by this vulnerability is the function sub_1105C of the file BS_HWMIO64_W10.sys of the component IOCTL Handler. Such manipulation of the argument PhysicalAddress leads to write-what-where condition. The attack… | |
| Deferred | Medium (5.5) | 0.43% | — | Sourcecodester Inventory AND Monitoring SystemAI | 9/16/2026 | 9/16/2026 | A vulnerability was detected in SourceCodester Inventory and Monitoring System 1.0. The impacted element is an unknown function of the file /admins/assessments/databank/btn_functions.php?action=add. Performing a manipulation of the argument difficulty_id results in sql injection. Remote exploitation of the attack is… | |
| Deferred | Medium (5.5) | 0.43% | — | Sourcecodester Inventory AND Monitoring SystemAI | 9/16/2026 | 9/16/2026 | A security vulnerability has been detected in SourceCodester Inventory and Monitoring System 1.0. The affected element is an unknown function of the file /index.php. Such manipulation of the argument Username leads to sql injection. The attack may be launched remotely. The exploit has been disclosed publicly and may… | |
| Deferred | High (7) | 0.09% | — | Duoxme ApplicationAIVEO Wifi MonitorAIVEO XS Wifi MonitorAI | 9/16/2026 | 9/18/2026 | Transmission of the home Wi-Fi credentials without encryption during the pairing process between the DuoxMe application and VEO and VEO-XS Wi-Fi monitors, in versions prior to 4.3.4 of the application and 01.50.001 of the monitor firmware, allows an attacker on the Wi-Fi Direct network to intercept the network… | |
| Awaiting Analysis | Low (2.7) | 0.22% | — | Paessler Prtg Network MonitorAI | 9/14/2026 | 9/22/2026 | PRTG Network Monitor before 23.1.82 allows remote attackers to write to files via the FTP Server Count Sensor. | |
| Deferred | Low (2.7) | 0.22% | — | Paessler Prtg Network MonitorAI | 9/14/2026 | 9/22/2026 | PRTG Network Monitor before 23.1.82 allows remote attackers to write to files via the HTTP XML/REST Sensor. | |
| Awaiting Analysis | Critical (9.8) | 0.52% | — | Fortinet FortimonitoronsightAI | 9/11/2026 | 9/11/2026 | A inclusion of sensitive information in source code vulnerability in Fortinet FortiMonitorOnSight 7.2.4 through 7.2.7, FortiMonitorOnSight 7.2.0 through 7.2.2 may allow attacker to improper access control via <insert attack vector here> | |
| Awaiting Analysis | High (8.6) | 0.46% | — | Tycon Systems Tpdin-monitor-web3AI | 9/4/2026 | 9/8/2026 | Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a Missing Authorization vulnerability. This could allow an attacker to extract system credentials, configurations, or flash contents. | |
| Awaiting Analysis | High (8.6) | 0.25% | — | Tycon Systems Tpdin-monitor-web3AI | 9/4/2026 | 9/8/2026 | Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a cross-site request forgery vulnerability. This could allow an attacker to perform state changing operations on the device. | |
| Awaiting Analysis | High (7.1) | 0.33% | — | Tycon Systems Tpdin-monitor-web3AI | 9/4/2026 | 9/9/2026 | Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a use of hard-coded credential vulnerability. This could allow an attacker to intercept sensitive information or credentials. | |
| Deferred | Medium (5.5) | 0.41% | — | Shenzhen Gongji Technology Xbrother Dynamic Environment Monitoring SystemAI | 8/24/2026 | 8/24/2026 | A security vulnerability has been detected in Shenzhen Gongji Technology XBROTHER Dynamic Environment Monitoring System up to 300R004C00B300. The affected element is the function PlanController.getImmediatePlans of the file /xbreport/api/v1/plamange/plansImmediate. The manipulation of the argument order/sort leads to… | |
| Deferred | Critical (9.9) | 0.55% | — | Nezha Monitoring NezhaAI | 8/21/2026 | 9/9/2026 | Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. Nezha versions 1.14.13 through 1.14.14 and 2.0.0 through 2.0.9 do not bind stream identifiers created by CreateStream in service/rpc/io_stream.go to their creating user, and `GET /ws/terminal/:id` and `GET /ws/file/:id`… | |
| Deferred | Medium (5.5) | 0.17% | — | Linuxfabrik-libAILinuxfabrik Monitoring PluginsAI | 8/18/2026 | 9/9/2026 | linuxfabrik-lib provides Python modules for database access, caching, shell execution, and API integrations, and Linuxfabrik Monitoring Plugins uses its shared testing helper across check plugins. Prior to linuxfabrik-lib 6.1.0 and Linuxfabrik Monitoring Plugins 7.0.0, lib.lftest.test() treated the first or second… | |
| Deferred | Medium (5.5) | 0.29% | — | Linuxfabrik Monitoring PluginsAI | 8/18/2026 | 9/9/2026 | Linuxfabrik Monitoring Plugins provides monitoring plugins for Icinga, Nagios, and related systems. Prior to version 7.0.0, check-plugins/logfile/logfile accepted a free-form --filename path and opened it as root when invoked through the shipped nagios or icinga sudoers allowlist, without confining the resolved path… | |
| Deferred | High (7.8) | 0.21% | — | Linuxfabrik-libAILinuxfabrik Monitoring PluginsAI | 8/18/2026 | 9/9/2026 | linuxfabrik-lib provides Python modules for database access, caching, shell execution, and API integrations, and Linuxfabrik Monitoring Plugins uses those modules to run external monitoring commands. From the earliest affected releases until linuxfabrik-lib 5.0.0 and Linuxfabrik Monitoring Plugins 6.0.0, check plugins… | |
| Deferred | High (7) | 0.18% | — | Linuxfabrik Monitoring PluginsAIDebian Apt-getAI | 8/18/2026 | 9/9/2026 | Linuxfabrik Monitoring Plugins provides monitoring plugins for Icinga, Nagios, and related systems. Prior to version 5.1.0, the shipped assets/sudoers/Debian.sudoers policy allowed the nagios or icinga account to execute /usr/bin/apt-get as root without restricting its arguments. An attacker who already controls that… | |
| Awaiting Analysis | High (8.7) | 0.40% | — | Mira Hormone MonitorAI | 8/11/2026 | 9/3/2026 | In the Mira hormone monitor device firmware v1.7.1.47 build 01070147, a remote unauthenticated attacker within BLE range (approximately 10–30 meters) can silently rebind the device to an attacker-controlled account, extract stored hormone measurements in cleartext, cause a denial-of-service via malformed or… | |
| Awaiting Analysis | High (7.1) | 0.32% | — | Mira Hormone MonitorAI | 8/11/2026 | 9/3/2026 | The Mira hormone monitor device firmware accepts a 0x01 write from any BLE central without authentication, causing the device to reboot into bootloader mode. An attacker could cause a denial-of-service condition or disrupt ovulation tracking and fertility monitoring workflow. | |
| Analyzed | High (7.2) | 1.0% | — | Microsoft Azure Monitor Agent | 8/11/2026 | 8/13/2026 | Improper neutralization of special elements used in a command ('command injection') in Azure Monitor Agent allows an authorized attacker to elevate privileges over a network. | |
| Undergoing Analysis | Medium (5.4) | 0.12% | — | Intel Performance Counter MonitorAI | 8/11/2026 | 8/12/2026 | Untrusted search path for some Intel(R) Performance Counter Monitor (Intel(R) PCM) before version tag 202604 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable escalation of privilege. This… |