Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
447 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.1) | 0.83% | — | Siemens Sicam PQ Analyzer Firmware | 11/1/2022 | 17/6/2026 | A vulnerability has been identified in SICAM PQ Analyzer (All versions < V3.18). A service is started by an unquoted registry entry. As there are spaces in this path, attackers with write privilege to those directories might be able to plant executables that will run in place of the legitimate process. Attackers might… | |
| Modificada | Alta (7.5) | 50% | 💥 PoC | OpensslNetapp Cloud BackupNetapp E-series Performance AnalyzerNetapp Ontap Select Deploy Administration Utility+12 | 14/12/2021 | 17/6/2026 | Internally libssl in OpenSSL calls X509_verify_cert() on the client side to verify a certificate supplied by a server. That function may return a negative return value to indicate an internal error (for example out of memory). Such a negative return value is mishandled by OpenSSL and will cause an IO function (such as… | |
| Modificada | Media (6.7) | 0.52% | — | Fortinet FortiadcFortinet FortianalyzerFortinet FortimailFortinet Fortimanager+9 | 8/12/2021 | 17/6/2026 | A buffer overflow [CWE-121] in the TFTP client library of FortiOS before 6.4.7 and FortiOS 7.0.0 through 7.0.2, may allow an authenticated local attacker to achieve arbitrary code execution via specially crafted command line arguments. | |
| Modificada | Media (5.4) | 0.47% | — | Fortinet Fortianalyzer | 2/11/2021 | 17/6/2026 | A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiAnalyzer version 6.0.6 and below, version 6.4.4 allows attacker to execute unauthorized code or commands via specifically crafted requests to the web GUI. | |
| Modificada | Media (4.7) | 0.58% | — | Solarwinds Database Performance Analyzer | 21/10/2021 | 17/6/2026 | This vulnerability occurred due to missing input sanitization for one of the output fields that is extracted from headers on specific section of page causing a reflective cross site scripting attack. An attacker would need to perform a Man in the Middle attack in order to change header for a remote victim. | |
| Modificada | Baja (3.2) | 0.22% | — | Fortinet FortianalyzerFortinet Fortimanager | 6/10/2021 | 17/6/2026 | An information disclosure vulnerability [CWE-200] in FortiAnalyzerVM and FortiManagerVM versions 7.0.0 and 6.4.6 and below may allow an authenticated attacker to read the FortiCloud credentials which were used to activate the trial license in cleartext. | |
| Modificada | Media (5.4) | 0.66% | — | Fortinet Fortianalyzer | 6/10/2021 | 17/6/2026 | An improper neutralization of input vulnerability [CWE-79] in FortiAnalyzer versions 6.4.3 and below, 6.2.7 and below and 6.0.10 and below may allow a remote authenticated attacker to perform a stored cross site scripting attack (XSS) via the column settings of Logview in FortiAnalyzer, should the attacker be able to… | |
| Modificada | Media (5.4) | 0.60% | — | Fortinet FortianalyzerFortinet Fortimanager | 6/8/2021 | 17/6/2026 | Multiple improper neutralization of input during web page generation (CWE-79) in FortiManager and FortiAnalyzer versions 7.0.0, 6.4.5 and below, 6.2.7 and below user interface, may allow a remote authenticated attacker to perform a Stored Cross Site Scripting attack (XSS) by injecting malicious payload in GET… | |
| Modificada | Media (4.3) | 0.65% | — | Fortinet FortianalyzerFortinet Fortimanager | 6/8/2021 | 17/6/2026 | An improper access control vulnerability in FortiManager and FortiAnalyzer GUI interface 7.0.0, 6.4.5 and below, 6.2.8 and below, 6.0.11 and below, 5.6.11 and below may allow a remote and authenticated attacker with restricted user profile to retrieve the list of administrative users of other ADOMs and their related… | |
| Modificada | Media (6.5) | 0.67% | — | Fortinet FortianalyzerFortinet Fortimanager | 5/8/2021 | 17/6/2026 | A server-side request forgery (SSRF) (CWE-918) vulnerability in FortiManager and FortiAnalyser GUI 7.0.0, 6.4.5 and below, 6.2.7 and below, 6.0.11 and below, 5.6.11 and below may allow a remote and authenticated attacker to access unauthorized files and services on the system via specifically crafted web requests. | |
| Modificada | Media (4.3) | 0.77% | — | Fortinet FortianalyzerFortinet Fortimanager | 5/8/2021 | 17/6/2026 | An improper neutralization of CRLF sequences in HTTP headers ('HTTP Response Splitting') vulnerability In FortiManager and FortiAnalyzer GUI 7.0.0, 6.4.6 and below, 6.2.8 and below, 6.0.11 and below, 5.6.11 and below may allow an authenticated and remote attacker to perform an HTTP request splitting attack which gives… | |
| Modificada | Media (4.4) | 0.22% | — | Fortinet FortianalyzerFortinet Fortimanager | 20/7/2021 | 17/6/2026 | A buffer overflow vulnerability in FortiAnalyzer CLI 6.4.5 and below, 6.2.7 and below, 6.0.x and FortiManager CLI 6.4.5 and below, 6.2.7 and below, 6.0.x may allow an authenticated, local attacker to perform a Denial of Service attack by running the `diagnose system geoip-city` command with a large ip value. | |
| Modificada | Media (6.1) | 0.94% | — | Adiscon Loganalyzer | 8/6/2021 | 17/6/2026 | Adiscon LogAnalyzer 4.1.10 and 4.1.11 allow login.php XSS. | |
| Modificada | Crítica (9.8) | 1.9% | — | Merge-deep Project Merge-deepNetapp E-series Performance Analyzer | 2/6/2021 | 17/6/2026 | The merge-deep library before 3.0.3 for Node.js can be tricked into overwriting properties of Object.prototype or adding new properties to it. These properties are then inherited by every object in the program, thus facilitating prototype-pollution attacks against applications using this library. | |
| Modificada | Alta (7.5) | 2.3% | — | Css-what Project Css-whatNetapp E-series Performance Analyzer | 28/5/2021 | 17/6/2026 | The css-what package 4.0.0 through 5.0.0 for Node.js does not ensure that attribute parsing has Linear Time Complexity relative to the size of the input. | |
| Modificada | Alta (7.5) | 2.9% | — | Trim-newlines Project Trim-newlinesNetapp E-series Performance AnalyzerDebian Linux | 28/5/2021 | 17/6/2026 | The trim-newlines package before 3.0.1 and 4.x before 4.0.1 for Node.js has an issue related to regular expression denial-of-service (ReDoS) for the .end() method. | |
| Modificada | Media (5.3) | 2.8% | — | WS Project WSNetapp E-series Performance Analyzer | 25/5/2021 | 17/6/2026 | ws is an open source WebSocket client and server library for Node.js. A specially crafted value of the `Sec-Websocket-Protocol` header can be used to significantly slow down a ws server. The vulnerability has been fixed in ws@7.4.6 (https://github.com/websockets/ws/commit/00c425ec77993773d823f018f64a5c44e17023ff). In… | |
| Modificada | Crítica (9.8) | 4.5% | 💥 PoC | Handlebarsjs HandlebarsNetapp E-series Performance Analyzer | 4/5/2021 | 17/6/2026 | The package handlebars before 4.7.7 are vulnerable to Prototype Pollution when selecting certain compiling options to compile templates coming from an untrusted source. | |
| Modificada | Crítica (9.8) | 17% | — | Zohocorp Manageengine Eventlog Analyzer | 30/4/2021 | 17/6/2026 | Zoho ManageEngine Eventlog Analyzer through 12147 is vulnerable to unauthenticated directory traversal via an entry in a ZIP archive. This leads to remote code execution. | |
| Modificada | Crítica (9.8) | 4.8% | — | Nagios Network Analyzer | 8/4/2021 | 17/6/2026 | SQL injection vulnerability in Nagios Network Analyzer before 2.4.3 via the o[col] parameter to api/checks/read/. | |
| Modificada | Media (6.1) | 11% | — | Nagios Network Analyzer | 8/4/2021 | 17/6/2026 | Self Authenticated XSS in Nagios Network Analyzer before 2.4.2 via the nagiosna/groups/queries page. | |
| Modificada | Alta (7.5) | 54% | 💥 PoC | Eclipse JettyOracle Autovue FOR Agile Product Lifecycle ManagementOracle Communications Cloud Native Core PolicyOracle Communications Element Manager+17 | 1/4/2021 | 17/6/2026 | In Eclipse Jetty 7.2.2 to 9.4.38, 10.0.0.alpha0 to 10.0.1, and 11.0.0.alpha0 to 11.0.1, CPU usage can reach 100% upon receiving a large invalid TLS frame. | |
| Modificada | Media (5.3) | 82% | 💥 Exploit | Eclipse JettyNetapp Cloud ManagerNetapp E-series Performance AnalyzerNetapp E-series Santricity OS Controller+13 | 1/4/2021 | 17/6/2026 | In Eclipse Jetty 9.4.37.v20210219 to 9.4.38.v20210224, the default compliance mode allows requests with URIs that contain %2e or %2e%2e segments to access protected resources within the WEB-INF directory. For example a request to /context/%2e/WEB-INF/web.xml can retrieve the web.xml file. This can reveal sensitive… | |
| Modificada | Baja (2.7) | 4.2% | — | Eclipse JettyFedoraproject FedoraApache IgniteApache Solr+19 | 1/4/2021 | 17/6/2026 | In Eclipse Jetty 9.4.32 to 9.4.38, 10.0.0.beta2 to 10.0.1, and 11.0.0.beta2 to 11.0.1, if a user uses a webapps directory that is a symlink, the contents of the webapps directory is deployed as a static webapp, inadvertently serving the webapps themselves and anything else that might be in that directory. | |
| Modificada | Media (5.9) | 64% | 💥 PoC | OpensslDebian LinuxFreebsdNetapp Active IQ Unified Manager+102 | 25/3/2021 | 17/6/2026 | An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension (where it was present in the initial ClientHello), but includes a signature_algorithms_cert extension then a NULL pointer… |