Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
1273 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.2) | 0.41% | — | Fortinet Fortiweb | 14/3/2025 | 17/6/2026 | An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] in FortiWeb version 7.0.1 and below, 6.4.2 and below, 6.3.20 and below, 6.2.7 and below may allow a privileged attacker to execute SQL commands over the log database via specifically crafted strings… | |
| Analizada | Media (6.5) | 0.22% | — | Fortinet Fortindr | 14/3/2025 | 17/6/2026 | An improper validation of integrity check value vulnerability [CWE-354] in FortiNDR version 7.4.2 and below, version 7.2.1 and below, version 7.1.1 and below, version 7.0.6 and below may allow an authenticated attacker with at least Read/Write permission on system maintenance to install a corrupted firmware image. | |
| Analizada | Alta (8.8) | 2.3% | — | Fortinet FortimanagerFortinet Fortimanager Cloud | 14/3/2025 | 17/6/2026 | A improper neutralization of special elements used in a command ('command injection') in Fortinet FortiManager versions 7.4.1 through 7.4.3, FortiManager Cloud versions 7.4.1 through 7.4.3 allows attacker to escalation of privilege via specifically crafted packets | |
| Analizada | Media (4.8) | 0.16% | — | Fortinet Fortiportal | 14/3/2025 | 17/6/2026 | An improper certificate validation vulnerability [CWE-295] in FortiPortal version 7.4.0, version 7.2.4 and below, version 7.0.8 and below, version 6.0.15 and below when connecting to a FortiManager device, a FortiAnalyzer device, or an SMTP server may allow an unauthenticated attacker in a Man-in-the-Middle position… | |
| Analizada | Media (6.1) | 0.61% | — | Fortinet FortiosFortinet Fortiproxy | 14/3/2025 | 17/6/2026 | An improper neutralization of input during web page Generation vulnerability [CWE-79] in FortiOS version 7.4.3 and below, version 7.2.7 and below, version 7.0.13 and below and FortiProxy version 7.4.3 and below, version 7.2.9 and below, version 7.0.16 and below web SSL VPN UI may allow a remote unauthenticated… | |
| Analizada | Alta (7.2) | 0.58% | — | Fortinet Fortiweb | 11/3/2025 | 17/6/2026 | A improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiWeb versions 7.0.0 through 7.6.0 allows attacker to execute unauthorized code or commands via crafted requests. | |
| Analizada | Baja (3.8) | 0.26% | — | Fortinet Fortisiem | 11/3/2025 | 17/6/2026 | An incorrect authorization vulnerability [CWE-863] in FortiSIEM 7.2 all versions, 7.1 all versions, 7.0 all versions, 6.7 all versions, 6.6 all versions, 6.5 all versions, 6.4 all versions, 6.3 all versions, 6.2 all versions, 6.1 all versions, 5.4 all versions, 5.3 all versions, may allow an authenticated attacker to… | |
| Analizada | Alta (8.8) | 1.0% | — | Fortinet Fortiisolator | 11/3/2025 | 17/6/2026 | Multiple improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] in Fortinet FortiIsolator version 2.4.0 through 2.4.5 allows an authenticated attacker with at least read-only admin permission and CLI access to execute unauthorized code via specifically… | |
| Modificada | Alta (8.8) | 0.42% | — | Fortinet FortisandboxFortinet Fortisandbox Cloud | 11/3/2025 | 17/6/2026 | An improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiSandbox 4.4.0 through 4.4.6, FortiSandbox 4.2 all versions, FortiSandbox 4.0 all versions, FortiSandbox 3.2 all versions, FortiSandbox 3.1 all versions, FortiSandbox 3.0 all versions, FortiSandbox Cloud 24.1 allows… | |
| Analizada | Alta (7.2) | 10% | — | Fortinet Fortisandbox | 11/3/2025 | 17/6/2026 | Multiple improper neutralization of special elements used in an OS Command vulnerabilities [CWE-78] in FortiSandbox before 4.4.5 allows a privileged attacker to execute unauthorized commands via crafted requests. | |
| Modificada | Alta (8.8) | 0.55% | — | Fortinet Fortisandbox | 11/3/2025 | 17/6/2026 | An improper neutralization of special elements used in an OS Command vulnerability [CWE-78] vulnerability in Fortinet FortiSandbox 5.0.0, FortiSandbox 4.4.0 through 4.4.6, FortiSandbox 4.2.1 through 4.2.7, FortiSandbox 4.0.0 through 4.0.5, FortiSandbox 3.2 all versions, FortiSandbox 3.1 all versions, FortiSandbox 3.0… | |
| Analizada | Alta (8.8) | 0.34% | — | Fortinet Fortisandbox | 11/3/2025 | 17/6/2026 | A client-side enforcement of server-side security vulnerability [CWE-602] in Fortinet FortiSandbox version 5.0.0, 4.4.0 through 4.4.6 and before 4.2.7 allows an authenticated attacker with at least read-only permission to execute unauthorized commands via crafted requests. | |
| Analizada | Media (6.7) | 0.18% | — | Fortinet Fortimail | 11/3/2025 | 17/6/2026 | A stack-buffer overflow vulnerability [CWE-121] in Fortinet FortiMail CLI version 7.6.0 through 7.6.1 and before 7.4.3 allows a privileged attacker to execute arbitrary code or commands via specifically crafted CLI commands. | |
| Analizada | Alta (7.8) | 0.14% | — | Fortinet Fortisandbox | 11/3/2025 | 17/6/2026 | An incorrect authorization vulnerability [CWE-863] in FortiSandbox 4.4.0 through 4.4.6 may allow a low priviledged administrator to execute elevated CLI commands via the GUI console menu. | |
| Analizada | Alta (7.2) | 0.73% | — | Fortinet FortiosFortinet FortipamFortinet FortiproxyFortinet Fortiweb+1 | 11/3/2025 | 17/6/2026 | A use of externally-controlled format string vulnerability [CWE-134] in FortiOS version 7.4.0 through 7.4.4, version 7.2.0 through 7.2.9, version 7.0.0 through 7.0.15 and before 6.4.15, FortiProxy version 7.4.0 through 7.4.6, version 7.2.0 through 7.2.12 and before 7.0.19, FortiPAM version 1.4.0 through 1.4.2 and… | |
| Analizada | Media (6.7) | 0.18% | — | Fortinet FortianalyzerFortinet Fortianalyzer BIG DataFortinet Fortimanager | 11/3/2025 | 17/6/2026 | Two improper neutralization of special elements used in an SQL Command ('SQL Injection') vulnerability [CWE-89] in Fortinet FortiAnalyzer version 7.4.0 through 7.4.2 and before 7.2.5, FortiManager version 7.4.0 through 7.4.2 and before 7.2.5 and FortiAnalyzer-BigData version 7.4.0 and before 7.2.7 allows a privileged… | |
| Analizada | Media (6.7) | 0.44% | — | Fortinet FortianalyzerFortinet Fortianalyzer BIG DataFortinet Fortimanager | 11/3/2025 | 17/6/2026 | Multiple improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiManager, FortiAnalyzer versions 7.4.0 through 7.4.2 7.2.0 through 7.2.5 and 7.0.0 through 7.0.12 and 6.4.0 through 6.4.14 and 6.2.0 through 6.2.12 and 6.0.0 through 6.0.12 and 5.6.0 through 5.6.11 and… | |
| Analizada | Alta (8.8) | 0.24% | — | Fortinet Fortindr | 11/3/2025 | 17/6/2026 | A cross site request forgery vulnerability [CWE-352] in Fortinet FortiNDR version 7.4.0, 7.2.0 through 7.2.1 and 7.1.0 through 7.1.1 and before 7.0.5 may allow a remote unauthenticated attacker to execute unauthorized actions via crafted HTTP GET requests. | |
| Analizada | Crítica (9.8) | 0.38% | — | Fortinet Fortiweb | 11/3/2025 | 17/6/2026 | An improper handling of syntactically invalid structure in Fortinet FortiWeb at least verions 7.4.0 through 7.4.6 and 7.2.0 through 7.2.10 and 7.0.0 through 7.0.10 allows attacker to execute unauthorized code or commands via HTTP/S crafted requests. | |
| Analizada | Alta (8.1) | 0.36% | — | Fortinet Fortisiem | 11/3/2025 | 17/6/2026 | An exposure of sensitive information to an unauthorized actor in Fortinet FortiSIEM version 6.7.0 through 6.7.4 and 6.6.0 through 6.6.3 and 6.5.0 through 6.5.1 and 6.4.0 through 6.4.2 and 6.3.0 through 6.3.3 and 6.2.0 through 6.2.1 and 6.1.0 through 6.1.2 and 5.4.0 and 5.3.0 through 5.3.3 and 5.2.5 through 5.2.8 and… | |
| Analizada | Media (6.1) | 0.33% | — | Fortinet Fortiadc | 11/3/2025 | 17/6/2026 | An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiADC GUI version 7.4.0, 7.2.0 through 7.2.1 and before 7.1.3 allows an authenticated attacker to perform an XSS attack via crafted HTTP or HTTPs requests. | |
| Analizada | Alta (8.1) | 7.2% | ⚠ Explotación activa💥 PoC | Fortinet FortiproxyFortinet Fortios | 11/2/2025 | 5/8/2026 | An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS 7.0.0 through 7.0.16 and FortiProxy 7.2.0 through 7.2.12, 7.0.0 through 7.0.19 may allow a remote unauthenticated attacker with prior knowledge of upstream and downstream devices serial numbers to gain super-admin… | |
| Analizada | Alta (8.6) | 1.3% | — | Fortinet Fortiportal | 11/2/2025 | 17/6/2026 | An Improper Resolution of Path Equivalence vulnerability [CWE-41] in FortiPortal 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.11 may allow a remote unauthenticated attacker to retrieve source code via crafted HTTP requests. | |
| Analizada | Alta (8.4) | 0.24% | — | Fortinet Forticlient | 11/2/2025 | 17/6/2026 | An improper authentication in Fortinet FortiClientMac 7.0.11 through 7.2.4 allows attacker to gain improper access to MacOS via empty password. | |
| Analizada | Baja (2.3) | 0.21% | — | Fortinet Fortianalyzer | 11/2/2025 | 17/6/2026 | An exposure of sensitive information to an unauthorized actor in Fortinet FortiAnalyzer 6.4.0 through 7.6.0 allows attacker to cause information disclosure via filter manipulation. |