Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
1273 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.2) | 1.8% | — | Fortinet Fortiweb | 11/2/2025 | 17/6/2026 | A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWeb 7.0.0 through 7.6.0 allows attacker to execute unauthorized code or commands via crafted input. | |
| Analizada | Alta (7.2) | 2.2% | — | Fortinet Fortiweb | 11/2/2025 | 17/6/2026 | An improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWeb 7.4.0 through 7.6.0 allows attacker to execute unauthorized code or commands via crafted input. | |
| Analizada | Alta (7.2) | 0.62% | — | Fortinet Fortios | 11/2/2025 | 17/6/2026 | An incorrect privilege assignment vulnerability [CWE-266] in Fortinet FortiOS version 7.6.0, 7.4.0 through 7.4.4, 7.2.0 through 7.2.9 and before 7.0.15 allows an authenticated admin whose access profile has the Security Fabric permission to escalate their privileges to super-admin by connecting the targetted FortiGate… | |
| Analizada | Media (6.7) | 0.25% | 💥 PoC | Fortinet Forticlient | 11/2/2025 | 17/6/2026 | An Improper Access Control vulnerability [CWE-284] in FortiClient Windows version 7.4.0, version 7.2.6 and below, version 7.0.13 and below may allow a local user to escalate his privileges via FortiSSLVPNd service pipe. | |
| Analizada | Alta (7.2) | 2.0% | — | Fortinet Fortimanager CloudFortinet FortimanagerFortinet Fortianalyzer BIG DataFortinet Fortianalyzer Cloud+1 | 11/2/2025 | 17/6/2026 | An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiAnalyzer version 7.4.0 through 7.4.3, 7.2.0 through 7.2.5, 7.0.0 through 7.0.13, 6.4.0 through 6.4.15 and 6.2.2 through 6.2.13, Fortinet FortiManager version 7.4.0 through 7.4.3, 7.2.0… | |
| Analizada | Media (6) | 0.24% | — | Fortinet FortimanagerFortinet Fortianalyzer | 11/2/2025 | 17/6/2026 | An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in Fortinet FortiManager version 7.4.0 through 7.4.2 and before 7.2.5 and Fortinet FortiAnalyzer version 7.4.0 through 7.4.2 and before 7.2.5 CLI allows an authenticated admin user with diagnose privileges to… | |
| Analizada | Alta (8.1) | 1.0% | — | Fortinet Fortios | 11/2/2025 | 17/6/2026 | A stack-based buffer overflow [CWE-121] vulnerability in Fortinet FortiOS version 7.2.4 through 7.2.8 and version 7.4.0 through 7.4.4 allows a remote unauthenticated attacker to execute arbitrary code or commands via crafted UDP packets through the CAPWAP control, provided the attacker were able to evade FortiOS stack… | |
| Analizada | Alta (7.7) | 0.30% | — | Fortinet FortimanagerFortinet Fortimanager Cloud | 11/2/2025 | 17/6/2026 | A use of hard-coded cryptographic key to encrypt sensitive data vulnerability [CWE-321] in FortiManager 7.6.0 through 7.6.1, 7.4.0 through 7.4.5, 7.2.0 through 7.2.9, 7.0 all versions, 6.4 all versions may allow an attacker with JSON API access permissions to decrypt some secrets even if the 'private-data-encryption'… | |
| Modificada | Crítica (9) | 28% | — | Fortinet Fortisandbox | 11/2/2025 | 17/6/2026 | An improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.4, FortiSandbox 4.2.1 through 4.2.6, FortiSandbox 4.0.0 through 4.0.4, FortiSandbox 3.2 all versions, FortiSandbox 3.1 all versions, FortiSandbox 3.0 all versions allows an… | |
| Analizada | Media (5.4) | 0.30% | — | Fortinet Fortisiem | 11/2/2025 | 17/6/2026 | Multiple Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilities [CWE-79] in FortiSIEM 7.1 all versions, 7.0 all versions, 6.7 all versions incident page may allow an authenticated attacker to perform a cross-site scripting attack via crafted HTTP requests. | |
| Modificada | Media (6.7) | 0.24% | — | Fortinet FortiosFortinet FortiswitchmanagerFortinet FortiproxyFortinet Fortipam | 11/2/2025 | 17/6/2026 | A use of externally-controlled format string vulnerability [CWE-134] vulnerability in Fortinet allows a privileged attacker to execute arbitrary code or commands via specially crafted requests. | |
| Modificada | Media (6.1) | 0.45% | — | Fortinet FortiadcFortinet FortiauthenticatorFortinet FortiddosFortinet Fortiddos-f+10 | 22/1/2025 | 17/6/2026 | A externally controlled reference to a resource in another sphere vulnerability in Fortinet allows attacker to poison web caches via crafted HTTP requests, where the `Host` header points to an arbitrary webserver | |
| Analizada | Crítica (9.8) | 0.58% | — | Fortinet FortianalyzerFortinet Fortianalyzer CloudFortinet FortimanagerFortinet Fortimanager Cloud | 16/1/2025 | 17/6/2026 | A weak authentication in Fortinet FortiManager Cloud, FortiAnalyzer versions 7.6.0 through 7.6.1, 7.4.1 through 7.4.3, FortiAnalyzer Cloud versions 7.4.1 through 7.4.3, FortiManager versions 7.6.0 through 7.6.1, 7.4.1 through 7.4.3, FortiManager Cloud versions 7.4.1 through 7.4.3 allows attacker to execute… | |
| Modificada | Crítica (9.1) | 0.79% | — | Fortinet FortirecorderFortinet FortivoiceFortinet Fortiweb | 16/1/2025 | 8/7/2026 | A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiRecorder 7.2.0 through 7.2.1, FortiRecorder 7.0.0 through 7.0.4, FortiVoice 7.0.0 through 7.0.4, FortiVoice 6.4.0 through 6.4.9, FortiVoice 6.0 all versions, FortiWeb 7.6.0, FortiWeb 7.4.0 through 7.4.4,… | |
| Modificada | Alta (7.8) | 0.21% | — | Fortinet FortianalyzerFortinet Fortianalyzer CloudFortinet FortimanagerFortinet Fortimanager Cloud | 16/1/2025 | 8/7/2026 | A incorrect privilege assignment vulnerability in Fortinet FortiAnalyzer 7.4.0 through 7.4.3, FortiAnalyzer 7.2.0 through 7.2.5, FortiAnalyzer 7.0 all versions, FortiAnalyzer 6.4 all versions, FortiAnalyzer Cloud 7.4.1 through 7.4.2, FortiAnalyzer Cloud 7.2.1 through 7.2.6, FortiAnalyzer Cloud 7.0 all versions,… | |
| Modificada | Media (6.1) | 0.29% | — | Fortinet Fortideceptor | 15/1/2025 | 17/6/2026 | A improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiDeceptor 5.3.0, FortiDeceptor 5.2.0, FortiDeceptor 5.1 all versions, FortiDeceptor 5.0 all versions, FortiDeceptor 4.3 all versions, FortiDeceptor 4.2 all versions, FortiDeceptor 4.1 all versions,… | |
| Analizada | Media (6.7) | 0.59% | — | Fortinet FortimailFortinet Fortirecorder | 14/1/2025 | 17/6/2026 | An improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiMail versions 7.2.0 through 7.2.4 and 7.0.0 through 7.0.6 and 6.4.0 through 6.4.7, FortiRecorder versions 7.0.0 and 6.4.0 through 6.4.4 allows attacker to execute unauthorized code or commands via the CLI. | |
| Analizada | Baja (2.7) | 0.41% | — | Fortinet Fortiweb | 14/1/2025 | 17/6/2026 | A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiWeb versions 6.3.17 through 7.6.1 allows attacker to gain information disclosure via crafted SQL queries | |
| Analizada | Crítica (9.8) | 94% | ⚠ Explotación activa💥 Exploit | Fortinet FortiproxyFortinet Fortios | 14/1/2025 | 5/8/2026 | An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy version 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12 allows a remote attacker to gain super-admin privileges via crafted requests to Node.js websocket module. | |
| Analizada | Media (5.8) | 0.78% | — | Fortinet FortiproxyFortinet Fortios | 14/1/2025 | 17/6/2026 | An Improper Neutralization of CRLF Sequences in HTTP Headers ('http response splitting') vulnerability [CWE-113] in Fortinet FortiOS 7.2.0 through 7.6.0, FortiProxy 7.2.0 through 7.4.5 may allow a remote unauthenticated attacker to bypass the file filter via crafted HTTP headers. | |
| Analizada | Media (6.5) | 0.50% | — | Fortinet Fortisiem | 14/1/2025 | 17/6/2026 | An Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability [CWE-89] in FortiSIEM ersion 7.1.7 and below, version 7.1.0, version 7.0.3 and below, version 6.7.9 and below, 6.7.8, version 6.6.5 and below, version 6.5.3 and below, version 6.4.4 and below Update/Create Case… | |
| Analizada | Media (4.8) | 0.36% | — | Fortinet Fortiportal | 14/1/2025 | 17/6/2026 | An improper neutralization of script-related html tags in a web page (basic xss) in Fortinet FortiPortal 6.0.0 through 6.0.14 allows attacker to execute unauthorized code or commands via html injection. | |
| Modificada | Media (5.9) | 0.76% | — | Fortinet Fortios | 14/1/2025 | 17/6/2026 | A out-of-bounds write in Fortinet FortiOS versions 7.6.0, 7.4.0 through 7.4.6, 7.2.0 through 7.2.10, 7.0.0 through 7.0.16, 6.4.0 through 6.4.15 allows attacker to trigger a denial of service via specially crafted packets. | |
| Modificada | Alta (8.8) | 1.1% | — | Fortinet FortimanagerFortinet Fortimanager Cloud | 14/1/2025 | 17/6/2026 | A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiManager Cloud 7.6.0 through 7.6.1, FortiManager Cloud 7.4.0 through 7.4.4, FortiManager Cloud 7.2.2 through 7.2.7, FortiManager 7.6.0 through 7.6.1, FortiManager 7.4.0 through 7.4.5, FortiManager… | |
| Analizada | Baja (3.3) | 0.22% | — | Fortinet Forticlient | 14/1/2025 | 17/6/2026 | A use of hard-coded cryptographic key in Fortinet FortiClientWindows version 7.4.0, 7.2.x all versions, 7.0.x all versions, and 6.4.x all versions may allow a low-privileged user to decrypt interprocess communication via monitoring named piped. |