Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
1579 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6) | 0.24% | — | Nozominetworks CMCNozominetworks Guardian | 7/10/2025 | 17/6/2026 | A SQL Injection vulnerability was discovered in the Alert functionality due to improper validation of an input parameter. An authenticated user with limited privileges can execute arbitrary SELECT SQL statements on the DBMS used by the web application, potentially exposing unauthorized data. | |
| Analizada | Alta (7.7) | 0.27% | — | Nozominetworks CMCNozominetworks Guardian | 7/10/2025 | 17/6/2026 | A SQL Injection vulnerability was discovered in the Alert functionality due to improper validation of an input parameter. An authenticated user with limited privileges can execute arbitrary SQL statements on the DBMS used by the web application, potentially exposing unauthorized data, altering their structure and… | |
| Analizada | Media (6) | 0.24% | — | Nozominetworks CMCNozominetworks Guardian | 7/10/2025 | 17/6/2026 | A SQL Injection vulnerability was discovered in the Smart Polling functionality due to improper validation of an input parameter. An authenticated user with limited privileges can execute arbitrary SELECT SQL statements on the DBMS used by the web application, potentially exposing unauthorized data. | |
| Analizada | Alta (7.2) | 0.27% | — | Nozominetworks CMCNozominetworks Guardian | 7/10/2025 | 17/6/2026 | An access control vulnerability was discovered in the CLI functionality due to a specific access restriction not being properly enforced for users with limited privileges. An authenticated user with limited privileges can issue administrative CLI commands, altering the device configuration, and/or affecting its… | |
| Analizada | Media (5.9) | 0.22% | — | Nozominetworks CMCNozominetworks Guardian | 7/10/2025 | 17/6/2026 | A client-side path traversal vulnerability was discovered in the web management interface front-end due to missing validation of an input parameter. An authenticated user with limited privileges can craft a malicious URL which, if visited by an authenticated victim, leads to a Cross-Site Scripting (XSS) attack. | |
| Modificada | Media (6.7) | 0.25% | — | Fortinet FortiosFortinet Fortiproxy | 2/10/2025 | 17/6/2026 | An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] in FortiOS 7.4.0 through 7.4.7, 7.2.0 through 7.2.11, 7.0.6 and above; and FortiProxy 7.6.0 through 7.6.2, 7.4.0 through 7.4.8, 7.2 all versions, 7.0.5 and above may allow an authenticated attacker to elevate their privileges via… | |
| Aplazada | Alta (7.1) | 0.24% | — | Shinetheme TravelerAI | 26/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in shinetheme Traveler traveler allows Reflected XSS.This issue affects Traveler: from n/a through < 3.2.3. | |
| Aplazada | Alta (7.5) | 0.38% | — | Shinetheme TravelerAI | 26/9/2025 | 17/6/2026 | Missing Authorization vulnerability in shinetheme Traveler traveler allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Traveler: from n/a through < 3.2.3. | |
| Analizada | Media (4.9) | 9.3% | — | Fortinet Fortiweb | 9/9/2025 | 17/6/2026 | A Relative Path Traversal vulnerability [CWE-23] in FortiWeb 7.6.0 through 7.6.4, 7.4.0 through 7.4.8, 7.2.0 through 7.2.11, 7.0.2 through 7.0.11 may allow an authenticated attacker to perform an arbitrary file read on the underlying system via crafted requests. | |
| Analizada | Media (6.7) | 0.47% | — | Fortinet Fortiddos-f | 9/9/2025 | 17/6/2026 | An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] in Fortinet FortiDDoS-F version 7.0.0 through 7.02 and before 6.6.3 may allow a privileged attacker to execute unauthorized code or commands via crafted CLI requests. | |
| Aplazada | Crítica (9) | 0.18% | — | CGM ClininetAI | 27/8/2025 | 17/6/2026 | The paths "/cgi-bin/CliniNET.prd/utils/userlogstat.pl", "/cgi-bin/CliniNET.prd/utils/usrlogstat.pl", and "/cgi-bin/CliniNET.prd/utils/dblogstat.pl" expose data containing session IDs. | |
| Aplazada | Crítica (9) | 0.18% | — | Clininetworks ClininetworkAI | 27/8/2025 | 17/6/2026 | Unauthenticated access to the "/cgi-bin/CliniNET.prd/GetActiveSessions.pl" endpoint allows takeover of any user session logged into the system, including users with admin privileges. | |
| Aplazada | Alta (7.3) | 0.17% | — | CGM ClininetAIMicrosoft WindowsAI | 27/8/2025 | 17/6/2026 | The vulnerability consists of a session ID leak when saving a file downloaded from CGM CLININET. The identifier is exposed through a built-in Windows security feature that stores additional metadata in an NTFS alternate data stream (ADS) for all files downloaded from potentially untrusted sources. | |
| Aplazada | Media (5.3) | 0.21% | — | Nozominetworks CMCAI | 26/8/2025 | 17/6/2026 | An access control vulnerability was discovered in the Request Trace and Download Trace functionalities of CMC before 25.1.0 due to a specific access restriction not being properly enforced for users with limited privileges. An authenticated user with limited privileges can request and download trace files due to… | |
| Modificada | Alta (7.2) | 0.64% | — | Fortinet Fortios | 12/8/2025 | 17/6/2026 | An incorrect privilege assignment vulnerability [CWE-266] in FortiOS Security Fabric version 7.6.0 through 7.6.2, 7.4.0 through 7.4.7, 7.2 all versions, 7.0 all versions, 6.4 all versions, may allow a remote authenticated attacker with high privileges to escalate their privileges to super-admin via registering the… | |
| Analizada | Alta (8.1) | 10% | 💥 Exploit | Fortinet Fortiweb | 12/8/2025 | 17/6/2026 | A improper handling of parameters in Fortinet FortiWeb versions 7.6.3 and below, versions 7.4.7 and below, versions 7.2.10 and below, and 7.0.10 and below may allow an unauthenticated remote attacker with non-public information pertaining to the device and targeted user to gain admin privileges on the device via a… | |
| Analizada | Alta (7.2) | 1.1% | — | Fortinet Fortiadc | 12/8/2025 | 17/6/2026 | An improper neutralization of special elements used in an OS Command ("OS Command Injection") vulnerability [CWE-78] in Fortinet FortiADC version 7.2.0 and before 7.1.1 allows a remote and authenticated attacker with low privilege to execute unauthorized code via specifically crafted HTTP parameters. | |
| Analizada | Media (6.7) | 0.48% | — | Fortinet Fortiweb | 12/8/2025 | 17/6/2026 | A improper neutralization of special elements used in an os command ('os command injection') vulnerability [CWE-78] in Fortinet FortiWeb CLI version 7.6.0 through 7.6.3 and before 7.4.8 allows a privileged attacker to execute arbitrary code or command via crafted CLI commands. | |
| Analizada | Media (5.4) | 0.20% | — | Fortinet Fortisoar | 12/8/2025 | 17/6/2026 | An Improper neutralization of input during web page generation ('cross-site scripting') vulnerability [CWE-79] in FortiSOAR version 7.6.1 and below, version 7.5.1 and below, 7.4 all versions, 7.3 all versions, 7.2 all versions, 7.0 all versions, 6.4 all versions WEB UI may allow an authenticated remote attacker to… | |
| Analizada | Media (6.7) | 0.14% | — | Fortinet Fortiweb | 12/8/2025 | 17/6/2026 | A stack-based buffer overflow vulnerability [CWE-121] in Fortinet FortiWeb CLI version 7.6.0 through 7.6.3 and before 7.4.8 allows a privileged attacker to execute arbitrary code or commands via crafted CLI commands | |
| Analizada | Media (6.7) | 0.45% | — | Fortinet Fortiweb | 12/8/2025 | 17/6/2026 | An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiWeb version 7.6.0 through 7.6.3, 7.4.0 through 7.4.7, 7.2.0 through 7.2.10 and before 7.0.10 allows an authenticated privileged attacker to execute unauthorized code or commands via… | |
| Modificada | Crítica (9.8) | 65% | 💥 Exploit | Fortinet Fortisiem | 12/8/2025 | 18/8/2026 | An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] vulnerability in Fortinet FortiSIEM 7.3.0 through 7.3.1, FortiSIEM 7.2.0 through 7.2.5, FortiSIEM 7.1.0 through 7.1.7, FortiSIEM 7.0.0 through 7.0.3, FortiSIEM 6.7.0 through 6.7.9, FortiSIEM 6.6 all… | |
| Modificada | Media (6.5) | 0.48% | — | Fortinet FortiosFortinet FortipamFortinet Fortiproxy | 12/8/2025 | 17/6/2026 | An Integer Overflow or Wraparound vulnerability [CWE-190] in FortiOS version 7.6.2 and below, version 7.4.7 and below, version 7.2.10 and below, 7.2 all versions, 6.4 all versions, FortiProxy version 7.6.2 and below, version 7.4.3 and below, 7.2 all versions, 7.0 all versions, 2.0 all versions and FortiPAM version… | |
| Analizada | Media (6.5) | 0.63% | — | Fortinet FortimanagerFortinet Fortimanager Cloud | 12/8/2025 | 17/6/2026 | An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in Fortinet FortiManager version 7.6.0 through 7.6.1, 7.4.0 through 7.4.5, 7.2.0 through 7.2.9 and below 7.0.13 & FortiManager Cloud version 7.6.0 through 7.6.1, 7.4.0 through 7.4.5 and before 7.2.9 allows an… | |
| Analizada | Media (4.9) | 0.40% | — | Fortinet Fortisoar | 12/8/2025 | 17/6/2026 | A relative path traversal vulnerability [CWE-23] in FortiSOAR 7.6.0, 7.5.0 through 7.5.1, 7.4 all versions, 7.3 all versions may allow an authenticated attacker to read arbitrary files via uploading a malicious solution pack. |