Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2720▼ 598 respecto a la semana anterior
Críticas / altas1299▼ 202 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
943 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.3) | 0.41% | — | IBM Sterling Secure Proxy | 15/3/2024 | 17/6/2026 | IBM Sterling Secure Proxy 6.0.3 and 6.1.0 could allow an attacker to overwrite a log message under specific conditions. IBM X-Force ID: 270598. | |
| Modificada | Baja (3.3) | 0.18% | — | IBM Sterling Secure Proxy | 15/3/2024 | 17/6/2026 | IBM Sterling Secure Proxy 6.0.3 and 6.1.0 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 269686. | |
| Modificada | Media (6.1) | 0.35% | — | IBM Sterling Secure Proxy | 15/3/2024 | 17/6/2026 | IBM Sterling Secure Proxy 6.0.3 and 6.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 270973. | |
| Modificada | Media (5.4) | 0.36% | — | IBM Sterling Secure Proxy | 15/3/2024 | 17/6/2026 | IBM Sterling Secure Proxy 6.0.3 and 6.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 269692. | |
| Modificada | Media (4.3) | 0.28% | — | IBM Sterling Secure Proxy | 15/3/2024 | 17/6/2026 | IBM Sterling Secure Proxy 6.0.3 and 6.1.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker… | |
| Aplazada | Media (5.5) | 0.16% | — | Mcafee Client ProxyAI | 14/3/2024 | 17/6/2026 | A malicious insider can uninstall Skyhigh Client Proxy without a valid uninstall password. | |
| Aplazada | Media (5.5) | 0.42% | 💥 PoC | Mcafee Client ProxyAI | 14/3/2024 | 17/6/2026 | A malicious insider can bypass the existing policy of Skyhigh Client Proxy without a valid release code. | |
| Modificada | Media (4.3) | 0.66% | — | Fortinet FortiproxyFortinet Fortios | 12/3/2024 | 17/6/2026 | An authorization bypass through user-controlled key vulnerability [CWE-639] in FortiOS version 7.4.0 through 7.4.1, 7.2.0 through 7.2.6, 7.0.1 through 7.0.13, 6.4.7 through 6.4.14, and FortiProxy version 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14 SSL-VPN may allow an authenticated attacker to gain… | |
| Modificada | Alta (8.1) | 1.1% | — | Fortinet FortiproxyFortinet Fortios | 12/3/2024 | 8/7/2026 | A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2.0 through 7.2.5, FortiOS 7.0.0 through 7.0.12, FortiOS 6.4.0 through 6.4.14, FortiOS 6.2.0 through 6.2.15, FortiProxy 7.4.0, FortiProxy 7.2.0 through 7.2.6, FortiProxy 7.0.0 through 7.0.12, FortiProxy 2.0.0 through 2.0.13,… | |
| Modificada | Crítica (9.8) | 3.3% | 💥 PoC | Fortinet FortiproxyFortinet Fortios | 12/3/2024 | 8/7/2026 | A out-of-bounds write vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2.0 through 7.2.5, FortiOS 7.0.0 through 7.0.12, FortiOS 6.4.0 through 6.4.14, FortiOS 6.2.0 through 6.2.15, FortiProxy 7.4.0, FortiProxy 7.2.0 through 7.2.6, FortiProxy 7.0.0 through 7.0.12, FortiProxy 2.0.0 through 2.0.13,… | |
| Analizada | Crítica (9.8) | 17% | — | Articatech Artica Proxy | 5/3/2024 | 17/6/2026 | Services that are running and bound to the loopback interface on the Artica Proxy are accessible through the proxy service. In particular, the "tailon" service is running, running as the root user, is bound to the loopback interface, and is listening on TCP port 7050. Security issues associated with exposing this… | |
| Analizada | Crítica (9.8) | 0.93% | — | Articatech Artica Proxy | 5/3/2024 | 17/6/2026 | The "Rich Filemanager" feature of Artica Proxy provides a web-based interface for file management capabilities. When the feature is enabled, it does not require authentication by default, and runs as the root user. | |
| Analizada | Alta (8.8) | 0.72% | — | Fortinet FortiproxyFortinet FortiosFortinet Fortipam | 22/2/2024 | 17/6/2026 | A use of externally-controlled format string in Fortinet FortiOS 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.12, 6.2.0 through 6.2.14, 6.0.0 through 6.0.16, FortiProxy 7.2.0 through 7.2.4, 7.0.0 through 7.0.10, 2.0.0 through 2.0.12, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6, 1.0.0 through 1.0.7,… | |
| Analizada | Alta (7.5) | 2.6% | — | Fortinet FortiproxyFortinet Fortios | 22/2/2024 | 17/6/2026 | A null pointer dereference in Fortinet FortiOS version 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.12, 6.2.0 through 6.2.14, 6.0.0 through 6.0.16, FortiProxy 7.2.0 through 7.2.3, 7.0.0 through 7.0.10, 2.0.0 through 2.0.12, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6, 1.0.0 through 1.0.7 allows attacker… | |
| Analizada | Media (6.5) | 2.5% | — | Fortinet FortiosFortinet Fortiproxy | 22/2/2024 | 17/6/2026 | A null pointer dereference in Fortinet FortiOS version 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.12, Fortiproxy version 7.2.0 through 7.2.4, 7.0.0 through 7.0.10 allows attacker to denial of service via specially crafted HTTP requests. | |
| Analizada | Crítica (9.8) | 62% | ⚠ Explotación activa💥 PoC | Fortinet FortiproxyFortinet FortiswitchmanagerFortinet FortiosFortinet Fortipam | 15/2/2024 | 17/6/2026 | A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14, FortiPAM versions 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiSwitchManager versions… | |
| Analizada | Alta (7.5) | 0.52% | — | F5 Big-ip Access Policy ManagerF5 Big-iq Centralized ManagementF5 Big-ip Advanced Firewall ManagerF5 Big-ip Analytics+9 | 14/2/2024 | 17/6/2026 | When HTTP/2 is configured on BIG-IP or BIG-IP Next SPK systems, undisclosed responses can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated | |
| Modificada | Alta (7.5) | 0.69% | — | Envoyproxy Envoy | 9/2/2024 | 17/6/2026 | Envoy is a high-performance edge/middle/service proxy. When PPv2 is enabled both on a listener and subsequent cluster, the Envoy instance will segfault when attempting to craft the upstream PPv2 header. This occurs when the downstream request has a command type of LOCAL and does not have the protocol block. This issue… | |
| Modificada | Alta (7.5) | 0.75% | — | Envoyproxy Envoy | 9/2/2024 | 17/6/2026 | Envoy is a high-performance edge/middle/service proxy. Envoy crashes in Proxy protocol when using an address type that isn’t supported by the OS. Envoy is susceptible to crashing on a host with IPv6 disabled and a listener config with proxy protocol enabled when it receives a request where the client presents its IPv6… | |
| Modificada | Alta (7.5) | 0.60% | — | Envoyproxy Envoy | 9/2/2024 | 17/6/2026 | Envoy is a high-performance edge/middle/service proxy. External authentication can be bypassed by downstream connections. Downstream clients can force invalid gRPC requests to be sent to ext_authz, circumventing ext_authz checks when failure_mode_allow is set to true. This issue has been addressed in released 1.29.1,… | |
| Modificada | Media (5.3) | 0.50% | — | Envoyproxy Envoy | 9/2/2024 | 17/6/2026 | Envoy is a high-performance edge/middle/service proxy. The regex expression is compiled for every request and can result in high CPU usage and increased request latency when multiple routes are configured with such matchers. This issue has been addressed in released 1.29.1, 1.28.1, 1.27.3, and 1.26.7. Users are… | |
| Modificada | Alta (7.5) | 0.68% | — | Envoyproxy Envoy | 9/2/2024 | 17/6/2026 | Envoy is a high-performance edge/middle/service proxy. Envoy will crash when certain timeouts happen within the same interval. The crash occurs when the following are true: 1. hedge_on_per_try_timeout is enabled, 2. per_try_idle_timeout is enabled (it can only be done in configuration), 3. per-try-timeout is enabled,… | |
| Analizada | Crítica (9.8) | 83% | ⚠ Explotación activa💥 PoC | Fortinet FortiproxyFortinet Fortios | 9/2/2024 | 4/8/2026 | A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0.0 through 6.0.17, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14, 2.0.0 through 2.0.13, 1.2.0 through 1.2.13, 1.1.0… | |
| Modificada | Alta (8.8) | 0.90% | — | Fortinet FortiproxyFortinet Fortios | 10/1/2024 | 17/6/2026 | An improper privilege management vulnerability [CWE-269] in a Fortinet FortiOS HA cluster version 7.4.0 through 7.4.1 and 7.2.5 and in a FortiProxy HA cluster version 7.4.0 through 7.4.1 allows an authenticated attacker to perform elevated actions via crafted HTTP or HTTPS requests. | |
| Modificada | Media (5.3) | 0.57% | — | Fortinet FortiproxyFortinet Fortios | 13/12/2023 | 17/6/2026 | An improper access control vulnerability [CWE-284] in FortiOS version 7.2.0, version 7.0.13 and below, version 6.4.14 and below and FortiProxy version 7.2.3 and below, version 7.0.9 and below, version 2.0.12 and below may allow a remote unauthenticated attacker to bypass the firewall deny geolocalisation policy via… |