Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2722▼ 518 respecto a la semana anterior
Críticas / altas1296▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
447 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 19% | 💥 Exploit | Adiscon Loganalyzer | 5/12/2018 | 17/6/2026 | login.php in Adiscon LogAnalyzer before 4.1.7 has XSS via the Login Button Referer field. | |
| Modificada | Media (6.1) | 0.87% | — | Fortinet Fortianalyzer FirmwareFortinet Fortimanager Firmware | 16/7/2018 | 17/6/2026 | A Cross-site Scripting (XSS) vulnerability in Fortinet FortiManager 6.0.0, 5.6.4 and below versions, FortiAnalyzer 6.0.0, 5.6.4 and below versions allows inject Javascript code and HTML tags through the CN value of CA and CRL certificates via the import CA and CRL certificates feature. | |
| Modificada | Alta (7.8) | 1.8% | — | Siemens EC 61850 System Configurator FirmwareSiemens Sicam PQ Analyzer FirmwareSiemens Sicam SCC FirmwareSiemens Digsi 4 Firmware+2 | 9/7/2018 | 17/6/2026 | A vulnerability has been identified in IEC 61850 system configurator (All versions < V5.80), DIGSI 5 (affected as IEC 61850 system configurator is incorporated) (All versions < V7.80), DIGSI 4 (All versions < V4.93), SICAM PAS/PQS (All versions < V8.11), SICAM PQ Analyzer (All versions < V3.11), SICAM SCC (All… | |
| Modificada | Media (6.1) | 1.3% | — | Zohocorp Manageengine Eventlog Analyzer | 2/7/2018 | 17/6/2026 | An issue was discovered in Zoho ManageEngine EventLog Analyzer 11.12. A Cross-Site Scripting vulnerability allows a remote attacker to inject arbitrary web script or HTML via the search functionality (the search box of the Dashboard). | |
| Modificada | Media (6.1) | 1.3% | — | Zohocorp Manageengine Eventlog Analyzer | 2/7/2018 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Zoho ManageEngine EventLog Analyzer 11.12 allows remote attackers to inject arbitrary web script or HTML via the import logs feature. | |
| Modificada | Media (6.1) | 99% | 💥 Exploit | Zohocorp Firewall AnalyzerZohocorp Manageengine Netflow AnalyzerZohocorp Manageengine Network Configuration ManagerZohocorp Manageengine Opmanager+1 | 29/6/2018 | 17/6/2026 | A reflected Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Netflow Analyzer before build 123137, Network Configuration Manager before build 123128, OpManager before build 123148, OpUtils before build 123161, and Firewall Analyzer before build 123147 allows remote attackers to inject arbitrary web script… | |
| Modificada | Alta (7.5) | 6.6% | — | Zohocorp Firewall AnalyzerZohocorp Manageengine Netflow AnalyzerZohocorp Manageengine Network Configuration ManagerZohocorp Manageengine Opmanager+1 | 29/6/2018 | 17/6/2026 | Incorrect Access Control in FailOverHelperServlet in Zoho ManageEngine Netflow Analyzer before build 123137, Network Configuration Manager before build 123128, OpManager before build 123148, OpUtils before build 123161, and Firewall Analyzer before build 123147 allows attackers to read certain files on the web server… | |
| Modificada | Media (6.1) | 1.6% | — | Fortinet FortianalyzerFortinet Fortimanager | 27/6/2018 | 17/6/2026 | An open redirect vulnerability in Fortinet FortiManager 6.0.0, 5.6.5 and below versions, FortiAnalyzer 6.0.0, 5.6.5 and below versions allows attacker to inject script code during converting a HTML table to a PDF document under the FortiView feature. An attacker may be able to social engineer an authenticated user… | |
| Modificada | Media (6.5) | 1.7% | — | Fortinet FortianalyzerFortinet Fortimanager | 27/6/2018 | 17/6/2026 | An improper access control vulnerability in Fortinet FortiManager 6.0.0, 5.6.5 and below versions, FortiAnalyzer 6.0.0, 5.6.5 and below versions allows a regular user edit the avatar picture of other users with arbitrary content. | |
| Modificada | Media (6.1) | 0.69% | — | Zohocorp Manageengine Netflow Analyzer | 10/5/2018 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the add credentials functionality in Zoho ManageEngine NetFlow Analyzer v12.3 before 12.3.125 (build 123125) allows remote attackers to inject arbitrary web script or HTML via a crafted description value. This can be exploited through CSRF. | |
| Modificada | Media (6.1) | 1.9% | — | Zohocorp Manageengine Eventlog Analyzer | 15/3/2018 | 17/6/2026 | Zoho ManageEngine EventLog Analyzer version 11.0 build 11000 has Stored XSS related to the index2.do?url=editAlertForm&tab=alert&alert=profile URI and the Edit Alert Profile screen | |
| Modificada | Media (6.1) | 1.3% | — | Zohocorp Manageengine Eventlog Analyzer | 13/3/2018 | 17/6/2026 | Cross-site scripting (XSS) in Zoho ManageEngine EventLog Analyzer before 11.12 Build 11120 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (5.4) | 0.71% | — | Sonicwall AnalyzerSonicwall Global Management System | 14/1/2018 | 17/6/2026 | SonicWall Global Management System (GMS) 8.1 has XSS via the `newName` and `Name` values of the `/sgms/TreeControl` module. | |
| Modificada | Crítica (9.3) | 4.5% | 💥 Exploit | Symantec Malware Analysis ApplianceSymantec Malware Analyzer G2 | 11/9/2017 | 17/6/2026 | Blue Coat Malware Analysis Appliance (MAA) before 4.2.5 and Malware Analyzer G2 allow remote attackers to bypass a virtual machine protection mechanism and consequently write to arbitrary files, cause a denial of service (host reboot or reset to factory defaults), or execute arbitrary code via vectors related to… | |
| Modificada | Alta (8.8) | 6.1% | — | Zohocorp Manageengine Firewall Analyzer | 4/9/2017 | 17/6/2026 | Zoho ManageEngine Firewall Analyzer 12200 has an unrestricted File Upload vulnerability in the "Group Chat" section. Any user can upload files with any extensions. By uploading a PHP file to the server, an attacker can cause it to execute in the server context, as demonstrated by /itplus/FileStorage/302/shell.jsp. | |
| Modificada | Media (6.1) | 1.3% | — | Zohocorp Manageengine Eventlog Analyzer | 27/7/2017 | 17/6/2026 | Multiple Persistent cross-site scripting (XSS) vulnerabilities in Event log parsing and Display functions in Zoho ManageEngine Event Log Analyzer 11.4 and 11.5 allow remote attackers to inject arbitrary web script or HTML via syslog. | |
| Modificada | Media (6.1) | 2.3% | — | Zohocorp Manageengine Eventlog Analyzer | 27/7/2017 | 17/6/2026 | Zoho ManageEngine Event Log Analyzer 11.4 and 11.5 allows remote attackers to obtain an authenticated user's password via XSS vulnerabilities or sniffing non-SSL traffic on the network, because the password is represented in a cookie with a reversible encoding method. | |
| Modificada | Media (6.1) | 1.3% | — | Zohocorp Manageengine Eventlog Analyzer | 27/7/2017 | 17/6/2026 | Multiple Reflective cross-site scripting (XSS) vulnerabilities in search and display of event data in Zoho ManageEngine Event Log Analyzer 11.4 and 11.5 allow remote attackers to inject arbitrary web script or HTML, as demonstrated by the fName parameter. | |
| Modificada | Alta (7.5) | 7.1% | — | Zohocorp Manageengine Firewall Analyzer | 27/6/2017 | 17/6/2026 | ManageEngine Firewall Analyzer before 8.0 does not restrict access permissions. | |
| Modificada | Media (6.5) | 11% | 💥 Exploit | Zohocorp Manageengine Firewall Analyzer | 27/6/2017 | 17/6/2026 | Directory traversal vulnerability in ManageEngine Firewall Analyzer before 8.0. | |
| Modificada | Media (6.1) | 0.94% | — | Fortinet Fortianalyzer FirmwareFortinet Fortimanager Firmware | 27/5/2017 | 17/6/2026 | An Open Redirect vulnerability in Fortinet FortiAnalyzer 5.4.0 through 5.4.2 and FortiManager 5.4.0 through 5.4.2 allows attacker to execute unauthorized code or commands via the next parameter. | |
| Modificada | Alta (7.3) | 0.97% | — | Intel AdvisorCryptography FOR Intel Integrated Performance PrimitivesIntel Data Analytics Acceleration LibraryIntel Inspector+8 | 28/2/2017 | 17/6/2026 | Intel PSET Application Install wrapper of Intel Parallel Studio XE, Intel System Studio, Intel VTune Amplifier, Intel Inspector, Intel Advisor, Intel MPI Library, Intel Trace Analyzer and Collector, Intel Integrated Performance Primitives, Cryptography for Intel Integrated Performance Primitives, Intel Math Kernel… | |
| Modificada | Media (6.1) | 1.2% | — | Jenkins Build Failure Analyzer | 9/2/2017 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Build Failure Analyzer plugin before 1.16.0 in Jenkins allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter. | |
| Modificada | Media (5.5) | 0.32% | — | IBM Rational Asset Analyzer | 25/11/2016 | 17/6/2026 | The installation component in IBM Rational Asset Analyzer (RAA) 6.1.0 before FP10 allows local users to discover the WAS Admin password by reading IM native logs. | |
| Modificada | Media (5.4) | 0.70% | — | Fortinet Fortimanager FirmwareFortinet Fortianalyzer Firmware | 7/10/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the advanced settings page in Fortinet FortiManager 5.x before 5.0.12 and 5.2.x before 5.2.3, in hardware models with a hard disk, and FortiAnalyzer 5.x before 5.0.13 and 5.2.x before 5.2.3 allows remote administrators to inject arbitrary web script or HTML via vectors… |