Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2722▼ 518 respecto a la semana anterior
Críticas / altas1296▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

447 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)19%💥 ExploitAdiscon Loganalyzer5/12/201817/6/2026
login.php in Adiscon LogAnalyzer before 4.1.7 has XSS via the Login Button Referer field.
ModificadaMedia (6.1)0.87%—Fortinet Fortianalyzer FirmwareFortinet Fortimanager Firmware16/7/201817/6/2026
A Cross-site Scripting (XSS) vulnerability in Fortinet FortiManager 6.0.0, 5.6.4 and below versions, FortiAnalyzer 6.0.0, 5.6.4 and below versions allows inject Javascript code and HTML tags through the CN value of CA and CRL certificates via the import CA and CRL certificates feature.
ModificadaAlta (7.8)1.8%—Siemens EC 61850 System Configurator FirmwareSiemens Sicam PQ Analyzer FirmwareSiemens Sicam SCC FirmwareSiemens Digsi 4 Firmware+29/7/201817/6/2026
A vulnerability has been identified in IEC 61850 system configurator (All versions < V5.80), DIGSI 5 (affected as IEC 61850 system configurator is incorporated) (All versions < V7.80), DIGSI 4 (All versions < V4.93), SICAM PAS/PQS (All versions < V8.11), SICAM PQ Analyzer (All versions < V3.11), SICAM SCC (All…
ModificadaMedia (6.1)1.3%—Zohocorp Manageengine Eventlog Analyzer2/7/201817/6/2026
An issue was discovered in Zoho ManageEngine EventLog Analyzer 11.12. A Cross-Site Scripting vulnerability allows a remote attacker to inject arbitrary web script or HTML via the search functionality (the search box of the Dashboard).
ModificadaMedia (6.1)1.3%—Zohocorp Manageengine Eventlog Analyzer2/7/201817/6/2026
Cross-site scripting (XSS) vulnerability in Zoho ManageEngine EventLog Analyzer 11.12 allows remote attackers to inject arbitrary web script or HTML via the import logs feature.
ModificadaMedia (6.1)99%💥 ExploitZohocorp Firewall AnalyzerZohocorp Manageengine Netflow AnalyzerZohocorp Manageengine Network Configuration ManagerZohocorp Manageengine Opmanager+129/6/201817/6/2026
A reflected Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Netflow Analyzer before build 123137, Network Configuration Manager before build 123128, OpManager before build 123148, OpUtils before build 123161, and Firewall Analyzer before build 123147 allows remote attackers to inject arbitrary web script…
ModificadaAlta (7.5)6.6%—Zohocorp Firewall AnalyzerZohocorp Manageengine Netflow AnalyzerZohocorp Manageengine Network Configuration ManagerZohocorp Manageengine Opmanager+129/6/201817/6/2026
Incorrect Access Control in FailOverHelperServlet in Zoho ManageEngine Netflow Analyzer before build 123137, Network Configuration Manager before build 123128, OpManager before build 123148, OpUtils before build 123161, and Firewall Analyzer before build 123147 allows attackers to read certain files on the web server…
ModificadaMedia (6.1)1.6%—Fortinet FortianalyzerFortinet Fortimanager27/6/201817/6/2026
An open redirect vulnerability in Fortinet FortiManager 6.0.0, 5.6.5 and below versions, FortiAnalyzer 6.0.0, 5.6.5 and below versions allows attacker to inject script code during converting a HTML table to a PDF document under the FortiView feature. An attacker may be able to social engineer an authenticated user…
ModificadaMedia (6.5)1.7%—Fortinet FortianalyzerFortinet Fortimanager27/6/201817/6/2026
An improper access control vulnerability in Fortinet FortiManager 6.0.0, 5.6.5 and below versions, FortiAnalyzer 6.0.0, 5.6.5 and below versions allows a regular user edit the avatar picture of other users with arbitrary content.
ModificadaMedia (6.1)0.69%—Zohocorp Manageengine Netflow Analyzer10/5/201817/6/2026
Cross-site scripting (XSS) vulnerability in the add credentials functionality in Zoho ManageEngine NetFlow Analyzer v12.3 before 12.3.125 (build 123125) allows remote attackers to inject arbitrary web script or HTML via a crafted description value. This can be exploited through CSRF.
ModificadaMedia (6.1)1.9%—Zohocorp Manageengine Eventlog Analyzer15/3/201817/6/2026
Zoho ManageEngine EventLog Analyzer version 11.0 build 11000 has Stored XSS related to the index2.do?url=editAlertForm&tab=alert&alert=profile URI and the Edit Alert Profile screen
ModificadaMedia (6.1)1.3%—Zohocorp Manageengine Eventlog Analyzer13/3/201817/6/2026
Cross-site scripting (XSS) in Zoho ManageEngine EventLog Analyzer before 11.12 Build 11120 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (5.4)0.71%—Sonicwall AnalyzerSonicwall Global Management System14/1/201817/6/2026
SonicWall Global Management System (GMS) 8.1 has XSS via the `newName` and `Name` values of the `/sgms/TreeControl` module.
ModificadaCrítica (9.3)4.5%💥 ExploitSymantec Malware Analysis ApplianceSymantec Malware Analyzer G211/9/201717/6/2026
Blue Coat Malware Analysis Appliance (MAA) before 4.2.5 and Malware Analyzer G2 allow remote attackers to bypass a virtual machine protection mechanism and consequently write to arbitrary files, cause a denial of service (host reboot or reset to factory defaults), or execute arbitrary code via vectors related to…
ModificadaAlta (8.8)6.1%—Zohocorp Manageengine Firewall Analyzer4/9/201717/6/2026
Zoho ManageEngine Firewall Analyzer 12200 has an unrestricted File Upload vulnerability in the "Group Chat" section. Any user can upload files with any extensions. By uploading a PHP file to the server, an attacker can cause it to execute in the server context, as demonstrated by /itplus/FileStorage/302/shell.jsp.
ModificadaMedia (6.1)1.3%—Zohocorp Manageengine Eventlog Analyzer27/7/201717/6/2026
Multiple Persistent cross-site scripting (XSS) vulnerabilities in Event log parsing and Display functions in Zoho ManageEngine Event Log Analyzer 11.4 and 11.5 allow remote attackers to inject arbitrary web script or HTML via syslog.
ModificadaMedia (6.1)2.3%—Zohocorp Manageengine Eventlog Analyzer27/7/201717/6/2026
Zoho ManageEngine Event Log Analyzer 11.4 and 11.5 allows remote attackers to obtain an authenticated user's password via XSS vulnerabilities or sniffing non-SSL traffic on the network, because the password is represented in a cookie with a reversible encoding method.
ModificadaMedia (6.1)1.3%—Zohocorp Manageengine Eventlog Analyzer27/7/201717/6/2026
Multiple Reflective cross-site scripting (XSS) vulnerabilities in search and display of event data in Zoho ManageEngine Event Log Analyzer 11.4 and 11.5 allow remote attackers to inject arbitrary web script or HTML, as demonstrated by the fName parameter.
ModificadaAlta (7.5)7.1%—Zohocorp Manageengine Firewall Analyzer27/6/201717/6/2026
ManageEngine Firewall Analyzer before 8.0 does not restrict access permissions.
ModificadaMedia (6.5)11%💥 ExploitZohocorp Manageengine Firewall Analyzer27/6/201717/6/2026
Directory traversal vulnerability in ManageEngine Firewall Analyzer before 8.0.
ModificadaMedia (6.1)0.94%—Fortinet Fortianalyzer FirmwareFortinet Fortimanager Firmware27/5/201717/6/2026
An Open Redirect vulnerability in Fortinet FortiAnalyzer 5.4.0 through 5.4.2 and FortiManager 5.4.0 through 5.4.2 allows attacker to execute unauthorized code or commands via the next parameter.
ModificadaAlta (7.3)0.97%—Intel AdvisorCryptography FOR Intel Integrated Performance PrimitivesIntel Data Analytics Acceleration LibraryIntel Inspector+828/2/201717/6/2026
Intel PSET Application Install wrapper of Intel Parallel Studio XE, Intel System Studio, Intel VTune Amplifier, Intel Inspector, Intel Advisor, Intel MPI Library, Intel Trace Analyzer and Collector, Intel Integrated Performance Primitives, Cryptography for Intel Integrated Performance Primitives, Intel Math Kernel…
ModificadaMedia (6.1)1.2%—Jenkins Build Failure Analyzer9/2/201717/6/2026
Cross-site scripting (XSS) vulnerability in the Build Failure Analyzer plugin before 1.16.0 in Jenkins allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter.
ModificadaMedia (5.5)0.32%—IBM Rational Asset Analyzer25/11/201617/6/2026
The installation component in IBM Rational Asset Analyzer (RAA) 6.1.0 before FP10 allows local users to discover the WAS Admin password by reading IM native logs.
ModificadaMedia (5.4)0.70%—Fortinet Fortimanager FirmwareFortinet Fortianalyzer Firmware7/10/201617/6/2026
Cross-site scripting (XSS) vulnerability in the advanced settings page in Fortinet FortiManager 5.x before 5.0.12 and 5.2.x before 5.2.3, in hardware models with a hard disk, and FortiAnalyzer 5.x before 5.0.13 and 5.2.x before 5.2.3 allows remote administrators to inject arbitrary web script or HTML via vectors…