Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
1579 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5) | 0.57% | — | Fortinet Fortios | 17/3/2025 | 17/6/2026 | An exposure of sensitive information to an unauthorized actor vulnerability in FortiOS version 6.2.4 and below, version 6.0.10 and belowmay allow remote authenticated actors to read the SSL VPN events log entries of users in other VDOMs by executing "get vpn ssl monitor" from the CLI. The sensitive data includes… | |
| Analizada | Media (6.1) | 0.35% | — | Fortinet Fortios | 17/3/2025 | 17/6/2026 | An Improper Neutralization of Input vulnerability affecting FortiGate version 6.2.0 through 6.2.1, 6.0.0 through 6.0.6 in the hostname parameter of a DHCP packet under DHCP monitor page may allow an unauthenticated attacker in the same network as the FortiGate to perform a Stored Cross Site Scripting attack (XSS) by… | |
| Analizada | Alta (8.1) | 0.65% | — | Fortinet Fortisiem | 17/3/2025 | 17/6/2026 | A use of hard-coded cryptographic key vulnerability in FortiSIEM version 5.2.6 may allow a remote unauthenticated attacker to obtain SSH access to the supervisor as the restricted user "tunneluser" by leveraging knowledge of the private key from another installation or a firmware image. | |
| Analizada | Media (5.4) | 0.43% | — | Fortinet FortiproxyFortinet Fortios | 17/3/2025 | 17/6/2026 | An improper neutralization of input during web page generation in the SSL VPN portal of FortiProxy version 2.0.0, version 1.2.9 and below and FortiOS version 6.2.1 and below, version 6.0.8 and below, version 5.6.12 may allow a remote authenticated attacker to perform a stored cross site scripting attack (XSS). | |
| Analizada | Crítica (9.8) | 0.53% | — | Fortinet Fortiweb | 14/3/2025 | 17/6/2026 | An improper handling of syntactically invalid structure in Fortinet FortiWeb at least vesrions 7.4.0 through 7.4.6 and 7.2.0 through 7.2.10 and 7.0.0 through 7.0.10 allows attacker to execute unauthorized code or commands via HTTP/S crafted requests. | |
| Analizada | Media (6.5) | 0.31% | — | Fortinet FortimanagerFortinet Fortianalyzer | 14/3/2025 | 17/6/2026 | An insertion of sensitive information into log file vulnerabilities [CWE-532] in FortiManager version 7.4.0, version 7.2.3 and below, version 7.0.8 and below, version 6.4.12 and below, version 6.2.11 and below and FortiAnalyzer version 7.4.0, version 7.2.3 and below, version 7.0.8 and below, version 6.4.12 and below,… | |
| Analizada | Media (4.8) | 0.17% | — | Fortinet Fortinac-f | 14/3/2025 | 17/6/2026 | An improper certificate validation vulnerability [CWE-295] in FortiNAC-F version 7.2.4 and below may allow a remote and unauthenticated attacker to perform a Man-in-the-Middle attack on the HTTPS communication channel between the FortiOS device, an inventory, and FortiNAC-F. | |
| Analizada | Alta (7.8) | 0.27% | — | Fortinet Forticlient | 14/3/2025 | 17/6/2026 | An external control of file name or path vulnerability [CWE-73] in FortiClientMac version 7.2.3 and below, version 7.0.10 and below installer may allow a local attacker to execute arbitrary code or commands via writing a malicious configuration file in /tmp before starting the installation process. | |
| Analizada | Media (5.3) | 14% | — | Fortinet Fortinac | 14/3/2025 | 17/6/2026 | A improper neutralization of special elements used in a command ('command injection') in Fortinet FortiNAC 7.2.1 and earlier, 9.4.3 and earlier allows attacker a limited, unauthorized file access via specifically crafted request in inter-server communication port. | |
| Analizada | Alta (7.2) | 0.41% | — | Fortinet Fortiweb | 14/3/2025 | 17/6/2026 | An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] in FortiWeb version 7.0.1 and below, 6.4.2 and below, 6.3.20 and below, 6.2.7 and below may allow a privileged attacker to execute SQL commands over the log database via specifically crafted strings… | |
| Analizada | Media (6.5) | 0.22% | — | Fortinet Fortindr | 14/3/2025 | 17/6/2026 | An improper validation of integrity check value vulnerability [CWE-354] in FortiNDR version 7.4.2 and below, version 7.2.1 and below, version 7.1.1 and below, version 7.0.6 and below may allow an authenticated attacker with at least Read/Write permission on system maintenance to install a corrupted firmware image. | |
| Analizada | Alta (8.8) | 2.3% | — | Fortinet FortimanagerFortinet Fortimanager Cloud | 14/3/2025 | 17/6/2026 | A improper neutralization of special elements used in a command ('command injection') in Fortinet FortiManager versions 7.4.1 through 7.4.3, FortiManager Cloud versions 7.4.1 through 7.4.3 allows attacker to escalation of privilege via specifically crafted packets | |
| Analizada | Media (4.8) | 0.16% | — | Fortinet Fortiportal | 14/3/2025 | 17/6/2026 | An improper certificate validation vulnerability [CWE-295] in FortiPortal version 7.4.0, version 7.2.4 and below, version 7.0.8 and below, version 6.0.15 and below when connecting to a FortiManager device, a FortiAnalyzer device, or an SMTP server may allow an unauthenticated attacker in a Man-in-the-Middle position… | |
| Analizada | Media (6.1) | 0.61% | — | Fortinet FortiosFortinet Fortiproxy | 14/3/2025 | 17/6/2026 | An improper neutralization of input during web page Generation vulnerability [CWE-79] in FortiOS version 7.4.3 and below, version 7.2.7 and below, version 7.0.13 and below and FortiProxy version 7.4.3 and below, version 7.2.9 and below, version 7.0.16 and below web SSL VPN UI may allow a remote unauthenticated… | |
| Analizada | Alta (7.2) | 0.58% | — | Fortinet Fortiweb | 11/3/2025 | 17/6/2026 | A improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiWeb versions 7.0.0 through 7.6.0 allows attacker to execute unauthorized code or commands via crafted requests. | |
| Analizada | Baja (3.8) | 0.26% | — | Fortinet Fortisiem | 11/3/2025 | 17/6/2026 | An incorrect authorization vulnerability [CWE-863] in FortiSIEM 7.2 all versions, 7.1 all versions, 7.0 all versions, 6.7 all versions, 6.6 all versions, 6.5 all versions, 6.4 all versions, 6.3 all versions, 6.2 all versions, 6.1 all versions, 5.4 all versions, 5.3 all versions, may allow an authenticated attacker to… | |
| Analizada | Alta (8.8) | 1.0% | — | Fortinet Fortiisolator | 11/3/2025 | 17/6/2026 | Multiple improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] in Fortinet FortiIsolator version 2.4.0 through 2.4.5 allows an authenticated attacker with at least read-only admin permission and CLI access to execute unauthorized code via specifically… | |
| Modificada | Alta (8.8) | 0.42% | — | Fortinet FortisandboxFortinet Fortisandbox Cloud | 11/3/2025 | 17/6/2026 | An improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiSandbox 4.4.0 through 4.4.6, FortiSandbox 4.2 all versions, FortiSandbox 4.0 all versions, FortiSandbox 3.2 all versions, FortiSandbox 3.1 all versions, FortiSandbox 3.0 all versions, FortiSandbox Cloud 24.1 allows… | |
| Analizada | Alta (7.2) | 10% | — | Fortinet Fortisandbox | 11/3/2025 | 17/6/2026 | Multiple improper neutralization of special elements used in an OS Command vulnerabilities [CWE-78] in FortiSandbox before 4.4.5 allows a privileged attacker to execute unauthorized commands via crafted requests. | |
| Modificada | Alta (8.8) | 0.55% | — | Fortinet Fortisandbox | 11/3/2025 | 17/6/2026 | An improper neutralization of special elements used in an OS Command vulnerability [CWE-78] vulnerability in Fortinet FortiSandbox 5.0.0, FortiSandbox 4.4.0 through 4.4.6, FortiSandbox 4.2.1 through 4.2.7, FortiSandbox 4.0.0 through 4.0.5, FortiSandbox 3.2 all versions, FortiSandbox 3.1 all versions, FortiSandbox 3.0… | |
| Analizada | Alta (8.8) | 0.34% | — | Fortinet Fortisandbox | 11/3/2025 | 17/6/2026 | A client-side enforcement of server-side security vulnerability [CWE-602] in Fortinet FortiSandbox version 5.0.0, 4.4.0 through 4.4.6 and before 4.2.7 allows an authenticated attacker with at least read-only permission to execute unauthorized commands via crafted requests. | |
| Analizada | Media (6.7) | 0.18% | — | Fortinet Fortimail | 11/3/2025 | 17/6/2026 | A stack-buffer overflow vulnerability [CWE-121] in Fortinet FortiMail CLI version 7.6.0 through 7.6.1 and before 7.4.3 allows a privileged attacker to execute arbitrary code or commands via specifically crafted CLI commands. | |
| Analizada | Alta (7.8) | 0.14% | — | Fortinet Fortisandbox | 11/3/2025 | 17/6/2026 | An incorrect authorization vulnerability [CWE-863] in FortiSandbox 4.4.0 through 4.4.6 may allow a low priviledged administrator to execute elevated CLI commands via the GUI console menu. | |
| Analizada | Alta (7.2) | 0.73% | — | Fortinet FortiosFortinet FortipamFortinet FortiproxyFortinet Fortiweb+1 | 11/3/2025 | 17/6/2026 | A use of externally-controlled format string vulnerability [CWE-134] in FortiOS version 7.4.0 through 7.4.4, version 7.2.0 through 7.2.9, version 7.0.0 through 7.0.15 and before 6.4.15, FortiProxy version 7.4.0 through 7.4.6, version 7.2.0 through 7.2.12 and before 7.0.19, FortiPAM version 1.4.0 through 1.4.2 and… | |
| Analizada | Media (6.7) | 0.18% | — | Fortinet FortianalyzerFortinet Fortianalyzer BIG DataFortinet Fortimanager | 11/3/2025 | 17/6/2026 | Two improper neutralization of special elements used in an SQL Command ('SQL Injection') vulnerability [CWE-89] in Fortinet FortiAnalyzer version 7.4.0 through 7.4.2 and before 7.2.5, FortiManager version 7.4.0 through 7.4.2 and before 7.2.5 and FortiAnalyzer-BigData version 7.4.0 and before 7.2.7 allows a privileged… |