Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
127 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.3) | 0.47% | — | Fortinet FortiosFortinet FortipamFortinet FortiproxyFortinet Fortiswitchmanager | 14/10/2025 | 17/6/2026 | An improper check or handling of exceptional conditions vulnerability [CWE-703] in FortiOS version 7.4.0 through 7.4.3 and before 7.2.7, FortiProxy version 7.4.0 through 7.4.3 and before 7.2.9, FortiPAM before 1.2.0 and FortiSwitchManager version 7.2.0 through 7.2.3 and version 7.0.0 through 7.0.3 fgfm daemon may… | |
| Analizada | Alta (7.8) | 0.19% | — | Fortinet FortiosFortinet Fortiproxy | 14/10/2025 | 17/6/2026 | A stack-based buffer overflow in Fortinet FortiOS version 7.4.0 through 7.4.1 and 7.2.0 through 7.2.7 and 7.0.0 through 7.0.12 and 6.4.6 through 6.4.15 and 6.2.9 through 6.2.16 and 6.0.13 through 6.0.18 allows attacker to execute unauthorized code or commands via specially crafted CLI commands. | |
| Modificada | Media (6.7) | 0.25% | — | Fortinet FortiosFortinet Fortiproxy | 2/10/2025 | 17/6/2026 | An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] in FortiOS 7.4.0 through 7.4.7, 7.2.0 through 7.2.11, 7.0.6 and above; and FortiProxy 7.6.0 through 7.6.2, 7.4.0 through 7.4.8, 7.2 all versions, 7.0.5 and above may allow an authenticated attacker to elevate their privileges via… | |
| Modificada | Media (6.5) | 0.48% | — | Fortinet FortiosFortinet FortipamFortinet Fortiproxy | 12/8/2025 | 17/6/2026 | An Integer Overflow or Wraparound vulnerability [CWE-190] in FortiOS version 7.6.2 and below, version 7.4.7 and below, version 7.2.10 and below, 7.2 all versions, 6.4 all versions, FortiProxy version 7.6.2 and below, version 7.4.3 and below, 7.2 all versions, 7.0 all versions, 2.0 all versions and FortiPAM version… | |
| Modificada | Alta (8.1) | 0.59% | — | Fortinet FortiswitchmanagerFortinet FortiproxyFortinet FortipamFortinet Fortios | 12/8/2025 | 17/6/2026 | An authentication bypass using an alternate path or channel [CWE-288] vulnerability in Fortinet FortiOS 6.4.0 through 6.4.15, FortiOS 6.2.0 through 6.2.16, FortiOS 6.0 all versions, FortiPAM 1.2.0, FortiPAM 1.1.0 through 1.1.2, FortiPAM 1.0.0 through 1.0.3, FortiProxy 7.4.0 through 7.4.2, FortiProxy 7.2.0 through… | |
| Modificada | Alta (7.2) | 0.59% | — | Fortinet FortiosFortinet FortipamFortinet Fortiproxy | 12/8/2025 | 17/6/2026 | A double free vulnerability [CWE-415] vulnerability in Fortinet FortiOS 7.4.0, FortiOS 7.2.0 through 7.2.5, FortiOS 7.0.0 through 7.0.12, FortiOS 6.4 all versions, FortiPAM 1.1 all versions, FortiPAM 1.0 all versions, FortiProxy 7.4.0 through 7.4.1, FortiProxy 7.2.0 through 7.2.7, FortiProxy 7.0.0 through 7.0.13… | |
| Modificada | Media (5.3) | 0.37% | — | Fortinet FortiproxyFortinet FortisaseFortinet Fortios | 8/7/2025 | 17/6/2026 | An Improperly Implemented Security Check for Standard vulnerability [CWE-358] in FortiOS version 7.6.0, version 7.4.7 and below, 7.0 all versions, 6.4 all versions and FortiProxy version 7.6.1 and below, version 7.4.8 and below, 7.2 all versions, 7.0 all versions may allow a remote unauthenticated user to bypass the… | |
| Analizada | Alta (7.2) | 0.28% | — | Fortinet FortiproxyFortinet Fortios | 8/7/2025 | 17/6/2026 | A missing critical step in authentication vulnerability [CWE-304] in Fortinet FortiOS version 7.6.0 through 7.6.1, 7.4.0 through 7.4.5, 7.2.0 through 7.2.10, and before 7.0.16 & FortiProxy version 7.6.0 through 7.6.1, 7.4.0 through 7.4.8, 7.2.0 through 7.2.13 and before 7.0.20 allows an API-user using api-key + PKI… | |
| Modificada | Alta (7.2) | 0.85% | — | Fortinet FortiosFortinet FortiproxyFortinet Fortiweb | 10/6/2025 | 17/6/2026 | An Improper Privilege Management vulnerability [CWE-269] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1, FortiOS 7.4.0 through 7.4.6, FortiOS 7.2.0 through 7.2.10, FortiOS 7.0.0 through 7.0.16, FortiOS 6.4.0 through 6.4.15, FortiProxy 7.6.0 through 7.6.1, FortiProxy 7.4.0 through 7.4.7, FortiWeb 7.6.0 through… | |
| Analizada | Media (5.9) | 0.45% | — | Fortinet FortiproxyFortinet Fortios | 10/6/2025 | 17/6/2026 | A channel accessible by non-endpoint vulnerability [CWE-300] in Fortinet FortiOS version 7.4.0 through 7.4.3, 7.2.0 through 7.2.7 and before 7.0.14 & FortiProxy version 7.4.0 through 7.4.3, 7.2.0 through 7.2.9 and before 7.0.16 allows an unauthenticated attacker with the knowledge of device specific data to spoof the… | |
| Analizada | Baja (2.3) | 0.21% | — | Fortinet FortiproxyFortinet Fortios | 10/6/2025 | 17/6/2026 | An incomplete cleanup vulnerability [CWE-459] in FortiOS 7.2 all versions and before & FortiProxy version 7.2.0 through 7.2.2 and before 7.0.8 allows a VDOM privileged attacker to add SSH key files on the system silently via crafted CLI requests. | |
| Analizada | Alta (7.2) | 0.94% | — | Fortinet FortiproxyFortinet FortiswitchmanagerFortinet Fortios | 28/5/2025 | 17/6/2026 | A missing authentication for critical function in Fortinet FortiProxy versions 7.6.0 through 7.6.1, FortiSwitchManager version 7.2.5, and FortiOS versions 7.4.4 through 7.4.6 and version 7.6.0 may allow an attacker with knowledge of an existing admin account to access the device as a valid admin via an authentication… | |
| Analizada | Alta (7.5) | 0.39% | — | Fortinet FortiwebFortinet FortivoiceFortinet FortiproxyFortinet Fortios+2 | 8/4/2025 | 17/6/2026 | A improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in Fortinet FortiOS version 7.4.0 through 7.4.3, 7.2.0 through 7.2.7, 7.0.0 through 7.0.14, 6.4.0 through 6.4.15 and 6.2.0 through 6.2.16, Fortinet FortiProxy version 7.4.0 through 7.4.2, 7.2.0 through 7.2.9, 7.0.0 through… | |
| Analizada | Alta (7.5) | 0.50% | — | Fortinet FortianalyzerFortinet FortimanagerFortinet FortiosFortinet Fortiproxy+2 | 8/4/2025 | 17/6/2026 | A improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in Fortinet FortiOS version 7.4.0 through 7.4.4, 7.2.0 through 7.2.8, 7.0.0 through 7.0.15, 6.4.0 through 6.4.15 and before 6.2.16, Fortinet FortiProxy version 7.4.0 through 7.4.2, 7.2.0 through 7.2.9 and before 7.0.15,… | |
| Modificada | Alta (8.8) | 0.63% | — | Fortinet FortiosFortinet Fortiproxy | 8/4/2025 | 17/6/2026 | Multiple issues including the use of uninitialized ressources [CWE-908] and excessive iteration [CWE-834] vulnerabilities vulnerability in Fortinet allows a VPN user to corrupt memory potentially leading to code or commands execution via specifically crafted requests. | |
| Analizada | Crítica (9.8) | 18% | 💥 PoC | Fortinet FortiwebFortinet FortiswitchmanagerFortinet FortiswitchFortinet Fortiproxy+4 | 24/3/2025 | 17/6/2026 | A buffer underwrite ('buffer underflow') vulnerability in the administrative interface of Fortinet FortiOS version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.6, version 6.4.0 through 6.4.11 and version 6.2.12 and below, FortiProxy version 7.2.0 through 7.2.2, version 7.0.0 through 7.0.8, version 2.0.12 and below… | |
| Analizada | Media (5.4) | 0.43% | — | Fortinet FortiproxyFortinet Fortios | 17/3/2025 | 17/6/2026 | An improper neutralization of input during web page generation in the SSL VPN portal of FortiProxy version 2.0.0, version 1.2.9 and below and FortiOS version 6.2.1 and below, version 6.0.8 and below, version 5.6.12 may allow a remote authenticated attacker to perform a stored cross site scripting attack (XSS). | |
| Analizada | Media (6.1) | 0.60% | — | Fortinet FortiosFortinet Fortiproxy | 14/3/2025 | 17/6/2026 | An improper neutralization of input during web page Generation vulnerability [CWE-79] in FortiOS version 7.4.3 and below, version 7.2.7 and below, version 7.0.13 and below and FortiProxy version 7.4.3 and below, version 7.2.9 and below, version 7.0.16 and below web SSL VPN UI may allow a remote unauthenticated… | |
| Analizada | Alta (7.2) | 0.73% | — | Fortinet FortiosFortinet FortipamFortinet FortiproxyFortinet Fortiweb+1 | 11/3/2025 | 17/6/2026 | A use of externally-controlled format string vulnerability [CWE-134] in FortiOS version 7.4.0 through 7.4.4, version 7.2.0 through 7.2.9, version 7.0.0 through 7.0.15 and before 6.4.15, FortiProxy version 7.4.0 through 7.4.6, version 7.2.0 through 7.2.12 and before 7.0.19, FortiPAM version 1.4.0 through 1.4.2 and… | |
| Analizada | Alta (8.1) | 7.2% | ⚠ Explotación activa💥 PoC | Fortinet FortiproxyFortinet Fortios | 11/2/2025 | 5/8/2026 | An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS 7.0.0 through 7.0.16 and FortiProxy 7.2.0 through 7.2.12, 7.0.0 through 7.0.19 may allow a remote unauthenticated attacker with prior knowledge of upstream and downstream devices serial numbers to gain super-admin… | |
| Modificada | Media (6.7) | 0.24% | — | Fortinet FortiosFortinet FortiswitchmanagerFortinet FortiproxyFortinet Fortipam | 11/2/2025 | 17/6/2026 | A use of externally-controlled format string vulnerability [CWE-134] vulnerability in Fortinet allows a privileged attacker to execute arbitrary code or commands via specially crafted requests. | |
| Modificada | Media (6.1) | 0.45% | — | Fortinet FortiadcFortinet FortiauthenticatorFortinet FortiddosFortinet Fortiddos-f+10 | 22/1/2025 | 17/6/2026 | A externally controlled reference to a resource in another sphere vulnerability in Fortinet allows attacker to poison web caches via crafted HTTP requests, where the `Host` header points to an arbitrary webserver | |
| Analizada | Crítica (9.8) | 94% | ⚠ Explotación activa💥 Exploit | Fortinet FortiproxyFortinet Fortios | 14/1/2025 | 5/8/2026 | An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy version 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12 allows a remote attacker to gain super-admin privileges via crafted requests to Node.js websocket module. | |
| Analizada | Media (5.8) | 0.78% | — | Fortinet FortiproxyFortinet Fortios | 14/1/2025 | 17/6/2026 | An Improper Neutralization of CRLF Sequences in HTTP Headers ('http response splitting') vulnerability [CWE-113] in Fortinet FortiOS 7.2.0 through 7.6.0, FortiProxy 7.2.0 through 7.4.5 may allow a remote unauthenticated attacker to bypass the file filter via crafted HTTP headers. | |
| Analizada | Crítica (9.8) | 0.48% | — | Fortinet FortianalyzerFortinet Fortianalyzer CloudFortinet FortimanagerFortinet Fortimanager Cloud+2 | 14/1/2025 | 17/6/2026 | A weak authentication in Fortinet FortiOS versions 7.4.0 through 7.4.4, 7.2.0 through 7.2.8, 7.0.0 through 7.0.15, 6.4.0 through 6.4.15, FortiProxy versions 7.4.0 through 7.4.4, 7.2.0 through 7.2.10, 7.0.0 through 7.0.17, 2.0.0 through 2.0.14, FortiManager versions 7.6.0 through 7.6.1, 7.4.1 through 7.4.3,… |