Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
34 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.20% | — | Fortinet Fortisiem | 2/11/2022 | 17/6/2026 | A improper authentication vulnerability in Fortinet FortiSIEM before 6.5.0 allows a local attacker with CLI access to perform operations on the Glassfish server directly via a hardcoded password. | |
| Modificada | Media (5.5) | 0.22% | — | Fortinet Fortisiem | 2/11/2021 | 17/6/2026 | A unprotected storage of credentials in Fortinet FortiSIEM Windows Agent version 4.1.4 and below allows an authenticated user to disclosure agent password due to plaintext credential storage in log files | |
| Modificada | Alta (7.8) | 0.21% | — | Fortinet Fortisiem | 2/11/2021 | 17/6/2026 | A improper privilege management in Fortinet FortiSIEM Windows Agent version 4.1.4 and below allows attacker to execute privileged code or commands via powershell scripts | |
| Modificada | Crítica (9.8) | 1.5% | — | Fortinet Fortisiem Windows Agent | 4/6/2020 | 17/6/2026 | An unquoted service path vulnerability in the FortiSIEM Windows Agent component may allow an attacker to gain elevated privileges via the AoWinAgt executable service path. | |
| Modificada | Alta (8.8) | 0.56% | — | Fortinet Fortisiem | 12/3/2020 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) vulnerability in the user interface of Fortinet FortiSIEM 5.2.5 could allow a remote, unauthenticated attacker to perform arbitrary actions using an authenticated user's session by persuading the victim to follow a malicious link. | |
| Modificada | Media (5.4) | 0.62% | — | Fortinet Fortisiem | 28/1/2020 | 17/6/2026 | An Improper Neutralization of Input vulnerability in the description and title parameters of a Device Maintenance Schedule in FortiSIEM version 5.2.5 and below may allow a remote authenticated attacker to perform a Stored Cross Site Scripting attack (XSS) by injecting malicious JavaScript code into the description… | |
| Modificada | Crítica (9.8) | 1.1% | — | Fortinet Fortisiem | 23/1/2020 | 17/6/2026 | A hard-coded password vulnerability in the Fortinet FortiSIEM database component version 5.2.5 and below may allow attackers to access the device database via the use of static credentials. | |
| Modificada | Media (6.5) | 0.89% | — | Fortinet Fortisiem | 7/1/2020 | 17/6/2026 | An information exposure vulnerability in the external authentication profile form of FortiSIEM 5.2.2 and earlier may allow an authenticated attacker to retrieve the external authentication password via the HTML source code. | |
| Modificada | Alta (7.2) | 1.3% | — | Fortinet Fortisiem | 17/4/2019 | 17/6/2026 | An information disclosure vulnerability in Fortinet FortiSIEM 5.2.0 and below versions exposes the LDAP server plaintext password via the HTML source code. |