Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
1579 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 0.28% | — | Fortinet Forticlient | 12/11/2024 | 17/6/2026 | A untrusted search path in Fortinet FortiClientWindows versions 7.4.0, versions 7.2.4 through 7.2.0, versions 7.0.12 through 7.0.0 allows an attacker to run arbitrary code via DLL hijacking and social engineering. | |
| Analizada | Baja (2.3) | 0.24% | — | Fortinet FortianalyzerFortinet Fortianalyzer BIG DataFortinet Fortimanager | 12/11/2024 | 17/6/2026 | An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in Fortinet FortiAnalyzer versions below 7.4.2, Fortinet FortiManager versions below 7.4.2 and Fortinet FortiAnalyzer-BigData version 7.4.0 and below 7.2.7 allows a privileged attacker with read write… | |
| Analizada | Media (4.3) | 0.57% | — | Fortinet FortiproxyFortinet Fortios | 12/11/2024 | 17/6/2026 | An improper neutralization of special elements in output used by a downstream component ('Injection') vulnerability [CWE-74] in FortiOS version 7.4.3 and below, version 7.2.8 and below, version 7.0.16 and below; FortiProxy version 7.4.3 and below, version 7.2.9 and below, version 7.0.16 and below; FortiSASE version… | |
| Analizada | Alta (7.3) | 0.48% | — | Fortinet FortianalyzerFortinet FortimanagerFortinet Fortimanager Cloud | 12/11/2024 | 17/6/2026 | A heap-based buffer overflow in Fortinet FortiAnalyzer version 7.4.0 through 7.4.2, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14, FortiManager version 7.4.0 through 7.4.2, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14 allows attacker to escalation of privilege via specially crafted… | |
| Analizada | Media (6.7) | 0.61% | — | Fortinet FortianalyzerFortinet Fortianalyzer BIG DataFortinet Fortimanager | 12/11/2024 | 17/6/2026 | Multiple improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] in Fortinet FortiManager version 7.4.0 through 7.4.2 and before 7.2.5, Fortinet FortiAnalyzer version 7.4.0 through 7.4.2 and before 7.2.5 and Fortinet FortiAnalyzer-BigData before 7.4.0 allows… | |
| Analizada | Media (4.9) | 0.85% | — | Fortinet FortianalyzerFortinet Fortianalyzer BIG DataFortinet Fortimanager | 12/11/2024 | 17/6/2026 | An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in Fortinet FortiManager version 7.4.0 through 7.4.2 and below 7.2.5, FortiAnalyzer version 7.4.0 through 7.4.2 and below 7.2.5 & FortiAnalyzer-BigData version 7.4.0 and below 7.2.7 allows a privileged attacker to… | |
| Analizada | Media (6) | 0.24% | — | Fortinet FortianalyzerFortinet Fortianalyzer BIG DataFortinet Fortimanager | 12/11/2024 | 17/6/2026 | Multiple relative path traversal vulnerabilities [CWE-23] in Fortinet FortiManager version 7.4.0 through 7.4.2 and before 7.2.5, FortiAnalyzer version 7.4.0 through 7.4.2 and before 7.2.5 and FortiAnalyzer-BigData version 7.4.0 and before 7.2.7 allows a privileged attacker to delete files from the underlying… | |
| Analizada | Media (6.7) | 0.23% | — | Fortinet FortianalyzerFortinet Fortianalyzer BIG DataFortinet Fortimanager | 12/11/2024 | 17/6/2026 | A stack-based buffer overflow vulnerability [CWE-121] in Fortinet FortiManager version 7.4.0 through 7.4.2 and before 7.2.5, FortiAnalyzer version 7.4.0 through 7.4.2 and before 7.2.5 and FortiAnalyzer-BigData 7.4.0 and before 7.2.7 allows a privileged attacker to execute unauthorized code or commands via crafted CLI… | |
| Analizada | Crítica (9.8) | 0.60% | — | Fortinet FortiosFortinet FortipamFortinet FortiproxyFortinet Fortimanager+2 | 12/11/2024 | 17/6/2026 | A missing authentication for critical function in Fortinet FortiManager version 7.4.0 through 7.4.2, 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.14, FortiPAM version 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiProxy version 7.4.0 through 7.4.2, 7.2.0 through 7.2.9, 7.0.0 through 7.0.17,… | |
| Analizada | Alta (8.8) | 2.7% | 💥 PoC | Fortinet FortianalyzerFortinet Fortianalyzer BIG DataFortinet Fortimanager | 12/11/2024 | 17/6/2026 | A client-side enforcement of server-side security in Fortinet FortiAnalyzer-BigData at least version 7.4.0 and 7.2.0 through 7.2.6 and 7.0.1 through 7.0.6 and 6.4.5 through 6.4.7 and 6.2.5, FortiManager version 7.4.0 through 7.4.1 and 7.2.0 through 7.2.4 and 7.0.0 through 7.0.11 and 6.4.0 through 6.4.14, FortiAnalyzer… | |
| Modificada | Alta (8.8) | 0.40% | — | Fortinet Fortios | 12/11/2024 | 24/8/2026 | A session fixation vulnerability in Fortinet FortiOS 7.4.0 through 7.4.3, FortiOS 7.2.0 through 7.2.7, FortiOS 7.0.0 through 7.0.13 allows attacker to execute unauthorized code or commands via phishing SAML authentication link. | |
| Analizada | Alta (8.1) | 0.39% | — | Fortinet Fortiportal | 12/11/2024 | 17/6/2026 | An authorization bypass through user-controlled key vulnerability [CWE-639] in Fortinet FortiPortal version 7.0.0 through 7.0.3 allows an authenticated attacker to interact with ressources of other organizations via HTTP or HTTPS requests. | |
| Analizada | Media (4.1) | 0.55% | — | Fortinet FortianalyzerFortinet Fortianalyzer BIG DataFortinet Fortimanager | 12/11/2024 | 17/6/2026 | An exposure of sensitive information to an unauthorized actor [CWE-200] in Fortinet FortiManager before 7.4.2, FortiAnalyzer before 7.4.2 and FortiAnalyzer-BigData before 7.2.5 may allow a privileged attacker with administrative read permissions to read event logs of another adom via crafted HTTP or HTTPs requests. | |
| Analizada | Alta (8.8) | 0.27% | — | Gl-inet Mt6000 FirmwareGl-inet Mt3000 FirmwareGl-inet Mt2500 FirmwareGl-inet Axt1800 Firmware+17 | 24/10/2024 | 17/6/2026 | An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. The upload interface allows the uploading of arbitrary files to the device. Once the device executes the files, it can lead to information leakage, enabling complete control. | |
| Analizada | Alta (8.8) | 0.67% | — | Gl-inet Mt2500 FirmwareGl-inet Axt1800 FirmwareGl-inet Ax1800 FirmwareGl-inet B3000 Firmware+17 | 24/10/2024 | 17/6/2026 | An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. The params parameter in the call method of the /rpc endpoint is vulnerable to arbitrary directory traversal, which enables attackers to execute scripts under any path. | |
| Analizada | Alta (8) | 0.49% | — | Gl-inet Mt2500 FirmwareGl-inet Axt1800 FirmwareGl-inet Ax1800 FirmwareGl-inet B3000 Firmware+17 | 24/10/2024 | 17/6/2026 | An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. The SID generated for a specific user is not tied to that user itself, which allows other users to potentially use it for authentication. Once an attacker bypasses the application's authentication… | |
| Analizada | Alta (8) | 4.1% | — | Gl-inet Mt6000 FirmwareGl-inet B1300 FirmwareGl-inet Mt2500 FirmwareGl-inet Axt1800 Firmware+17 | 24/10/2024 | 17/6/2026 | An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. Users who belong to unauthorized groups can invoke any interface of the device, thereby gaining complete control over it. | |
| Analizada | Media (6.5) | 0.23% | — | Gl-inet Mt3000 FirmwareGl-inet Mt2500 FirmwareGl-inet Axt1800 FirmwareGl-inet Ax1800 Firmware+17 | 24/10/2024 | 17/6/2026 | An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. By intercepting an HTTP request and changing the filename property in the download interface, any file on the device can be deleted. | |
| Aplazada | Alta (8.6) | 0.50% | — | Ininet Solutions Spidercontrol Scada PC HMI EditorAI | 24/10/2024 | 17/6/2026 | iniNet Solutions SpiderControl SCADA PC HMI Editor has a path traversal vulnerability. When the software loads a malicious ‘ems' project template file constructed by an attacker, it can write files to arbitrary directories. This can lead to overwriting system files, causing system paralysis, or writing to startup… | |
| Analizada | Crítica (9.8) | 95% | ⚠ Explotación activa💥 Exploit | Fortinet FortimanagerFortinet Fortimanager Cloud | 23/10/2024 | 17/6/2026 | A missing authentication for critical function in FortiManager 7.6.0, FortiManager 7.4.0 through 7.4.4, FortiManager 7.2.0 through 7.2.7, FortiManager 7.0.0 through 7.0.12, FortiManager 6.4.0 through 6.4.14, FortiManager 6.2.0 through 6.2.12, Fortinet FortiManager Cloud 7.4.1 through 7.4.4, FortiManager Cloud 7.2.1… | |
| Analizada | Alta (7.2) | 0.63% | — | Fortinet FortianalyzerFortinet Fortianalyzer Cloud | 8/10/2024 | 17/6/2026 | A use of externally-controlled format string in Fortinet FortiAnalyzer versions 7.4.0 through 7.4.3, 7.2.2 through 7.2.5 allows attacker to escalate its privileges via specially crafted requests. | |
| Analizada | Media (4.3) | 0.45% | — | Fortinet Fortimanager | 8/10/2024 | 17/6/2026 | An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiManager 7.4.2 and below, 7.2.5 and below, 7.0.12 and below allows a remote authenticated attacker assigned to an Administrative Domain (ADOM) to access device summary of unauthorized ADOMs via crafted HTTP requests. | |
| Analizada | Media (6.1) | 0.39% | — | Yoginetwork Rabbitloader | 2/10/2024 | 17/6/2026 | The RabbitLoader – Website Speed Optimization for improving Core Web Vital metrics with Cache, Image Optimization, and more plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.21.0. This… | |
| Analizada | Media (6.9) | 0.66% | — | Definetlynotai Logicytics | 1/10/2024 | 17/6/2026 | Logicytics is designed to harvest and collect data for forensic analysis. Logicytics has a basic vuln affecting compromised devices from shell injections. This vulnerability is fixed in 2.3.2. | |
| Modificada | Media (5.8) | 0.22% | — | Nozominetworks CMCNozominetworks Guardian | 11/9/2024 | 17/6/2026 | An access control vulnerability was discovered in the Reports section due to a specific access restriction not being properly enforced for users with limited privileges. If a logged-in user with reporting privileges learns how to create a specific application request, they might be able to make limited changes to the… |