Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2671▼ 680 respecto a la semana anterior
Críticas / altas1271▼ 290 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)230▼ 272 respecto a la semana anterior
1273 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 2.1% | — | Fortinet Fortiwlm | 10/10/2023 | 17/6/2026 | A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specifically crafted http get request parameters. | |
| Modificada | Crítica (9.8) | 18% | 💥 Exploit | Fortinet Fortiwlm | 10/10/2023 | 17/6/2026 | A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specifically crafted http get request parameters. | |
| Modificada | Crítica (9.8) | 80% | 💥 Exploit | Fortinet Fortisiem | 10/10/2023 | 17/6/2026 | A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet allows attacker to execute unauthorized code or commands via crafted API requests. | |
| Modificada | Alta (8.8) | 2.1% | — | Fortinet Fortiwlm | 10/10/2023 | 17/6/2026 | A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specifically crafted HTTP get request parameters. | |
| Modificada | Alta (8.8) | 2.1% | — | Fortinet Fortiwlm | 10/10/2023 | 17/6/2026 | A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specifically crafted HTTP get request parameters. | |
| Modificada | Alta (8.8) | 2.1% | — | Fortinet Fortiwlm | 10/10/2023 | 17/6/2026 | A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specifically crafted HTTP get request parameters. | |
| Modificada | Alta (8.8) | 2.1% | — | Fortinet Fortiwlm | 10/10/2023 | 17/6/2026 | A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specifically crafted HTTP get request parameters. | |
| Modificada | Alta (8.8) | 2.1% | — | Fortinet Fortiwlm | 10/10/2023 | 17/6/2026 | A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specifically crafted HTTP get request parameters. | |
| Modificada | Media (4.3) | 0.37% | — | Fortinet Fortios | 10/10/2023 | 17/6/2026 | An improper access control vulnerability in Fortinet FortiOS 7.2.0 - 7.2.4 and 7.4.0 allows an attacker to access a restricted resource from a non trusted host. | |
| Modificada | Alta (7.8) | 1.5% | — | Fortinet FortiadcFortinet FortianalyzerFortinet Fortimanager | 10/10/2023 | 17/6/2026 | An improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78 ] in FortiManager 7.2.0 through 7.2.2, 7.0.0 through 7.0.7, 6.4.0 through 6.4.11, 6.2 all versions, 6.0 all versions, FortiAnalyzer 7.2.0 through 7.2.2, 7.0.0 through 7.0.7, 6.4.0 through 6.4.11, 6.2 all… | |
| Modificada | Media (5.5) | 0.16% | — | Fortinet Fortiguest | 10/10/2023 | 17/6/2026 | An insertion of sensitive information into log file vulnerability in Fortinet FortiGuest 1.0.0 allows a local attacker to access plaintext passwords in the RADIUS logs. | |
| Modificada | Alta (7.8) | 0.46% | — | Fortinet Fortiisolator | 10/10/2023 | 17/6/2026 | A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiIsolator version 1.0.0, FortiIsolator version 1.1.0, FortiIsolator version 1.2.0 through 1.2.2, FortiIsolator version 2.0.0 through 2.0.1, FortiIsolator version 2.1.0 through 2.1.2, FortiIsolator version… | |
| Modificada | Alta (7.8) | 0.21% | — | Fortinet Fortitester | 13/9/2023 | 17/6/2026 | A use of hard-coded credentials vulnerability [CWE-798] in FortiTester 2.3.0 through 7.2.3 may allow an attacker who managed to get a shell on the device to access the database via shell commands. | |
| Modificada | Media (5.5) | 0.17% | — | Fortinet Fortitester | 13/9/2023 | 17/6/2026 | A cleartext storage of sensitive information vulnerability [CWE-312] in FortiTester 2.3.0 through 7.2.3 may allow an attacker with access to the DB contents to retrieve the plaintext password of external servers configured in the device. | |
| Modificada | Alta (7.8) | 0.21% | — | Fortinet Fortitester | 13/9/2023 | 17/6/2026 | An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in the management interface of FortiTester 3.0.0 through 7.2.3 may allow an authenticated attacker to execute unauthorized commands via specifically crafted arguments to existing commands. | |
| Modificada | Media (4.3) | 0.41% | — | Fortinet FortianalyzerFortinet Fortimanager | 13/9/2023 | 17/6/2026 | An improper privilege management vulnerability [CWE-269] in FortiManager 7.2.0 through 7.2.2, 7.0.0 through 7.0.7, 6.4.0 through 6.4.11, 6.2 all versions, 6.0 all versions and FortiAnalyzer 7.2.0 through 7.2.2, 7.0.0 through 7.0.7, 6.4.0 through 6.4.11, 6.2 all versions, 6.0 all versions API may allow a remote and… | |
| Modificada | Alta (8.8) | 0.63% | — | Fortinet Fortiap-u | 13/9/2023 | 17/6/2026 | An incomplete filtering of one or more instances of special elements vulnerability [CWE-792] in the command line interpreter of FortiAP-U 7.0.0, 6.2.0 through 6.2.5, 6.0 all versions, 5.4 all versions may allow an authenticated attacker to list and delete arbitrary files and directory via specially crafted command… | |
| Modificada | Media (5.3) | 0.67% | — | Fortinet Fortisiem | 13/9/2023 | 17/6/2026 | A exposure of sensitive information to an unauthorized actor in Fortinet FortiSIEM version 6.7.0 through 6.7.5 allows attacker to information disclosure via a crafted http request. | |
| Modificada | Alta (8.8) | 0.73% | — | Fortinet Fortiweb | 13/9/2023 | 17/6/2026 | A protection mechanism failure in Fortinet FortiWeb 7.2.0 through 7.2.1, 7.0.0 through 7.0.6, 6.4.0 through 6.4.3, 6.3.6 through 6.3.23 allows attacker to execute unauthorized code or commands via specially crafted HTTP requests. | |
| Modificada | Media (5.4) | 1.3% | — | Fortinet FortiproxyFortinet Fortios | 13/9/2023 | 17/6/2026 | An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiProxy 7.2.0 through 7.2.4, 7.0.0 through 7.0.10 and FortiOS 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.12, 6.2.0 through 6.2.14 GUI may allow an authenticated attacker to trigger… | |
| Modificada | Media (5.3) | 0.48% | — | Fortinet Fortipresence | 13/9/2023 | 17/6/2026 | A lack of custom error pages vulnerability [CWE-756] in FortiPresence versions 1.2.0 through 1.2.1 and all versions of 1.1 and 1.0 may allow an unauthenticated attacker with the ability to navigate to the login GUI to gain sensitive information via navigating to specific HTTP(s) paths. | |
| Modificada | Media (6.5) | 0.60% | — | Fortinet FortiapFortinet Fortiap-cFortinet Fortiap-uFortinet Fortiap-w2 | 13/9/2023 | 17/6/2026 | An incomplete filtering of one or more instances of special elements vulnerability [CWE-792] in the command line interpreter of FortiAP-W2 7.2.0 through 7.2.1, 7.0.3 through 7.0.5, 7.0.0 through 7.0.1, 6.4 all versions, 6.2 all versions, 6.0 all versions; FortiAP-C 5.4.0 through 5.4.4, 5.2 all versions; FortiAP 7.2.0… | |
| Modificada | Alta (8.8) | 0.46% | — | Fortinet Fortiadc | 13/9/2023 | 17/6/2026 | An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in the management interface of FortiADC 7.1.0 through 7.1.1, 7.0.0 through 7.0.3, 6.2.0 through 6.2.5 and 6.1.0 all versions may allow an authenticated attacker to execute unauthorized commands via specifically crafted… | |
| Modificada | Media (5.3) | 0.85% | — | Fortinet Forticlient Endpoint Management Server | 13/9/2023 | 17/6/2026 | An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiClientEMS versions 7.0.0 through 7.0.4, 7.0.6 through 7.0.7, in all 6.4 and 6.2 version management interface may allow an unauthenticated attacker to gain information on environment variables such as the EMS installation path. | |
| Modificada | Media (4.3) | 0.50% | — | Fortinet Fortiswitchmanager | 7/9/2023 | 17/6/2026 | An improper access control in Fortinet FortiSwitchManager version 7.2.0 through 7.2.2 7.0.0 through 7.0.1 may allow a remote authenticated read-only user to modify the interface settings via the API. |