Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
1273 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.2) | 0.48% | — | Fortinet FortianalyzerFortinet FortimanagerFortinet FortisandboxFortinet Fortios | 1/9/2023 | 17/6/2026 | Una vulnerabilidad de validación de certificado incorrecta [CWE-295] en FortiManager v7.0.1 y versiones inferiores, v6.4.6 y versiones inferiores; FortiAnalyzer v7.0.2 y versiones inferiores, v6.4.7 y versiones inferiores; FortiOS v6.2.x y v6.0.x; FortiSandbox v4.0.x, 3.2.x y 3.1.x puede permitir a un atacante… | |
| Modificada | Crítica (9.8) | 0.95% | — | Metaways Tine | 1/9/2023 | 17/6/2026 | En tine hasta 2023.01.14.325, el parámetro sort del endpoint "/index.php" permite inyección SQL. | |
| Modificada | Media (6.7) | 0.29% | — | Fortinet Fortios | 17/8/2023 | 17/6/2026 | A stack-based buffer overflow vulnerability [CWE-121] in Fortinet FortiOS before 7.0.3 allows a privileged attacker to execute arbitrary code via specially crafted CLI commands, provided the attacker were able to evade FortiOS stack protections. | |
| Modificada | Crítica (9.8) | 2.1% | — | Fortinet FortiproxyFortinet Fortios | 26/7/2023 | 17/6/2026 | A stack-based overflow vulnerability [CWE-124] in Fortinet FortiOS version 7.0.0 through 7.0.10 and 7.2.0 through 7.2.3 and FortiProxy version 7.0.0 through 7.0.9 and 7.2.0 through 7.2.2 allows a remote unauthenticated attacker to execute arbitrary code or command via crafted packets reaching proxy policies or… | |
| Modificada | Media (6.7) | 0.18% | — | Fortinet FortianalyzerFortinet FortimanagerFortinet FortiproxyFortinet Fortios | 18/7/2023 | 17/6/2026 | A buffer copy without checking size of input ('classic buffer overflow') in Fortinet FortiAnalyzer version 7.0.2 and below, version 6.4.7 and below, version 6.2.9 and below, version 6.0.11 and below, version 5.6.11 and below, FortiManager version 7.0.2 and below, version 6.4.7 and below, version 6.2.9 and below,… | |
| Modificada | Crítica (9.8) | 0.51% | — | Fortinet Fortios | 11/7/2023 | 17/6/2026 | An insufficient session expiration in Fortinet FortiOS 7.0.0 - 7.0.12 and 7.2.0 - 7.2.4 allows an attacker to execute unauthorized code or commands via reusing the session of a deleted user in the REST API. | |
| Modificada | Media (6.5) | 0.55% | — | Fortinet FortianalyzerFortinet Fortimanager | 11/7/2023 | 17/6/2026 | An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-23] in FortiAnalyzer and FortiManager management interface 7.2.0 through 7.2.1, 7.0.0 through 7.0.5, 6.4 all versions may allow a remote and authenticated attacker to retrieve arbitrary files from the underlying… | |
| Modificada | Alta (7.5) | 0.80% | — | Fortinet Fortiextender Firmware | 11/7/2023 | 17/6/2026 | An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in FortiExtender management interface 7.0.0 through 7.0.3, 4.2.0 through 4.2.4, 4.1.1 through 4.1.8, 4.0.0 through 4.0.2, 3.3.0 through 3.3.2, 3.2.1 through 3.2.3, 5.3 all versions may allow an unauthenticated and… | |
| Modificada | Alta (7.2) | 1.3% | — | Fortinet Fortiweb | 11/7/2023 | 17/6/2026 | An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in FortiWeb version 7.0.1 and below, 6.4 all versions, version 6.3.18 and below may allow a privileged attacker to execute arbitrary bash commands via crafted cli backup parameters. | |
| Modificada | Baja (3.3) | 0.29% | — | Fortinet FortiauthenticatorFortinet Fortios | 11/7/2023 | 17/6/2026 | A clear text storage of sensitive information (CWE-312) vulnerability in both FortiGate version 6.4.0 through 6.4.1, 6.2.0 through 6.2.9 and 6.0.0 through 6.0.13 and FortiAuthenticator version 5.5.0 and all versions of 6.1 and 6.0 may allow a local unauthorized party to retrieve the Fortinet private keys used to… | |
| Modificada | Crítica (9.8) | 24% | — | Fortinet Fortinac | 23/6/2023 | 17/6/2026 | A deserialization of untrusted data in Fortinet FortiNAC below 7.2.1, below 9.4.3, below 9.2.8 and all earlier versions of 8.x allows attacker to execute unauthorized code or commands via specifically crafted request on inter-server communication port. Note FortiNAC versions 8.x will not be fixed. | |
| Modificada | Media (6.5) | 0.59% | — | Fortinet FortiproxyFortinet Fortios | 16/6/2023 | 17/6/2026 | A null pointer dereference in Fortinet FortiOS before 7.2.5 and before 7.0.11, FortiProxy before 7.2.3 and before 7.0.9 allows attacker to denial of sslvpn service via specifically crafted request in network parameter. | |
| Modificada | Media (6.5) | 0.84% | — | Fortinet FortiproxyFortinet Fortios | 16/6/2023 | 17/6/2026 | A null pointer dereference in Fortinet FortiOS before 7.2.5, before 7.0.11 and before 6.4.13, FortiProxy before 7.2.4 and before 7.0.10 allows attacker to denial of sslvpn service via specifically crafted request in bookmark parameter. | |
| Modificada | Media (6.5) | 0.83% | — | Fortinet FortiproxyFortinet FortiwebFortinet Fortios | 13/6/2023 | 17/6/2026 | A loop with unreachable exit condition ('infinite loop') in Fortinet FortiOS version 7.2.0 through 7.2.4, FortiOS version 7.0.0 through 7.0.10, FortiOS 6.4 all versions, FortiOS 6.2 all versions, FortiOS 6.0 all versions, FortiProxy version 7.2.0 through 7.2.3, FortiProxy version 7.0.0 through 7.0.9, FortiProxy 2.0… | |
| Modificada | Media (4.3) | 0.88% | — | Fortinet FortiproxyFortinet Fortios | 13/6/2023 | 17/6/2026 | A access of uninitialized pointer vulnerability [CWE-824] in Fortinet FortiProxy version 7.2.0 through 7.2.3 and before 7.0.9 and FortiOS version 7.2.0 through 7.2.4 and before 7.0.11 allows an authenticated attacker to repetitively crash the httpsd process via crafted HTTP or HTTPS requests. | |
| Modificada | Media (4.8) | 0.19% | — | Fortinet FortiproxyFortinet Fortios | 13/6/2023 | 17/6/2026 | An improper certificate validation vulnerability [CWE-295] in FortiOS 6.2 all versions, 6.4 all versions, 7.0.0 through 7.0.10, 7.2.0 and FortiProxy 1.2 all versions, 2.0 all versions, 7.0.0 through 7.0.9, 7.2.0 through 7.2.3 may allow a remote and unauthenticated attacker to perform a Man-in-the-Middle attack on the… | |
| Modificada | Alta (7.8) | 0.21% | — | Fortinet Fortiadc | 13/6/2023 | 17/6/2026 | An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in FortiADC CLI 7.1.0, 7.0.0 through 7.0.3, 6.2.0 through 6.2.4, 6.1 all versions, 6.0 all versions may allow a local and authenticated attacker to execute unauthorized commands via specifically crafted arguments in diagnose… | |
| Analizada | Crítica (9.8) | 86% | ⚠ Explotación activa💥 PoC | Fortinet FortiproxyFortinet Fortios | 13/6/2023 | 31/7/2026 | A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, version 6.4.12 and below, version 6.0.16 and below and FortiProxy version 7.2.3 and below, version 7.0.9 and below, version 2.0.12 and below, version 1.2 all versions, version 1.1 all versions SSL-VPN may… | |
| Modificada | Alta (7.8) | 0.50% | — | Fortinet FortiadcFortinet Fortiadc Manager | 13/6/2023 | 17/6/2026 | Multiple improper neutralization of special elements used in an os command ('OS Command Injection') vulnerabilties [CWE-78] vulnerability in Fortinet allows a local authenticated attacker to execute arbitrary shell code as `root` user via crafted CLI requests. | |
| Modificada | Media (6.5) | 0.50% | — | Fortinet FortiproxyFortinet Fortios | 13/6/2023 | 17/6/2026 | An insertion of sensitive information into log file vulnerability in Fortinet FortiOS 7.2.0 through 7.2.4 and FortiProxy 7.0.0 through 7.0.10. 7.2.0 through 7.2.1 allows an attacker to read certain passwords in plain text. | |
| Modificada | Crítica (9.8) | 0.43% | — | Fortinet Fortisiem | 13/6/2023 | 17/6/2026 | A plaintext storage of a password vulnerability [CWE-256] in FortiSIEM 6.7 all versions, 6.6 all versions, 6.5 all versions, 6.4 all versions, 6.3 all versions, 6.2 all versions, 6.1 all versions, 5.4 all versions, 5.3 all versions may allow an attacker able to access user DB content to impersonate any admin user on… | |
| Modificada | Media (6.5) | 0.38% | — | Fortinet FortianalyzerFortinet Fortimanager | 13/6/2023 | 17/6/2026 | A server-side request forgery (SSRF) vulnerability [CWE-918] in FortiManager and FortiAnalyzer GUI 7.2.0 through 7.2.1, 7.0.0 through 7.0.6, 6.4.8 through 6.4.11 may allow a remote and authenticated attacker to access unauthorized files and services on the system via specially crafted web requests. | |
| Modificada | Alta (7.8) | 0.19% | — | Fortinet FortiproxyFortinet Fortios | 13/6/2023 | 17/6/2026 | A out-of-bounds write in Fortinet FortiOS version 7.2.0 through 7.2.3, FortiOS version 7.0.0 through 7.0.10, FortiOS version 6.4.0 through 6.4.12, FortiOS all versions 6.2, FortiOS all versions 6.0, FortiProxy version 7.2.0 through 7.2.2, FortiProxy version 7.0.0 through 7.0.8, FortiProxy all versions 2.0, FortiProxy… | |
| Modificada | Alta (7.5) | 0.65% | — | Fortinet FortinacFortinet Fortinac-f | 13/6/2023 | 17/6/2026 | An improper permissions, privileges, and access controls vulnerability [CWE-264] in FortiNAC-F 7.2.0, FortiNAC 9.4.1 and below, 9.2.6 and below, 9.1.8 and below, 8.8.0 all versions 8.7.0 all versions may allow an unauthenticated attacker to perform a DoS attack on the device via client-secure renegotiation. | |
| Modificada | Alta (7.8) | 0.25% | — | Fortinet FortiproxyFortinet Fortios | 13/6/2023 | 17/6/2026 | A use of externally-controlled format string in Fortinet FortiOS version 7.2.0 through 7.2.4, FortiOS all versions 7.0, FortiOS all versions 6.4, FortiOS all versions 6.2, FortiProxy version 7.2.0 through 7.2.1, FortiProxy version 7.0.0 through 7.0.7 allows attacker to execute unauthorized code or commands via… |