Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
196 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.1) | 0.29% | — | Microfocus Imanager | 22/11/2024 | 17/6/2026 | Possible XSS in iManager URL for access Component has been discovered in OpenText™ iManager 3.2.5.0000. | |
| Analizada | Media (6.1) | 0.31% | — | Microfocus Imanager | 22/11/2024 | 17/6/2026 | Possible Reflected Cross-Site Scripting (XSS) Vulnerability in iManager has been discovered in OpenText™ iManager 3.2.4.0000. | |
| Analizada | Alta (7.8) | 0.21% | — | Microfocus Imanager | 22/11/2024 | 17/6/2026 | Possible improper input validation Vulnerability in iManager has been discovered in OpenText™ iManager 3.2.4.0000. | |
| Analizada | Crítica (9.8) | 1.1% | — | Microfocus Imanager | 22/11/2024 | 17/6/2026 | Possible Command injection Vulnerability in iManager has been discovered in OpenText™ iManager 3.2.4.0000. | |
| Analizada | Alta (8.8) | 0.62% | — | Microfocus Imanager | 22/11/2024 | 17/6/2026 | Possible Elevation of Privilege Vulnerability in iManager has been discovered in OpenText™ iManager. This impacts all versions before 3.2.5 | |
| Analizada | Crítica (9.8) | 1.3% | — | Icdsoft Multimanager WP | 13/11/2024 | 17/6/2026 | The MultiManager WP – Manage All Your WordPress Sites Easily plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.0.5. This is due to the user impersonation feature inappropriately determining the current user via user-supplied input. This makes it possible for… | |
| Analizada | Baja (2.3) | 0.24% | — | Fortinet FortianalyzerFortinet Fortianalyzer BIG DataFortinet Fortimanager | 12/11/2024 | 17/6/2026 | An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in Fortinet FortiAnalyzer versions below 7.4.2, Fortinet FortiManager versions below 7.4.2 and Fortinet FortiAnalyzer-BigData version 7.4.0 and below 7.2.7 allows a privileged attacker with read write… | |
| Analizada | Alta (7.3) | 0.48% | — | Fortinet FortianalyzerFortinet FortimanagerFortinet Fortimanager Cloud | 12/11/2024 | 17/6/2026 | A heap-based buffer overflow in Fortinet FortiAnalyzer version 7.4.0 through 7.4.2, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14, FortiManager version 7.4.0 through 7.4.2, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14 allows attacker to escalation of privilege via specially crafted… | |
| Analizada | Media (6.7) | 0.61% | — | Fortinet FortianalyzerFortinet Fortianalyzer BIG DataFortinet Fortimanager | 12/11/2024 | 17/6/2026 | Multiple improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] in Fortinet FortiManager version 7.4.0 through 7.4.2 and before 7.2.5, Fortinet FortiAnalyzer version 7.4.0 through 7.4.2 and before 7.2.5 and Fortinet FortiAnalyzer-BigData before 7.4.0 allows… | |
| Analizada | Media (4.9) | 0.85% | — | Fortinet FortianalyzerFortinet Fortianalyzer BIG DataFortinet Fortimanager | 12/11/2024 | 17/6/2026 | An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in Fortinet FortiManager version 7.4.0 through 7.4.2 and below 7.2.5, FortiAnalyzer version 7.4.0 through 7.4.2 and below 7.2.5 & FortiAnalyzer-BigData version 7.4.0 and below 7.2.7 allows a privileged attacker to… | |
| Analizada | Media (6) | 0.24% | — | Fortinet FortianalyzerFortinet Fortianalyzer BIG DataFortinet Fortimanager | 12/11/2024 | 17/6/2026 | Multiple relative path traversal vulnerabilities [CWE-23] in Fortinet FortiManager version 7.4.0 through 7.4.2 and before 7.2.5, FortiAnalyzer version 7.4.0 through 7.4.2 and before 7.2.5 and FortiAnalyzer-BigData version 7.4.0 and before 7.2.7 allows a privileged attacker to delete files from the underlying… | |
| Analizada | Media (6.7) | 0.23% | — | Fortinet FortianalyzerFortinet Fortianalyzer BIG DataFortinet Fortimanager | 12/11/2024 | 17/6/2026 | A stack-based buffer overflow vulnerability [CWE-121] in Fortinet FortiManager version 7.4.0 through 7.4.2 and before 7.2.5, FortiAnalyzer version 7.4.0 through 7.4.2 and before 7.2.5 and FortiAnalyzer-BigData 7.4.0 and before 7.2.7 allows a privileged attacker to execute unauthorized code or commands via crafted CLI… | |
| Analizada | Crítica (9.8) | 0.60% | — | Fortinet FortiosFortinet FortipamFortinet FortiproxyFortinet Fortimanager+2 | 12/11/2024 | 17/6/2026 | A missing authentication for critical function in Fortinet FortiManager version 7.4.0 through 7.4.2, 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.14, FortiPAM version 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiProxy version 7.4.0 through 7.4.2, 7.2.0 through 7.2.9, 7.0.0 through 7.0.17,… | |
| Analizada | Alta (8.8) | 2.7% | 💥 PoC | Fortinet FortianalyzerFortinet Fortianalyzer BIG DataFortinet Fortimanager | 12/11/2024 | 17/6/2026 | A client-side enforcement of server-side security in Fortinet FortiAnalyzer-BigData at least version 7.4.0 and 7.2.0 through 7.2.6 and 7.0.1 through 7.0.6 and 6.4.5 through 6.4.7 and 6.2.5, FortiManager version 7.4.0 through 7.4.1 and 7.2.0 through 7.2.4 and 7.0.0 through 7.0.11 and 6.4.0 through 6.4.14, FortiAnalyzer… | |
| Analizada | Media (4.1) | 0.55% | — | Fortinet FortianalyzerFortinet Fortianalyzer BIG DataFortinet Fortimanager | 12/11/2024 | 17/6/2026 | An exposure of sensitive information to an unauthorized actor [CWE-200] in Fortinet FortiManager before 7.4.2, FortiAnalyzer before 7.4.2 and FortiAnalyzer-BigData before 7.2.5 may allow a privileged attacker with administrative read permissions to read event logs of another adom via crafted HTTP or HTTPs requests. | |
| Analizada | Media (5.4) | 0.33% | — | Microfocus Imanager | 6/11/2024 | 17/6/2026 | Improper Input Validation vulnerability in OpenText iManager allows Cross-Site Scripting (XSS). This issue affects iManager before 3.2.3 | |
| Analizada | Crítica (9.8) | 95% | ⚠ Explotación activa💥 Exploit | Fortinet FortimanagerFortinet Fortimanager Cloud | 23/10/2024 | 17/6/2026 | A missing authentication for critical function in FortiManager 7.6.0, FortiManager 7.4.0 through 7.4.4, FortiManager 7.2.0 through 7.2.7, FortiManager 7.0.0 through 7.0.12, FortiManager 6.4.0 through 6.4.14, FortiManager 6.2.0 through 6.2.12, Fortinet FortiManager Cloud 7.4.1 through 7.4.4, FortiManager Cloud 7.2.1… | |
| Analizada | Media (4.3) | 0.45% | — | Fortinet Fortimanager | 8/10/2024 | 17/6/2026 | An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiManager 7.4.2 and below, 7.2.5 and below, 7.0.12 and below allows a remote authenticated attacker assigned to an Administrative Domain (ADOM) to access device summary of unauthorized ADOMs via crafted HTTP requests. | |
| Analizada | Media (6.5) | 0.53% | — | Fortinet FortianalyzerFortinet FortimanagerFortinet Fortianalyzer BIG Data | 10/9/2024 | 17/6/2026 | An authorization bypass through user-controlled key [CWE-639] vulnerability in FortiAnalyzer version 7.4.1 and before 7.2.5 and FortiManager version 7.4.1 and before 7.2.5 may allow a remote attacker with low privileges to read sensitive data via a crafted HTTP request. | |
| Analizada | Alta (7.8) | 0.19% | — | Fortinet FortianalyzerFortinet Fortimanager | 13/8/2024 | 17/6/2026 | A unverified password change in Fortinet FortiManager versions 7.0.0 through 7.0.10, versions 7.2.0 through 7.2.4, and versions 7.4.0 through 7.4.1, as well as Fortinet FortiAnalyzer versions 7.0.0 through 7.0.10, versions 7.2.0 through 7.2.4, and versions 7.4.0 through 7.4.1, allows an attacker to modify admin… | |
| Analizada | Alta (7.4) | 0.18% | — | Microfocus Imanager | 28/5/2024 | 17/6/2026 | Cross-Site Request Forgery vulnerability has been discovered in OpenText™ iManager 3.2.6.0200. This could lead to sensitive information disclosure. | |
| Analizada | Crítica (9.8) | 0.50% | — | Microfocus Imanager | 28/5/2024 | 17/6/2026 | XML External Entity injection vulnerability found in OpenText™ iManager 3.2.6.0200. This could lead to remote code execution by parsing untrusted XML payload | |
| Analizada | Alta (7.5) | 0.51% | — | Microfocus Imanager | 15/5/2024 | 17/6/2026 | Server Side Request Forgery vulnerability has been discovered in OpenText™ iManager 3.2.6.0200. This could lead to senstive information disclosure by directory traversal. | |
| Analizada | Crítica (9.8) | 0.68% | — | Microfocus Imanager | 15/5/2024 | 17/6/2026 | Remote Code Execution has been discovered in OpenText™ iManager 3.2.6.0200. The vulnerability can trigger remote code execution using custom file upload task. | |
| Analizada | Crítica (9.8) | 0.64% | — | Microfocus Imanager | 15/5/2024 | 17/6/2026 | Remote Code Execution has been discovered in OpenText™ iManager 3.2.6.0200. The vulnerability can trigger remote code execution unisng unsafe java object deserialization. |