Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2823▼ 249 respecto a la semana anterior
Críticas / altas1318▼ 180 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
1579 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.1) | 1.3% | — | Rockwellautomation Kinetix 5500 Firmware | 11/5/2023 | 17/6/2026 | Rockwell Automation was made aware that Kinetix 5500 drives, manufactured between May 2022 and January 2023, and are running v7.13 may have the telnet and FTP ports open by default. This could potentially allow attackers unauthorized access to the device through the open ports. | |
| Modificada | Crítica (9.8) | 14% | — | Gl-inet Gl-s20 FirmwareGl-inet Gl-x3000 FirmwareGl-inet Gl-mt3000 FirmwareGl-inet Gl-mt2500 Firmware+28 | 11/5/2023 | 17/6/2026 | An issue was discovered on GL.iNet devices before 3.216. The function guci2_get() found in libglutil.so has a buffer overflow when an item is requested from a UCI context, and the value is pasted into a char pointer to a buffer without checking the size of the buffer. | |
| Modificada | Media (4.9) | 3.9% | — | Gl-inet Gl-s20 FirmwareGl-inet Gl-x3000 FirmwareGl-inet Gl-mt3000 FirmwareGl-inet Gl-mt2500 Firmware+28 | 11/5/2023 | 17/6/2026 | An issue was discovered on GL.iNet devices before 3.216. There is an arbitrary file write in which an empty file can be created anywhere on the filesystem. This is caused by a command injection vulnerability with a filter applied. Through the software installation feature, it is possible to inject arbitrary parameters… | |
| Modificada | Alta (7.5) | 0.94% | — | Gl-inet Gl-s20 FirmwareGl-inet Gl-x3000 FirmwareGl-inet Gl-mt3000 FirmwareGl-inet Gl-mt2500 Firmware+28 | 11/5/2023 | 17/6/2026 | A path traversal issue was discovered on GL.iNet devices before 3.216. Through the file sharing feature, it is possible to share an arbitrary directory, such as /tmp or /etc, because there is no server-side restriction to limit sharing to the USB path. | |
| Modificada | Crítica (9.8) | 1.1% | — | Gl-inet Gl-s20 FirmwareGl-inet Gl-x3000 FirmwareGl-inet Gl-mt3000 FirmwareGl-inet Gl-mt2500 Firmware+28 | 10/5/2023 | 17/6/2026 | An issue was discovered on GL.iNet devices before 3.216. Through the software installation feature, it is possible to install arbitrary software, such as a reverse shell, because the restrictions on the available package list are limited to client-side verification. It is possible to install software from the… | |
| Modificada | Alta (7.5) | 30% | 💥 Exploit | Gl-inet Gl-s20 FirmwareGl-inet Gl-x3000 FirmwareGl-inet Gl-mt3000 FirmwareGl-inet Gl-mt2500 Firmware+28 | 9/5/2023 | 17/6/2026 | An issue was discovered on GL.iNet devices before 3.216. An API endpoint reveals information about the Wi-Fi configuration, including the SSID and key. | |
| Modificada | Alta (7.5) | 0.82% | — | Gl-inet Gl-s20 FirmwareGl-inet Gl-x3000 FirmwareGl-inet Gl-mt3000 FirmwareGl-inet Gl-mt2500 Firmware+28 | 9/5/2023 | 17/6/2026 | An issue was discovered on GL.iNet devices before 3.216. Through the software installation feature, it is possible to inject arbitrary parameters in a request to cause opkg to obtain a list of files in a specific directory, by using the regex feature in a package name. | |
| Modificada | Alta (7.5) | 20% | — | Gl-inet Gl-s20 FirmwareGl-inet Gl-x3000 FirmwareGl-inet Gl-mt3000 FirmwareGl-inet Gl-mt2500 Firmware+28 | 9/5/2023 | 17/6/2026 | An issue was discovered on GL.iNet devices before 3.216. There is an arbitrary file write in which an empty file can be created anywhere on the filesystem. This is caused by a command injection vulnerability with a filter applied. | |
| Modificada | Alta (7.5) | 0.80% | — | Gl-inet Gl-mv1000w FirmwareGl-inet Gl-mv1000 Firmware | 9/5/2023 | 17/6/2026 | An issue was discovered on GL.iNet devices running firmware before 3.216. There is an arbitrary file write in which an empty file can be created almost anywhere on the filesystem, as long as the filename and path is no more than 6 characters (the working directory is /www). | |
| Modificada | Alta (8.7) | 0.60% | — | Nozominetworks CMCNozominetworks Guardian | 4/5/2023 | 17/6/2026 | Due to improper input validation in the Alerts controller, a SQL injection vulnerability in Nozomi Networks Guardian and CMC allows an authenticated attacker to execute arbitrary SQL queries on the DBMS used by the web application. | |
| Modificada | Alta (7.8) | 0.50% | — | Fortinet Fortiadc | 3/5/2023 | 17/6/2026 | An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in FortiADC 7.2.0, 7.1.0 through 7.1.1 may allow an authenticated attacker to execute unauthorized commands via specifically crafted arguments to existing commands. | |
| Modificada | Alta (7.1) | 0.23% | — | Fortinet Fortiadc | 3/5/2023 | 17/6/2026 | A relative path traversal [CWE-23] in Fortinet FortiADC version 7.2.0 and before 7.1.1 allows a privileged attacker to delete arbitrary directories from the underlying file system via crafted CLI commands. | |
| Modificada | Alta (7.8) | 0.16% | — | Fortinet FortinacFortinet Fortinac-f | 3/5/2023 | 17/6/2026 | A use of hard-coded credentials vulnerability [CWE-798] in FortiNAC-F version 7.2.0, FortiNAC version 9.4.2 and below, 9.2 all versions, 9.1 all versions, 8.8 all versions, 8.7 all versions may allow an authenticated attacker to access to the database via shell commands. | |
| Modificada | Alta (8.8) | 0.89% | — | Fortinet FortiproxyFortinet Fortios | 3/5/2023 | 17/6/2026 | A out-of-bounds write in Fortinet FortiOS version 7.2.0 through 7.2.3, FortiOS version 7.0.0 through 7.0.10, FortiOS version 6.4.0 through 6.4.11, FortiOS version 6.2.0 through 6.2.13, FortiOS all versions 6.0, FortiProxy version 7.2.0 through 7.2.1, FortiProxy version 7.0.0 through 7.0.7, FortiProxy all versions 2.0,… | |
| Modificada | Crítica (9) | 0.61% | — | Fortinet FortinacFortinet Fortinac-f | 3/5/2023 | 17/6/2026 | An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiNAC-F version 7.2.0, FortiNAC version 9.4.2 and below, 9.2 all versions, 9.1 all versions, 8.8 all versions, 8.7 all versions in License Management would permit an authenticated attacker to trigger… | |
| Modificada | Alta (7.5) | 0.49% | — | Fortinet FortinacFortinet Fortinac-f | 3/5/2023 | 17/6/2026 | A weak authentication vulnerability [CWE-1390] in FortiNAC-F version 7.2.0, FortiNAC version 9.4.2 and below, 9.2 all versions, 9.1 all versions, 8.8 all versions, 8.7 all versions in device registration page may allow an unauthenticated attacker to perform password spraying attacks with an increased chance of success. | |
| Modificada | Media (4.4) | 0.14% | — | Fortinet FortinacFortinet Fortinac-f | 3/5/2023 | 17/6/2026 | An insufficiently protected credentials vulnerability [CWE-522] in FortiNAC-F 7.2.0, FortiNAC 9.4.1 and below, 9.2.6 and below, 9.1.8 and below, 8.8.0 all versions, 8.7.0 all versions may allow a local attacker with system access to retrieve users' passwords. | |
| Modificada | Alta (7.4) | 0.20% | — | Fortinet Fortinac | 3/5/2023 | 17/6/2026 | A use of a weak cryptographic algorithm vulnerability [CWE-327] in FortiNAC 9.4.1 and below, 9.2.6 and below, 9.1.0 all versions, 8.8.0 all versions, 8.7.0 all versions may increase the chances of an attacker to have access to sensitive information or to perform man-in-the-middle attacks. | |
| Modificada | Media (4.7) | 0.42% | — | Fortinet FortinacFortinet Fortinac-f | 3/5/2023 | 17/6/2026 | A URL redirection to untrusted site ('Open Redirect') vulnerability [CWE-601] in FortiNAC-F version 7.2.0, FortiNAC version 9.4.1 and below, 9.2 all versions, 9.1 all versions, 8.8 all versions, 8.7 all versions may allow an unauthenticated attacker to redirect users to any arbitrary website via a crafted URL. | |
| Modificada | Crítica (9.8) | 16% | — | Gl-inet Gl-mt3000 Firmware | 2/5/2023 | 9/7/2026 | GL.iNET MT3000 4.1.0 Release 2 is vulnerable to OS Command Injection via /usr/lib/oui-httpd/rpc/logread. | |
| Modificada | Alta (8.8) | 1.1% | — | Fortinet Fortisoar | 11/4/2023 | 17/6/2026 | A improper neutralization of special elements used in a template engine vulnerability in Fortinet FortiSOAR 7.3.0 through 7.3.1 allows an authenticated, remote attacker to execute arbitrary code via a crafted payload. | |
| Modificada | Alta (8.1) | 0.27% | — | Fortinet FortianalyzerFortinet Fortimanager | 11/4/2023 | 17/6/2026 | An improper certificate validation vulnerability [CWE-295] in FortiAnalyzer and FortiManager 7.2.0 through 7.2.1, 7.0.0 through 7.0.5, 6.4.8 through 6.4.10 may allow a remote and unauthenticated attacker to perform a Man-in-the-Middle attack on the communication channel between the device and the remote FortiGuard… | |
| Modificada | Media (5.4) | 0.30% | — | Fortinet FortiproxyFortinet Fortios | 11/4/2023 | 17/6/2026 | A url redirection to untrusted site ('open redirect') in Fortinet FortiOS version 7.2.0 through 7.2.3, FortiOS version 7.0.0 through 7.0.9, FortiOS versions 6.4.0 through 6.4.12, FortiOS all versions 6.2, FortiOS all versions 6.0, FortiProxy version 7.2.0 through 7.2.2, FortiProxy version 7.0.0 through 7.0.8,… | |
| Modificada | Alta (7.8) | 0.12% | — | Fortinet Forticlient | 11/4/2023 | 17/6/2026 | A download of code without Integrity check vulnerability [CWE-494] in FortiClientMac version 7.0.0 through 7.0.7, 6.4 all versions, 6.2 all versions, 6.0 all versions, 5.6 all versions, 5.4 all versions, 5.2 all versions, 5.0 all versions and 4.0 all versions may allow a local attacker to escalate their privileges via… | |
| Modificada | Media (6.1) | 0.64% | — | Fortinet Fortiweb | 11/4/2023 | 17/6/2026 | An improper neutralization of input during web page generation [CWE-79] in the FortiWeb web interface 7.0.0 through 7.0.3, 6.3.0 through 6.3.21, 6.4 all versions, 6.2 all versions, 6.1 all versions and 6.0 all versions may allow an unauthenticated and remote attacker to perform a reflected cross site scripting attack… |