Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
1579 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.53% | — | Fortinet Fortiauthenticator | 14/7/2026 | 29/9/2026 | A out-of-bounds read vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.2, FortiAuthenticator 6.5 all versions may allow a remote unauthenticated attacker to retrieve sensitive information via a specially crafted request. | |
| Modificada | Media (4.3) | 0.38% | — | Fortinet FortiproxyFortinet Fortios | 14/7/2026 | 29/9/2026 | A buffer over-read vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions may allow an authenticated remote attacker to return a portion of device memory in the redirect response via submitting a specially crafted… | |
| Modificada | Alta (7.2) | 0.40% | — | Nozominetworks CMCNozominetworks Guardian | 9/7/2026 | 11/8/2026 | An Incorrect Privilege Assignment vulnerability was discovered in the synchronization functionality due to Arc sensors receiving CLI permissions. An authenticated user with limited privileges can push administrative CLI commands through the sync, altering the device configuration, and/or affecting its availability. | |
| Modificada | Alta (8.7) | 0.51% | — | Nozominetworks CMCNozominetworks Guardian | 9/7/2026 | 11/8/2026 | A denial-of-service vulnerability caused by unbounded resource allocation was discovered in the audit logging functionality, due to a missing size limit on input recorded into audit entries. An unauthenticated attacker can submit requests containing excessively large input that is recorded into audit entries, possibly… | |
| Modificada | Media (6.9) | 0.44% | — | Nozominetworks CMCNozominetworks Guardian | 9/7/2026 | 11/8/2026 | A Missing Authentication vulnerability was discovered in the SSH keys synchronization endpoint. An unauthenticated attacker can send a request to the SSH keys synchronization endpoint and obtain the list of users that have uploaded their public SSH keys, their groups, and the uploaded public SSH keys. | |
| Modificada | Media (5.3) | 0.31% | — | Nozominetworks CMCNozominetworks Guardian | 9/7/2026 | 11/8/2026 | An Open Redirect vulnerability was discovered in the SAML Single Sign-On functionality due to insufficient validation of a user-controlled redirection parameter. An unauthenticated attacker can craft a request to the SAML sign-in endpoint and poison the cached SAML redirection for other users who subsequently initiate… | |
| Modificada | Media (4.8) | 0.25% | — | Nozominetworks CMCNozominetworks Guardian | 9/7/2026 | 11/8/2026 | A Stored HTML Injection vulnerability was discovered in the Diagram tab and Graph view due to a shared input validation function being insufficiently restrictive. An authenticated user with administrative privileges can inject malicious HTML tags into N2OS configuration data through multiple input vectors. When a… | |
| Aplazada | Alta (8.5) | 0.36% | — | Inet WebkitAI | 2/7/2026 | 2/7/2026 | Contributor SQL Injection in iNET Webkit 1.2.4 versions. | |
| Aplazada | Alta (8.1) | 0.43% | — | MaxinetAI | 17/6/2026 | 6/10/2026 | Unauthenticated Local File Inclusion in MaxiNet <= 1.2.10 versions. | |
| Aplazada | Alta (7.4) | 1.9% | — | Gl-inet Gl-mt3000AI | 14/6/2026 | 24/7/2026 | A security vulnerability has been detected in GL.iNet GL-MT3000 up to 4.4.5. Affected by this vulnerability is an unknown functionality of the file /usr/bin/one_click_upgrade of the component Online Firmware Upgrade Handler. Such manipulation leads to command injection. The attack can be launched remotely. The exploit… | |
| Aplazada | Alta (7.4) | 2.0% | — | Gl-inet Gl-mt3000AI | 14/6/2026 | 24/7/2026 | A weakness has been identified in GL.iNet GL-MT3000 up to 4.4.5. Affected is the function replace_country in the library /usr/lib/oui-httpd/rpc/tor of the component Tor Proxy Service Configuration Handler. This manipulation causes command injection. The attack can be initiated remotely. The exploit has been made… | |
| Modificada | Media (6.3) | 0.23% | — | Erlang/inetsErlang/otpErlang FTP | 10/6/2026 | 24/7/2026 | Server-Side Request Forgery (SSRF) vulnerability in Erlang/OTP ftp (ftp_internal module) allows FTP bounce attacks and SSRF via an unvalidated PASV response IP address. The ftp_internal:handle_ctrl_result/2 PASV handler (mode=passive, ipfamily=inet, ftp_extension=false) extracts the IP address from the server's 227… | |
| Modificada | Alta (7.1) | 0.34% | — | Erlang/inetsErlang/otp | 10/6/2026 | 24/9/2026 | Sensitive Data Exposure vulnerability in Erlang OTP inets (httpc_response module) allows Retrieve Embedded Sensitive Data. The httpc client forwards the Authorization and Proxy-Authorization request headers to redirect targets without checking whether the redirect crosses an origin boundary. httpc_response:redirect/2… | |
| Analizada | Media (6.5) | 0.34% | — | Fortinet Fortiportal | 9/6/2026 | 23/7/2026 | A improper access control vulnerability in Fortinet FortiPortal 7.4.0 through 7.4.7, FortiPortal 7.2.0 through 7.2.8, FortiPortal 7.0 all versions may allow attacker to improper access control via <insert attack vector here> | |
| Analizada | Crítica (9.8) | 76% | ⚠ Explotación activa | Fortinet FortisandboxFortinet Fortisandbox CloudFortinet Fortisandbox Paas | 9/6/2026 | 23/7/2026 | A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow an… | |
| Modificada | Media (6.7) | 0.15% | — | Fortinet FortiosFortinet Fortiproxy | 9/6/2026 | 23/7/2026 | An Internal Asset Exposed to Unsafe Debug Access Level or State vulnerability [CWE-1244] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.2, FortiOS 7.4.0 through 7.4.7, FortiOS 7.2.0 through 7.2.10, FortiOS 7.0.0 through 7.0.16, FortiOS 6.4 all versions, FortiProxy 7.6.0 through 7.6.3, FortiProxy 7.4.0 through… | |
| Aplazada | Baja (2.3) | 0.20% | — | Gl-inet A1300AIGl-inet Ax1800AIGl-inet Axt1800AIGl-inet Mt2500AI+4 | 8/6/2026 | 23/7/2026 | A flaw has been found in GL.iNet A1300, AX1800, AXT1800, MT2500, MT3000, MT6000, X3000 and XE3000 4.8.x. This affects an unknown function of the component glnassys. Executing a manipulation can lead to use of hard-coded cryptographic key . The attack may be launched remotely. The attack requires a high level of… | |
| Aplazada | Media (6.9) | 1.7% | — | Gl-inet Gl-mt3000AI | 7/6/2026 | 23/7/2026 | A vulnerability has been found in GL.iNet GL-MT3000 up to 4.4.5. Affected is the function FUN_0042e200 of the file /cgi-bin/glc of the component SET_USER_PWD Handler. The manipulation of the argument Password leads to command injection. The attack can be initiated remotely. Upgrading to version 4.8.1 is able to… | |
| Aplazada | Media (6.9) | 2.0% | — | Gl-inet Gl-mt3000AI | 7/6/2026 | 23/7/2026 | A flaw has been found in GL.iNet GL-MT3000 4.4.5. This impacts the function snprintf of the file /cgi-bin/glc of the component FTP Protocol Handler. Executing a manipulation of the argument media_dir can lead to command injection. It is possible to launch the attack remotely. Upgrading to version 4.8.1 will fix this… | |
| Aplazada | Media (6.9) | 1.6% | — | Gl-inet Gl-mt3000AI | 7/6/2026 | 23/7/2026 | A vulnerability was detected in GL.iNet GL-MT3000 4.4.5. This affects the function dlopen in the library /usr/lib/oui-httpd/rpc/ of the component Path Normalization Handler. Performing a manipulation of the argument dev_name results in command injection. It is possible to initiate the attack remotely. Upgrading to… | |
| Aplazada | Media (5.3) | 1.1% | — | LuciAIGl-inet Gl-mt3000AI | 7/6/2026 | 23/7/2026 | A security vulnerability has been detected in GL.iNet GL-MT3000 4.4.5. The impacted element is the function rpc_sys of the file /cgi-bin/luci/rpc of the component LuCI JSON-RPC Interface. Such manipulation leads to command injection. The attack may be performed from remote. Upgrading to version 4.8.1 is sufficient to… | |
| Aplazada | Media (5.1) | 1.6% | — | MinidlnaAIGl-inet Gl-mt3000AI | 7/6/2026 | 23/7/2026 | A weakness has been identified in GL.iNet GL-MT3000 up to 4.4.5. The affected element is the function realpath of the file /rpc of the component Minidlna Service. This manipulation of the argument kube. set causes command injection. The attack is possible to be carried out remotely. Upgrading to version 4.7 is… | |
| Aplazada | Baja (2.1) | 1.1% | — | Gl-inet Gl-mt3000AI | 7/6/2026 | 23/7/2026 | A security flaw has been discovered in GL.iNet GL-MT3000 up to 4.4.5. Impacted is the function iwinfo_backend of the file iwinfo.so of the component MTK Backend. The manipulation of the argument device results in command injection. The attack can be executed remotely. The exploit has been released to the public and… | |
| Aplazada | Baja (2.1) | 1.2% | — | OpenvpnAIGl-inet Mt3000AI | 6/6/2026 | 23/7/2026 | A vulnerability was determined in GL.iNet MT3000 up to 4.4.5. This vulnerability affects unknown code of the file ovpnclient.sh of the component OpenVPN Client Import Workflow. This manipulation causes command injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be… | |
| Aplazada | Crítica (9.8) | 0.48% | — | Gladinet Triofox Cloud Server Agent Access ServiceAI | 27/5/2026 | 17/6/2026 | Gladinet Triofox Cloud Server Agent Access Service (GladServerAgentService.exe) listens on TCP port 7878 and processes remote HTTP messages with URL paths starting with /resources, /status, /sysinfo, /woshome, /Settings, /schedule, or /DavCache. |