Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
447 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.2) | 0.63% | — | Fortinet FortianalyzerFortinet Fortianalyzer Cloud | 8/10/2024 | 17/6/2026 | A use of externally-controlled format string in Fortinet FortiAnalyzer versions 7.4.0 through 7.4.3, 7.2.2 through 7.2.5 allows attacker to escalate its privileges via specially crafted requests. | |
| Analizada | Media (6.5) | 0.53% | — | Fortinet FortianalyzerFortinet FortimanagerFortinet Fortianalyzer BIG Data | 10/9/2024 | 17/6/2026 | An authorization bypass through user-controlled key [CWE-639] vulnerability in FortiAnalyzer version 7.4.1 and before 7.2.5 and FortiManager version 7.4.1 and before 7.2.5 may allow a remote attacker with low privileges to read sensitive data via a crafted HTTP request. | |
| Aplazada | Media (4.3) | 0.26% | — | SAP Business WarehouseAISAP BEX AnalyzerAI | 10/9/2024 | 17/6/2026 | Due to missing authorization checks, SAP Business Warehouse (BEx Analyzer) allows an authenticated attacker to access information over the network which is otherwise restricted. On successful exploitation the attacker can enumerate information causing a limited impact on confidentiality of the application. | |
| Aplazada | Media (4.3) | 0.26% | — | SAP BEX AnalyzerAI | 10/9/2024 | 17/6/2026 | Due to missing authorization checks, SAP BEx Analyzer allows an authenticated attacker to access information over the network which is otherwise restricted. On successful exploitation the attacker can enumerate information causing a limited impact on confidentiality of the application. | |
| Analizada | Media (5.4) | 0.14% | — | Intel Oneapi HPC ToolkitIntel Trace Analyzer AND Collector | 14/8/2024 | 17/6/2026 | Uncontrolled search path for some Intel(R) Trace Analyzer and Collector software before version 2022.1 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Analizada | Media (5.4) | 0.14% | — | Intel Graphics Performance Analyzers | 14/8/2024 | 17/6/2026 | Uncontrolled search path in some Intel(R) GPA software before version 2024.1 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Analizada | Alta (7.8) | 0.19% | — | Fortinet FortianalyzerFortinet Fortimanager | 13/8/2024 | 17/6/2026 | A unverified password change in Fortinet FortiManager versions 7.0.0 through 7.0.10, versions 7.2.0 through 7.2.4, and versions 7.4.0 through 7.4.1, as well as Fortinet FortiAnalyzer versions 7.0.0 through 7.0.10, versions 7.2.0 through 7.2.4, and versions 7.4.0 through 7.4.1, allows an attacker to modify admin… | |
| Analizada | Baja (2.1) | 0.22% | — | Siemens Sinec Traffic Analyzer | 13/8/2024 | 17/6/2026 | A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V2.0). The affected application is missing general HTTP security headers in the web server. This could allow an attacker to make the servers more prone to clickjacking attack. | |
| Analizada | Media (6.3) | 0.23% | — | Siemens Sinec Traffic Analyzer | 13/8/2024 | 17/6/2026 | A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V2.0). The affected application does not properly handle cacheable HTTP responses in the web service. This could allow an attacker to read and modify data stored in the local cache. | |
| Analizada | Alta (7.6) | 0.30% | — | Siemens Sinec Traffic Analyzer | 13/8/2024 | 17/6/2026 | A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V2.0). The affected application do not have access control for accessing the files. This could allow an authenticated attacker with low privilege's to get access to sensitive information. | |
| Analizada | Alta (8.7) | 0.54% | — | Siemens Sinec Traffic Analyzer | 13/8/2024 | 17/6/2026 | A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V2.0). The affected application do not properly enforce restriction of excessive authentication attempts. This could allow an unauthenticated attacker to conduct brute force attacks against legitimate user credentials or… | |
| Analizada | Alta (7.5) | 0.39% | — | Siemens Sinec Traffic Analyzer | 13/8/2024 | 17/6/2026 | A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V2.0). The affected application mounts the container's root filesystem with read and write privileges. This could allow an attacker to alter the container's filesystem leading to unauthorized modifications and data… | |
| Aplazada | Crítica (9.8) | 10% | 💥 Exploit | Sonicwall AnalyzerAI | 21/6/2024 | 17/6/2026 | Actual Analyzer through 2014-08-29 allows code execution via shell metacharacters because untrusted input is used for part of the input data passed to an eval operation. | |
| Modificada | Media (6.9) | 0.34% | — | Siemens Sinec Traffic Analyzer | 11/6/2024 | 17/6/2026 | A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V1.2). The affected application lacks input validation due to which an attacker can gain access to the Database entries. | |
| Modificada | Media (6.8) | 0.22% | — | Siemens Sinec Traffic Analyzer | 11/6/2024 | 17/6/2026 | A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V1.2). The affected web server, after a successful login, sets the session cookie on the browser, without applying any security attributes (such as “Secure”, “HttpOnly”, or “SameSite”). | |
| Modificada | Media (5.1) | 0.15% | — | Siemens Sinec Traffic Analyzer | 11/6/2024 | 17/6/2026 | A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V1.2). The affected web server is not enforcing HSTS. This could allow an attacker to perform downgrade attacks exposing confidential information. | |
| Modificada | Media (6.9) | 0.32% | — | Siemens Sinec Traffic Analyzer | 11/6/2024 | 17/6/2026 | A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V1.2). The affected web server is allowing HTTP methods like PUT and Delete. This could allow an attacker to modify unauthorized files. | |
| Modificada | Media (4.8) | 0.15% | — | Siemens Sinec Traffic Analyzer | 11/6/2024 | 17/6/2026 | A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V1.2). The affected web server stored the password in cleartext. This could allow attacker in a privileged position to obtain access passwords. | |
| Modificada | Alta (8.5) | 0.15% | — | Siemens Sinec Traffic Analyzer | 11/6/2024 | 17/6/2026 | A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V1.2). The web interface of the affected devices are vulnerable to Cross-Site Request Forgery(CSRF) attacks. By tricking an authenticated victim user to click a malicious link, an attacker could perform arbitrary actions… | |
| Modificada | Alta (8.5) | 0.33% | — | Siemens Sinec Traffic Analyzer | 11/6/2024 | 17/6/2026 | A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V1.2). The affected application does not expire the session. This could allow an attacker to get unauthorized access. | |
| Aplazada | Baja (2.8) | 0.20% | — | Intel Trace Analyzer AND CollectorAI | 16/5/2024 | 17/6/2026 | Out-of-bounds read for some Intel(R) Trace Analyzer and Collector software before version 2022.0.0 published Nov 2023 may allow an authenticated user to potentially enable information disclosure via local access. | |
| Analizada | Alta (7.8) | 0.18% | — | Intel Graphics Performance Analyzers Framework | 16/5/2024 | 17/6/2026 | Uncontrolled search path in some Intel(R) GPA Framework software before version 2023.4 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Analizada | Alta (7.8) | 0.19% | — | Intel Graphics Performance Analyzers | 16/5/2024 | 17/6/2026 | Uncontrolled search path in some Intel(R) GPA software before version 2023.4 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Analizada | Alta (7.8) | 0.21% | — | Intel Graphics Performance Analyzers Framework | 16/5/2024 | 17/6/2026 | Improper access control in some Intel(R) GPA Framework software installers before version 2023.3 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Analizada | Alta (7.8) | 0.21% | — | Intel Graphics Performance Analyzers | 16/5/2024 | 17/6/2026 | Incorrect default permissions in some Intel(R) GPA software installers before version 2023.3 may allow an authenticated user to potentially enable escalation of privilege via local access. |