Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
472 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.68% | — | Fortinet FortiproxyFortinet FortipamFortinet Fortios | 14/10/2025 | 17/6/2026 | An Heap-based Buffer Overflow vulnerability [CWE-122] in FortiOS version 7.6.2 and below, version 7.4.7 and below, version 7.2.10 and below, 7.0 all versions, 6.4 all versions; FortiPAM version 1.5.0, version 1.4.2 and below, 1.3 all versions, 1.2 all versions, 1.1 all versions, 1.0 all versions and FortiProxy version… | |
| Modificada | Crítica (9.8) | 0.58% | — | Fortinet FortipamFortinet Fortiswitchmanager | 14/10/2025 | 17/6/2026 | A weak authentication vulnerability in Fortinet FortiPAM 1.5.0, FortiPAM 1.4.0 through 1.4.2, FortiPAM 1.3 all versions, FortiPAM 1.2 all versions, FortiPAM 1.1 all versions, FortiPAM 1.0 all versions, FortiSwitchManager 7.2.0 through 7.2.4 allows attacker to execute unauthorized code or commands via specially crafted… | |
| Analizada | Alta (7.2) | 0.56% | — | Fortinet FortiosFortinet FortipamFortinet FortiproxyFortinet Fortisra+1 | 14/10/2025 | 17/6/2026 | A heap-based buffer overflow in Fortinet FortiSRA 1.5.0, 1.4.0 through 1.4.2, FortiPAM 1.5.0, 1.4.0 through 1.4.2, 1.3.0 through 1.3.1, 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiProxy 7.6.0 through 7.6.1, 7.4.0 through 7.4.7, FortiOS 7.6.0 through 7.6.2, 7.4.0 through 7.4.6, 7.2.0 through 7.2.10, 7.0.2… | |
| Modificada | Media (4.3) | 0.47% | — | Fortinet FortimailFortinet FortimanagerFortinet Fortimanager CloudFortinet Fortindr+8 | 14/10/2025 | 17/6/2026 | A insertion of sensitive information into sent data vulnerability in Fortinet FortiMail 7.4.0 through 7.4.2, FortiMail 7.2.0 through 7.2.6, FortiMail 7.0 all versions, FortiManager 7.6.0 through 7.6.1, FortiManager 7.4.1 through 7.4.3, FortiManager Cloud 7.4.1 through 7.4.3, FortiNDR 7.6.0 through 7.6.1, FortiNDR… | |
| Analizada | Media (5.3) | 0.47% | — | Fortinet FortiosFortinet FortipamFortinet FortiproxyFortinet Fortiswitchmanager | 14/10/2025 | 17/6/2026 | An improper check or handling of exceptional conditions vulnerability [CWE-703] in FortiOS version 7.4.0 through 7.4.3 and before 7.2.7, FortiProxy version 7.4.0 through 7.4.3 and before 7.2.9, FortiPAM before 1.2.0 and FortiSwitchManager version 7.2.0 through 7.2.3 and version 7.0.0 through 7.0.3 fgfm daemon may… | |
| Aplazada | Alta (7.1) | 0.13% | — | Nixsolutions NIX Anti-spam LightAI | 22/9/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in NIX Solutions Ltd NIX Anti-Spam Light nix-anti-spam-light allows Cross Site Request Forgery.This issue affects NIX Anti-Spam Light: from n/a through <= 0.0.4. | |
| Aplazada | Media (5.9) | 0.24% | — | Ricky Dawn BOT Block Stop Spam Google Analytics ReferralsAI | 22/9/2025 | 30/9/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ricky Dawn Bot Block – Stop Spam Referrals in Google Analytics bot-block-stop-spam-google-analytics-referrals allows Stored XSS.This issue affects Bot Block – Stop Spam Referrals in Google Analytics: from n/a through… | |
| Aplazada | Alta (7.2) | 0.27% | — | Securden Unified PAM Remote Vendor GatewayAI | 25/8/2025 | 17/6/2026 | Securden’s Unified PAM Remote Vendor Gateway access portal shares infrastructure and access tokens across multiple tenants. A malicious actor can obtain authentication material and access the gateway server with low-privilege permissions. | |
| Aplazada | Crítica (9.4) | 11% | — | PAMAI | 25/8/2025 | 17/6/2026 | A path traversal vulnerability in unauthenticated upload functionality allows a malicious actor to upload binaries and scripts to the server’s configuration and web root directories, achieving remote code execution on the Unified PAM server. | |
| Aplazada | Crítica (9.8) | 33% | 💥 Exploit | PAMAI | 25/8/2025 | 17/6/2026 | An authentication bypass vulnerability exists which allows an unauthenticated attacker to control administrator backup functions, leading to compromise of passwords, secrets, and application session tokens stored by the Unified PAM. | |
| Aplazada | Alta (8.7) | 1.2% | — | Barracuda Spam AND Virus FirewallAIBarracuda SSL VPNAIBarracuda WEB Application FirewallAI | 21/8/2025 | 16/6/2026 | Barracuda products, confirmed in Spam & Virus Firewall, SSL VPN, and Web Application Firewall versions prior to October 2010, contain a path traversal vulnerability in the view_help.cgi endpoint. The locale parameter fails to properly sanitize user input, allowing attackers to inject traversal sequences and null-byte… | |
| Aplazada | Crítica (9.1) | 0.56% | — | Titanhq Spamtitan Email Security GatewayAI | 21/8/2025 | 17/6/2026 | An issue was discovered in TitanHQ SpamTitan Email Security Gateway 8.00.x before 8.00.101 and 8.01.x before 8.01.14. The file quarantine.php within the SpamTitan interface allows unauthenticated users to trigger account-level actions using a crafted GET request. Notably, when a non-existent email address is provided… | |
| Aplazada | Alta (7.8) | 0.27% | — | Linux-pamAI | 13/8/2025 | 17/6/2026 | A flaw was found in linux-pam. The pam_namespace module may improperly handle user-controlled paths, allowing local users to exploit symlink attacks and race conditions to elevate their privileges to root. This CVE provides a "complete" fix for CVE-2025-6020. | |
| Modificada | Media (6.5) | 0.48% | — | Fortinet FortiosFortinet FortipamFortinet Fortiproxy | 12/8/2025 | 17/6/2026 | An Integer Overflow or Wraparound vulnerability [CWE-190] in FortiOS version 7.6.2 and below, version 7.4.7 and below, version 7.2.10 and below, 7.2 all versions, 6.4 all versions, FortiProxy version 7.6.2 and below, version 7.4.3 and below, 7.2 all versions, 7.0 all versions, 2.0 all versions and FortiPAM version… | |
| Modificada | Alta (8.1) | 0.59% | — | Fortinet FortiswitchmanagerFortinet FortiproxyFortinet FortipamFortinet Fortios | 12/8/2025 | 17/6/2026 | An authentication bypass using an alternate path or channel [CWE-288] vulnerability in Fortinet FortiOS 6.4.0 through 6.4.15, FortiOS 6.2.0 through 6.2.16, FortiOS 6.0 all versions, FortiPAM 1.2.0, FortiPAM 1.1.0 through 1.1.2, FortiPAM 1.0.0 through 1.0.3, FortiProxy 7.4.0 through 7.4.2, FortiProxy 7.2.0 through… | |
| Modificada | Alta (7.2) | 0.59% | — | Fortinet FortiosFortinet FortipamFortinet Fortiproxy | 12/8/2025 | 17/6/2026 | A double free vulnerability [CWE-415] vulnerability in Fortinet FortiOS 7.4.0, FortiOS 7.2.0 through 7.2.5, FortiOS 7.0.0 through 7.0.12, FortiOS 6.4 all versions, FortiPAM 1.1 all versions, FortiPAM 1.0 all versions, FortiProxy 7.4.0 through 7.4.1, FortiProxy 7.2.0 through 7.2.7, FortiProxy 7.0.0 through 7.0.13… | |
| Aplazada | Media (6.1) | 0.35% | — | Kron Technologies Kron PAMAI | 25/7/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Kron Technologies Kron PAM allows Stored XSS. This issue affects Kron PAM: before 3.7. | |
| Aplazada | Media (6.5) | 0.40% | — | Kron Technologies Kron PAMAI | 25/7/2025 | 17/6/2026 | Allocation of Resources Without Limits or Throttling vulnerability in Kron Technologies Kron PAM allows HTTP DoS. This issue affects Kron PAM: before 3.7. | |
| Modificada | Alta (7.8) | 1.1% | 💥 Exploit | Suse Pam-config | 23/7/2025 | 30/6/2026 | A Local Privilege Escalation (LPE) vulnerability has been discovered in pam-config within Linux Pluggable Authentication Modules (PAM). This flaw allows an unprivileged local attacker (for example, a user logged in via SSH) to obtain the elevated privileges normally reserved for a physically present, "allow_active"… | |
| Aplazada | Media (5.4) | 0.14% | — | Erik Antispam Antispam FOR Contact Form 7AI | 16/7/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Erik AntiSpam for Contact Form 7 cf7-antispam allows Cross Site Request Forgery.This issue affects AntiSpam for Contact Form 7: from n/a through <= 0.6.3. | |
| Analizada | Baja (2) | 0.27% | — | Pushpam02 ZOO Management System | 10/7/2025 | 17/6/2026 | A vulnerability has been found in SourceCodester Zoo Management System 1.0 and classified as problematic. This vulnerability affects unknown code of the file /admin/templates/animal_form_template.php. The manipulation of the argument msg leads to cross site scripting. The attack can be initiated remotely. The exploit… | |
| Aplazada | Alta (7.8) | 0.46% | — | Linux-pamAI | 17/6/2025 | 7/10/2026 | A flaw was found in linux-pam. The module pam_namespace may use access user-controlled paths without proper protection, allowing local users to elevate their privileges to root via multiple symlink attacks and race conditions. | |
| Analizada | Alta (8.8) | 0.37% | — | Fortinet FortipamFortinet Fortisra | 10/6/2025 | 17/6/2026 | A improper handling of insufficient permissions or privileges in Fortinet FortiPAM 1.4.0 through 1.4.1, 1.3.0, 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiSRA 1.4.0 through 1.4.1 allows attacker to improper access control via specially crafted HTTP requests | |
| Aplazada | Media (5.4) | 0.32% | — | DE Paragon NO Spam AT ALLAI | 6/6/2025 | 17/6/2026 | Missing Authorization vulnerability in De paragon No Spam At All no-spam-at-all allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects No Spam At All: from n/a through <= 1.3. | |
| Aplazada | Media (5.4) | 0.19% | — | Anti Spam Spam Protection Block Spam Users Comments FormsAI | 6/6/2025 | 17/6/2026 | The Anti-Spam: Spam Protection | Block Spam Users, Comments, Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2024.7. This is due to missing or incorrect nonce validation in the 'ss_option_maint.php' and 'ss_user_filter_list' files. This makes it possible for… |