Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2783▼ 434 respecto a la semana anterior
Críticas / altas1335▼ 118 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
447 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 0.20% | — | Intel Graphics Performance Analyzers | 16/5/2024 | 17/6/2026 | Uncontrolled search path in some Intel(R) GPA software before version 2023.3 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Analizada | Alta (7.8) | 0.21% | — | Intel Graphics Performance Analyzers | 16/5/2024 | 17/6/2026 | Improper access control in some Intel(R) GPA software installers before version 2023.3 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Analizada | Alta (7.8) | 0.20% | — | Intel Graphics Performance Analyzers Framework | 16/5/2024 | 17/6/2026 | Uncontrolled search path in some Intel(R) GPA Framework software before version 2023.3 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Analizada | Alta (7.8) | 0.19% | — | Intel Graphics Performance Analyzers | 16/5/2024 | 17/6/2026 | Incorrect default permissions in some Intel(R) GPA software installers before version 2023.3 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Analizada | Media (4.3) | 0.49% | — | Redhat Trusted Profile Analyzer | 25/4/2024 | 17/6/2026 | A flaw was found in Bombastic, which allows authenticated users to upload compressed (bzip2 or zstd) SBOMs. The API endpoint verifies the presence of some fields and values in the JSON. To perform this verification, the uploaded file must first be decompressed. | |
| Aplazada | Media (4.3) | 0.20% | — | Coschedule Headline AnalyzerAI | 24/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in CoSchedule Headline Analyzer.This issue affects Headline Analyzer: from n/a through 1.3.3. | |
| Aplazada | Alta (7.5) | 0.31% | — | Hitachi OPS Center AnalyzerAI | 23/4/2024 | 17/6/2026 | Session Hijacking vulnerability in Hitachi Ops Center Analyzer.This issue affects Hitachi Ops Center Analyzer: from 10.0.0-00 before 11.0.1-00. | |
| Modificada | Media (6.7) | 0.22% | — | Fortinet FortianalyzerFortinet Fortianalyzer BIG DataFortinet FortimanagerFortinet Fortiportal | 12/3/2024 | 17/6/2026 | A use of externally-controlled format string vulnerability [CWE-134] vulnerability in Fortinet allows a privileged attacker to execute unauthorized code or commands via specially crafted command arguments. | |
| Modificada | Media (5) | 0.68% | — | Fortinet FortianalyzerFortinet Fortimanager | 15/2/2024 | 17/6/2026 | An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in Fortinet FortiManager version 7.4.0 through 7.4.1 and before 7.2.5, FortiAnalyzer version 7.4.0 through 7.4.1 and before 7.2.5 and FortiAnalyzer-BigData before 7.2.5 allows an adom administrator to enumerate other adoms and device… | |
| Analizada | Alta (7.8) | 0.16% | — | Intel AdvisorIntel Cluster CheckerIntel Distribution FOR PythonIntel Inspector+12 | 14/2/2024 | 17/6/2026 | Improper access control in the Intel(R) oneAPI DPC++/C++ Compiler before version 2022.2.1 for some Intel(R) oneAPI Toolkits before version 2022.3.1 may allow authenticated user to potentially enable escalation of privilege via local access. | |
| Analizada | Media (6) | 0.17% | — | Intel AdvisorIntel Cluster CheckerIntel Distribution FOR PythonIntel Inspector+12 | 14/2/2024 | 17/6/2026 | Improper buffer restrictions the Intel(R) C++ Compiler Classic before version 2021.8 for Intel(R) oneAPI Toolkits before version 2022.3.1 may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (8.6) | 47% | 💥 Exploit | Zohocorp Manageengine Firewall AnalyzerZohocorp Manageengine Netflow AnalyzerZohocorp Manageengine Network Configuration ManagerZohocorp Manageengine Opmanager+3 | 8/1/2024 | 17/6/2026 | A directory traversal vulnerability exists in the uploadMib functionality of ManageEngine OpManager 12.7.258. A specially crafted HTTP request can lead to arbitrary file creation. An attacker can send a malicious MiB file to trigger this vulnerability. | |
| Modificada | Alta (7.1) | 0.32% | — | Eclipse Memory Analyzer | 11/12/2023 | 17/6/2026 | In Eclipse Memory Analyzer versions 0.7 to 1.14.0, report definition XML files are not filtered to prohibit document type definition (DTD) references to external entities. This means that if a user chooses to use a malicious report definition XML file containing an external entity reference to generate a report then… | |
| Modificada | Media (5.5) | 0.69% | — | Zohocorp Manageengine Analytics PlusZohocorp Manageengine AppcreatorZohocorp Manageengine Application Control PlusZohocorp Manageengine Browser Security Plus+35 | 15/11/2023 | 17/6/2026 | An information disclosure vulnerability exists in multiple ManageEngine products that can result in encryption keys being exposed. A low-privileged OS user with access to the host where an affected ManageEngine product is installed can view and use the exposed key to decrypt product database passwords. This allows the… | |
| Modificada | Media (5.5) | 0.19% | — | Fortinet FortianalyzerFortinet Fortimanager | 14/11/2023 | 17/6/2026 | A use of hard-coded credentials vulnerability in Fortinet FortiAnalyzer and FortiManager 7.0.0 - 7.0.8, 7.2.0 - 7.2.3 and 7.4.0 allows an attacker to access Fortinet private testing data via the use of static credentials. | |
| Modificada | Media (6.5) | 1.2% | — | Fortinet FortianalyzerFortinet Fortimanager | 20/10/2023 | 17/6/2026 | A server-side request forgery vulnerability [CWE-918] in Fortinet FortiAnalyzer version 7.4.0, version 7.2.0 through 7.2.3 and before 7.0.8 and FortiManager version 7.4.0, version 7.2.0 through 7.2.3 and before 7.0.8 allows a remote attacker with low privileges to view sensitive data from internal servers or perform a… | |
| Modificada | Media (6.5) | 0.87% | — | Fortinet FortianalyzerFortinet Fortimanager | 10/10/2023 | 17/6/2026 | An authorization bypass through user-controlled key [CWE-639] vulnerability in Fortinet FortiManager version 7.4.0 and before 7.2.3 and FortiAnalyzer version 7.4.0 and before 7.2.3 allows a remote attacker with low privileges to read sensitive information via crafted HTTP requests. | |
| Modificada | Media (6.7) | 1.3% | — | Fortinet FortianalyzerFortinet Fortimanager | 10/10/2023 | 17/6/2026 | An improper neutralization of special elements used in an os command ('OS Command Injection') vulnerability [CWE-78] in FortiManager & FortiAnalyzer version 7.4.0, version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.8, version 6.4.0 through 6.4.12 and version 6.2.0 through 6.2.11 may allow a local attacker with low… | |
| Modificada | Media (6.5) | 1.4% | — | Fortinet FortianalyzerFortinet Fortimanager | 10/10/2023 | 12/8/2026 | A client-side enforcement of server-side security [CWE-602] vulnerability in Fortinet FortiManager version 7.4.0 and before 7.2.3 and FortiAnalyzer version 7.4.0 and before 7.2.3 may allow a remote attacker with low privileges to access a privileged web console via client side code execution. | |
| Modificada | Media (5.3) | 0.31% | — | Fortinet Fortianalyzer | 10/10/2023 | 17/6/2026 | A insufficient verification of data authenticity vulnerability [CWE-345] in FortiAnalyzer version 7.4.0 and below 7.2.3 allows a remote unauthenticated attacker to send messages to the syslog server of FortiAnalyzer via the knoweldge of an authorized device serial number. | |
| Modificada | Alta (7.1) | 0.51% | — | Fortinet FortianalyzerFortinet Fortimanager | 10/10/2023 | 17/6/2026 | An improper neutralization of special elements used in an os command ('os command injection') in FortiManager 7.4.0 and 7.2.0 through 7.2.3 may allow attacker to execute unauthorized code or commands via FortiManager cli. | |
| Modificada | Alta (7.8) | 1.5% | — | Fortinet FortiadcFortinet FortianalyzerFortinet Fortimanager | 10/10/2023 | 17/6/2026 | An improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78 ] in FortiManager 7.2.0 through 7.2.2, 7.0.0 through 7.0.7, 6.4.0 through 6.4.11, 6.2 all versions, 6.0 all versions, FortiAnalyzer 7.2.0 through 7.2.2, 7.0.0 through 7.0.7, 6.4.0 through 6.4.11, 6.2 all… | |
| Modificada | Media (4.3) | 0.39% | — | Jenkins Build Failure Analyzer | 20/9/2023 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins Build Failure Analyzer Plugin 2.4.1 and earlier allows attackers to delete Failure Causes. | |
| Modificada | Media (6.5) | 0.61% | — | Jenkins Build Failure Analyzer | 20/9/2023 | 17/6/2026 | A missing permission check in Jenkins Build Failure Analyzer Plugin 2.4.1 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified hostname and port using attacker-specified username and password. | |
| Modificada | Alta (8.8) | 0.47% | — | Jenkins Build Failure Analyzer | 20/9/2023 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins Build Failure Analyzer Plugin 2.4.1 and earlier allows attackers to connect to an attacker-specified hostname and port using attacker-specified username and password. |