Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
–

196 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.4)0.22%—Fortinet FortianalyzerFortinet Fortimanager20/7/202117/6/2026
A buffer overflow vulnerability in FortiAnalyzer CLI 6.4.5 and below, 6.2.7 and below, 6.0.x and FortiManager CLI 6.4.5 and below, 6.2.7 and below, 6.0.x may allow an authenticated, local attacker to perform a Denial of Service attack by running the `diagnose system geoip-city` command with a large ip value.
ModificadaMedia (6.5)0.63%—Huawei Imanager Neteco 600029/12/202017/6/2026
There is an information leak vulnerability in iManager NetEco 6000 versions V600R021C00. A module is lack of authentication. Attackers without access to the module can exploit this vulnerability to obtain extra information, leading to information leak.
ModificadaAlta (7.8)0.31%—Huawei Imanager Neteco 600024/12/202017/6/2026
There has a CSV injection vulnerability in iManager NetEco 6000 versions V600R021C00. An attacker with common privilege may exploit this vulnerability through some operations to inject the CSV files. Due to insufficient input validation of some parameters, the attacker can exploit this vulnerability to inject CSV…
ModificadaMedia (6.1)0.80%—Fortinet FortianalyzerFortinet Fortimanager24/9/202017/6/2026
An improper neutralization of script-related HTML tags in a web page in FortiManager 6.2.0, 6.2.1, 6.2.2, and 6.2.3and FortiAnalyzer 6.2.0, 6.2.1, 6.2.2, and 6.2.3 may allow an attacker to execute a cross site scripting (XSS) via the Identify Provider name field.
ModificadaAlta (7.5)2.2%💥 PoCFortinet FortianalyzerFortinet Fortimanager16/6/202017/6/2026
Use of a hard-coded cryptographic key to encrypt password data in CLI configuration in FortiManager 6.2.3 and below, FortiAnalyzer 6.2.3 and below may allow an attacker with access to the CLI configuration or the CLI backup file to decrypt the sensitive data, via knowledge of the hard-coded key.
ModificadaAlta (7.5)2.4%—Fortinet FortianalyzerFortinet Fortiap-sFortinet Fortiap-w2Fortinet Fortimanager+17/4/202017/6/2026
An Uncontrolled Resource Consumption vulnerability in Fortinet FortiSwitch below 3.6.11, 6.0.6 and 6.2.2, FortiAnalyzer below 6.2.3, FortiManager below 6.2.3 and FortiAP-S/W2 below 6.2.2 may allow an attacker to cause admin webUI denial of service (DoS) via handling special crafted HTTP requests/responses in pieces…
ModificadaAlta (8.8)0.47%—Fortinet Fortimanager15/3/202017/6/2026
An Insufficient Verification of Data Authenticity vulnerability in FortiManager 6.2.1, 6.2.0, 6.0.6 and below may allow an unauthenticated attacker to perform a Cross-Site WebSocket Hijacking (CSWSH) attack.
ModificadaCrítica (9.8)2.2%—Fortinet Fortimanager4/2/202017/6/2026
A vulnerability exists in in FortiManager 5.2.1 and earlier and 5.0.10 and earlier in the WebUI FTP backup page
ModificadaMedia (5.4)0.79%—Fortinet Fortimanager4/2/202017/6/2026
A Cross-site Scripting (XSS) vulnerability exists in FortiManager 5.2.1 and earlier and 5.0.10 and earlier via an unspecified parameter in the FortiWeb auto update service page.
ModificadaAlta (8.8)5.6%—Fortinet Fortimanager4/2/202017/6/2026
A Command Injection vulnerability exists in FortiManager 5.2.1 and earlier and FortiManager 5.0.10 and earlier via unspecified vectors, which could let a malicious user run systems commands when executing a report.
ModificadaAlta (7.8)0.62%—Linux KernelCanonical Ubuntu LinuxDebian LinuxFedoraproject Fedora+3017/9/201917/6/2026
A buffer overflow flaw was found, in versions from 2.6.34 to 5.2.x, in the way Linux kernel's vhost functionality that translates virtqueue buffers to IOVs, logged the buffer descriptors during migration. A privileged guest user able to pass descriptors with invalid length to the host when migration is underway, could…
ModificadaCrítica (9.8)0.77%—Fortinet Fortimanager23/8/201917/6/2026
Lack of root file system integrity checking in Fortinet FortiManager VM application images of 6.2.0, 6.0.6 and below may allow an attacker to implant third-party programs by recreating the image through specific methods.
ModificadaAlta (8.1)2.7%💥 PoCGoogle AndroidApple Iphone OSApple MAC OS XApple Tvos+14314/8/201917/6/2026
The Bluetooth BR/EDR specification up to and including version 5.1 permits sufficiently low encryption key length and does not prevent an attacker from influencing the key length negotiation. This allows practical brute-force attacks (aka "KNOB") that can decrypt traffic and inject arbitrary ciphertext without the…
ModificadaCrítica (9.8)28%—Dlink Central Wifimanager6/7/201917/6/2026
A SQL Injection was discovered in D-Link Central WiFi Manager CWM(100) before v1.03R0100_BETA6 in PayAction.class.php with the index.php/Pay/passcodeAuth parameter passcode. The vulnerability does not need any authentication.
ModificadaMedia (6.1)2.4%—Dlink Central Wifimanager6/7/201917/6/2026
A cross-site scripting (XSS) vulnerability in resource view in PayAction.class.php in D-Link Central WiFi Manager CWM(100) before v1.03R0100_BETA6 allows remote attackers to inject arbitrary web script or HTML via the index.php/Pay/passcodeAuth passcode parameter.
ModificadaCrítica (9.8)68%—Dlink Central Wifimanager6/7/201917/6/2026
An issue was discovered in the D-Link Central WiFi Manager CWM(100) before v1.03R0100_BETA6. Input does not get validated and arbitrary SQL statements can be executed in the database via the /web/Public/Conn.php parameter dbSQL.
ModificadaCrítica (9.8)82%💥 ExploitDlink Central Wifimanager6/7/201917/6/2026
/web/Lib/Action/IndexAction.class.php in D-Link Central WiFi Manager CWM(100) before v1.03R0100_BETA6 allows remote attackers to execute arbitrary PHP code via a cookie because a cookie's username field allows eval injection, and an empty password bypasses authentication.
ModificadaMedia (6.1)0.65%—Fortinet FortianalyzerFortinet Fortimanager28/5/201917/6/2026
An Improper Neutralization of Script-Related HTML Tags in Fortinet FortiAnalyzer 5.6.0 and below and FortiManager 5.6.0 and below allows an attacker to send DHCP request containing malicious scripts in the HOSTNAME parameter. The malicious script code is executed while viewing the logs in FortiAnalyzer and…
ModificadaAlta (8.1)0.86%—Fortinet Fortimanager25/4/201917/6/2026
A cleartext transmission of sensitive information vulnerability in Fortinet FortiManager 5.2.0 through 5.2.7, 5.4.0 and 5.4.1 may allow an unauthenticated attacker in a man in the middle position to retrieve the admin password via intercepting REST API JSON responses.
ModificadaAlta (8.6)44%💥 ExploitDlink Central Wifimanager31/1/201917/6/2026
The MailConnect feature on D-Link Central WiFiManager CWM-100 1.03 r0098 devices is intended to check a connection to an SMTP server but actually allows outbound TCP to any port on any IP address, leading to SSRF, as demonstrated by an index.php/System/MailConnect/host/127.0.0.1/port/22/secure/ URI.
ModificadaMedia (5.8)2.0%—Dlink Central Wifimanager31/1/201917/6/2026
The FTP service on D-Link Central WiFiManager CWM-100 1.03 r0098 devices allows remote attackers to conduct a PORT command bounce scan via port 8000, resulting in SSRF.
ModificadaAlta (7.8)2.5%—Dlink Central Wifimanager31/1/201917/6/2026
The CaptivelPortal service on D-Link Central WiFiManager CWM-100 1.03 r0098 devices will load a Trojan horse "quserex.dll" from the CaptivelPortal.exe subdirectory under the D-Link directory, which allows unprivileged local users to gain SYSTEM privileges.
ModificadaMedia (6.1)0.65%—Microfocus Imanager12/12/201817/6/2026
Cross site scripting vulnerability in iManager prior to 3.1 SP2.
ModificadaMedia (6.1)5.7%💥 ExploitDlink Central Wifimanager8/10/201817/6/2026
An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. The 'sitename' parameter of the UpdateSite endpoint is vulnerable to stored XSS.
ModificadaAlta (8.8)14%💥 ExploitDlink Central Wifimanager8/10/201817/6/2026
An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. An unrestricted file upload vulnerability in the onUploadLogPic endpoint allows remote authenticated users to execute arbitrary PHP code.