Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2778▼ 418 respecto a la semana anterior
Críticas / altas1332▼ 108 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
447 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.60% | — | Jenkins Build Failure Analyzer | 20/9/2023 | 17/6/2026 | Jenkins Build Failure Analyzer Plugin 2.4.1 and earlier does not escape Failure Cause names in build logs, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to create or update Failure Causes. | |
| Modificada | Media (4.3) | 0.41% | — | Fortinet FortianalyzerFortinet Fortimanager | 13/9/2023 | 17/6/2026 | An improper privilege management vulnerability [CWE-269] in FortiManager 7.2.0 through 7.2.2, 7.0.0 through 7.0.7, 6.4.0 through 6.4.11, 6.2 all versions, 6.0 all versions and FortiAnalyzer 7.2.0 through 7.2.2, 7.0.0 through 7.0.7, 6.4.0 through 6.4.11, 6.2 all versions, 6.0 all versions API may allow a remote and… | |
| Modificada | Media (4.2) | 0.48% | — | Fortinet FortianalyzerFortinet FortimanagerFortinet FortisandboxFortinet Fortios | 1/9/2023 | 17/6/2026 | An improper certificate validation vulnerability [CWE-295] in FortiManager 7.0.1 and below, 6.4.6 and below; FortiAnalyzer 7.0.2 and below, 6.4.7 and below; FortiOS 6.2.x and 6.0.x; FortiSandbox 4.0.x, 3.2.x and 3.1.x may allow a network adjacent and unauthenticated attacker to man-in-the-middle the communication… | |
| Modificada | Alta (8.1) | 2.4% | — | Zohocorp Manageengine Ad360Zohocorp Manageengine Adaudit PlusZohocorp Manageengine Admanager PlusZohocorp Manageengine Assetexplorer+13 | 28/8/2023 | 17/6/2026 | Zoho ManageEngine Active Directory 360 versions 4315 and below, ADAudit Plus 7202 and below, ADManager Plus 7200 and below, Asset Explorer 6993 and below and 7xxx 7002 and below, Cloud Security Plus 4161 and below, Data Security Plus 6110 and below, Eventlog Analyzer 12301 and below, Exchange Reporter Plus 5709 and… | |
| Modificada | Alta (7.3) | 0.17% | — | Intel Advisor FOR OneapiIntel CPU Runtime FOR Opencl ApplicationsIntel Distribution FOR Python Programming LanguageIntel Dpc++ Compatibility Tool+25 | 11/8/2023 | 17/6/2026 | Uncontrolled search path in some Intel(R) oneAPI Toolkit and component software installers before version 4.3.1.493 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.8) | 0.14% | — | Intel Advanced Link Analyzer | 11/8/2023 | 17/6/2026 | Incorrect default permissions in some Intel(R) Advanced Link Analyzer Standard Edition software installers before version 22.1 .1 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (6.7) | 0.18% | — | Intel Advisor FOR OneapiIntel CPU Runtime FOR Opencl ApplicationsIntel Distribution FOR Python Programming LanguageIntel Dpc++ Compatibility Tool+25 | 11/8/2023 | 17/6/2026 | Improper access control in some Intel(R) oneAPI Toolkit and component software installers before version 4.3.1.493 may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (6.1) | 5.3% | 💥 Exploit | Adiscon Loganalyzer | 8/8/2023 | 17/6/2026 | A Cross Site Scripting (XSS) vulnerability in Adiscon Aiscon LogAnalyzer through 4.1.13 allows a remote attacker to execute arbitrary code via the asktheoracle.php, details.php, index.php, search.php, export.php, reports.php, and statistics.php components. | |
| Modificada | Media (6.1) | 0.50% | — | Solarwinds Database Performance Analyzer | 18/7/2023 | 17/6/2026 | XSS attack was possible in DPA 2023.2 due to insufficient input validation | |
| Modificada | Media (6.7) | 0.18% | — | Fortinet FortianalyzerFortinet FortimanagerFortinet FortiproxyFortinet Fortios | 18/7/2023 | 17/6/2026 | A buffer copy without checking size of input ('classic buffer overflow') in Fortinet FortiAnalyzer version 7.0.2 and below, version 6.4.7 and below, version 6.2.9 and below, version 6.0.11 and below, version 5.6.11 and below, FortiManager version 7.0.2 and below, version 6.4.7 and below, version 6.2.9 and below,… | |
| Modificada | Media (6.5) | 0.55% | — | Fortinet FortianalyzerFortinet Fortimanager | 11/7/2023 | 17/6/2026 | An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-23] in FortiAnalyzer and FortiManager management interface 7.2.0 through 7.2.1, 7.0.0 through 7.0.5, 6.4 all versions may allow a remote and authenticated attacker to retrieve arbitrary files from the underlying… | |
| Modificada | Crítica (9.8) | 24% | 💥 PoC | Adiscon Loganalyzer | 20/6/2023 | 17/6/2026 | Adiscon LogAnalyzer v4.1.13 and before is vulnerable to SQL Injection. | |
| Modificada | Media (6.5) | 0.38% | — | Fortinet FortianalyzerFortinet Fortimanager | 13/6/2023 | 17/6/2026 | A server-side request forgery (SSRF) vulnerability [CWE-918] in FortiManager and FortiAnalyzer GUI 7.2.0 through 7.2.1, 7.0.0 through 7.0.6, 6.4.8 through 6.4.11 may allow a remote and authenticated attacker to access unauthorized files and services on the system via specially crafted web requests. | |
| Modificada | Media (6.1) | 0.38% | — | Hitachi OPS Center Analyzer | 23/5/2023 | 17/6/2026 | Cross-site Scripting vulnerability in Hitachi Ops Center Analyzer (Hitachi Ops Center Analyzer detail view component) allows Reflected XSS.This issue affects Hitachi Ops Center Analyzer: from 10.9.1-00 before 10.9.2-00. | |
| Modificada | Alta (7.8) | 0.16% | — | Intel Trace Analyzer AND Collector | 12/5/2023 | 17/6/2026 | Uncontrolled search path in the Intel(R) Trace Analyzer and Collector before version 2020 update 3 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.8) | 0.19% | — | Intel Oneapi HPC ToolkitIntel Trace Analyzer AND Collector | 10/5/2023 | 17/6/2026 | Out-of-bounds write for some Intel(R) Trace Analyzer and Collector software before version 2021.8.0 published Dec 2022 may allow an authenticated user to potentially escalation of privilege via local access. | |
| Modificada | Media (5.5) | 0.18% | — | Intel Oneapi HPC ToolkitIntel Trace Analyzer AND Collector | 10/5/2023 | 17/6/2026 | Out-of-bounds read for some Intel(R) Trace Analyzer and Collector software before version 2021.8.0 published Dec 2022 may allow an authenticated user to potentially enable information disclosure via local access. | |
| Modificada | Alta (7.8) | 0.19% | — | Intel Oneapi HPC ToolkitIntel Trace Analyzer AND Collector | 10/5/2023 | 17/6/2026 | Stack-based buffer overflow for some Intel(R) Trace Analyzer and Collector software before version 2021.8.0 published Dec 2022 may allow an authenticated user to potentially escalation of privilege via local access. | |
| Modificada | Alta (7.8) | 0.20% | — | Intel Oneapi HPC ToolkitIntel Trace Analyzer AND Collector | 10/5/2023 | 17/6/2026 | Stack-based buffer overflow for some Intel(R) Trace Analyzer and Collector software before version 2021.8.0 published Dec 2022 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.8) | 0.21% | — | Intel AdvisorIntel CPU RuntimeIntel Distribution FOR PythonIntel Dpc++ Compatibility Tool+25 | 10/5/2023 | 17/6/2026 | Uncontrolled search path in some Intel(R) oneAPI Toolkit and component software installers before version 4.3.0.251 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (5.5) | 0.18% | — | Intel Oneapi HPC ToolkitIntel Trace Analyzer AND Collector | 10/5/2023 | 17/6/2026 | Null pointer dereference for some Intel(R) Trace Analyzer and Collector software before version 2021.8.0 published Dec 2022 may allow an authenticated user to potentially enable information disclosure via local access. | |
| Modificada | Media (6.5) | 1.3% | — | Solarwinds Database Performance Analyzer | 25/4/2023 | 17/6/2026 | Directory traversal and file enumeration vulnerability which allowed users to enumerate to different folders of the server. | |
| Modificada | Alta (7.5) | 0.81% | — | Solarwinds Database Performance Analyzer | 25/4/2023 | 17/6/2026 | No exception handling vulnerability which revealed sensitive or excessive information to users. | |
| Modificada | Alta (8.1) | 0.27% | — | Fortinet FortianalyzerFortinet Fortimanager | 11/4/2023 | 17/6/2026 | An improper certificate validation vulnerability [CWE-295] in FortiAnalyzer and FortiManager 7.2.0 through 7.2.1, 7.0.0 through 7.0.5, 6.4.8 through 6.4.10 may allow a remote and unauthenticated attacker to perform a Man-in-the-Middle attack on the communication channel between the device and the remote FortiGuard… | |
| Modificada | Media (5.5) | 0.19% | — | Fortinet Fortianalyzer | 11/4/2023 | 17/6/2026 | An improper input validation vulnerability [CWE-20] in FortiAnalyzer version 7.2.1 and below, version 7.0.6 and below, 6.4 all versions may allow an authenticated attacker to disclose file system information via custom dataset SQL queries. |