Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

196 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)5.7%💥 ExploitDlink Central Wifimanager8/10/201817/6/2026
An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. The 'username' parameter of the addUser endpoint is vulnerable to stored XSS.
ModificadaCrítica (9.8)38%💥 ExploitDlink Central Wifimanager8/10/201817/6/2026
An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. They expose an FTP server that serves by default on port 9000 and has hardcoded credentials (admin, admin). Taking advantage of this, a remote unauthenticated attacker could execute arbitrary PHP code by uploading any file in the web root…
ModificadaMedia (4.3)0.70%—Fortinet Fortimanager5/9/201817/6/2026
An information disclosure vulnerability in Fortinet FortiManager 6.0.1 and below versions allows a standard user with adom assignment read the interface settings of vdoms unrelated to the assigned adom.
ModificadaMedia (6.1)0.87%—Fortinet Fortianalyzer FirmwareFortinet Fortimanager Firmware16/7/201817/6/2026
A Cross-site Scripting (XSS) vulnerability in Fortinet FortiManager 6.0.0, 5.6.4 and below versions, FortiAnalyzer 6.0.0, 5.6.4 and below versions allows inject Javascript code and HTML tags through the CN value of CA and CRL certificates via the import CA and CRL certificates feature.
ModificadaMedia (6.1)0.58%—Netiq Imanager10/7/201817/6/2026
NetIQ iManager 3.1.1 addresses potential XSS vulnerabilities.
ModificadaMedia (4.8)1.2%—Fortinet Fortimanager28/6/201817/6/2026
A Cross-site Scripting (XSS) vulnerability in Fortinet FortiManager 6.0.0, 5.6.6 and below versions allows attacker to execute HTML/javascript code via managed remote devices CLI commands by viewing the remote device CLI config installation log.
ModificadaMedia (6.1)1.6%—Fortinet FortianalyzerFortinet Fortimanager27/6/201817/6/2026
An open redirect vulnerability in Fortinet FortiManager 6.0.0, 5.6.5 and below versions, FortiAnalyzer 6.0.0, 5.6.5 and below versions allows attacker to inject script code during converting a HTML table to a PDF document under the FortiView feature. An attacker may be able to social engineer an authenticated user…
ModificadaMedia (6.5)1.7%—Fortinet FortianalyzerFortinet Fortimanager27/6/201817/6/2026
An improper access control vulnerability in Fortinet FortiManager 6.0.0, 5.6.5 and below versions, FortiAnalyzer 6.0.0, 5.6.5 and below versions allows a regular user edit the avatar picture of other users with arbitrary content.
ModificadaMedia (6.1)0.73%—Netiq Imanager21/3/201817/6/2026
The administrative web interface in NetIQ iManager, versions prior to 3.1, are vulnerable to reflected cross site scripting.
ModificadaAlta (8.8)0.65%—Netiq Imanager21/3/201817/6/2026
NetIQ iManager, versions prior to 3.1, under some circumstances could be susceptible to an elevation of privilege attack.
ModificadaAlta (8.6)0.86%—Netiq Imanager21/3/201817/6/2026
Addresses potential communication downgrade attack in NetIQ iManager versions prior to 3.1
ModificadaAlta (7.5)1.2%—Netiq Imanager2/3/201817/6/2026
NetIQ iManager before 3.0.3 delivered a SSL private key in a Java application (JAR file) for authentication to Sentinel, allowing attackers to extract and establish their own connections to the Sentinel appliance.
ModificadaMedia (6.1)0.89%—Netiq Imanager6/11/201717/6/2026
Multiple potential reflected XSS issues exist in NetIQ iManager versions before 2.7.7 Patch 10 HF2 and 3.0.3.2.
ModificadaAlta (7.8)0.39%—Fortinet Fortimanager Firmware22/8/201717/6/2026
Fortinet FortiManager 5.0 before 5.0.11 and 5.2 before 5.2.2 allow local users to gain privileges via crafted CLI commands.
ModificadaCrítica (9.8)2.3%—Fortinet Fortimanager Firmware11/8/201717/6/2026
SQL injection vulnerability in Fortinet FortiManager 5.0.x before 5.0.11, 5.2.x before 5.2.2 allows remote attackers to execute arbitrary commands via unspecified parameters.
ModificadaMedia (5.4)1.2%—Fortinet Fortimanager Firmware11/8/201717/6/2026
Cross-site scripting (XSS) vulnerability in Fortinet FortiManager 5.0.x before 5.0.11, 5.2.x before 5.2.2 allows remote authenticated users to inject arbitrary web script or HTML via vectors involving unspecified parameters and a privilege escalation attack.
ModificadaAlta (7.5)2.0%—Fortinet Fortimanager Firmware11/8/201717/6/2026
Fortinet FortiManager 5.0.x before 5.0.11, 5.2.x before 5.2.2 allows remote attackers to obtain arbitrary files via vectors involving another unspecified vulnerability.
ModificadaMedia (6.1)0.94%—Fortinet Fortianalyzer FirmwareFortinet Fortimanager Firmware27/5/201717/6/2026
An Open Redirect vulnerability in Fortinet FortiAnalyzer 5.4.0 through 5.4.2 and FortiManager 5.4.0 through 5.4.2 allows attacker to execute unauthorized code or commands via the next parameter.
ModificadaCrítica (9.8)1.5%—Novell ImanagerNetiq Imanager3/5/201717/6/2026
Novell iManager 2.7.x before 2.7 SP7 Patch 10 HF1 and NetIQ iManager 3.x before 3.0.3.1 have a webshell upload vulnerability.
ModificadaAlta (8.8)0.58%—Novell ImanagerNetiq Imanager3/5/201717/6/2026
Novell iManager 2.7.x before 2.7 SP7 Patch 10 HF1 and NetIQ iManager 3.x before 3.0.3.1 have persistent CSRF in object management.
ModificadaMedia (6.1)1.0%—Novell ImanagerNetiq Imanager3/5/201717/6/2026
Novell iManager 2.7.x before 2.7 SP7 Patch 10 HF1 and NetIQ iManager 3.x before 3.0.3.1 have a persistent XSS vulnerability in Framework.
ModificadaMedia (5.3)1.3%—Netiq Imanager3/5/201717/6/2026
NetIQ iManager 3.x before 3.0.3.1 has an issue in the renegotiation of connection parameters with Tomcat.
ModificadaAlta (7.5)0.65%—Netiq EdirectoryNetiq ImanagerNovell EdirectoryNovell Imanager27/4/201717/6/2026
Novell iManager 2.7 before SP7 Patch 9, NetIQ iManager 3.x before 3.0.2.1, Novell eDirectory 8.8.x before 8.8 SP8 Patch 9 Hotfix 2, and NetIQ eDirectory 9.x before 9.0.2 Hotfix 2 (9.0.2.2) use the deprecated MD5 hashing algorithm in a communications certificate.
ModificadaAlta (7.4)0.90%—Fortinet Fortimanager Firmware13/2/201717/6/2026
An improper certificate validation vulnerability in Fortinet FortiManager 5.0.6 through 5.2.7 and 5.4.0 through 5.4.1 allows remote attacker to spoof a trusted entity by using a man-in-the-middle (MITM) attack via the Fortisandbox devices probing feature.
ModificadaMedia (5.4)0.70%—Fortinet Fortimanager FirmwareFortinet Fortianalyzer Firmware7/10/201617/6/2026
Cross-site scripting (XSS) vulnerability in the advanced settings page in Fortinet FortiManager 5.x before 5.0.12 and 5.2.x before 5.2.3, in hardware models with a hard disk, and FortiAnalyzer 5.x before 5.0.13 and 5.2.x before 5.2.3 allows remote administrators to inject arbitrary web script or HTML via vectors…
Orbitaley — Vulnerabilidades