Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
196 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 5.7% | 💥 Exploit | Dlink Central Wifimanager | 8/10/2018 | 17/6/2026 | An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. The 'username' parameter of the addUser endpoint is vulnerable to stored XSS. | |
| Modificada | Crítica (9.8) | 38% | 💥 Exploit | Dlink Central Wifimanager | 8/10/2018 | 17/6/2026 | An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. They expose an FTP server that serves by default on port 9000 and has hardcoded credentials (admin, admin). Taking advantage of this, a remote unauthenticated attacker could execute arbitrary PHP code by uploading any file in the web root… | |
| Modificada | Media (4.3) | 0.70% | — | Fortinet Fortimanager | 5/9/2018 | 17/6/2026 | An information disclosure vulnerability in Fortinet FortiManager 6.0.1 and below versions allows a standard user with adom assignment read the interface settings of vdoms unrelated to the assigned adom. | |
| Modificada | Media (6.1) | 0.87% | — | Fortinet Fortianalyzer FirmwareFortinet Fortimanager Firmware | 16/7/2018 | 17/6/2026 | A Cross-site Scripting (XSS) vulnerability in Fortinet FortiManager 6.0.0, 5.6.4 and below versions, FortiAnalyzer 6.0.0, 5.6.4 and below versions allows inject Javascript code and HTML tags through the CN value of CA and CRL certificates via the import CA and CRL certificates feature. | |
| Modificada | Media (6.1) | 0.58% | — | Netiq Imanager | 10/7/2018 | 17/6/2026 | NetIQ iManager 3.1.1 addresses potential XSS vulnerabilities. | |
| Modificada | Media (4.8) | 1.2% | — | Fortinet Fortimanager | 28/6/2018 | 17/6/2026 | A Cross-site Scripting (XSS) vulnerability in Fortinet FortiManager 6.0.0, 5.6.6 and below versions allows attacker to execute HTML/javascript code via managed remote devices CLI commands by viewing the remote device CLI config installation log. | |
| Modificada | Media (6.1) | 1.6% | — | Fortinet FortianalyzerFortinet Fortimanager | 27/6/2018 | 17/6/2026 | An open redirect vulnerability in Fortinet FortiManager 6.0.0, 5.6.5 and below versions, FortiAnalyzer 6.0.0, 5.6.5 and below versions allows attacker to inject script code during converting a HTML table to a PDF document under the FortiView feature. An attacker may be able to social engineer an authenticated user… | |
| Modificada | Media (6.5) | 1.7% | — | Fortinet FortianalyzerFortinet Fortimanager | 27/6/2018 | 17/6/2026 | An improper access control vulnerability in Fortinet FortiManager 6.0.0, 5.6.5 and below versions, FortiAnalyzer 6.0.0, 5.6.5 and below versions allows a regular user edit the avatar picture of other users with arbitrary content. | |
| Modificada | Media (6.1) | 0.73% | — | Netiq Imanager | 21/3/2018 | 17/6/2026 | The administrative web interface in NetIQ iManager, versions prior to 3.1, are vulnerable to reflected cross site scripting. | |
| Modificada | Alta (8.8) | 0.65% | — | Netiq Imanager | 21/3/2018 | 17/6/2026 | NetIQ iManager, versions prior to 3.1, under some circumstances could be susceptible to an elevation of privilege attack. | |
| Modificada | Alta (8.6) | 0.86% | — | Netiq Imanager | 21/3/2018 | 17/6/2026 | Addresses potential communication downgrade attack in NetIQ iManager versions prior to 3.1 | |
| Modificada | Alta (7.5) | 1.2% | — | Netiq Imanager | 2/3/2018 | 17/6/2026 | NetIQ iManager before 3.0.3 delivered a SSL private key in a Java application (JAR file) for authentication to Sentinel, allowing attackers to extract and establish their own connections to the Sentinel appliance. | |
| Modificada | Media (6.1) | 0.89% | — | Netiq Imanager | 6/11/2017 | 17/6/2026 | Multiple potential reflected XSS issues exist in NetIQ iManager versions before 2.7.7 Patch 10 HF2 and 3.0.3.2. | |
| Modificada | Alta (7.8) | 0.39% | — | Fortinet Fortimanager Firmware | 22/8/2017 | 17/6/2026 | Fortinet FortiManager 5.0 before 5.0.11 and 5.2 before 5.2.2 allow local users to gain privileges via crafted CLI commands. | |
| Modificada | Crítica (9.8) | 2.3% | — | Fortinet Fortimanager Firmware | 11/8/2017 | 17/6/2026 | SQL injection vulnerability in Fortinet FortiManager 5.0.x before 5.0.11, 5.2.x before 5.2.2 allows remote attackers to execute arbitrary commands via unspecified parameters. | |
| Modificada | Media (5.4) | 1.2% | — | Fortinet Fortimanager Firmware | 11/8/2017 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Fortinet FortiManager 5.0.x before 5.0.11, 5.2.x before 5.2.2 allows remote authenticated users to inject arbitrary web script or HTML via vectors involving unspecified parameters and a privilege escalation attack. | |
| Modificada | Alta (7.5) | 2.0% | — | Fortinet Fortimanager Firmware | 11/8/2017 | 17/6/2026 | Fortinet FortiManager 5.0.x before 5.0.11, 5.2.x before 5.2.2 allows remote attackers to obtain arbitrary files via vectors involving another unspecified vulnerability. | |
| Modificada | Media (6.1) | 0.94% | — | Fortinet Fortianalyzer FirmwareFortinet Fortimanager Firmware | 27/5/2017 | 17/6/2026 | An Open Redirect vulnerability in Fortinet FortiAnalyzer 5.4.0 through 5.4.2 and FortiManager 5.4.0 through 5.4.2 allows attacker to execute unauthorized code or commands via the next parameter. | |
| Modificada | Crítica (9.8) | 1.5% | — | Novell ImanagerNetiq Imanager | 3/5/2017 | 17/6/2026 | Novell iManager 2.7.x before 2.7 SP7 Patch 10 HF1 and NetIQ iManager 3.x before 3.0.3.1 have a webshell upload vulnerability. | |
| Modificada | Alta (8.8) | 0.58% | — | Novell ImanagerNetiq Imanager | 3/5/2017 | 17/6/2026 | Novell iManager 2.7.x before 2.7 SP7 Patch 10 HF1 and NetIQ iManager 3.x before 3.0.3.1 have persistent CSRF in object management. | |
| Modificada | Media (6.1) | 1.0% | — | Novell ImanagerNetiq Imanager | 3/5/2017 | 17/6/2026 | Novell iManager 2.7.x before 2.7 SP7 Patch 10 HF1 and NetIQ iManager 3.x before 3.0.3.1 have a persistent XSS vulnerability in Framework. | |
| Modificada | Media (5.3) | 1.3% | — | Netiq Imanager | 3/5/2017 | 17/6/2026 | NetIQ iManager 3.x before 3.0.3.1 has an issue in the renegotiation of connection parameters with Tomcat. | |
| Modificada | Alta (7.5) | 0.65% | — | Netiq EdirectoryNetiq ImanagerNovell EdirectoryNovell Imanager | 27/4/2017 | 17/6/2026 | Novell iManager 2.7 before SP7 Patch 9, NetIQ iManager 3.x before 3.0.2.1, Novell eDirectory 8.8.x before 8.8 SP8 Patch 9 Hotfix 2, and NetIQ eDirectory 9.x before 9.0.2 Hotfix 2 (9.0.2.2) use the deprecated MD5 hashing algorithm in a communications certificate. | |
| Modificada | Alta (7.4) | 0.90% | — | Fortinet Fortimanager Firmware | 13/2/2017 | 17/6/2026 | An improper certificate validation vulnerability in Fortinet FortiManager 5.0.6 through 5.2.7 and 5.4.0 through 5.4.1 allows remote attacker to spoof a trusted entity by using a man-in-the-middle (MITM) attack via the Fortisandbox devices probing feature. | |
| Modificada | Media (5.4) | 0.70% | — | Fortinet Fortimanager FirmwareFortinet Fortianalyzer Firmware | 7/10/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the advanced settings page in Fortinet FortiManager 5.x before 5.0.12 and 5.2.x before 5.2.3, in hardware models with a hard disk, and FortiAnalyzer 5.x before 5.0.13 and 5.2.x before 5.2.3 allows remote administrators to inject arbitrary web script or HTML via vectors… |