Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

447 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.5)0.18%—Hitachi OPS Center Analyzer1/11/202217/6/2026
Insertion of Sensitive Information into Log File vulnerability in Hitachi Ops Center Analyzer on Linux (Virtual Strage Software Agent component) allows local users to gain sensitive information. This issue affects Hitachi Ops Center Analyzer: from 10.8.1-00 before 10.9.0-00
ModificadaMedia (4.4)0.15%—Hitachi Infrastructure Analytics AdvisorHitachi OPS Center AnalyzerHitachi OPS Center Viewpoint1/11/202217/6/2026
Incorrect Default Permissions vulnerability in Hitachi Infrastructure Analytics Advisor on Linux (Analytics probe component), Hitachi Ops Center Analyzer on Linux (Analyzer probe component), Hitachi Ops Center Viewpoint on Linux (Viewpoint RAID Agent component) allows local users to read and write specific files. This…
ModificadaAlta (7.8)0.27%—GrafanaNetapp E-series Performance Analyzer13/10/202217/6/2026
Grafana is an open source observability and data visualization platform. Versions prior to 9.1.8 and 8.5.14 are vulnerable to a bypass in the plugin signature verification. An attacker can convince a server admin to download and successfully run a malicious plugin even though unsigned plugins are not allowed. Versions…
ModificadaMedia (5.3)0.89%—Fortinet FortimanagerFortinet Fortianalyzer10/10/202217/6/2026
An exposure of resource to wrong sphere vulnerability [CWE-668] in FortiAnalyzer and FortiManager GUI 7.0.0 through 7.0.3, 6.4.0 through 6.4.8, 6.2.0 through 6.2.9, 6.0.0 through 6.0.11, 5.6.0 through 5.6.11 may allow an unauthenticated and remote attacker to access report template images via referencing the name in…
ModificadaAlta (8.8)78%—Zohocorp Manageengine Netflow AnalyzerZohocorp Manageengine Network Configuration ManagerZohocorp Manageengine OpmanagerZohocorp Manageengine Opmanager MSP+229/8/202217/6/2026
Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, and OpUtils before 125658, 126003, 126105, and 126120 allow authenticated users to make database changes that lead to remote code execution in the NMAP feature.
ModificadaAlta (7.8)0.75%—GNU GlibcDebian LinuxNetapp E-series Performance AnalyzerNetapp NFS Plug-in+624/8/202217/6/2026
A flaw was found in glibc. An off-by-one buffer overflow and underflow in getcwd() may lead to memory corruption when the size of the buffer is exactly 1. A local attacker who can control the input buffer and size passed to getcwd() in a setuid program could use this flaw to potentially execute arbitrary code and…
ModificadaAlta (8.8)80%—Zohocorp Manageengine Firewall AnalyzerZohocorp Manageengine Netflow AnalyzerZohocorp Manageengine Network Configuration ManagerZohocorp Manageengine Opmanager+310/8/202217/6/2026
Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, and OpUtils before 2022-07-29 through 2022-07-30 ( 125658, 126003, 126105, and 126120) allow authenticated users to make database changes that lead to remote code execution.
AnalizadaAlta (7.5)7.3%💥 ExploitZohocorp Manageengine Firewall AnalyzerZohocorp Manageengine Netflow AnalyzerZohocorp Manageengine Network Configuration ManagerZohocorp Manageengine Opmanager+310/8/202217/6/2026
Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, Firewall Analyzer, and OpUtils before 2022-07-27 through 2022-07-28 (125657, 126002, 126104, and 126118) allow unauthenticated attackers to obtain a user's API key, and then access external APIs.
ModificadaMedia (6.5)1.4%—Synology Storage Analyzer3/8/202217/6/2026
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Synology Storage Analyzer before 2.1.0-0390 allows remote authenticated users to delete arbitrary files via unspecified vectors.
ModificadaAlta (7.2)2.2%—Fortinet FortianalyzerFortinet Fortimanager19/7/202217/6/2026
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiManager version 7.0.0 through 7.0.3, 6.4.0 through 6.4.7, 6.2.x and 6.0.x and FortiAnalyzer version 7.0.0 through 7.0.3, version 6.4.0 through 6.4.7, 6.2.x and 6.0.x allows attacker to execute arbitrary shell…
ModificadaMedia (6.7)0.27%—Fortinet FortianalyzerFortinet Fortimanager18/7/202217/6/2026
A privilege chaining vulnerability [CWE-268] in FortiManager and FortiAnalyzer 6.0.x, 6.2.x, 6.4.0 through 6.4.7, 7.0.0 through 7.0.3 may allow a local and authenticated attacker with a restricted shell to escalate their privileges to root due to incorrect permissions of some folders and executable files on the system.
ModificadaAlta (8.2)2.9%—Zohocorp Manageengine OpmanagerZohocorp Manageengine Network Configuration ManagerZohocorp Manageengine Netflow AnalyzerZohocorp Manageengine Firewall Analyzer18/7/202217/6/2026
ManageEngine Password Manager Pro 12100 and prior and OPManager 126100 and prior are vulnerable to unauthorized file and directory creation on a server machine.
ModificadaAlta (7.5)2.9%—GrafanaNetapp E-series Performance Analyzer15/7/202217/6/2026
Grafana is an open-source platform for monitoring and observability. In versions 5.3 until 9.0.3, 8.5.9, 8.4.10, and 8.3.10, it is possible for a malicious user who has authorization to log into a Grafana instance via a configured OAuth IdP which provides a login name to take over the account of another user in that…
ModificadaAlta (8.7)70%—GrafanaNetapp E-series Performance Analyzer15/7/202217/6/2026
Grafana is an open-source platform for monitoring and observability. Versions on the 8.x and 9.x branch prior to 9.0.3, 8.5.9, 8.4.10, and 8.3.10 are vulnerable to stored cross-site scripting via the Unified Alerting feature of Grafana. An attacker can exploit this vulnerability to escalate privilege from editor to…
ModificadaMedia (6.1)3.2%—Solarwinds Database Performance AnalyzerSolarwinds Database Performance Monitor21/4/202217/6/2026
Cross-site scripting vulnerability is present in Database Performance Monitor 2022.1.7779 and previous versions when using a complex SQL query
ModificadaAlta (7.8)3.0%—Fortinet FortianalyzerFortinet FortimanagerFortinet Fortiportal6/4/202217/6/2026
Multiple OS command injection (CWE-78) vulnerabilities in the command line interface of FortiManager 6.2.7 and below, 6.4.5 and below and all versions of 6.2.x, 6.0.x and 5.6.x, FortiAnalyzer 6.2.7 and below, 6.4.5 and below and all versions of 6.2.x, 6.0.x and 5.6.x, and FortiPortal 5.2.5 and below, 5.3.5 and below…
ModificadaAlta (8.8)0.91%—Fortinet FortianalyzerFortinet Fortimanager1/3/202217/6/2026
A improper handling of insufficient permissions or privileges in Fortinet FortiAnalyzer version 5.6.0 through 5.6.11, FortiAnalyzer version 6.0.0 through 6.0.11, FortiAnalyzer version 6.2.0 through 6.2.9, FortiAnalyzer version 6.4.0 through 6.4.7, FortiAnalyzer version 7.0.0 through 7 .0.2, FortiManager version 5.6.0…
ModificadaMedia (5.5)0.25%—Intel Trace Analyzer AND Collector9/2/202217/6/2026
Out-of-bounds read in the Intel(R) Trace Analyzer and Collector before version 2021.5 may allow an authenticated user to potentially enable information disclosure via local access.
ModificadaMedia (5.5)0.25%—Intel Trace Analyzer AND Collector9/2/202217/6/2026
Uncaught exception in the Intel(R) Trace Analyzer and Collector before version 2021.5 may allow an authenticated user to potentially enable information disclosure via local access.
ModificadaMedia (5.5)0.23%—Intel Trace Analyzer AND Collector9/2/202217/6/2026
Access of uninitialized pointer in the Intel(R) Trace Analyzer and Collector before version 2021.5 may allow an authenticated user to potentially enable denial of service via local access.
ModificadaMedia (5.5)0.23%—Intel Trace Analyzer AND Collector9/2/202217/6/2026
Out-of-bounds read in the Intel(R) Trace Analyzer and Collector before version 2021.5 may allow an authenticated user to potentially enable denial of service via local access.
ModificadaAlta (7.8)0.24%—Intel Graphics Performance Analyzers9/2/202217/6/2026
Uncontrolled search path in the Intel(R) GPA software before version 21.2 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaMedia (4.3)1.2%—GrafanaNetapp E-series Performance AnalyzerFedoraproject Fedora8/2/202217/6/2026
Grafana is an open-source platform for monitoring and observability. Affected versions of Grafana expose multiple API endpoints which do not properly handle user authorization. `/teams/:teamId` will allow an authenticated attacker to view unintended data by querying for the specific team ID, `/teams/:search` will…
ModificadaAlta (8.8)2.3%—GrafanaNetapp E-series Performance AnalyzerFedoraproject Fedora8/2/202217/6/2026
Grafana is an open-source platform for monitoring and observability. Affected versions are subject to a cross site request forgery vulnerability which allows attackers to elevate their privileges by mounting cross-origin attacks against authenticated high-privilege Grafana users (for example, Editors or Admins). An…
ModificadaMedia (5.4)2.3%—GrafanaNetapp E-series Performance AnalyzerFedoraproject Fedora8/2/202217/6/2026
Grafana is an open-source platform for monitoring and observability. In affected versions an attacker could serve HTML content thru the Grafana datasource or plugin proxy and trick a user to visit this HTML page using a specially crafted link and execute a Cross-site Scripting (XSS) attack. The attacker could either…