Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2635▼ 214 respecto a la semana anterior
Críticas / altas1385▲ 153 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
447 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (5.3) | 0.97% | — | Zoho Eventlog AnalyzerAIZoho Log360AI | 24/9/2026 | 24/9/2026 | ZohoCorp ManageEngine EventLog Analyzer and Log360 before build 13071 were vulnerable to a DoS vulnerability that allowed attackers to crash the log collector using malformed syslog packets. | |
| Pendiente de análisis | Alta (7.4) | 0.39% | — | Zohocorp Manageengine OpmanagerAIZohocorp Manageengine Firewall AnalyzerAI | 23/9/2026 | 23/9/2026 | ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.709 and below were vulnerable to a Data Exposure vulnerability in the Firewall Analyzer syslog collector. | |
| Pendiente de análisis | Alta (7.7) | 1.1% | — | Zoho Manageengine OpmanagerAIZoho Manageengine Firewall AnalyzerAI | 23/9/2026 | 23/9/2026 | ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.709 and below were vulnerable to an XML Injection vulnerability in the Rule Tracking Compare Policies feature. | |
| Pendiente de análisis | Alta (8.8) | 3.7% | — | Zoho Manageengine OpmanagerAIZoho Manageengine Firewall AnalyzerAI | 23/9/2026 | 24/9/2026 | ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.709 and below were vulnerable to a Command Injection vulnerability in the Diagnose Settings feature. | |
| Pendiente de análisis | Alta (7.1) | 0.60% | — | Zoho Manageengine OpmanagerAIZoho Manageengine Firewall AnalyzerAI | 23/9/2026 | 23/9/2026 | ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.710 and below were vulnerable to a Broken Access Control vulnerability that allowed an authenticated low-privilege user to modify Change Management report schedule configurations for firewalls outside their assigned scope. | |
| Pendiente de análisis | Alta (7.1) | 0.60% | — | Zoho Manageengine OpmanagerAIZoho Manageengine Firewall AnalyzerAI | 23/9/2026 | 23/9/2026 | ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.710 and below were vulnerable to a Broken Access Control vulnerability that allowed an authenticated low-privilege user to create alert notifications for firewalls outside their assigned scope. | |
| Pendiente de análisis | Alta (8.1) | 0.85% | — | Zoho Manageengine OpmanagerAIZoho Manageengine Firewall AnalyzerAI | 23/9/2026 | 24/9/2026 | ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.710 and below were vulnerable to a Privilege Escalation vulnerability that allowed an authenticated low-privilege user to gain Administrator privileges through Report Profile import. | |
| Pendiente de análisis | Alta (8.8) | 0.97% | — | Zoho Manageengine OpmanagerAIZoho Manageengine Firewall AnalyzerAI | 23/9/2026 | 24/9/2026 | ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.669 and below were vulnerable to an SQL Injection vulnerability in Rule Management Search Reports. | |
| Pendiente de análisis | Alta (7.6) | 1.5% | — | Zohocorp Manageengine OpmanagerAIZohocorp Netflow AnalyzerAIZohocorp Network Configuration ManagerAI | 23/9/2026 | 24/9/2026 | ZohoCorp ManageEngine OpManager, NetFlow Analyzer, and Network Configuration Manager versions 12.8.667 and below were vulnerable to a Server-Side Template Injection vulnerability in Configlet processing, which could lead to Remote Code Execution. | |
| Aplazada | Baja (2.1) | 0.47% | — | 00kisumi00 Mcp-file-analyzerAI | 20/9/2026 | 22/9/2026 | A weakness has been identified in 00Kisumi00 mcp-file-analyzer up to 84740852f0cf0cf5db4781b1ca6d7c6a6d210405. This affects the function ControlFlowNode of the file main.py of the component analyze_csv_data MCP tool. This manipulation of the argument filename causes path traversal. Remote exploitation of the attack is… | |
| Pendiente de análisis | Media (6.5) | 0.41% | — | Fortinet FortianalyzerAI | 8/9/2026 | 8/9/2026 | A use of uninitialized variable vulnerability in Fortinet FortiAnalyzer 7.6.3 through 7.6.6 may allow attacker to denial of service via <insert attack vector here> | |
| Aplazada | Media (6.1) | 0.14% | — | Radcom Horizon Security AnalyzerAI | 8/9/2026 | 8/9/2026 | Improper Privilege Management vulnerability in Horizon Security Analyzer (formerly AlgoSec Firewall Analyzer) on Linux, 64 bit allows Privilege Escalation and Parameter Injection. A local user with access to the command line may escalate their privileges by abusing the parameters of a command that is approved in the… | |
| Pendiente de análisis | Media (4.1) | 0.10% | — | HCL Bigfix Quantum Risk AnalyzerAI | 26/8/2026 | 28/8/2026 | HCL BigFix Quantum Risk Analyzer generates highly detailed logging information by default which increases the risk of sensitive data leakage and can provide an attacker with internal application logic and architectural details. | |
| Pendiente de análisis | Baja (3.9) | 0.09% | — | HCL Bigfix Quantum Risk AnalyzerAI | 26/8/2026 | 28/8/2026 | HCL BigFix Quantum Risk Analyzer binary lacks several critical, industry-standard hardening protections that could allow an attacker to cause a stack-based buffer overflow. | |
| Pendiente de análisis | Media (4.4) | 0.07% | — | HCL Bigfix Quantum Risk AnalyzerAI | 26/8/2026 | 28/8/2026 | HCL BigFix Quantum Risk Analyzer is affected by a hardcoded external resource reference and a lack of binary integrity which could allow an attacker to obtain sensitive information or modify the binary. | |
| Pendiente de análisis | Baja (3.9) | 0.09% | — | HCL Bigfix Quantum Risk AnalyzerAI | 26/8/2026 | 28/8/2026 | HCL BigFix Quantum Risk Analyzer has a certain validation process that provides overly descriptive error messages when it encounters malformed input which can allow an attacker to conduct more efficient reconnaissance and fine-tune automated fuzzing tools to produce valid input. | |
| Pendiente de análisis | Media (4.3) | 0.19% | — | Attack Analyzer Connector FOR Splunk SoarAI | 19/8/2026 | 20/8/2026 | In versions below 2.2.1 of the Splunk Attack Analyzer Connector for Splunk SOAR, a user who holds a role with permission to run actions could expose a sensitive archive password by invoking either the detonate file or detonate url action, because the action's archive_password parameter is not masked and is shown in… | |
| Aplazada | Baja (1.9) | 0.17% | — | Azer React Analyzer MCPAI | 9/8/2026 | 12/8/2026 | A security flaw has been discovered in azer react-analyzer-mcp up to 335f2a3585f265e2e88352b59b10d3b478d678b0. Affected by this vulnerability is the function generateProjectDocs of the file src/index.ts of the component analyze-projec. The manipulation of the argument projectName results in path traversal. The attack… | |
| Analizada | Alta (8.3) | 0.14% | — | Thermofisher ABI Prism 310 Data Collection SoftwareThermofisher ABI Prism 3100/3100-avant Data Collection SoftwareThermofisher Applied Biosystems 3130 Series Data Collection SoftwareThermofisher Applied Biosystems 3500/3500xl Series Data Collection Software+4 | 5/8/2026 | 26/8/2026 | The affected Thermo Fisher Applied Biosystems Genetic Analyzers are vulnerable because .fsa/.hid output files can be edited. An attacker could tamper with these files, altering DNA data and resulting in inaccurate DNA test outcomes. | |
| Analizada | Media (5.4) | 0.23% | — | J-vee AI Seo/geo Analyzer | 10/7/2026 | 6/8/2026 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal AI SEO/GEO Analyzer allows Stored XSS. This issue affects AI SEO/GEO Analyzer versions: from 0.0.0 to 1.1.3. | |
| Pendiente de análisis | Media (5.6) | 0.39% | — | Solarwinds Database Performance AnalyzerAI | 30/6/2026 | 2/7/2026 | SolarWinds Database Performance Analyzer was found to be affected by a stored cross-site scripting vulnerability, which when exploited, can lead to unintended script execution. | |
| Aplazada | Media (4.6) | 0.20% | — | Hitachi OPS Center AnalyzerAIHitachi OPS Center Analyzer ViewpointAIHitachi Infrastructure Analytics AdvisorAI | 26/5/2026 | 24/7/2026 | Missing password field masking vulnerability in Hitachi Ops Center Analyzer (Hitachi Ops Center Analyzer detail view, Hitachi Ops Center Analyzer probe modules), Hitachi Ops Center Analyzer viewpoint, Hitachi Infrastructure Analytics Advisor (Data Center Analytics, Analytics probe modules). This issue affects Hitachi… | |
| Analizada | Media (5.3) | 0.42% | — | Fortinet FortianalyzerFortinet Fortimanager | 12/5/2026 | 17/6/2026 | A use of potentially dangerous function vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 through 7.4.8, FortiAnalyzer 7.2 all versions, FortiAnalyzer 7.0 all versions, FortiAnalyzer 6.4 all versions, FortiManager 7.6.0 through 7.6.4, FortiManager 7.4.0 through 7.4.8, FortiManager 7.2… | |
| Analizada | Alta (8.1) | 0.90% | — | Fortinet Fortianalyzer CloudFortinet Fortimanager Cloud | 14/4/2026 | 17/6/2026 | A heap-based buffer overflow vulnerability in Fortinet FortiAnalyzer Cloud 7.6.2 through 7.6.4, FortiManager Cloud 7.6.2 through 7.6.4 may allow a remote unauthenticated attacker to execute arbitrary code or commands via specifically crafted requests. Successful exploitation would require a large amount of effort in… | |
| Analizada | Media (6.5) | 0.41% | — | Fortinet Fortimanager CloudFortinet FortimanagerFortinet Fortianalyzer CloudFortinet Fortianalyzer | 14/4/2026 | 17/6/2026 | An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 through 7.4.7, FortiAnalyzer 7.2 all versions, FortiAnalyzer 7.0 all versions, FortiAnalyzer Cloud 7.6.0 through 7.6.4, FortiAnalyzer Cloud 7.4.0 through… |