Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3007▼ 67 respecto a la semana anterior
Críticas / altas1403▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)390▼ 120 respecto a la semana anterior
13 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.2) | 0.45% | — | Fortinet FortianalyzerFortinet Fortianalyzer BIG Data | 10/3/2026 | 17/6/2026 | An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 through 7.4.7, FortiAnalyzer 7.2 all versions, FortiAnalyzer 7.0 all versions, FortiAnalyzer 6.4 all versions, FortiAnalyzer-BigData 7.6.0,… | |
| Analizada | Media (6.7) | 0.18% | — | Fortinet FortianalyzerFortinet Fortianalyzer BIG DataFortinet Fortimanager | 11/3/2025 | 17/6/2026 | Two improper neutralization of special elements used in an SQL Command ('SQL Injection') vulnerability [CWE-89] in Fortinet FortiAnalyzer version 7.4.0 through 7.4.2 and before 7.2.5, FortiManager version 7.4.0 through 7.4.2 and before 7.2.5 and FortiAnalyzer-BigData version 7.4.0 and before 7.2.7 allows a privileged… | |
| Analizada | Media (6.7) | 0.44% | — | Fortinet FortianalyzerFortinet Fortianalyzer BIG DataFortinet Fortimanager | 11/3/2025 | 17/6/2026 | Multiple improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiManager, FortiAnalyzer versions 7.4.0 through 7.4.2 7.2.0 through 7.2.5 and 7.0.0 through 7.0.12 and 6.4.0 through 6.4.14 and 6.2.0 through 6.2.12 and 6.0.0 through 6.0.12 and 5.6.0 through 5.6.11 and… | |
| Analizada | Alta (7.2) | 2.0% | — | Fortinet Fortimanager CloudFortinet FortimanagerFortinet Fortianalyzer BIG DataFortinet Fortianalyzer Cloud+1 | 11/2/2025 | 17/6/2026 | An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiAnalyzer version 7.4.0 through 7.4.3, 7.2.0 through 7.2.5, 7.0.0 through 7.0.13, 6.4.0 through 6.4.15 and 6.2.2 through 6.2.13, Fortinet FortiManager version 7.4.0 through 7.4.3, 7.2.0… | |
| Analizada | Baja (2.3) | 0.24% | — | Fortinet FortianalyzerFortinet Fortianalyzer BIG DataFortinet Fortimanager | 12/11/2024 | 17/6/2026 | An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in Fortinet FortiAnalyzer versions below 7.4.2, Fortinet FortiManager versions below 7.4.2 and Fortinet FortiAnalyzer-BigData version 7.4.0 and below 7.2.7 allows a privileged attacker with read write… | |
| Analizada | Media (6.7) | 0.61% | — | Fortinet FortianalyzerFortinet Fortianalyzer BIG DataFortinet Fortimanager | 12/11/2024 | 17/6/2026 | Multiple improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] in Fortinet FortiManager version 7.4.0 through 7.4.2 and before 7.2.5, Fortinet FortiAnalyzer version 7.4.0 through 7.4.2 and before 7.2.5 and Fortinet FortiAnalyzer-BigData before 7.4.0 allows… | |
| Analizada | Media (4.9) | 0.85% | — | Fortinet FortianalyzerFortinet Fortianalyzer BIG DataFortinet Fortimanager | 12/11/2024 | 17/6/2026 | An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in Fortinet FortiManager version 7.4.0 through 7.4.2 and below 7.2.5, FortiAnalyzer version 7.4.0 through 7.4.2 and below 7.2.5 & FortiAnalyzer-BigData version 7.4.0 and below 7.2.7 allows a privileged attacker to… | |
| Analizada | Media (6) | 0.24% | — | Fortinet FortianalyzerFortinet Fortianalyzer BIG DataFortinet Fortimanager | 12/11/2024 | 17/6/2026 | Multiple relative path traversal vulnerabilities [CWE-23] in Fortinet FortiManager version 7.4.0 through 7.4.2 and before 7.2.5, FortiAnalyzer version 7.4.0 through 7.4.2 and before 7.2.5 and FortiAnalyzer-BigData version 7.4.0 and before 7.2.7 allows a privileged attacker to delete files from the underlying… | |
| Analizada | Media (6.7) | 0.23% | — | Fortinet FortianalyzerFortinet Fortianalyzer BIG DataFortinet Fortimanager | 12/11/2024 | 17/6/2026 | A stack-based buffer overflow vulnerability [CWE-121] in Fortinet FortiManager version 7.4.0 through 7.4.2 and before 7.2.5, FortiAnalyzer version 7.4.0 through 7.4.2 and before 7.2.5 and FortiAnalyzer-BigData 7.4.0 and before 7.2.7 allows a privileged attacker to execute unauthorized code or commands via crafted CLI… | |
| Analizada | Alta (8.8) | 2.7% | — | Fortinet FortianalyzerFortinet Fortianalyzer BIG DataFortinet Fortimanager | 12/11/2024 | 17/6/2026 | A client-side enforcement of server-side security in Fortinet FortiAnalyzer-BigData at least version 7.4.0 and 7.2.0 through 7.2.6 and 7.0.1 through 7.0.6 and 6.4.5 through 6.4.7 and 6.2.5, FortiManager version 7.4.0 through 7.4.1 and 7.2.0 through 7.2.4 and 7.0.0 through 7.0.11 and 6.4.0 through 6.4.14, FortiAnalyzer… | |
| Analizada | Media (4.1) | 0.55% | — | Fortinet FortianalyzerFortinet Fortianalyzer BIG DataFortinet Fortimanager | 12/11/2024 | 17/6/2026 | An exposure of sensitive information to an unauthorized actor [CWE-200] in Fortinet FortiManager before 7.4.2, FortiAnalyzer before 7.4.2 and FortiAnalyzer-BigData before 7.2.5 may allow a privileged attacker with administrative read permissions to read event logs of another adom via crafted HTTP or HTTPs requests. | |
| Analizada | Media (6.5) | 0.53% | — | Fortinet FortianalyzerFortinet FortimanagerFortinet Fortianalyzer BIG Data | 10/9/2024 | 17/6/2026 | An authorization bypass through user-controlled key [CWE-639] vulnerability in FortiAnalyzer version 7.4.1 and before 7.2.5 and FortiManager version 7.4.1 and before 7.2.5 may allow a remote attacker with low privileges to read sensitive data via a crafted HTTP request. | |
| Modificada | Media (6.7) | 0.22% | — | Fortinet FortianalyzerFortinet Fortianalyzer BIG DataFortinet FortimanagerFortinet Fortiportal | 12/3/2024 | 17/6/2026 | A use of externally-controlled format string vulnerability [CWE-134] vulnerability in Fortinet allows a privileged attacker to execute unauthorized code or commands via specially crafted command arguments. |