Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2841▼ 157 respecto a la semana anterior
Críticas / altas1370▲ 51 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 258 respecto a la semana anterior
–

44 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisMedia (4.8)0.15%—Fortra Boks Server AgentAI1/10/20261/10/2026
Fortra BoKS Server Agent contains a predictable password generation vulnerability in the adjoin utility. Machine-account passwords generated during Active Directory join or password renewal operations may have significantly less entropy than intended, making them more susceptible to prediction by an attacker who can…
Pendiente de análisisAlta (7.5)0.33%—Fortra Boks ManagerAI1/10/20261/10/2026
Fortra BoKS Manager contains an out-of-bounds read vulnerability in the custom TLS ClientHello parser used by boks_portmux. A remote unauthenticated attacker can submit a malformed ClientHello and terminate boks_portmux. Although the daemon is normally restarted automatically, repeated requests can sustain the service…
Pendiente de análisisCrítica (9.8)0.44%—Fortra Core Privileged Access ManagerAI1/10/20261/10/2026
Fortra's Core Privileged Access Manager (BoKS) contains a stack-based buffer overflow vulnerability in boks_autoregisterd. A remote attacker with network access to the autoregistration service may be able to trigger memory corruption during client response processing.
Pendiente de análisisAlta (7.9)0.07%—Fortra Boks ManagerAI1/10/20261/10/2026
Fortra BoKS Manager contains an insecure temporary file vulnerability in bccgethostcert. The utility creates predictable temporary files without first setting a restrictive umask. A local user on the BoKS Master who can read files under BOKS_tmp may be able to obtain CA secret or host private-key material while the…
Pendiente de análisisCrítica (9.1)0.98%—Fortra Boks ManagerAI1/10/20261/10/2026
Fortra BoKS Manager contains a command injection vulnerability in crlserver. An authenticated user authorized to add CRL URLs through BCC, the WSI REST or SOAP API, or the cacrl command-line interface could cause shell command substitution to be processed by crlserver as root on the BoKS Master. BCC and WSI provide…
AplazadaAlta (7.7)0.39%—Fortra Goanywhere MFTAI9/9/202610/9/2026
In versions prior to 7.10.2 a path traversal vulnerability in the /attachRemoteFiles endpoint of Fortra's GoAnywhere MFT allows Web Users with both Secure Folders and Secure Mail permissions to escape their sandboxed home directory, achieving arbitrary file read.
AnalizadaMedia (4.4)0.14%—Fortra File Integrity Monitoring23/6/202629/6/2026
Fortra File Integrity Monitoring (FIM), formerly Tripwire Enterprise, versions prior to 9.4.0 may assign incorrect or elevated effective permissions to users created by the tetool import command while FIM is running, particularly when the import also creates or changes roles or role-permission relationships.
AnalizadaMedia (4.8)0.24%—Fortra File Integrity Monitoring23/6/202628/6/2026
Fortra File Integrity Monitoring (FIM), formerly Tripwire Enterprise, versions prior to 9.4.0.1 contain a stored cross-site scripting (XSS) vulnerability in the Asset View UI component. An authenticated user with sufficient privileges to create or modify affected node or database configuration fields could store…
AnalizadaAlta (8.8)1.0%—Fortra Core Privileged Access Manager Server15/6/202628/7/2026
Fortra BoKS Manager contains an OS command injection vulnerability in the client upgrade and patch tooling for legacy tar-based client installations. A malicious or compromised legacy tar-installed client selected for upgrade or patching may be able to cause commands to be executed on the BoKS Master during client…
AnalizadaCrítica (9.8)1.5%—Fortra Core Privileged Access Manager Server15/6/202628/7/2026
Fortra's Core Privileged Access Manager (BoKS) contains an OS command injection vulnerability in the boks_autoregisterd service. A remote attacker with network access to the service may be able to cause commands to be executed with the privileges of the service during the autoregistration processing.
AnalizadaMedia (6.5)0.23%—Fortra Goanywhere Managed File Transfer21/4/202617/6/2026
User‑Controlled HTTP Header in Fortra's GoAnywhere MFT prior to version 7.10.0 allows attackers to trigger a DNS lookup, as well as DNS Rebinding and Information Disclosure.
ModificadaMedia (5.4)0.15%—Fortra Goanywhere Managed File Transfer21/4/202617/6/2026
HTML injection is possible in system generated emails in Fortra's GoAnywhere MFT prior to 7.10.0. Note: The title, details, and description of this CVE were corrected post-publishing.
AnalizadaMedia (4.3)0.18%—Fortra Goanywhere Managed File Transfer21/4/202617/6/2026
An improper session timeout issue in Fortra's GoAnywhere MFT prior to version 7.10.0 results in SAML configured Web Users being redirected to the regular login page instead of the SAML login page.
AnalizadaMedia (4.9)0.13%—Fortra Goanywhere AgentsFortra Goanywhere Managed File Transfer21/4/202630/9/2026
Encrypted values in Fortra's GoAnywhere MFT prior to version 7.10.0 and GoAnywhere Agents prior to version 2.2.0 utilize a static IV which allows admin users to brute-force decryption of data.
AnalizadaAlta (7.3)0.19%—Fortra Goanywhere Managed File Transfer21/4/202630/9/2026
The login limit is not enforced on the SFTP service of Fortra's GoAnywhere MFT prior to 7.10.0 if the Web User attempting to be logged in to is configured to log in with an SSH Key, making the SSH key vulnerable to being guessed via Brute Force.
AplazadaMedia (6.2)0.10%—Fortra Core Privileged Access ManagerAIFortra Boks Server AgentAI16/12/202517/6/2026
Insecure defaults in the Server Agent component of Fortra's Core Privileged Access Manager (BoKS) can result in the selection of weak password hash algorithms. This issue affects BoKS Server Agent 9.0 instances that support yescrypt and are running in a BoKS 8.1 domain.
AnalizadaMedia (4.2)0.17%—Fortra Goanywhere Managed File Transfer5/12/202525/9/2026
An Improper Access Control in the SFTP service in Fortra's GoAnywhere MFT prior to version 7.9.0 allows Web Users with an Authentication Alias and a valid SSH key but limited to Password authentication for SFTP to still login using their SSH key.
AnalizadaCrítica (9.8)100%⚠ Explotación activaFortra Goanywhere Managed File Transfer18/9/20254/8/2026
A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, possibly leading to command injection.
AplazadaAlta (8.2)0.28%—Fortra FilecatalystAI19/8/202517/6/2026
Improper Access Control issue in the Workflow component of Fortra's FileCatalyst allows unauthenticated users to upload arbitrary files via the order forms page.
AplazadaMedia (5.3)0.34%—Fortra Goanywhere MFTAI16/7/202517/6/2026
Broken access control in Fortra's GoAnywhere MFT prior to 7.8.1 allows an attacker to create a denial of service situation when configured to use GoAnywhere One-Time Password (GOTP) email two-factor authentication (2FA) and the user has not set an email address. In this scenario, the attacker may enter the email…
AplazadaMedia (5.5)0.14%—Fortra Core Privileged Access ManagerAI17/6/202517/6/2026
A binary in the BoKS Server Agent component of Fortra's Core Privileged Access Manager (BoKS) on versions 7.2.0 (up to 7.2.0.17), 8.1.0 (up to 8.1.0.22), 8.1.1 (up to 8.1.1.7), 9.0.0 (up to 9.0.0.1) and also legacy tar installs of BoKS 7.2 without hotfix #0474 on Linux, AIX, and Solaris allows low privilege local…
AnalizadaMedia (4.3)0.27%—Fortra Goanywhere Managed File Transfer28/4/202517/6/2026
When a Web User without Create permission on subfolders attempts to upload a file to a non-existent directory, the error message includes the absolute server path which may allow Fuzzing for application mapping. This issue affects GoAnywhere: before 7.8.0.
AnalizadaMedia (5.4)0.23%—Fortra Goanywhere Managed File Transfer28/4/202517/6/2026
Missing input validation in certain features of the Web Client of Fortra's GoAnywhere prior to version 7.8.0 allows an attacker with permission to trigger emails to insert arbitrary HTML or JavaScript into an email.
AplazadaMedia (5.5)0.21%—Fortra Application HUBAIFortra IAMAIFortra CoreAI18/1/202517/6/2026
Under certain log settings the IAM or CORE service will log credentials in the iam logfile in Fortra Application Hub (Formerly named Helpsystems One) prior to version 1.3
AplazadaMedia (5.3)0.32%—Fortra Goanywhere MFTAI13/12/202417/6/2026
An information-disclosure vulnerability exists in Fortra's GoAnywhere MFT application prior to version 7.7.0 that allows external access to the resources in certain admin root folders.