Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2682▼ 88 respecto a la semana anterior
Críticas / altas1443▲ 300 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
1579 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 1.8% | ⚠ Explotación activa | Fortinet Fortimail | 1/10/2026 | 2/10/2026 | An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8, FortiMail 7.2.0 through 7.2.9 may allow an unauthenticated attacker to write arbitrary files on the underlying system… | |
| Pendiente de análisis | Crítica (9.6) | 0.38% | — | Fortinet Fortipam Chrome ExtensionAI | 22/9/2026 | 26/9/2026 | A improper restriction of rendered ui layers or frames vulnerability in Fortinet FortiPAM Chrome Extension 8.0 all versions, FortiPAM Chrome Extension 7.4 all versions may allow attacker to information disclosure via remote unauthenticated attack | |
| Pendiente de análisis | Crítica (9.8) | 0.52% | — | Fortinet FortimonitoronsightAI | 11/9/2026 | 11/9/2026 | A inclusion of sensitive information in source code vulnerability in Fortinet FortiMonitorOnSight 7.2.4 through 7.2.7, FortiMonitorOnSight 7.2.0 through 7.2.2 may allow attacker to improper access control via <insert attack vector here> | |
| Aplazada | Media (6.9) | 0.26% | — | Dreyrik GabinetAI | 10/9/2026 | 10/9/2026 | DrEryk Gabinet before 11.5.0 uses hard-coded API credentials in its ticket reporting component. These credentials can be used to authenticate directly to the ticket system API. This allows an attacker to perform privileged operations beyond what is offered by the application, including reading and modifying tickets. | |
| Pendiente de análisis | Alta (8.1) | 0.25% | — | Fortinet FortiosAIFortinet FortiproxyAI | 8/9/2026 | 10/9/2026 | A improper validation of certificate with host mismatch vulnerability in Fortinet FortiOS 7.6.1 through 7.6.6, FortiProxy 7.6.2 through 7.6.6 may allow attacker to information disclosure via <insert attack vector here> | |
| Pendiente de análisis | Baja (2.7) | 0.50% | — | Fortinet FortiosAIFortinet FortipamAIFortinet FortiproxyAI | 8/9/2026 | 8/9/2026 | A NULL Pointer Dereference vulnerability [CWE-476] vulnerability in Fortinet FortiOS 7.4 all versions, FortiOS 7.2 all versions, FortiPAM 1.9.0, FortiPAM 1.8 all versions, FortiPAM 1.7 all versions, FortiPAM 1.6 all versions, FortiPAM 1.5 all versions, FortiPAM 1.4 all versions, FortiPAM 1.3 all versions, FortiPAM 1.2… | |
| Pendiente de análisis | Media (6.5) | 0.41% | — | Fortinet FortianalyzerAI | 8/9/2026 | 8/9/2026 | A use of uninitialized variable vulnerability in Fortinet FortiAnalyzer 7.6.3 through 7.6.6 may allow attacker to denial of service via <insert attack vector here> | |
| Pendiente de análisis | Baja (3.1) | 0.22% | — | Fortinet FortisiemAI | 8/9/2026 | 10/9/2026 | A url redirection to untrusted site ('open redirect') vulnerability in Fortinet FortiSIEM 7.5.0 through 7.5.1, FortiSIEM 7.4.1 through 7.4.2 may allow attacker to execute unauthorized code or commands via <insert attack vector here> | |
| Pendiente de análisis | Alta (7.2) | 1.4% | — | Fortinet FortisandboxAI | 8/9/2026 | 8/9/2026 | A improper neutralization of special elements used in a command ('command injection') vulnerability in Fortinet FortiSandbox 5.2.0, FortiSandbox 5.0.0 through 5.0.6, FortiSandbox 4.4.0 through 4.4.9 may allow attacker to execute unauthorized code or commands via <insert attack vector here> | |
| Pendiente de análisis | Media (5.4) | 0.23% | — | Fortinet FortisoarAI | 8/9/2026 | 10/9/2026 | A improper access control vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.6, FortiSOAR PaaS 7.5.0 through 7.5.3, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.0 through 7.6.6, FortiSOAR on-premise 7.5.0 through 7.5.3, FortiSOAR on-premise 7.4 all versions,… | |
| Pendiente de análisis | Crítica (9.9) | 0.39% | — | Fortinet FortisandboxAIFortinet Fortisandbox CloudAIFortinet Fortisandbox PaasAI | 8/9/2026 | 8/9/2026 | A improper access control vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow attacker to access sensitive information via crafted HTTP requests. | |
| Pendiente de análisis | Media (4.9) | 0.24% | — | Fortinet FortimanagerAI | 8/9/2026 | 8/9/2026 | An improper access control vulnerability in Fortinet FortiManager 7.6.0 through 7.6.4, FortiManager 7.4.0 through 7.4.10, FortiManager 7.2 all versions, FortiManager Cloud 7.6.2 through 7.6.4, FortiManager Cloud 7.4.1 through 7.4.10, FortiManager Cloud 7.2 all versions may allow an administrator to bypass the approval… | |
| Pendiente de análisis | Media (5.1) | 0.14% | — | Fortinet Forticlient WindowsAI | 8/9/2026 | 2/10/2026 | A unverified ownership vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.7, FortiClientWindows 7.2 all versions may allow attacker to improper access control via via an exposed minifilter communication port. | |
| Aplazada | Media (6) | 0.63% | — | Erlang OTPAIErlang InetsAI | 1/9/2026 | 8/9/2026 | The mod_auth module in OTP's inets httpd server, when configured with dets or mnesia authentication backends and multiple directory configuration blocks, collapses all directory blocks into a single shared user/group namespace. A user added to one protected directory is accepted as valid for all other protected… | |
| Aplazada | Alta (8.7) | 0.58% | — | Erlang OTPAIErlang InetsAI | 1/9/2026 | 8/9/2026 | The inets application HTTP server httpd fails to enforce a configured body-size limit on chunked request. This issue affects OTP from OTP 17.0 before OTP 27.3.4.17, from OTP 28.0 before OTP 28.5.0.6, and from OTP 29.0 before OTP 29.0.6, corresponding to inets from 5.10 before 9.3.2.7, from 9.4 before 9.6.2.3, and from… | |
| Aplazada | Alta (8.3) | 0.52% | — | Erlang OTPAIErlang InetsAI | 1/9/2026 | 8/9/2026 | httpd function check_header/3 rejects duplicate Content-Length (per CVE-2026-23941) but never checks for the TE+CL co-presence that RFC 9112 §6.3 identifies as a probable smuggling attempt. handle_body/3 frames by chunked and silently discards Content-Length. A CL-preferring front-end paired with chunked-preferring… | |
| Aplazada | Alta (8.3) | 0.58% | — | Erlang OTPAIErlang InetsAI | 1/9/2026 | 8/9/2026 | Gracefulness code ignored cases that should be rejected, resulting in possible HTTP Request Smuggling opportunities. This issue affects OTP from OTP 22.2 before OTP 27.3.4.17, from OTP 28.0 before OTP 28.5.0.6, and from OTP 29.0 before OTP 29.0.6, corresponding to inets from 7.1.2 before 9.3.2.7, from 9.4 before… | |
| Aplazada | Alta (8.2) | 0.93% | — | Erlang OTPAIErlang InetsAI | 1/9/2026 | 8/9/2026 | Improper Handling of Case Sensitivity vulnerability in Erlang/OTP inets httpd allows a remote unauthenticated attacker to read files inside a mod_auth protected directory by requesting them with different casing, on deployments whose filesystem is case-insensitive. mod_auth:secret_path/3 decides whether a resolved… | |
| Aplazada | Media (6.3) | 0.58% | — | Erlang OTPAIErlang InetsAI | 1/9/2026 | 8/9/2026 | Improper Validation of Specified Quantity in Input vulnerability in Erlang/OTP inets httpc allows a malicious or compromised HTTP server to degrade availability by returning a numeric header whose value is a very long run of digits. httpc_handler.erl converts the server-supplied Content-Length with list_to_integer/1… | |
| Aplazada | Alta (8.7) | 0.67% | — | Erlang OTPAIErlang InetsAI | 1/9/2026 | 8/9/2026 | Missing Release of Resource after Effective Lifetime vulnerability in Erlang/OTP inets httpd allows an unauthenticated remote attacker to cause denial of service by sending valid request headers with a large Content-Length and then stalling before the body is complete. httpd_request_handler:handle_info/2 cancels the… | |
| Aplazada | Alta (8.7) | 0.93% | — | Erlang OTPAIErlang InetsAI | 1/9/2026 | 8/9/2026 | Allocation of Resources Without Limits or Throttling vulnerability in Erlang/OTP inets httpd allows an unauthenticated remote attacker to cause denial of service by opening and holding open a large number of connections. The max_clients option is documented to default to 150, and the inets hardening guide presents… | |
| Aplazada | Alta (8.2) | 0.97% | — | Erlang OTPAIErlang InetsAI | 1/9/2026 | 8/9/2026 | Path Equivalence vulnerability in Erlang/OTP inets httpd allows a remote unauthenticated attacker to read files inside a mod_auth protected directory by prefixing the request path with an extra slash. httpd_request:validate_uri/1 normalises the request URI with uri_string:normalize/1, which performs RFC 3986… | |
| Aplazada | Alta (8.3) | 0.58% | — | Erlang OTPAIErlang InetsAI | 1/9/2026 | 8/9/2026 | httpd has never implemented obs-fold (RFC 2616 §2.2 / RFC 7230 §3.2.4 header continuation lines). Every CRLF followed by a non-CRLF octet unconditionally starts a new header. This missing feature became a security concern as the understanding of HTTP request smuggling attacks evolved. This issue affects OTP from OTP… | |
| Aplazada | Alta (8.2) | 0.69% | — | Erlang OTPAIErlang InetsAI | 1/9/2026 | 8/9/2026 | The Erlang/OTP httpc HTTP client does not enforce a limit on the total size of response headers received from a server. The max_header_size option defaults to nolimit, and httpc_response:parse_headers/6 accumulates every header into a list before the length check runs (which only fires after the terminating CRLF CRLF… | |
| Aplazada | Alta (8.7) | 0.95% | — | Erlang OTPAIErlang InetsAI | 1/9/2026 | 22/9/2026 | Missing Release of Resource after Effective Lifetime vulnerability in Erlang/OTP inets httpd allows an unauthenticated remote attacker to cause denial of service by sending a request with a chunked body whose chunk-size line is not a hexadecimal number. The worker serving the connection is never released and no… |