Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2950▲ 8 respecto a la semana anterior
Críticas / altas1450▲ 184 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
1273 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 2.2% | ⚠ Explotación activa | Fortinet Fortimail | 1/10/2026 | 2/10/2026 | An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8, FortiMail 7.2.0 through 7.2.9 may allow an unauthenticated attacker to write arbitrary files on the underlying system… | |
| Aplazada | Alta (8.7) | 0.30% | — | Nicotine-plus Nicotine+AI | 29/9/2026 | 30/9/2026 | Nicotine+ is a graphical client for the Soulseek peer-to-peer network. Prior to version 3.3.11, a modified remote client can send zlib-compressed peer messages containing a decompression bomb, exhausting available memory of the recipient's operating system. This issue has been patched in version 3.3.11. | |
| Pendiente de análisis | Crítica (9.6) | 0.38% | — | Fortinet Fortipam Chrome ExtensionAI | 22/9/2026 | 26/9/2026 | A improper restriction of rendered ui layers or frames vulnerability in Fortinet FortiPAM Chrome Extension 8.0 all versions, FortiPAM Chrome Extension 7.4 all versions may allow attacker to information disclosure via remote unauthenticated attack | |
| Aplazada | Alta (7.1) | 0.47% | — | Continew AdminAI | 16/9/2026 | 24/9/2026 | ContiNew Admin through 4.1.0 contains an authorization bypass vulnerability in the personal message delete endpoint that allows authenticated users to delete other users' messages and announcements. Attackers can supply arbitrary message identifiers in the IdsReq parameter to remove any message row and purge all… | |
| Pendiente de análisis | Crítica (9.8) | 0.52% | — | Fortinet FortimonitoronsightAI | 11/9/2026 | 11/9/2026 | A inclusion of sensitive information in source code vulnerability in Fortinet FortiMonitorOnSight 7.2.4 through 7.2.7, FortiMonitorOnSight 7.2.0 through 7.2.2 may allow attacker to improper access control via <insert attack vector here> | |
| Pendiente de análisis | Media (6.2) | 0.19% | — | Modelcontextprotocol Kotlin SDKAIKotlinx CoroutinesAIScala-sbt IOAI | 9/9/2026 | 14/9/2026 | MCP Kotlin SDK is the Kotlin Multiplatform software development kit for the Model Context Protocol. In versions 0.7.0 through 0.12.0, `ReadBuffer.append` in `kotlin-sdk-core/src/commonMain/kotlin/io/modelcontextprotocol/kotlin/sdk/shared/ReadBuffer.kt` writes every chunk of bytes received from the stdio transport into… | |
| Pendiente de análisis | Alta (8.1) | 0.25% | — | Fortinet FortiosAIFortinet FortiproxyAI | 8/9/2026 | 10/9/2026 | A improper validation of certificate with host mismatch vulnerability in Fortinet FortiOS 7.6.1 through 7.6.6, FortiProxy 7.6.2 through 7.6.6 may allow attacker to information disclosure via <insert attack vector here> | |
| Pendiente de análisis | Baja (2.7) | 0.50% | — | Fortinet FortiosAIFortinet FortipamAIFortinet FortiproxyAI | 8/9/2026 | 8/9/2026 | A NULL Pointer Dereference vulnerability [CWE-476] vulnerability in Fortinet FortiOS 7.4 all versions, FortiOS 7.2 all versions, FortiPAM 1.9.0, FortiPAM 1.8 all versions, FortiPAM 1.7 all versions, FortiPAM 1.6 all versions, FortiPAM 1.5 all versions, FortiPAM 1.4 all versions, FortiPAM 1.3 all versions, FortiPAM 1.2… | |
| Pendiente de análisis | Media (6.5) | 0.41% | — | Fortinet FortianalyzerAI | 8/9/2026 | 8/9/2026 | A use of uninitialized variable vulnerability in Fortinet FortiAnalyzer 7.6.3 through 7.6.6 may allow attacker to denial of service via <insert attack vector here> | |
| Pendiente de análisis | Baja (3.1) | 0.22% | — | Fortinet FortisiemAI | 8/9/2026 | 10/9/2026 | A url redirection to untrusted site ('open redirect') vulnerability in Fortinet FortiSIEM 7.5.0 through 7.5.1, FortiSIEM 7.4.1 through 7.4.2 may allow attacker to execute unauthorized code or commands via <insert attack vector here> | |
| Pendiente de análisis | Alta (7.2) | 1.4% | — | Fortinet FortisandboxAI | 8/9/2026 | 8/9/2026 | A improper neutralization of special elements used in a command ('command injection') vulnerability in Fortinet FortiSandbox 5.2.0, FortiSandbox 5.0.0 through 5.0.6, FortiSandbox 4.4.0 through 4.4.9 may allow attacker to execute unauthorized code or commands via <insert attack vector here> | |
| Pendiente de análisis | Media (5.4) | 0.23% | — | Fortinet FortisoarAI | 8/9/2026 | 10/9/2026 | A improper access control vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.6, FortiSOAR PaaS 7.5.0 through 7.5.3, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.0 through 7.6.6, FortiSOAR on-premise 7.5.0 through 7.5.3, FortiSOAR on-premise 7.4 all versions,… | |
| Pendiente de análisis | Crítica (9.9) | 0.39% | — | Fortinet FortisandboxAIFortinet Fortisandbox CloudAIFortinet Fortisandbox PaasAI | 8/9/2026 | 8/9/2026 | A improper access control vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow attacker to access sensitive information via crafted HTTP requests. | |
| Pendiente de análisis | Media (4.9) | 0.24% | — | Fortinet FortimanagerAI | 8/9/2026 | 8/9/2026 | An improper access control vulnerability in Fortinet FortiManager 7.6.0 through 7.6.4, FortiManager 7.4.0 through 7.4.10, FortiManager 7.2 all versions, FortiManager Cloud 7.6.2 through 7.6.4, FortiManager Cloud 7.4.1 through 7.4.10, FortiManager Cloud 7.2 all versions may allow an administrator to bypass the approval… | |
| Pendiente de análisis | Media (5.1) | 0.14% | — | Fortinet Forticlient WindowsAI | 8/9/2026 | 2/10/2026 | A unverified ownership vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.7, FortiClientWindows 7.2 all versions may allow attacker to improper access control via via an exposed minifilter communication port. | |
| Aplazada | Alta (7.1) | 0.30% | — | Continew AdminAI | 25/8/2026 | 24/9/2026 | ContiNew Admin fails to apply file-upload permission checks or file-type allowlist validation to multipart upload endpoints, allowing authenticated users to store files with arbitrary extensions. Attackers can initialize chunked uploads, send file parts, and complete uploads to leave arbitrary files in the storage… | |
| Aplazada | Alta (7.5) | 0.60% | — | Bottinelli Informatica Vedo SuiteAI | 19/8/2026 | 9/9/2026 | An issue in Bottinelli Informatica Vedo Suite v.1.2.5 allows a remote attacker to obtain sensitive information via the api_vedo/chat endpoint and the utente_chat parameter | |
| Aplazada | Crítica (9.9) | 0.78% | — | Bottinelli Informatica Vedo SuiteAI | 19/8/2026 | 9/9/2026 | SQL Injection vulnerability in Bottinelli Informatica Vedo Suite v.1.2.5 allows a remote attacker to execute arbitrary code via the api_vedo/chat endpoint and the utente_chat parameter | |
| Analizada | Media (5.3) | 0.40% | — | Fortinet Fortios | 12/8/2026 | 8/9/2026 | A allocation of resources without limits or throttling vulnerability in Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.4 all versions, FortiOS 7.2 all versions may allow attacker to denial of service via <insert attack vector here> | |
| Analizada | Alta (8.1) | 0.42% | — | Fortinet Fortios | 12/8/2026 | 8/9/2026 | A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet FortiOS 7.6.1 through 7.6.6 may allow an unauthenticated attacker who can bypass stack protection and ASLR to execute arbitrary code or commands in the context of the WAD daemon via crafted sockets, only if the explicit proxy is configured… | |
| Analizada | Alta (8.1) | 0.46% | — | Fortinet FortimanagerFortinet Fortimanager Cloud | 12/8/2026 | 8/9/2026 | A authentication bypass using an alternate path or channel vulnerability in Fortinet FortiManager 7.6.1, FortiManager 7.4.3 through 7.4.5, FortiManager 7.2.5 through 7.2.9, FortiManager Cloud 7.6.1, FortiManager Cloud 7.4.3 through 7.4.5, FortiManager Cloud 7.2.5 through 7.2.9 may allow attacker to improper access… | |
| Analizada | Baja (3.8) | 0.26% | — | Fortinet Fortisiem | 12/8/2026 | 8/9/2026 | A server-side request forgery (ssrf) vulnerability in Fortinet FortiSIEM 7.5.0, FortiSIEM 7.4.0 through 7.4.2, FortiSIEM 7.3.0 through 7.3.5, FortiSIEM 7.2 all versions, FortiSIEM 7.1 all versions, FortiSIEM 7.0 all versions, FortiSIEM 6.7 all versions, FortiSIEM 6.6 all versions, FortiSIEM 6.5 all versions may allow… | |
| Analizada | Media (5.3) | 0.31% | — | Fortinet Fortiweb | 12/8/2026 | 8/9/2026 | A incomplete list of disallowed inputs vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4 all versions, FortiWeb 7.2 all versions, FortiWeb 7.0 all versions may allow attacker to improper access control via <insert attack vector here> | |
| Analizada | Crítica (9.8) | 0.75% | — | Fortinet Fortiweb | 12/8/2026 | 8/9/2026 | An Improper Authentication vulnerability [CWE-287] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11, FortiWeb 7.2.0 through 7.2.12, FortiWeb 7.0.0 through 7.0.12 may allow a remote unauthenticated attacker to login into the Fortiweb GUI/CLI with a… | |
| Analizada | Alta (8.1) | 0.52% | — | Fortinet Forticlient | 12/8/2026 | 8/9/2026 | A buffer copy without checking size of input ('classic buffer overflow') vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.3, FortiClientWindows 7.2.0 through 7.2.11 may allow an unauthenticated attacker in a position to alter or craft DNS responses to the targeted host to execute arbitrary code via… |