Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3063▲ 563 respecto a la semana anterior
Críticas / altas1461▲ 283 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
103 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Crítica (9.8) | — | ⚠ Explotación activa | Fortinet FortimailAI | 1/10/2026 | 1/10/2026 | An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8, FortiMail 7.2.0 through 7.2.9 may allow an unauthenticated attacker to write arbitrary files on the underlying system… | |
| Analizada | Alta (7.2) | 0.36% | — | Fortinet Fortimail | 12/5/2026 | 30/9/2026 | An improper neutralization of special elements used in an SQL Command ("SQL Injection&") vulnerability [CWE-89] vulnerability in Fortinet FortiMail 7.6.0 through 7.6.3, FortiMail 7.4.0 through 7.4.5, FortiMail 7.2.0 through 7.2.8 allows an authenticated privileged attacker to execute unauthorized code or commands via… | |
| Analizada | Media (4) | 0.08% | — | Fortinet FortivoiceFortinet FortirecorderFortinet Fortimail | 10/3/2026 | 17/6/2026 | A cleartext storage of sensitive information vulnerability [CWE-312] vulnerability in Fortinet FortiMail 7.6.0 through 7.6.2, FortiMail 7.4.0 through 7.4.4, FortiMail 7.2.0 through 7.2.7, FortiMail 7.0.0 through 7.0.8, FortiRecorder 7.2.0 through 7.2.3, FortiRecorder 7.0 all versions, FortiRecorder 6.4 all versions,… | |
| Modificada | Media (4.3) | 0.20% | — | Fortinet Fortimail | 18/11/2025 | 17/6/2026 | An improper neutralization of crlf sequences ('crlf injection') vulnerability in Fortinet FortiMail 7.6.0 through 7.6.3, FortiMail 7.4.0 through 7.4.5, FortiMail 7.2 all versions, FortiMail 7.0 all versions may allow an attacker to inject headers in the response via convincing a user to click on a specifically crafted… | |
| Modificada | Media (4.3) | 0.47% | — | Fortinet FortimailFortinet FortimanagerFortinet Fortimanager CloudFortinet Fortindr+8 | 14/10/2025 | 17/6/2026 | A insertion of sensitive information into sent data vulnerability in Fortinet FortiMail 7.4.0 through 7.4.2, FortiMail 7.2.0 through 7.2.6, FortiMail 7.0 all versions, FortiManager 7.6.0 through 7.6.1, FortiManager 7.4.1 through 7.4.3, FortiManager Cloud 7.4.1 through 7.4.3, FortiNDR 7.6.0 through 7.6.1, FortiNDR… | |
| Modificada | Media (4.4) | 0.18% | — | Fortinet Forticamera FirmwareFortinet FortimailFortinet FortindrFortinet Fortirecorder+1 | 12/8/2025 | 17/6/2026 | Multiple relative path traversal vulnerabilities [CWE-23] vulnerability in Fortinet FortiCamera 2.1 all versions, FortiCamera 2.0.0, FortiCamera 1.1 all versions, FortiCamera 1.0 all versions, FortiMail 7.6.0 through 7.6.1, FortiMail 7.4.0 through 7.4.3, FortiMail 7.2 all versions, FortiMail 7.0 all versions,… | |
| Analizada | Crítica (9.8) | 30% | ⚠ Explotación activa | Fortinet FortimailFortinet FortindrFortinet FortirecorderFortinet Fortivoice+1 | 13/5/2025 | 17/6/2026 | A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 through 2.1.3, FortiCamera 2.0 all versions, FortiCamera 1.1 all versions, FortiMail 7.6.0 through 7.6.2, FortiMail 7.4.0 through 7.4.4, FortiMail 7.2.0 through 7.2.7, FortiMail 7.0.0 through 7.0.8, FortiNDR 7.6.0,… | |
| Analizada | Alta (8.8) | 0.36% | — | Fortinet FortimailFortinet Fortindr | 31/3/2025 | 17/6/2026 | A buffer copy without checking size of input ('classic buffer overflow') in Fortinet FortiMail webmail and administrative interface version 6.4.0 through 6.4.4 and before 6.2.6 and FortiNDR administrative interface version 7.2.0 and before 7.1.0 allows an authenticated attacker with regular webmail access to trigger a… | |
| Analizada | Media (5.3) | 0.50% | — | Fortinet FortimailFortinet FortiddosFortinet FortivoiceFortinet Fortirecorder+1 | 28/3/2025 | 17/6/2026 | An exposure of sensitive system information to an unauthorized control sphere vulnerability [CWE-497] in FortiDDoS version 5.4.0, version 5.3.2 and below, version 5.2.0, version 5.1.0, version 5.0.0, version 4.7.0, version 4.6.0, version 4.5.0, version 4.4.2 and below, FortiDDoS-CM version 5.3.0, version 5.2.0,… | |
| Analizada | Alta (7.5) | 0.31% | — | Fortinet Fortimail | 24/3/2025 | 17/6/2026 | A use of a cryptographically weak pseudo-random number generator vulnerability in the authenticator of the Identity Based Encryption service of FortiMail 6.4.0 through 6.4.4, and 6.2.0 through 6.2.7 may allow an unauthenticated attacker to infer parts of users authentication tokens and reset their credentials. | |
| Analizada | Crítica (9.8) | 1.0% | — | Fortinet Fortimail | 18/3/2025 | 17/6/2026 | An improper access control vulnerability in FortiMail version 7.4.0 configured with RADIUS authentication and remote_wildcard enabled may allow a remote unauthenticated attacker to bypass admin login via a crafted HTTP request. | |
| Analizada | Media (6.7) | 0.18% | — | Fortinet Fortimail | 11/3/2025 | 17/6/2026 | A stack-buffer overflow vulnerability [CWE-121] in Fortinet FortiMail CLI version 7.6.0 through 7.6.1 and before 7.4.3 allows a privileged attacker to execute arbitrary code or commands via specifically crafted CLI commands. | |
| Modificada | Media (6.1) | 0.45% | — | Fortinet FortiadcFortinet FortiauthenticatorFortinet FortiddosFortinet Fortiddos-f+10 | 22/1/2025 | 17/6/2026 | A externally controlled reference to a resource in another sphere vulnerability in Fortinet allows attacker to poison web caches via crafted HTTP requests, where the `Host` header points to an arbitrary webserver | |
| Analizada | Media (6.7) | 0.59% | — | Fortinet FortimailFortinet Fortirecorder | 14/1/2025 | 17/6/2026 | An improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiMail versions 7.2.0 through 7.2.4 and 7.0.0 through 7.0.6 and 6.4.0 through 6.4.7, FortiRecorder versions 7.0.0 and 6.4.0 through 6.4.4 allows attacker to execute unauthorized code or commands via the CLI. | |
| Modificada | Alta (8.8) | 0.49% | — | Fortinet FortiaiFortinet FortimailFortinet FortindrFortinet Fortirecorder+2 | 13/12/2023 | 17/6/2026 | A cross-site request forgery (CSRF) in Fortinet FortiVoiceEnterprise version 6.4.x, 6.0.x, FortiSwitch version 7.0.0 through 7.0.4, 6.4.0 through 6.4.10, 6.2.0 through 6.2.7, 6.0.x, FortiMail version 7.0.0 through 7.0.3, 6.4.0 through 6.4.6, 6.2.x, 6.0.x FortiRecorder version 6.4.0 through 6.4.2, 6.0.x, 2.7.x, 2.6.x,… | |
| Modificada | Alta (7.3) | 0.52% | — | Fortinet Fortimail | 14/11/2023 | 17/6/2026 | An improper restriction of excessive authentication attempts vulnerability [CWE-307] in FortiMail webmail version 7.2.0 through 7.2.4, 7.0.0 through 7.0.6 and before 6.4.8 may allow an unauthenticated attacker to perform a brute force attack on the affected endpoints via repeated login attempts. | |
| Modificada | Media (5.4) | 0.47% | — | Fortinet Fortimail | 14/11/2023 | 17/6/2026 | An improper authorization vulnerability [CWE-285] in FortiMail webmail version 7.2.0 through 7.2.2 and before 7.0.5 allows an authenticated attacker to see and modify the title of address book folders of other users via crafted HTTP or HTTPs requests. | |
| Modificada | Media (5.4) | 0.39% | — | Fortinet Fortimail | 10/10/2023 | 17/6/2026 | An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiMail version 7.2.0 through 7.2.2 and before 7.0.5 allows an authenticated attacker to inject HTML tags in FortiMail's calendar via input fields. | |
| Modificada | Alta (8.8) | 0.84% | — | Fortinet Fortimail | 10/10/2023 | 17/6/2026 | An incorrect authorization vulnerability [CWE-863] in FortiMail webmail version 7.2.0 through 7.2.2, version 7.0.0 through 7.0.5 and below 6.4.7 allows an authenticated attacker to login on other users accounts from the same web domain via crafted HTTP or HTTPs requests. | |
| Modificada | Media (5.3) | 1.8% | — | Fortinet Fortimail | 9/3/2023 | 17/6/2026 | A improper restriction of excessive authentication attempts vulnerability [CWE-307] in Fortinet FortiMail version 6.4.0, version 6.2.0 through 6.2.4 and before 6.0.9 allows a remote unauthenticated attacker to partially exhaust CPU and memory via sending numerous HTTP requests to the login form. | |
| Modificada | Media (6.5) | 0.38% | — | Fortinet Fortimail | 2/11/2022 | 17/6/2026 | An improper access control vulnerability [CWE-284] in FortiMail 7.2.0, 7.0.0 through 7.0.3, 6.4 all versions, 6.2 all versions, 6.0 all versions may allow an authenticated admin user assigned to a specific domain to access and modify other domains information via insecure direct object references (IDOR). | |
| Modificada | Alta (8.6) | 0.48% | — | Fortinet Antivirus EngineFortinet FortimailFortinet Fortios | 2/11/2022 | 17/6/2026 | An insufficient verification of data authenticity vulnerability [CWE-345] in FortiClient, FortiMail and FortiOS AV engines version 6.2.168 and below and version 6.4.274 and below may allow an attacker to bypass the AV engine via manipulating MIME attachment with junk and pad characters in base64. | |
| Modificada | Media (6.1) | 0.47% | — | Fortinet Fortimail | 6/9/2022 | 17/6/2026 | An improper neutralization of input during web page generation vulnerability [CWE-79] in the Webmail of FortiMail before 7.2.0 may allow an unauthenticated attacker to trigger a cross-site scripting (XSS) attack via sending specially crafted mail messages. | |
| Modificada | Alta (7.8) | 0.21% | — | Fortinet FortiadcFortinet FortimailFortinet FortiproxyFortinet Fortios | 5/8/2022 | 17/6/2026 | A format string vulnerability [CWE-134] in the command line interpreter of FortiADC version 6.0.0 through 6.0.4, FortiADC version 6.1.0 through 6.1.5, FortiADC version 6.2.0 through 6.2.1, FortiProxy version 1.0.0 through 1.0.7, FortiProxy version 1.1.0 through 1.1.6, FortiProxy version 1.2.0 through 1.2.13,… | |
| Modificada | Crítica (9.8) | 1.1% | — | Fortinet Fortimail | 1/3/2022 | 17/6/2026 | An improper input validation vulnerability in the web server CGI facilities of FortiMail before 7.0.1 may allow an unauthenticated attacker to alter the environment of the underlying script interpreter via specifically crafted HTTP requests. |