Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2811▲ 64 respecto a la semana anterior
Críticas / altas1484▲ 296 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 448 respecto a la semana anterior
122 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Crítica (9.3) | 0.89% | — | Checkpoint Security Management ServerAICheckpoint Multi Domain Security Management ServerAI | 3/8/2026 | 5/8/2026 | An authentication bypass vulnerability in Check Point Security Management Server and Multi-Domain Security Management Server (MDS) could allow an unauthenticated remote attacker with network access to Management services to execute arbitrary commands on the Security Management Server. Successful exploitation could… | |
| Analizada | Alta (7.5) | 0.21% | — | Opentext WEB Site Management Server | 19/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in OpenText™ Web Site Management Server allows Stored XSS. The vulnerability could execute malicious scripts on the client side when the download query parameter is removed from the file URL, allowing attackers to… | |
| Analizada | Alta (7) | 0.21% | — | Opentext WEB Site Management Server | 19/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in OpenText™ Web Site Management Server allows Reflected XSS. The vulnerability could allow injecting malicious JavaScript inside URL parameters that was then rendered with the preview of the page, so that… | |
| Analizada | Media (5.9) | 0.16% | — | Opentext WEB Site Management Server | 19/2/2026 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in OpenText™ Web Site Management Server allows Cross Site Request Forgery. The vulnerability could make a user, with active session inside the product, click on a page that contains this malicious HTML triggering to perform changes unconsciously. This issue affects Web… | |
| Analizada | Baja (2.3) | 0.59% | — | Proofpoint Insider Threat Management Server | 3/11/2025 | 17/6/2026 | Insider Threat Management (ITM) Server versions prior to 7.17.2 contain an authentication bypass vulnerability that allows unauthenticated users on an adjacent network to perform agent unregistration when the number of registered agents exceeds the licensed limit. Successful exploitation prevents the server from… | |
| Analizada | Media (5.5) | 0.14% | — | Dell TechadvisorDell Xtremio Management Server | 30/7/2025 | 17/6/2026 | Dell XtremIO, version(s) 6.4.0-22, contain(s) an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information exposure. The attacker may be able to use the exposed credentials to access the vulnerable… | |
| Analizada | Media (5.5) | 0.14% | — | Dell TechadvisorDell Xtremio Management Server | 30/7/2025 | 17/6/2026 | TechAdvisor versions 2.6 through 3.37-30 for Dell XtremIO X2, contain(s) an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information exposure. The attacker may be able to use the exposed credentials… | |
| Analizada | Alta (7.8) | 0.14% | — | Dell EncryptionDell Security Management Server | 30/7/2025 | 17/6/2026 | Dell Encryption and Dell Security Management Server, versions prior to 11.11.0, contain an Improper Link Resolution Before File Access ('Link Following') Vulnerability. A local malicious user could potentially exploit this vulnerability, leading to privilege escalation. | |
| Analizada | Crítica (9.1) | 0.47% | — | Samsung Data Management Server Firmware | 29/7/2025 | 17/6/2026 | An 'Arbitrary File Deletion' in Samsung DMS(Data Management Server) allows attackers to delete arbitrary files from unintended locations on the filesystem. Exploitation is restricted to specific, authorized private IP addresses. | |
| Analizada | Crítica (9.1) | 0.39% | — | Samsung Data Management Server Firmware | 29/7/2025 | 17/6/2026 | An 'Arbitrary File Creation' in Samsung DMS(Data Management Server) allows attackers to create arbitrary files in unintended locations on the filesystem. Exploitation is restricted to specific, authorized private IP addresses. | |
| Analizada | Media (6.5) | 0.34% | — | Samsung Data Management Server Firmware | 29/7/2025 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Samsung DMS(Data Management Server) allows authenticated attackers to create arbitrary files in unintended locations on the filesystem | |
| Analizada | Media (4.9) | 0.46% | — | Samsung Data Management Server Firmware | 29/7/2025 | 17/6/2026 | Absolute Path Traversal in Samsung DMS(Data Management Server) allows authenticated attacker (Administrator) to read sensitive files | |
| Analizada | Crítica (9.8) | 0.38% | — | Samsung Data Management Server Firmware | 29/7/2025 | 17/6/2026 | Deserialization of Untrusted Data in Samsung DMS(Data Management Server) allows attackers to execute arbitrary code via write file to system | |
| Analizada | Media (6.5) | 0.31% | — | Samsung Data Management Server Firmware | 29/7/2025 | 17/6/2026 | An execution after redirect in Samsung DMS(Data Management Server) allows attackers to execute limited functions without permissions. An attacker could compromise the integrity of the platform by executing this vulnerability. | |
| Aplazada | Alta (8.7) | 0.85% | — | Hikvision Streaming Media Management ServerAI | 1/7/2025 | 17/6/2026 | Hikvision Streaming Media Management Server v2.3.5 uses default credentials that allow remote attackers to authenticate and access restricted functionality. After authenticating with these credentials, an attacker can exploit an arbitrary file read vulnerability in the /systemLog/downFile.php endpoint via directory… | |
| Aplazada | Alta (7.3) | 0.17% | — | Gdata Management ServerAI | 25/1/2025 | 17/6/2026 | Local privilege escalation due to incorrect assignment of privileges of temporary files in the update mechanism of G DATA Management Server. This vulnerability allows a local, unprivileged attacker to escalate privileges on affected installations by placing a crafted ZIP archive in a globally writable directory, which… | |
| Analizada | Alta (7.3) | 1.3% | — | Fortinet Forticlient Enterprise Management Server | 10/9/2024 | 17/6/2026 | An improper neutralization of special elements used in a command ('Command Injection') vulnerability [CWE-77] in Fortinet FortiClientEMS 7.2.0 through 7.2.4, 7.0.0 through 7.0.12 may allow an unauthenticated attacker to execute limited and temporary operations on the underlying database via crafted requests. | |
| Analizada | Media (6) | 0.74% | — | Fortinet Forticlient Endpoint Management Server | 10/9/2024 | 17/6/2026 | A improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiClientEMS versions 7.2.0 through 7.2.4, 7.0.0 through 7.0.13, 6.4.0 through 6.4.9, 6.2.0 through 6.2.9, 6.0.0 through 6.0.8, 1.2.1 through 1.2.5 allows attacker to perform a denial of service, read or write a limited… | |
| Analizada | Crítica (9.8) | 98% | ⚠ Explotación activa | Fortinet Forticlient Enterprise Management Server | 12/3/2024 | 17/6/2026 | A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiClientEMS version 7.2.0 through 7.2.2, FortiClientEMS 7.0.1 through 7.0.10 allows attacker to execute unauthorized code or commands via specially crafted packets. | |
| Modificada | Alta (8.8) | 1.1% | — | Fortinet Forticlient Endpoint Management Server | 12/3/2024 | 17/6/2026 | A improper neutralization of formula elements in a csv file in Fortinet FortiClientEMS version 7.2.0 through 7.2.2, 7.0.0 through 7.0.10, 6.4.0 through 6.4.9, 6.2.0 through 6.2.9, 6.0.0 through 6.0.8 allows attacker to execute unauthorized code or commands via specially crafted packets. | |
| Modificada | Alta (7.2) | 0.82% | — | Fortinet Forticlient Enterprise Management Server | 15/2/2024 | 17/6/2026 | An improper privilege management vulnerability [CWE-269] in Fortinet FortiClientEMS version 7.2.0 through 7.2.2 and before 7.0.10 allows an Site administrator with Super Admin privileges to perform global administrative operations affecting other sites via crafted HTTP or HTTPS requests. | |
| Modificada | Alta (7.8) | 0.09% | — | Dell EncryptionDell Endpoint Security Suite EnterpriseDell Security Management Server | 6/2/2024 | 17/6/2026 | Dell Encryption, Dell Endpoint Security Suite Enterprise, and Dell Security Management Server versions prior to 11.9.0 contain privilege escalation vulnerability due to improper ACL of the non-default installation directory. A local malicious user could potentially exploit this vulnerability by replacing binaries in… | |
| Modificada | Alta (7.3) | 0.15% | — | Dell Endpoint Security Suite EnterpriseDell EncryptionDell Security Management Server | 16/11/2023 | 17/6/2026 | Dell Encryption, Dell Endpoint Security Suite Enterprise, and Dell Security Management Server version prior to 11.8.1 contain an Insecure Operation on Windows Junction Vulnerability during installation. A local malicious user could potentially exploit this vulnerability to create an arbitrary folder inside a… | |
| Modificada | Media (5.3) | 0.85% | — | Fortinet Forticlient Endpoint Management Server | 13/9/2023 | 17/6/2026 | An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiClientEMS versions 7.0.0 through 7.0.4, 7.0.6 through 7.0.7, in all 6.4 and 6.2 version management interface may allow an unauthenticated attacker to gain information on environment variables such as the EMS installation path. | |
| Modificada | Media (4.3) | 0.25% | — | Proofpoint Insider Threat Management Server | 27/6/2023 | 17/6/2026 | A missing authorization check in multiple URL validation endpoints of the Insider Threat Management Server enables an anonymous attacker on an adjacent network to smuggle content via DNS lookups. All versions before 7.14.3 are affected. |