Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

5318 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.8)2.3%—Inhandnetworks Ir915l-fq39-s FirmwareInhandnetworks Ir912l-fq58 Firmware18/6/202622/6/2026
InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to contain a command injection vulnerability in the Python application export function. This vulnerability allows remote attackers to execute arbitrary commands as root via a crafted input.
AnalizadaCrítica (9.8)2.3%—Inhandnetworks Ir915l-fq39-s FirmwareInhandnetworks Ir912l-fq58 Firmware18/6/202622/6/2026
InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to contain a command injection vulnerability in the log viewing function. This vulnerability allows remote attackers to execute arbitrary commands as root via a crafted input.
AnalizadaCrítica (9.8)2.3%—Inhandnetworks Ir915l-fq39-s FirmwareInhandnetworks Ir912l-fq58 Firmware18/6/202622/6/2026
InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to contain a command injection vulnerability in the Python configuration function. This vulnerability allows remote attackers to execute arbitrary commands as root via a crafted input.
AplazadaCrítica (9.3)0.39%—WorksnapsAIAmazon AWSAIAmazon S3AI18/6/20266/10/2026
Worksnaps before version 1.6.20260201 contains hardcoded cloud credentials and related secret material in the Worksnaps client application binaries. The exposed credentials included AWS access keys, S3 bucket names, and related cloud access information. The originally exposed AWS credentials authenticated as the AWS…
AplazadaMedia (6.5)0.41%—Workscout-coreAI17/6/202617/6/2026
Unauthenticated Arbitrary File Deletion in WorkScout-Core <= 1.7.11 versions.
Pendiente de análisisCrítica (9.8)0.38%—Solidworks VisualizeAI17/6/202617/6/2026
A Path Traversal vulnerability affecting SOLIDWORKS Visualize from SOLIDWORKS Desktop Release 2024 through SOLIDWORKS Desktop Release 2026 could allow an attacker to write arbitrary files on the server.
AplazadaMedia (4.8)0.10%—Genspark AI Workspace APPAI14/6/202624/7/2026
A vulnerability has been found in Genspark AI Workspace App 2.8.4 on Android. This vulnerability affects unknown code of the component ai.mainfunc.genspark. The manipulation leads to improper authorization in handler for custom url scheme. The attack can only be performed from a local environment. The vendor was…
AnalizadaAlta (8.7)0.63%—Paloaltonetworks Idira Privileged Access Manager Vault12/6/20267/7/2026
Idira Privileged Access Manager (PAM) Self-Hosted Vault versions prior to 15.0.3, 14.6.5, 14.2.7, and 14.0.8 exhibit a validation vulnerability. Under specific circumstances and configuration scenarios, processing unexpected input could potentially lead to an unexpected service termination, resulting in a localized…
ModificadaAlta (7.5)0.17%—Paloaltonetworks Idira Privilege Cloud Connector12/6/202623/6/2026
Idira Vendor PAM - Self-Hosted Connector versions prior 1.1.100504 under specific conditions and configuration scenarios, TLS certificate validation may not be fully enforced. CyberArk Security Bulletin: CA26-17
AnalizadaAlta (8.5)0.17%—Paloaltonetworks Idira Endpoint Privilege Manager11/6/202622/6/2026
Idira Endpoint Privilege Manager Linux Agent versions prior to 26.5 allow a local attacker to potentially compromise the agent daemon initialization. CyberArk Security Bulletin: CA26-19
AnalizadaAlta (8.4)0.21%—Paloaltonetworks Idira Identity Browser Extension11/6/202622/6/2026
Idira Identity Browser Extension (Chrome, Firefox, and Edge builds) versions prior to 26.8.1 exhibit an origin validation flaw within its internal web-page verification routines. If an authenticated user navigates to a specially crafted webpage, this interaction could potentially allow a remote attacker to trigger…
AnalizadaAlta (8.7)0.81%—Paloaltonetworks Idira Privileged Session Manager FOR SSH11/6/202623/6/2026
Due to incomplete input validation in Idira Privileged Session Manager for SSH (PSMP) versions prior to 15.0.2, 14.6.3, 14.2.5, and 14.0.6, an authenticated, low-privileged user could potentially execute arbitrary commands on the PSMP host. CyberArk Security Bulletins: CA26-17 and CA26-18
AnalizadaAlta (8.7)0.72%—Paloaltonetworks Idira Privileged Session Manager11/6/202623/6/2026
Incomplete input validation and improperly configured folder permissions within Idira Privileged Session Manager (PSM) versions prior to 15.0.3, 14.6.3, 14.2.5, and 14.0.5, an authenticated, low-privileged user could potentially execute arbitrary code. CyberArk Security Bulletin: CA26-17 and CA26-18
AnalizadaAlta (8.5)0.17%—Paloaltonetworks Idira Endpoint Privilege Manager11/6/202622/6/2026
Idira Endpoint Privilege Manager Agent versions prior to 26.5 exhibit improper access control within internal agent validation processes. A local attacker could potentially bypass built-in security controls or cryptographic validations. Under specific circumstances, this could allow the attacker to circumvent agent…
AnalizadaAlta (8.4)0.51%—Paloaltonetworks Idira Secrets ManagerPaloaltonetworks Idira Secrets Manager Credential Providers11/6/202622/6/2026
Idira Secrets Manager Self-Hosted versions 13.8.0 and lower exhibit improper access control within internal cluster endpoints. A remote, authenticated attacker possessing standard node-level credentials could leverage these endpoints to potentially retrieve unauthorized secrets or cause a denial of service (DoS).…
AnalizadaCrítica (9.1)0.73%—Paloaltonetworks Idira Secrets Manager Edge11/6/202622/6/2026
Idira Secrets Manager SaaS Edge versions prior to 1.8 exhibit improper access control within its internal authentication components. A remote, unauthenticated attacker could exploit this by submitting a specially crafted request. Under specific circumstances, this could allow the attacker to manipulate internal…
AnalizadaAlta (8.9)0.17%—Paloaltonetworks Idira Endpoint Privilege Manager11/6/202622/6/2026
Idira Endpoint Privilege Manager Agent versions prior to 26.5 exhibit improper access control within high-privileged agent components. A local, low-privileged attacker could exploit this by manipulating an internal communication mechanism or file operation. Under specific circumstances, this could potentially allow…
En análisisAlta (8.1)0.29%—Paloaltonetworks Cortex Xsiam Commvaultsecurityiq MarketplacePaloaltonetworks Cortex Xsoar Commvaultsecurityiq Marketplace10/6/202623/7/2026
An improper validation of credentials vulnerability in the CommvaultSecurityIQ integration for Cortex XSOAR and Cortex XSIAM allows an unauthenticated attacker to access and modify protected resources.
ModificadaMedia (6.1)1.3%💥 PoCPaloaltonetworks Pan-os10/6/202623/7/2026
A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as a root user. To be able to exploit this issue, the user must have access to the PAN-OS CLI or Web UI. The security risk posed by this issue is…
ModificadaMedia (6)0.26%—Paloaltonetworks Pan-os10/6/202623/7/2026
A privilege escalation vulnerability in Palo Alto Networks PAN-OS® software allows an authenticated administrator with access to the Command Line Interface (CLI) to perform actions on the device with root privileges. The security risk posed by this issue is significantly minimized when CLI access is restricted to a…
AnalizadaMedia (5.9)0.11%—Paloaltonetworks Prisma Access Agent10/6/202623/7/2026
A privilege escalation (PE) vulnerability in the Palo Alto Networks Prisma Access Agent app on Linux devices enables a local user to execute code with elevated privileges. This does not impact Prisma Access Agent on Windows, macOS, iOS, Android, or ChromeOS.
AnalizadaMedia (4.8)0.20%—Paloaltonetworks Cortex Xsoar10/6/202623/7/2026
A path traversal vulnerability in Palo Alto Networks Cortex XSOAR engine software running on Linux allows an unauthenticated attacker on an adjacent network, with the ability to intercept and manipulate network response traffic via a man-in-the-middle (MITM) attack, to write arbitrary files to the host.
ModificadaMedia (4.6)0.22%—Paloaltonetworks Pan-os10/6/202623/7/2026
A memory corruption vulnerability in the processing of tunnel traffic in Palo Alto Networks PAN-OS® software allows an authenticated user to initiate system reboots using a maliciously crafted packet. Repeated attempts to initiate a reboot causes the firewall to enter maintenance mode. Panorama, Cloud NGFW, and…
AnalizadaMedia (4.4)0.10%—Paloaltonetworks Prisma Access Agent10/6/202623/7/2026
A security control bypass vulnerability in Prisma Access Agent for Linux allows a local attacker to route network traffic outside the VPN tunnel. This does not impact Prisma Access Agent on Windows, macOS, iOS, Android, or ChromeOS.
AnalizadaMedia (4.4)0.10%—Paloaltonetworks Globalprotect10/6/202623/7/2026
An information exposure vulnerability in the Palo Alto Networks GlobalProtect app on macOS enables a local user to learn the configured passcodes for disabling, disconnecting, or uninstalling the GlobalProtect app. After the passcode is known, the user can perform these actions even if the GlobalProtect app…