Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

4193 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.7)0.72%—Paloaltonetworks Idira Privileged Session Manager11/6/202623/6/2026
Incomplete input validation and improperly configured folder permissions within Idira Privileged Session Manager (PSM) versions prior to 15.0.3, 14.6.3, 14.2.5, and 14.0.5, an authenticated, low-privileged user could potentially execute arbitrary code. CyberArk Security Bulletin: CA26-17 and CA26-18
AnalizadaAlta (8.5)0.17%—Paloaltonetworks Idira Endpoint Privilege Manager11/6/202622/6/2026
Idira Endpoint Privilege Manager Agent versions prior to 26.5 exhibit improper access control within internal agent validation processes. A local attacker could potentially bypass built-in security controls or cryptographic validations. Under specific circumstances, this could allow the attacker to circumvent agent…
AnalizadaAlta (8.4)0.51%—Paloaltonetworks Idira Secrets ManagerPaloaltonetworks Idira Secrets Manager Credential Providers11/6/202622/6/2026
Idira Secrets Manager Self-Hosted versions 13.8.0 and lower exhibit improper access control within internal cluster endpoints. A remote, authenticated attacker possessing standard node-level credentials could leverage these endpoints to potentially retrieve unauthorized secrets or cause a denial of service (DoS).…
AnalizadaCrítica (9.1)0.73%—Paloaltonetworks Idira Secrets Manager Edge11/6/202622/6/2026
Idira Secrets Manager SaaS Edge versions prior to 1.8 exhibit improper access control within its internal authentication components. A remote, unauthenticated attacker could exploit this by submitting a specially crafted request. Under specific circumstances, this could allow the attacker to manipulate internal…
AnalizadaAlta (8.9)0.17%—Paloaltonetworks Idira Endpoint Privilege Manager11/6/202622/6/2026
Idira Endpoint Privilege Manager Agent versions prior to 26.5 exhibit improper access control within high-privileged agent components. A local, low-privileged attacker could exploit this by manipulating an internal communication mechanism or file operation. Under specific circumstances, this could potentially allow…
En análisisAlta (8.1)0.29%—Paloaltonetworks Cortex Xsiam Commvaultsecurityiq MarketplacePaloaltonetworks Cortex Xsoar Commvaultsecurityiq Marketplace10/6/202623/7/2026
An improper validation of credentials vulnerability in the CommvaultSecurityIQ integration for Cortex XSOAR and Cortex XSIAM allows an unauthenticated attacker to access and modify protected resources.
ModificadaMedia (6.1)1.3%💥 PoCPaloaltonetworks Pan-os10/6/202623/7/2026
A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as a root user. To be able to exploit this issue, the user must have access to the PAN-OS CLI or Web UI. The security risk posed by this issue is…
ModificadaMedia (6)0.26%—Paloaltonetworks Pan-os10/6/202623/7/2026
A privilege escalation vulnerability in Palo Alto Networks PAN-OS® software allows an authenticated administrator with access to the Command Line Interface (CLI) to perform actions on the device with root privileges. The security risk posed by this issue is significantly minimized when CLI access is restricted to a…
AnalizadaMedia (5.9)0.11%—Paloaltonetworks Prisma Access Agent10/6/202623/7/2026
A privilege escalation (PE) vulnerability in the Palo Alto Networks Prisma Access Agent app on Linux devices enables a local user to execute code with elevated privileges. This does not impact Prisma Access Agent on Windows, macOS, iOS, Android, or ChromeOS.
AnalizadaMedia (4.8)0.20%—Paloaltonetworks Cortex Xsoar10/6/202623/7/2026
A path traversal vulnerability in Palo Alto Networks Cortex XSOAR engine software running on Linux allows an unauthenticated attacker on an adjacent network, with the ability to intercept and manipulate network response traffic via a man-in-the-middle (MITM) attack, to write arbitrary files to the host.
ModificadaMedia (4.6)0.22%—Paloaltonetworks Pan-os10/6/202623/7/2026
A memory corruption vulnerability in the processing of tunnel traffic in Palo Alto Networks PAN-OS® software allows an authenticated user to initiate system reboots using a maliciously crafted packet. Repeated attempts to initiate a reboot causes the firewall to enter maintenance mode. Panorama, Cloud NGFW, and…
AnalizadaMedia (4.4)0.10%—Paloaltonetworks Prisma Access Agent10/6/202623/7/2026
A security control bypass vulnerability in Prisma Access Agent for Linux allows a local attacker to route network traffic outside the VPN tunnel. This does not impact Prisma Access Agent on Windows, macOS, iOS, Android, or ChromeOS.
AnalizadaMedia (4.4)0.10%—Paloaltonetworks Globalprotect10/6/202623/7/2026
An information exposure vulnerability in the Palo Alto Networks GlobalProtect app on macOS enables a local user to learn the configured passcodes for disabling, disconnecting, or uninstalling the GlobalProtect app. After the passcode is known, the user can perform these actions even if the GlobalProtect app…
ModificadaBaja (1.1)0.14%—Paloaltonetworks Pan-os10/6/202623/7/2026
A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS® software enables a malicious authenticated administrator to store a JavaScript payload using the web interface. This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series). Cloud NGFW…
AplazadaMedia (5.3)0.51%—NimiqAINimiq Network-libp2pAI10/6/202623/7/2026
Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. network-libp2p handles kad get-record query progress in handle_dht_get (network-libp2p/src/swarm.rs). Prior to version 1.4.0, when a peer returns a FoundRecord, the code verifies the record via…
AplazadaCrítica (9.8)0.21%—Shenzhen Kangda XIN Intelligent Network Technology Dr300AI9/6/202623/7/2026
Shenzhen Kangda Xin Intelligent Network Technology Company's router, model DR300, version 2.1.2.121, contains hardcoded login credentials and has telnet enabled by default on WAN and LAN interfaces. These vulnerabilities allow attackers to read and write to memory, modify firmware stored in flash, inspect active…
AnalizadaAlta (8.2)0.35%—Microsoft Azure Network Adapter9/6/202623/7/2026
Use after free in Linux MANA Driver allows an authorized attacker to elevate privileges locally.
AplazadaAlta (7.5)0.46%—Cloudburst NetworkAINettyAI5/6/202617/6/2026
Cloudburst Network provides network components used within Cloudburst projects. A vulnerability in versions prior to `1.0.0.CR3-20260418.124334-32` impacts publicly accessible software depending on the affected versions of Network and allows an attacker to exploit a bug in Network to close the parent netty channel,…
AplazadaAlta (7.5)0.46%—Cloudburst NetworkAINettyAI5/6/202617/6/2026
Cloudburst Network provides network components used within Cloudburst projects. A vulnerability in versions prior to `1.0.0.CR3-20260417.085727-30` impacts publicly accessible software depending on the affected versions of Network and allows an attacker to exploit a vulnerability in Network to stall the netty event…
Pendiente de análisisAlta (8.4)0.62%—Teltonika-networks RutosAITeltonika-networks TswosAI5/6/202617/6/2026
In Teltonika Networks RUTOS devices, running versions 7.22 through 7.23.2 and TSWOS devices running versions 1.09 through 1.09.1, due to unsafe calls to an eval function in rpc-profile, a vulnerability exists where a lower privileged user could perform command injection as the root user.
Pendiente de análisisMedia (6.7)0.17%—NetworkmanagerAI4/6/202625/9/2026
A flaw was found in NetworkManager. This local privilege escalation vulnerability exists in NetworkManager's dhclient backend when processing malformed Manufacturer Usage Description (MUD) URLs. A local user can exploit this flaw to escalate privileges by triggering a script via a crafted MUD URL, provided an…
AnalizadaAlta (8.2)0.07%💥 PoCQualcomm Ar9380 FirmwareQualcomm Csr8811 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 Firmware+2421/6/202622/7/2026
Cryptographic Issue while processing a specific partition which allows unauthorized write access to load a customized bootloader.
AnalizadaMedia (5.5)0.09%—Qualcomm 5G Fixed Wireless Access Platform FirmwareQualcomm Ar8035 FirmwareQualcomm Csr8811 FirmwareQualcomm Fastconnect 6700 Firmware+1831/6/202622/7/2026
Information Disclosure when processing advertisement frames with malformed MBSSID elements of insufficient length.
AplazadaMedia (5.3)0.30%—Stormshield Network SecurityAI1/6/202622/7/2026
A vulnerability was discovered on Stormshield Network Security It is possible to execute a reflected XSS attack on the login API available on Stormshield SNS appliance by executing a script on the victim's machine. The risks include the theft of cookies or other sensitive data, as well as the modification of page…
Pendiente de análisisAlta (7.5)0.24%—Networkoptix NX Witness VMSAI29/5/202621/7/2026
CORS misconfiguration in the REST API of Network Optix Nx Witness VMS before version 6.1.2, when running in the default Standard security mode, on Linux and Windows allows an unauthenticated remote attacker to steal the session token of an authenticated user and perform Administrator Account Takeover via a malicious…