Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
5318 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Baja (1.1) | 0.14% | — | Paloaltonetworks Pan-os | 10/6/2026 | 23/7/2026 | A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS® software enables a malicious authenticated administrator to store a JavaScript payload using the web interface. This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series). Cloud NGFW… | |
| Pendiente de análisis | Alta (7.8) | 0.13% | — | Omnissa Workspace ONE AssistAI | 9/6/2026 | 23/7/2026 | Omnissa Workspace ONE® Assist for macOS contains a Local Privilege Escalation Vulnerability. | |
| Pendiente de análisis | Alta (8.4) | 0.62% | — | Teltonika-networks RutosAITeltonika-networks TswosAI | 5/6/2026 | 17/6/2026 | In Teltonika Networks RUTOS devices, running versions 7.22 through 7.23.2 and TSWOS devices running versions 1.09 through 1.09.1, due to unsafe calls to an eval function in rpc-profile, a vulnerability exists where a lower privileged user could perform command injection as the root user. | |
| Analizada | Alta (8.8) | 0.67% | — | Accellion Kiteworks | 1/6/2026 | 22/7/2026 | Kiteworks is a private data network (PDN). Prior to version 9.3.0,ultiple SQL Injection vulnerabilities in Kiteworks Secure Data Forms could be exploited by an authenticated attacker with the FormBuilder role to retrieve information on or modify other users' form definitions and some global configuration parameters.… | |
| Analizada | Media (4.3) | 0.14% | — | Accellion Kiteworks | 1/6/2026 | 22/7/2026 | Kiteworks is a private data network (PDN). Prior to version 9.3.0, an Insecure Direct Object Reference (IDOR) vulnerability in Kiteworks Secure Data Forms allows an authenticated user to access metadata of resources belonging to other users due to insufficient authorization checks on resource ownership. Upgrade… | |
| Analizada | Media (4.3) | 0.15% | — | Accellion Kiteworks | 1/6/2026 | 22/7/2026 | Kiteworks is a private data network (PDN). Prior to version 9.3.0, an Insecure Direct Object Reference (IDOR) vulnerability in Kiteworks Secure Data Forms allows an authenticated user to modify resources belonging to other users due to insufficient authorization checks on resource ownership. Upgrade Kiteworks to… | |
| Analizada | Media (5.4) | 0.14% | — | Accellion Kiteworks | 1/6/2026 | 22/7/2026 | Kiteworks is a private data network (PDN). Prior to version 9.3.0, an Insecure Direct Object Reference (IDOR) vulnerability in Kiteworks Secure Data Forms allows an authenticated user to modify permissions on resources belonging to other users due to insufficient authorization checks on resource ownership. Upgrade… | |
| Analizada | Media (5.4) | 0.14% | — | Accellion Kiteworks | 1/6/2026 | 22/7/2026 | Kiteworks is a private data network (PDN). Prior to version 9.3.0, a stored XSS vulnerability in Kiteworks Secure Data Forms could allow an authenticated attacker to execute arbitrary JavaScript code in other users' sessions. Upgrade Kiteworks to version 9.3.0 or later to receive a patch. | |
| Analizada | Media (6.5) | 0.17% | — | Accellion Kiteworks | 1/6/2026 | 22/7/2026 | Kiteworks is a private data network (PDN). Prior to version 9.3.0, an Insecure Direct Object Reference (IDOR) vulnerability in Kiteworks Secure Data Forms allows an authenticated user to modify resources belonging to other users due to insufficient authorization checks on resource ownership. Upgrade Kiteworks to… | |
| Analizada | Alta (8.2) | 0.28% | — | Accellion Kiteworks | 1/6/2026 | 22/7/2026 | Kiteworks is a private data network (PDN). Prior to version 9.3.0, a reflected XSS vulnerability in Kiteworks Secure Data Forms could allow an external attacker to trick a user into executing arbitrary JavaScript code. Upgrade Kiteworks to version 9.3.0 or later to receive a patch. | |
| Analizada | Alta (8.2) | 0.29% | — | Accellion Kiteworks | 1/6/2026 | 22/7/2026 | Kiteworks is a private data network (PDN). Prior to version 9.3.0, a reflected XSS vulnerability in Kiteworks Secure Data Forms could allow an external attacker to trick a user into executing arbitrary JavaScript code. Upgrade Kiteworks to version 9.3.0 or later to receive a patch. | |
| Analizada | Media (6.5) | 0.18% | — | Accellion Kiteworks | 1/6/2026 | 22/7/2026 | Kiteworks is a private data network (PDN). Prior to version 9.3.0, an Insecure Direct Object Reference (IDOR) vulnerability in Kiteworks Secure Data Forms allows an authenticated attacker to tamper with the internal approval flow configurations of forms belonging to other users due to insufficient authorization checks… | |
| Aplazada | Baja (2.1) | 0.28% | — | J3k0 MCP Google WorkspaceAI | 1/6/2026 | 22/7/2026 | A vulnerability was found in j3k0 mcp-google-workspace up to 831790e7d5c2663325733d9f5579cc339a267c4c. This issue affects the function saveToDisk of the file src/tools/gmail.ts of the component MCP Gmail Tool. Performing a manipulation results in improper access controls. It is possible to initiate the attack… | |
| Analizada | Crítica (9.8) | 1.8% | — | Inhandnetworks Ir315 FirmwareInhandnetworks Ir302 FirmwareInhandnetworks Ir615 FirmwareInhandnetworks Ir305 Firmware | 28/5/2026 | 17/6/2026 | A command injection vulnerability exists in the IPSec VPN feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR315 firmware V1.0.118, IR615 firmware V1.0.118, and earlier versions. Attackers can exploit this vulnerability to obtain ROOT privileges on remote target devices. | |
| Analizada | Crítica (9.8) | 1.8% | — | Inhandnetworks Ir315 FirmwareInhandnetworks Ir302 FirmwareInhandnetworks Ir615 FirmwareInhandnetworks Ir305 Firmware | 28/5/2026 | 17/6/2026 | A command injection vulnerability exists in the WireGuard VPN feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR315 firmware V1.0.118, IR615 firmware V1.0.118, and earlier versions. Attackers can exploit this vulnerability to obtain ROOT privileges on remote target devices. | |
| Analizada | Crítica (9.8) | 1.8% | — | Inhandnetworks Ir315 FirmwareInhandnetworks Ir302 FirmwareInhandnetworks Ir615 FirmwareInhandnetworks Ir305 Firmware | 28/5/2026 | 17/6/2026 | A command injection vulnerability exists in the ZeroTier VPN feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR315 firmware V1.0.118, IR615 firmware V1.0.118, and earlier versions. Attackers can exploit this vulnerability to obtain ROOT privileges on remote target devices. | |
| Analizada | Crítica (9.8) | 1.8% | — | Inhandnetworks Ir315 FirmwareInhandnetworks Ir302 FirmwareInhandnetworks Ir615 FirmwareInhandnetworks Ir305 Firmware | 28/5/2026 | 17/6/2026 | A command injection vulnerability exists in the Admin Access feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR315 firmware V1.0.118, IR615 firmware V1.0.118, and earlier versions. Attackers can exploit this vulnerability to obtain ROOT privileges on remote target devices. | |
| Modificada | Media (5.1) | 0.19% | — | Nozominetworks CMCNozominetworks Guardian | 19/5/2026 | 17/6/2026 | A Stored HTML Injection vulnerability was discovered in the Smart Polling functionality due to improper validation of an input parameter. An authenticated user with limited privileges can push malicious remote strategies containing HTML tags through the sync. When a victim views the affected remote strategy in the… | |
| Modificada | Media (4.8) | 0.19% | — | Nozominetworks CMCNozominetworks Guardian | 19/5/2026 | 17/6/2026 | A Stored HTML Injection vulnerability was discovered in the Schedule Restore Archive functionality due to improper validation of an input parameter. An authenticated user with administrative privileges can define a malicious restore schedule containing HTML tags. When a victim views the affected schedule, the injected… | |
| Modificada | Media (4.8) | 0.19% | — | Nozominetworks CMCNozominetworks Guardian | 19/5/2026 | 17/6/2026 | A Stored HTML Injection vulnerability was discovered in the Users functionality due to improper validation of an input parameter. An authenticated user with administrative privileges can create a malicious user whose username contains HTML tags. When a victim attempts to delete a group containing the affected user,… | |
| Modificada | Media (4.8) | 0.19% | — | Nozominetworks CMCNozominetworks Guardian | 19/5/2026 | 17/6/2026 | A Stored HTML Injection vulnerability was discovered in the Credentials Manager functionality due to improper validation of an input parameter. An authenticated user with administrative privileges can define a malicious identity containing HTML tags. When a victim attempts to delete the affected identity, the injected… | |
| Modificada | Media (5.1) | 0.20% | — | Nozominetworks CMCNozominetworks Guardian | 19/5/2026 | 17/6/2026 | An Angular template injection vulnerability was discovered in the Reports functionality due to improper validation of an input parameter. An authenticated user with report privileges can define a malicious report containing an Angular template payload, or a victim can be socially engineered to import a malicious… | |
| Analizada | Media (4.9) | 0.17% | — | Paloaltonetworks Prisma Sd-wan | 13/5/2026 | 14/7/2026 | A denial of service (DoS) vulnerability in Palo Alto Networks Prisma SD-WAN ION devices enables an unauthenticated attacker in a network adjacent to a Prisma SD-WAN ION device to cause a system disruption by sending a specially crafted IPv6 packet. | |
| Analizada | Media (6.6) | 0.36% | — | Paloaltonetworks Pan-osSiemens Ruggedcom Ape1808 Firmware | 13/5/2026 | 14/7/2026 | Multiple denial of service vulnerabilities in Palo Alto Networks PAN-OS® software allow an unauthenticated attacker with network access to cause a denial of service (DoS) condition by sending specially crafted network traffic. Panorama and Cloud NGFW are not impacted by these vulnerabilities. | |
| Analizada | Media (6.1) | 1.4% | — | Paloaltonetworks Pan-osSiemens Ruggedcom Ape1808 Firmware | 13/5/2026 | 14/7/2026 | Multiple command injection vulnerabilities in Palo Alto Networks PAN-OS® software enable an authenticated administrator to bypass system restrictions and run arbitrary commands as a root user. To be able to exploit this issue, the user must have access to the PAN-OS CLI or Web UI. The security risk posed by this issue… |