Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
567 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.3) | 0.80% | — | Lopalopa College Management System | 14/5/2024 | 17/6/2026 | A vulnerability was found in Kashipara College Management System 1.0 and classified as critical. This issue affects some unknown processing of the file submit_new_faculty.php. The manipulation of the argument address leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the… | |
| Analizada | Media (5.3) | 0.83% | — | Lopalopa College Management System | 14/5/2024 | 17/6/2026 | A vulnerability has been found in Kashipara College Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file submit_student.php. The manipulation of the argument date_of_birth leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to… | |
| Analizada | Media (5.3) | 0.81% | — | Lopalopa College Management System | 14/5/2024 | 17/6/2026 | A vulnerability, which was classified as critical, was found in Kashipara College Management System 1.0. This affects an unknown part of the file view_each_faculty.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the… | |
| Analizada | Alta (7.6) | 4.1% | 💥 PoC | Fortinet ForticlientCisco Anyconnect VPN ClientCisco Secure ClientPaloaltonetworks Globalprotect+5 | 6/5/2024 | 17/6/2026 | DHCP can add routes to a client’s routing table via the classless static route option (121). VPN-based security solutions that rely on routes to redirect traffic can be forced to leak traffic over the physical interface. An attacker on the same local network can read, disrupt, or possibly modify network traffic that… | |
| Analizada | Crítica (10) | 100% | ⚠ Explotación activa💥 Exploit | Paloaltonetworks Pan-os | 12/4/2024 | 17/6/2026 | A command injection as a result of arbitrary file creation vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software for specific PAN-OS versions and distinct feature configurations may enable an unauthenticated attacker to execute arbitrary code with root privileges on the firewall. Cloud NGFW,… | |
| Analizada | Media (5) | 0.35% | — | Paloaltonetworks Pan-osPaloaltonetworks Prisma Access | 10/4/2024 | 17/6/2026 | A vulnerability in the GlobalProtect Gateway in Palo Alto Networks PAN-OS software enables an authenticated attacker to impersonate another user and send network packets to internal assets. However, this vulnerability does not allow the attacker to receive response packets from those internal assets. | |
| Analizada | Media (5.9) | 0.17% | — | Paloaltonetworks Pan-os | 10/4/2024 | 17/6/2026 | A weak (low bit strength) device certificate in Palo Alto Networks Panorama software enables an attacker to perform a meddler-in-the-middle (MitM) attack to capture encrypted traffic between the Panorama management server and the firewalls it manages. With sufficient computing resources, the attacker could break… | |
| Analizada | Media (5.3) | 0.44% | — | Paloaltonetworks Pan-os | 10/4/2024 | 17/6/2026 | An incorrect string comparison vulnerability in Palo Alto Networks PAN-OS software prevents Predefined Decryption Exclusions from functioning as intended. This can cause traffic destined for domains that are not specified in Predefined Decryption Exclusions to be unintentionally excluded from decryption. | |
| Analizada | Alta (7.5) | 0.91% | — | Paloaltonetworks Pan-os | 10/4/2024 | 17/6/2026 | A packet processing mechanism in Palo Alto Networks PAN-OS software enables a remote attacker to reboot hardware-based firewalls. Repeated attacks eventually cause the firewall to enter maintenance mode, which requires manual intervention to bring the firewall back online. This affects the following hardware firewall… | |
| Analizada | Alta (7.5) | 0.89% | — | Paloaltonetworks Pan-os | 10/4/2024 | 17/6/2026 | A vulnerability in Palo Alto Networks PAN-OS software enables a remote attacker to reboot PAN-OS firewalls when receiving Windows New Technology LAN Manager (NTLM) packets from Windows servers. Repeated attacks eventually cause the firewall to enter maintenance mode, which requires manual intervention to bring the… | |
| Analizada | Crítica (9.1) | 0.58% | — | Paloaltonetworks Pan-os | 10/4/2024 | 17/6/2026 | A vulnerability in how Palo Alto Networks PAN-OS software processes data received from Cloud Identity Engine (CIE) agents enables modification of User-ID groups. This impacts user access to network resources where users may be inappropriately denied or allowed access to resources based on your existing Security Policy… | |
| Analizada | Alta (7.5) | 0.93% | — | Paloaltonetworks Pan-os | 10/4/2024 | 17/6/2026 | A memory leak exists in Palo Alto Networks PAN-OS software that enables an attacker to send a burst of crafted packets through the firewall that eventually prevents the firewall from processing traffic. This issue applies only to PA-5400 Series devices that are running PAN-OS software with the SSL Forward Proxy… | |
| Analizada | Baja (2.7) | 0.57% | — | Paloaltonetworks Pan-os | 13/3/2024 | 17/6/2026 | An improper authorization vulnerability in Palo Alto Networks Panorama software enables an authenticated read-only administrator to upload files using the web interface and completely fill one of the disk partitions with those uploaded files, which prevents the ability to log into the web interface or to download… | |
| Analizada | Alta (7) | 0.39% | 💥 PoC | Paloaltonetworks Globalprotect | 13/3/2024 | 17/6/2026 | A privilege escalation (PE) vulnerability in the Palo Alto Networks GlobalProtect app on Windows devices enables a local user to execute programs with elevated privileges. However, execution requires that the local user is able to successfully exploit a race condition. | |
| Analizada | Media (5.5) | 0.15% | — | Paloaltonetworks Globalprotect | 13/3/2024 | 17/6/2026 | An issue in the Palo Alto Networks GlobalProtect app enables a non-privileged user to disable the GlobalProtect app in configurations that allow a user to disable GlobalProtect with a passcode. | |
| Analizada | Alta (8.6) | 0.74% | — | Lopalopa Dynamic LAB Management System | 27/2/2024 | 17/6/2026 | SQL injection vulnerability in Dynamic Lab Management System Project in PHP v.1.0 allows a remote attacker to execute arbitrary code via a crafted script. | |
| Analizada | Media (6.1) | 0.38% | — | Paloaltonetworks Pan-os | 14/2/2024 | 17/6/2026 | A reflected cross-site scripting (XSS) vulnerability in the Captive Portal feature of Palo Alto Networks PAN-OS software enables execution of malicious JavaScript (in the context of an authenticated Captive Portal user’s browser) if a user clicks on a malicious link, allowing phishing attacks that could lead to… | |
| Analizada | Media (6.1) | 0.51% | — | Paloaltonetworks Pan-os | 14/2/2024 | 17/6/2026 | A reflected cross-site scripting (XSS) vulnerability in the GlobalProtect portal feature of Palo Alto Networks PAN-OS software enables execution of malicious JavaScript (in the context of a user’s browser) if a user clicks on a malicious link, allowing phishing attacks that could lead to credential theft. | |
| Analizada | Media (6.3) | 0.20% | — | Paloaltonetworks Pan-os | 14/2/2024 | 17/6/2026 | An improper verification vulnerability in the GlobalProtect gateway feature of Palo Alto Networks PAN-OS software enables a malicious user with stolen credentials to establish a VPN connection from an unauthorized IP address. | |
| Analizada | Alta (8.8) | 0.50% | — | Paloaltonetworks Pan-os | 14/2/2024 | 17/6/2026 | Web sessions in the management interface in Palo Alto Networks PAN-OS software do not expire in certain situations, making it susceptible to unauthorized access. | |
| Analizada | Media (4.8) | 0.40% | — | Paloaltonetworks Pan-os | 14/2/2024 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software enables a malicious authenticated read-write administrator to store a JavaScript payload using the web interface on Panorama appliances. This enables the impersonation of another authenticated administrator. | |
| Modificada | Alta (7.5) | 0.73% | — | Lopalopa Dynamic LAB Management System | 8/1/2024 | 17/6/2026 | A vulnerability was found in Kashipara Dynamic Lab Management System up to 1.0. It has been declared as critical. This vulnerability affects unknown code of the file login_process.php. The manipulation of the argument password leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed… | |
| Modificada | Alta (7.5) | 0.67% | — | Lopalopa Dynamic LAB Management System | 8/1/2024 | 17/6/2026 | A vulnerability was found in Kashipara Dynamic Lab Management System up to 1.0. It has been classified as critical. This affects an unknown part of the file /admin/admin_login_process.php. The manipulation of the argument admin_password leads to sql injection. It is possible to initiate the attack remotely. The… | |
| Modificada | Media (4.7) | 1.1% | — | Paloaltonetworks Pan-os | 13/12/2023 | 17/6/2026 | An OS command injection vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to disrupt system processes and potentially execute arbitrary code with limited privileges on the firewall. | |
| Modificada | Media (4.7) | 0.57% | — | Paloaltonetworks Pan-os | 13/12/2023 | 17/6/2026 | An arbitrary file upload vulnerability in Palo Alto Networks PAN-OS software enables an authenticated read-write administrator with access to the web interface to disrupt system processes and potentially execute arbitrary code with limited privileges on the firewall. |