Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

1845 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9)0.18%—Clininetworks ClininetworkAI27/8/202517/6/2026
Unauthenticated access to the "/cgi-bin/CliniNET.prd/GetActiveSessions.pl" endpoint allows takeover of any user session logged into the system, including users with admin privileges.
AplazadaMedia (5.3)0.21%—Nozominetworks CMCAI26/8/202517/6/2026
An access control vulnerability was discovered in the Request Trace and Download Trace functionalities of CMC before 25.1.0 due to a specific access restriction not being properly enforced for users with limited privileges. An authenticated user with limited privileges can request and download trace files due to…
AnalizadaBaja (2.1)7.7%—Dcnetworks Dcme-720 Firmware24/8/202517/6/2026
A vulnerability was found in DCN DCME-720 9.1.5.11. This affects an unknown function of the file /usr/local/www/function/audit/newstatistics/ip_block.php of the component Web Management Backend. Performing manipulation of the argument ip results in os command injection. It is possible to initiate the attack remotely.…
AplazadaAlta (8.7)1.1%💥 ExploitRealnetworks RealarcadeAIRealnetworks GamehouseAI20/8/202516/6/2026
The RealNetworks RealArcade platform includes an ActiveX control (InstallerDlg.dll, version 2.6.0.445) that exposes a method named Exec via the StubbyUtil.ProcessMgr COM object. This method allows remote attackers to execute arbitrary commands on a victim's Windows machine without proper validation or restrictions.…
AplazadaCrítica (9.3)0.49%💥 ExploitRealnetworks Netzip ClassicAI13/8/202516/6/2026
Real Networks Netzip Classic version 7.5.1.86 is vulnerable to a stack-based buffer overflow when parsing a specially crafted ZIP archive. The vulnerability is triggered when the application attempts to process a file name within the archive that exceeds the expected buffer size. Exploitation allows arbitrary code…
AplazadaMedia (5.3)0.17%—Paloaltonetworks Cortex XDR Broker VMAI13/8/202517/6/2026
A credential management flaw in Palo Alto Networks Cortex XDR® Broker VM causes different Broker VM images to share identical default credentials for internal services. Users knowing these default credentials could access internal services on other Broker VM installations. The attacker must have network access to the…
AplazadaMedia (5.3)0.12%—Paloaltonetworks GlobalprotectAI13/8/202517/6/2026
An insufficient certificate validation issue in the Palo Alto Networks GlobalProtect™ app enables attackers to connect the GlobalProtect app to arbitrary servers. This can enable a local non-administrative operating system user or an attacker on the same subnet to install malicious root certificates on the endpoint…
AplazadaMedia (5.6)0.12%—Paloaltonetworks Pan-osAIPaloaltonetworks Pa-7500AI13/8/202517/6/2026
A problem with the implementation of the MACsec protocol in Palo Alto Networks PAN-OS® results in the cleartext exposure of the connectivity association key (CAK). This issue is only applicable to PA-7500 Series devices which are in an NGFW cluster. A user who possesses this key can read messages being sent between…
AplazadaMedia (5.9)0.16%—Paloaltonetworks CheckovAI13/8/202517/6/2026
A sensitive information disclosure vulnerability in Palo Alto Networks Checkov by Prisma® Cloud can result in the cleartext exposure of Prisma Cloud access keys in Checkov's output.
AplazadaMedia (4.8)0.18%—Paloaltonetworks CheckovAI13/8/202517/6/2026
An unsafe deserialization vulnerability in Palo Alto Networks Checkov by Prisma® Cloud allows an authenticated user to execute arbitrary code as a non administrative user by scanning a malicious terraform file when using Checkov in Prisma® Cloud. This issue impacts Checkov 3.0 versions earlier than Checkov 3.2.415.
AplazadaAlta (8.8)3.0%—A10networks AX LoadbalancerAI31/7/202517/6/2026
A path traversal vulnerability exists in A10 Networks AX Loadbalancer versions 2.6.1-GR1-P5, 2.7.0, and earlier. The vulnerability resides in the handling of the filename parameter in the /xml/downloads endpoint, which fails to properly sanitize user input. An unauthenticated attacker can exploit this flaw by sending…
AplazadaCrítica (10)1.3%💥 ExploitArraynetworks VapvAIArraynetworks VxagAI31/7/202517/6/2026
Array Networks vAPV (version 8.3.2.17) and vxAG (version 9.2.0.34) appliances are affected by a privilege escalation vulnerability caused by a combination of hardcoded SSH credentials (or SSH private key) and insecure permissions on a startup script. The devices ship with a default SSH login or a hardcoded DSA private…
AplazadaMedia (6.8)0.13%—Paloaltonetworks Globalprotect APPAI29/7/202517/6/2026
An incorrect privilege assignment vulnerability in the Palo Alto Networks GlobalProtect™ App on Linux devices enables a locally authenticated non administrative user to disable the app even if the GlobalProtect app configuration would not normally permit them to do so. The GlobalProtect app on Windows, macOS, iOS,…
AnalizadaMedia (5.3)0.22%—Extremenetworks Extremecontrol21/7/202517/6/2026
In ExtremeControl before 25.5.12, a cross-site scripting (XSS) vulnerability was discovered in a login interface of the affected application. The issue stems from improper handling of user-supplied input within HTML attributes, allowing an attacker to inject script code that may execute in a user's browser under…
AplazadaAlta (8.6)0.16%—Catonetworks CatoclientAI13/7/202517/6/2026
An issue in Cato Networks' CatoClient for Linux, before version 5.5, allows a local attacker to escalate privileges to root by exploiting improper symbolic link handling.
AplazadaAlta (8.4)0.17%—Paloaltonetworks Globalprotect APPAI9/7/202517/6/2026
An incorrect privilege assignment vulnerability in the Palo Alto Networks GlobalProtect™ App on enables a locally authenticated non administrative user to escalate their privileges to root on macOS and Linux or NT AUTHORITY\SYSTEM on Windows. The GlobalProtect app on iOS, Android, Chrome OS and GlobalProtect UWP app…
AplazadaMedia (6.8)0.14%—Paloaltonetworks Globalprotect APPAI9/7/202517/6/2026
An incorrect privilege assignment vulnerability in the Palo Alto Networks GlobalProtect™ App on macOS devices enables a locally authenticated non administrative user to disable the app even if the GlobalProtect app configuration would not normally permit them to do so. The GlobalProtect app on Windows, Linux, iOS,…
AplazadaMedia (6.3)0.14%—Paloaltonetworks Autonomous Digital Experience ManagerAI9/7/202517/6/2026
An incorrect privilege assignment vulnerability in Palo Alto Networks Autonomous Digital Experience Manager allows a locally authenticated low privileged user on macOS endpoints to escalate their privileges to root.
AnalizadaMedia (6.1)0.38%—Versa-networks Versa Director19/6/20258/9/2026
The Versa Director SD-WAN orchestration platform provides functionality to upload various types of files. However, the Java code handling file uploads contains an argument injection vulnerability. By appending additional arguments to the file name, an attacker can bypass MIME type validation, allowing the upload of…
AnalizadaCrítica (9.8)0.47%—Versa-networks Versa Director19/6/20252/9/2026
The Versa Director software exposes a number of services by default and allow attackers an easy foothold due to default credentials and multiple accounts (most with sudo access) that utilize the same default credentials. By default, Versa director exposes ssh and postgres to the internet, alongside a host of other…
AnalizadaAlta (7.5)0.62%—Versa-networks Versa Director19/6/20258/9/2026
The Versa Director SD-WAN orchestration platform provides direct web-based access to uCPE virtual machines through the Director GUI. By default, the websockify service is exposed on port 6080 and accessible from the internet. This exposure introduces significant risk, as websockify has known weaknesses that can be…
AnalizadaAlta (7.2)1.1%—Versa-networks Versa Director19/6/20253/9/2026
The Versa Director SD-WAN orchestration platform includes a Webhook feature for sending notifications to external HTTP endpoints. However, the "Add Webhook" and "Test Webhook" functionalities can be abused by an authenticated user to send crafted HTTP requests to localhost. This can be leveraged to execute commands on…
AnalizadaAlta (7.2)0.55%—Versa-networks Versa Director19/6/202525/8/2026
The Versa Director SD-WAN orchestration platform provides an option to upload various types of files. The Versa Director does not correctly limit file upload permissions. The UI appears not to allow file uploads but uploads still succeed. In addition, the Versa Director discloses the full filename of uploaded…
AnalizadaMedia (6.7)0.59%—Versa-networks Versa Director19/6/20253/9/2026
The Versa Director SD-WAN orchestration platform includes functionality to initiate SSH sessions to remote CPEs and the Director shell via Shell-In-A-Box. The underlying Python script, shell-connect.py, is vulnerable to command injection through the user argument. This allows an attacker to execute arbitrary commands…
AnalizadaMedia (6.1)0.38%—Versa-networks Versa Director19/6/20253/9/2026
The Versa Director SD-WAN orchestration platform allows customization of the user interface, including the header, footer, and logo. However, the input provided for these customizations is not properly validated or sanitized, allowing a malicious user to inject and store cross-site scripting (XSS) payloads.…
Orbitaley — Vulnerabilidades