Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
6557 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.41% | — | Image Uploader FOR WelcartAI | 15/8/2026 | 20/8/2026 | The Image Uploader for Welcart plugin for WordPress is vulnerable to generic SQL Injection via the 'post_title' parameter in all versions up to, and including, 1.4.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for… | |
| Aplazada | Alta (8.8) | 1.0% | — | MaxuploadAI | 15/8/2026 | 20/8/2026 | The MaxUpload – Big File Uploads – Increase Maximum File Upload Size plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.4.0 via the handle_upload function. This is due to a filename-validation mismatch in the handle_upload function where extension and MIME checks are… | |
| Pendiente de análisis | Media (6.9) | 0.17% | — | Kunbus RevpipyloadAI | 14/8/2026 | 28/8/2026 | Nozomi Networks Labs identified a CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in the file management functionality of the XML-RPC management interface of KUNBUS RevPiPyLoad in version 0.11.0 that allows a local unauthenticated attacker to delete arbitrary files… | |
| Pendiente de análisis | Media (6.8) | 0.17% | — | Kunbus RevpipyloadAI | 14/8/2026 | 28/8/2026 | Nozomi Networks Labs identified a CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in the file management functionality of the XML-RPC management interface of KUNBUS RevPiPyLoad in version 0.11.0 that allows a local unauthenticated attacker to read arbitrary files… | |
| Aplazada | Alta (8.7) | 0.54% | 💥 PoC | Netis Nc63AIBOAAI | 14/8/2026 | 24/9/2026 | Netis NC63 router firmware V3.0.0.3327 contains an unauthenticated firmware update vulnerability that allows unauthenticated attackers to submit unsigned firmware images by exploiting a missing authentication enforcement flaw in the Boa web server and netis.cgi CGI dispatcher. Attackers can send a multipart POST… | |
| Aplazada | Alta (7.1) | 0.25% | — | Mangboard Mang Board WPAI | 13/8/2026 | 14/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Mang Board WP <= 2.3.4 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Meril Blog Floating ButtonAI | 13/8/2026 | 14/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Blog Floating Button <= 1.4.20 versions. | |
| Aplazada | Crítica (9.8) | 0.61% | — | Digitialpixies Oauth ClientAI | 13/8/2026 | 14/8/2026 | Unauthenticated Broken Authentication in OAuth Single Sign On – SSO (OAuth Client) <= 7.0.0 versions. | |
| Analizada | Baja (1.7) | 0.32% | — | Paloaltonetworks Cloud NgfwPaloaltonetworks Prisma AccessPaloaltonetworks Pan-os | 13/8/2026 | 28/8/2026 | An information disclosure vulnerability in the URL Filtering feature of Palo Alto Networks PAN-OS® software enables an unauthenticated user with network access to obtain sensitive information. Panorama is not impacted by this vulnerability. | |
| Analizada | Media (5.9) | 0.20% | — | Paloaltonetworks Globalprotect | 13/8/2026 | 3/9/2026 | Local privilege escalation vulnerabilities in the Palo Alto Networks GlobalProtect™ app enable a local user to escalate their privileges to NT AUTHORITY\SYSTEM on Windows, and root on macOS and Linux. This enables a non-administrative user to execute arbitrary commands with administrative privileges. The GlobalProtect… | |
| En análisis | Media (5.2) | 0.33% | — | Paloaltonetworks Globalprotect | 13/8/2026 | 10/9/2026 | An improper input validation vulnerability exists in the Windows Pre-Logon Access Provider (PLAP) component of the Palo Alto Networks GlobalProtect™ app on Windows devices which enables a man-in-the-middle (MitM) attacker to execute arbitrary code with SYSTEM privileges on an affected client. The GlobalProtect app on… | |
| En análisis | Media (5.2) | 0.31% | — | Paloaltonetworks Globalprotect | 13/8/2026 | 10/9/2026 | A buffer overflow vulnerability exists in the Palo Alto Networks GlobalProtect™ app that enables a man-in-the-middle (MitM) attacker or a rogue gateway to disrupt system processes and potentially execute arbitrary code with elevated privileges (SYSTEM privileges on Windows, and root privileges on macOS and Linux). | |
| En análisis | Media (4.5) | 0.14% | — | Paloaltonetworks Globalprotect | 13/8/2026 | 10/9/2026 | Improper certificate validation vulnerabilities in Palo Alto Networks GlobalProtect™ app enable an unauthenticated attacker with man-in-the-middle (MitM) access to intercept and modify application communications. VPN tunnel traffic is not impacted. The GlobalProtect app on iOS, Android, and Chrome OS is not affected. | |
| Analizada | Media (4.1) | 0.07% | — | Paloaltonetworks Globalprotect | 13/8/2026 | 10/9/2026 | A race condition in the Palo Alto Networks GlobalProtect™ client on macOS enables a locally authenticated low-privileged attacker to escalate their privileges to root. The GlobalProtect app on Linux, Windows, iOS, Android, and Chrome OS is not affected. | |
| Analizada | Media (6) | 0.11% | — | Paloaltonetworks Prisma Access Agent | 13/8/2026 | 9/9/2026 | A privilege escalation (PE) vulnerability in the Palo Alto Networks Prisma® Access Agent app on Windows and macOS devices enables a local user to execute code with elevated privileges. The Prisma Access Agent on Linux, iOS, Android, and ChromeOS is not affected. | |
| Analizada | Media (5.6) | 0.11% | — | Paloaltonetworks Prisma Access Agent | 13/8/2026 | 9/9/2026 | A vulnerability in Palo Alto Networks Prisma® Access Agent on Windows enables a local attacker with administrator privileges to bypass the anti-tamper protection, enabling unauthorized access to protected processes and files. The Prisma Access Agent on Linux, macOS, iOS, Android, and Chrome OS is not affected. | |
| Analizada | Baja (2.1) | 0.13% | — | Paloaltonetworks Prisma Access Agent | 13/8/2026 | 9/9/2026 | An authentication bypass vulnerability in the network driver of Palo Alto Networks Prisma® Access Agent on Windows enables a local administrator to bypass security inspection, subsequently allowing them to inject and intercept arbitrary network traffic. The Prisma Access Agent on Linux, macOS, iOS, Android, and Chrome… | |
| Analizada | Baja (1.1) | 0.11% | — | Paloaltonetworks Prisma Access Agent | 13/8/2026 | 9/9/2026 | An improper link resolution before file access vulnerability exists in the Palo Alto Networks Prisma® Access Agent on Linux platforms that enables a local low privileged user to delete system files in a limited scope and disable Prisma Access Agent. The Prisma Access Agent on macOS, Windows, iOS, Android, and Chrome… | |
| Analizada | Baja (0.5) | 0.13% | — | Paloaltonetworks Prisma Browser | 13/8/2026 | 9/9/2026 | An information disclosure vulnerability in the Account Protection feature of Palo Alto Networks Prisma® Browser enables a local attacker to view sensitive data. | |
| Analizada | Baja (0.5) | 0.22% | — | Paloaltonetworks Prisma Browser | 13/8/2026 | 9/9/2026 | A security bypass vulnerability in the Account Protection feature of Palo Alto Networks Prisma® Browser enables a user to bypass intended security controls. | |
| Aplazada | Alta (7.5) | 0.38% | — | WpphotoalbumplusAI | 12/8/2026 | 26/8/2026 | The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not validate a client-controlled value used to build a file path in one of its public endpoint actions, and performs no authorisation check on it, allowing unauthenticated attackers to delete arbitrary ZIP archives on the server, including ones stored… | |
| Pendiente de análisis | Baja (2.4) | 0.15% | — | Intel Slim BootloaderAI | 11/8/2026 | 12/8/2026 | Integer overflow in the UEFI firmware for the Intel(R) Slim Bootloader may allow an information disclosure. System software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via local access when attack requirements are not… | |
| Pendiente de análisis | Baja (1.8) | 0.16% | — | Intel Slim BootloaderAI | 11/8/2026 | 12/8/2026 | Out-of-bounds write in the firmware for the Intel(R) Slim Bootloader may allow a denial of service. System software adversary with a privileged user combined with a low complexity attack may enable denial of service. This result may potentially occur via local access when attack requirements are present without… | |
| Pendiente de análisis | Media (4.3) | 0.36% | — | Oauth-serverAI | 11/8/2026 | 14/8/2026 | A flaw was found in the oauth-server component. This open redirect vulnerability occurs when the 'then' parameter in the grant approval handler is not properly validated. A remote attacker can craft a malicious URL that, when approved or denied by an authenticated user, redirects them to an attacker-controlled… | |
| Analizada | Media (5.4) | 0.12% | — | Intel Workload Sevices Framework | 11/8/2026 | 2/10/2026 | Protection mechanism failure for some Intel(R) Workload Services Framework software within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This result may potentially occur… |