Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

6557 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.5)0.41%—Image Uploader FOR WelcartAI15/8/202620/8/2026
The Image Uploader for Welcart plugin for WordPress is vulnerable to generic SQL Injection via the 'post_title' parameter in all versions up to, and including, 1.4.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for…
AplazadaAlta (8.8)1.0%—MaxuploadAI15/8/202620/8/2026
The MaxUpload – Big File Uploads – Increase Maximum File Upload Size plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.4.0 via the handle_upload function. This is due to a filename-validation mismatch in the handle_upload function where extension and MIME checks are…
Pendiente de análisisMedia (6.9)0.17%—Kunbus RevpipyloadAI14/8/202628/8/2026
Nozomi Networks Labs identified a CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in the file management functionality of the XML-RPC management interface of KUNBUS RevPiPyLoad in version 0.11.0 that allows a local unauthenticated attacker to delete arbitrary files…
Pendiente de análisisMedia (6.8)0.17%—Kunbus RevpipyloadAI14/8/202628/8/2026
Nozomi Networks Labs identified a CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in the file management functionality of the XML-RPC management interface of KUNBUS RevPiPyLoad in version 0.11.0 that allows a local unauthenticated attacker to read arbitrary files…
AplazadaAlta (8.7)0.54%💥 PoCNetis Nc63AIBOAAI14/8/202624/9/2026
Netis NC63 router firmware V3.0.0.3327 contains an unauthenticated firmware update vulnerability that allows unauthenticated attackers to submit unsigned firmware images by exploiting a missing authentication enforcement flaw in the Boa web server and netis.cgi CGI dispatcher. Attackers can send a multipart POST…
AplazadaAlta (7.1)0.25%—Mangboard Mang Board WPAI13/8/202614/8/2026
Unauthenticated Cross Site Scripting (XSS) in Mang Board WP <= 2.3.4 versions.
AplazadaAlta (7.1)0.25%—Meril Blog Floating ButtonAI13/8/202614/8/2026
Unauthenticated Cross Site Scripting (XSS) in Blog Floating Button <= 1.4.20 versions.
AplazadaCrítica (9.8)0.61%—Digitialpixies Oauth ClientAI13/8/202614/8/2026
Unauthenticated Broken Authentication in OAuth Single Sign On – SSO (OAuth Client) <= 7.0.0 versions.
AnalizadaBaja (1.7)0.32%—Paloaltonetworks Cloud NgfwPaloaltonetworks Prisma AccessPaloaltonetworks Pan-os13/8/202628/8/2026
An information disclosure vulnerability in the URL Filtering feature of Palo Alto Networks PAN-OS® software enables an unauthenticated user with network access to obtain sensitive information. Panorama is not impacted by this vulnerability.
AnalizadaMedia (5.9)0.20%—Paloaltonetworks Globalprotect13/8/20263/9/2026
Local privilege escalation vulnerabilities in the Palo Alto Networks GlobalProtect™ app enable a local user to escalate their privileges to NT AUTHORITY\SYSTEM on Windows, and root on macOS and Linux. This enables a non-administrative user to execute arbitrary commands with administrative privileges. The GlobalProtect…
En análisisMedia (5.2)0.33%—Paloaltonetworks Globalprotect13/8/202610/9/2026
An improper input validation vulnerability exists in the Windows Pre-Logon Access Provider (PLAP) component of the Palo Alto Networks GlobalProtect™ app on Windows devices which enables a man-in-the-middle (MitM) attacker to execute arbitrary code with SYSTEM privileges on an affected client. The GlobalProtect app on…
En análisisMedia (5.2)0.31%—Paloaltonetworks Globalprotect13/8/202610/9/2026
A buffer overflow vulnerability exists in the Palo Alto Networks GlobalProtect™ app that enables a man-in-the-middle (MitM) attacker or a rogue gateway to disrupt system processes and potentially execute arbitrary code with elevated privileges (SYSTEM privileges on Windows, and root privileges on macOS and Linux).
En análisisMedia (4.5)0.14%—Paloaltonetworks Globalprotect13/8/202610/9/2026
Improper certificate validation vulnerabilities in Palo Alto Networks GlobalProtect™ app enable an unauthenticated attacker with man-in-the-middle (MitM) access to intercept and modify application communications. VPN tunnel traffic is not impacted. The GlobalProtect app on iOS, Android, and Chrome OS is not affected.
AnalizadaMedia (4.1)0.07%—Paloaltonetworks Globalprotect13/8/202610/9/2026
A race condition in the Palo Alto Networks GlobalProtect™ client on macOS enables a locally authenticated low-privileged attacker to escalate their privileges to root. The GlobalProtect app on Linux, Windows, iOS, Android, and Chrome OS is not affected.
AnalizadaMedia (6)0.11%—Paloaltonetworks Prisma Access Agent13/8/20269/9/2026
A privilege escalation (PE) vulnerability in the Palo Alto Networks Prisma® Access Agent app on Windows and macOS devices enables a local user to execute code with elevated privileges. The Prisma Access Agent on Linux, iOS, Android, and ChromeOS is not affected.
AnalizadaMedia (5.6)0.11%—Paloaltonetworks Prisma Access Agent13/8/20269/9/2026
A vulnerability in Palo Alto Networks Prisma® Access Agent on Windows enables a local attacker with administrator privileges to bypass the anti-tamper protection, enabling unauthorized access to protected processes and files. The Prisma Access Agent on Linux, macOS, iOS, Android, and Chrome OS is not affected.
AnalizadaBaja (2.1)0.13%—Paloaltonetworks Prisma Access Agent13/8/20269/9/2026
An authentication bypass vulnerability in the network driver of Palo Alto Networks Prisma® Access Agent on Windows enables a local administrator to bypass security inspection, subsequently allowing them to inject and intercept arbitrary network traffic. The Prisma Access Agent on Linux, macOS, iOS, Android, and Chrome…
AnalizadaBaja (1.1)0.11%—Paloaltonetworks Prisma Access Agent13/8/20269/9/2026
An improper link resolution before file access vulnerability exists in the Palo Alto Networks Prisma® Access Agent on Linux platforms that enables a local low privileged user to delete system files in a limited scope and disable Prisma Access Agent. The Prisma Access Agent on macOS, Windows, iOS, Android, and Chrome…
AnalizadaBaja (0.5)0.13%—Paloaltonetworks Prisma Browser13/8/20269/9/2026
An information disclosure vulnerability in the Account Protection feature of Palo Alto Networks Prisma® Browser enables a local attacker to view sensitive data.
AnalizadaBaja (0.5)0.22%—Paloaltonetworks Prisma Browser13/8/20269/9/2026
A security bypass vulnerability in the Account Protection feature of Palo Alto Networks Prisma® Browser enables a user to bypass intended security controls.
AplazadaAlta (7.5)0.38%—WpphotoalbumplusAI12/8/202626/8/2026
The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not validate a client-controlled value used to build a file path in one of its public endpoint actions, and performs no authorisation check on it, allowing unauthenticated attackers to delete arbitrary ZIP archives on the server, including ones stored…
Pendiente de análisisBaja (2.4)0.15%—Intel Slim BootloaderAI11/8/202612/8/2026
Integer overflow in the UEFI firmware for the Intel(R) Slim Bootloader may allow an information disclosure. System software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via local access when attack requirements are not…
Pendiente de análisisBaja (1.8)0.16%—Intel Slim BootloaderAI11/8/202612/8/2026
Out-of-bounds write in the firmware for the Intel(R) Slim Bootloader may allow a denial of service. System software adversary with a privileged user combined with a low complexity attack may enable denial of service. This result may potentially occur via local access when attack requirements are present without…
Pendiente de análisisMedia (4.3)0.36%—Oauth-serverAI11/8/202614/8/2026
A flaw was found in the oauth-server component. This open redirect vulnerability occurs when the 'then' parameter in the grant approval handler is not properly validated. A remote attacker can craft a malicious URL that, when approved or denied by an authenticated user, redirects them to an attacker-controlled…
AnalizadaMedia (5.4)0.12%—Intel Workload Sevices Framework11/8/20262/10/2026
Protection mechanism failure for some Intel(R) Workload Services Framework software within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This result may potentially occur…