Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
567 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.2) | 1.6% | — | Paloaltonetworks Pan-os | 11/5/2022 | 17/6/2026 | A vulnerability exists in Palo Alto Networks PAN-OS software that enables an authenticated network-based PAN-OS administrator to upload a specifically created configuration that disrupts system processes and potentially execute arbitrary code with root privileges when the configuration is committed on both hardware… | |
| Modificada | Media (5.9) | 0.73% | — | Paloaltonetworks Pan-os | 13/4/2022 | 17/6/2026 | An improper handling of exceptional conditions vulnerability exists in the DNS proxy feature of Palo Alto Networks PAN-OS software that enables a meddler-in-the-middle (MITM) to send specifically crafted traffic to the firewall that causes the service to restart unexpectedly. Repeated attempts to send this request… | |
| Modificada | Media (4.4) | 0.13% | — | Paloaltonetworks Pan-os | 9/3/2022 | 17/6/2026 | Usage of a weak cryptographic algorithm in Palo Alto Networks PAN-OS software where the password hashes of administrator and local user accounts are not created with a sufficient level of computational effort, which allows for password cracking attacks on accounts in normal (non-FIPS-CC) operational mode. An attacker… | |
| Modificada | Media (5.5) | 0.22% | — | Paloaltonetworks Globalprotect | 10/2/2022 | 17/6/2026 | An information exposure through log file vulnerability exists in the Palo Alto Networks GlobalProtect app on Windows that logs the cleartext credentials of the connecting GlobalProtect user when authenticating using Connect Before Logon feature. This issue impacts GlobalProtect App 5.2 versions earlier than 5.2.9 on… | |
| Modificada | Media (5.4) | 1.7% | 💥 Exploit | Paloaltonetworks Cortex Xsoar | 10/2/2022 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in Palo Alto Network Cortex XSOAR web interface enables an authenticated network-based attacker to store a persistent javascript payload that will perform arbitrary actions in the Cortex XSOAR web interface on behalf of authenticated administrators who encounter the… | |
| Modificada | Media (5.5) | 0.17% | — | Paloaltonetworks Globalprotect | 10/2/2022 | 17/6/2026 | An insufficiently protected credentials vulnerability exists in the Palo Alto Networks GlobalProtect app on Linux that exposes the hashed credentials of GlobalProtect users that saved their password during previous GlobalProtect app sessions to other local users on the system. The exposed credentials enable a local… | |
| Modificada | Media (6.5) | 0.75% | — | Paloaltonetworks Globalprotect | 10/2/2022 | 17/6/2026 | An information exposure vulnerability exists in the Palo Alto Networks GlobalProtect app on Windows and MacOS where the credentials of the local user account are sent to the GlobalProtect portal when the Single Sign-On feature is enabled in the GlobalProtect portal configuration. This product behavior is intentional… | |
| Modificada | Alta (7.8) | 0.28% | — | Paloaltonetworks Globalprotect | 10/2/2022 | 17/6/2026 | An improper link resolution before file access ('link following') vulnerability exists in the Palo Alto Networks GlobalProtect app on Windows that enables a local attacker to disrupt system processes and potentially execute arbitrary code with SYSTEM privileges under certain circumstances. This issue impacts:… | |
| Modificada | Alta (7.8) | 0.21% | — | Paloaltonetworks Globalprotect | 10/2/2022 | 17/6/2026 | An improper handling of exceptional conditions vulnerability exists within the Connect Before Logon feature of the Palo Alto Networks GlobalProtect app that enables a local attacker to escalate to SYSTEM or root privileges when authenticating with Connect Before Logon under certain circumstances. This issue impacts… | |
| Modificada | Media (6.5) | 0.66% | — | Paloaltonetworks Pan-osPaloaltonetworks Prisma Access | 10/2/2022 | 17/6/2026 | PAN-OS software provides options to exclude specific websites from URL category enforcement and those websites are blocked or allowed (depending on your rules) regardless of their associated URL category. This is done by creating a custom URL category list or by using an external dynamic list (EDL) in a URL Filtering… | |
| Modificada | Alta (7.8) | 0.23% | — | Paloaltonetworks Cortex XDR Agent | 12/1/2022 | 17/6/2026 | A local privilege escalation (PE) vulnerability exists in the Palo Alto Networks Cortex XDR agent that enables an authenticated local user to execute programs with elevated privileges. This issue impacts: Cortex XDR agent 5.0 versions earlier than Cortex XDR agent 5.0.12; Cortex XDR agent 6.1 versions earlier than… | |
| Modificada | Alta (7.3) | 0.25% | — | Paloaltonetworks Cortex XDR Agent | 12/1/2022 | 17/6/2026 | An untrusted search path vulnerability exists in the Palo Alto Networks Cortex XDR agent that enables a local attacker with file creation privilege in the Windows root directory (such as C:\) to store a program that can then be unintentionally executed by another local user when that user utilizes a Live Terminal… | |
| Modificada | Media (5.5) | 0.22% | — | Paloaltonetworks Cortex XDR Agent | 12/1/2022 | 17/6/2026 | A file information exposure vulnerability exists in the Palo Alto Networks Cortex XDR agent that enables a local attacker to read the contents of arbitrary files on the system with elevated privileges when generating a support file. This issue impacts: Cortex XDR agent 5.0 versions earlier than Cortex XDR agent… | |
| Modificada | Alta (7.1) | 0.24% | — | Paloaltonetworks Cortex XDR Agent | 12/1/2022 | 17/6/2026 | An improper link resolution before file access vulnerability exists in the Palo Alto Networks Cortex XDR agent on Windows platforms that enables a local user to delete arbitrary system files and impact the system integrity or cause a denial of service condition. This issue impacts: Cortex XDR agent 5.0 versions… | |
| Modificada | Crítica (9.8) | 20% | 💥 PoC | Paloaltonetworks Pan-os | 10/11/2021 | 17/6/2026 | A memory corruption vulnerability exists in Palo Alto Networks GlobalProtect portal and gateway interfaces that enables an unauthenticated network-based attacker to disrupt system processes and potentially execute arbitrary code with root privileges. The attacker must have network access to the GlobalProtect interface… | |
| Modificada | Alta (7.5) | 0.93% | — | Paloaltonetworks Pan-os | 10/11/2021 | 17/6/2026 | An improper handling of exceptional conditions vulnerability exists in Palo Alto Networks GlobalProtect portal and gateway interfaces that enables an unauthenticated network-based attacker to send specifically crafted traffic to a GlobalProtect interface that causes the service to stop responding. Repeated attempts to… | |
| Modificada | Alta (8.8) | 0.72% | — | Paloaltonetworks Pan-os | 10/11/2021 | 17/6/2026 | An improper access control vulnerability in PAN-OS software enables an attacker with authenticated access to GlobalProtect portals and gateways to connect to the EC2 instance metadata endpoint for VM-Series firewalls hosted on Amazon AWS. Exploitation of this vulnerability enables an attacker to perform any operations… | |
| Modificada | Alta (7.2) | 0.86% | — | Paloaltonetworks Prisma AccessPaloaltonetworks Pan-os | 10/11/2021 | 17/6/2026 | An OS command injection vulnerability in the Palo Alto Networks PAN-OS command line interface (CLI) enables an authenticated administrator with access to the CLI to execute arbitrary OS commands to escalate privileges. This issue impacts: PAN-OS 8.1 versions earlier than PAN-OS 8.1.20-h1; PAN-OS 9.0 versions earlier… | |
| Modificada | Alta (8.1) | 33% | 💥 PoC | Paloaltonetworks Prisma AccessPaloaltonetworks Pan-os | 10/11/2021 | 17/6/2026 | An OS command injection vulnerability in the Simple Certificate Enrollment Protocol (SCEP) feature of PAN-OS software allows an unauthenticated network-based attacker with specific knowledge of the firewall configuration to execute arbitrary code with root user privileges. The attacker must have network access to the… | |
| Modificada | Alta (8.1) | 1.5% | — | Paloaltonetworks Pan-os | 10/11/2021 | 17/6/2026 | An OS command injection vulnerability in the Palo Alto Networks PAN-OS management interface exists when performing dynamic updates. This vulnerability enables a man-in-the-middle attacker to execute arbitrary OS commands to escalate privileges. This issue impacts: PAN-OS 8.1 versions earlier than PAN-OS 8.1.20-h1;… | |
| Modificada | Alta (7.2) | 1.6% | — | Paloaltonetworks Pan-os | 10/11/2021 | 17/6/2026 | An OS command injection vulnerability in the Palo Alto Networks PAN-OS web interface enables an authenticated administrator with permissions to use XML API the ability to execute arbitrary OS commands to escalate privileges. This issue impacts: PAN-OS 8.1 versions earlier than PAN-OS 8.1.20-h1; PAN-OS 9.0 versions… | |
| Modificada | Alta (8.8) | 1.5% | — | Paloaltonetworks Pan-os | 10/11/2021 | 17/6/2026 | A memory corruption vulnerability in Palo Alto Networks PAN-OS GlobalProtect Clientless VPN enables an authenticated attacker to execute arbitrary code with root user privileges during SAML authentication. This issue impacts: PAN-OS 8.1 versions earlier than PAN-OS 8.1.20; PAN-OS 9.0 versions earlier than PAN-OS… | |
| Modificada | Alta (8.1) | 1.4% | — | Paloaltonetworks Globalprotect | 13/10/2021 | 17/6/2026 | A stack-based buffer overflow vulnerability exists in the Palo Alto Networks GlobalProtect app that enables a man-in-the-middle attacker to disrupt system processes and potentially execute arbitrary code with SYSTEM privileges. This issue impacts: GlobalProtect app 5.1 versions earlier than GlobalProtect app 5.1.9 on… | |
| Modificada | Media (6.5) | 1.1% | — | Paloaltonetworks Pan-os | 8/9/2021 | 17/6/2026 | An improper restriction of XML external entity (XXE) reference vulnerability in the Palo Alto Networks PAN-OS web interface enables an authenticated administrator to read any arbitrary file from the file system and send a specifically crafted request to the firewall that causes the service to crash. Repeated attempts… | |
| Modificada | Media (6.6) | 0.92% | — | Paloaltonetworks Pan-os | 8/9/2021 | 17/6/2026 | A time-of-check to time-of-use (TOCTOU) race condition vulnerability in the Palo Alto Networks PAN-OS web interface enables an authenticated administrator with permission to upload plugins to execute arbitrary code with root user privileges. This issue impacts: PAN-OS 8.1 versions earlier than PAN-OS 8.1.20; PAN-OS… |