Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
1845 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.33% | — | R-fx Networks Linux Malware DetectAI | 6/5/2025 | 17/6/2026 | An issue in the component /internals/functions of R-fx Networks Linux Malware Detect v1.6.5 allows attackers to escalate privileges and execute arbitrary code via supplying a file that contains a crafted filename. | |
| Analizada | Media (5.7) | 0.25% | — | Catonetworks Cato Client | 27/4/2025 | 17/6/2026 | An issue in CatoNetworks CatoClient before v.5.8.0 allows attackers to escalate privileges and achieve a race condition (TOCTOU) via the PrivilegedHelperTool component. | |
| Aplazada | Crítica (9.3) | 0.18% | — | Paloaltonetworks Prisma Access BrowserAI | 11/4/2025 | 17/6/2026 | An improper exception check in Palo Alto Networks Prisma Access Browser allows a low privileged user to prevent Prisma Access Browser from applying it's Policy Rules. This enables the user to use Prisma Access Browser without any restrictions. | |
| Aplazada | Media (5.9) | 0.12% | — | Paloaltonetworks Pan-osAI | 11/4/2025 | 17/6/2026 | A vulnerability in the Palo Alto Networks PAN-OS® software enables unlicensed administrators to view clear-text data captured using the packet capture feature https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-admin/monitoring/take-packet-captures/take-a-custom-packet-capture in decrypted HTTP/2 data streams… | |
| Aplazada | Media (6.3) | 0.56% | — | Paloaltonetworks Cortex XDR Broker VMAI | 11/4/2025 | 17/6/2026 | A command injection vulnerability in the Palo Alto Networks Cortex XDR® Broker VM allows an authenticated user to execute arbitrary OS commands with root privileges on the host operating system running Broker VM. | |
| Aplazada | Alta (8.7) | 0.32% | — | Paloaltonetworks Pan-osAI | 11/4/2025 | 17/6/2026 | A denial-of-service (DoS) vulnerability in the Simple Certificate Enrollment Protocol (SCEP) authentication feature of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker to initiate system reboots using a maliciously crafted packet. Repeated attempts to initiate a reboot causes the firewall to… | |
| Aplazada | Alta (7.1) | 0.57% | — | Paloaltonetworks Pan-osAIPaloaltonetworks Vm-seriesAI | 11/4/2025 | 17/6/2026 | A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as a root user. This issue is only applicable to PAN-OS VM-Series. This issue does not affect firewalls that are already deployed. Cloud NGFW and… | |
| Aplazada | Alta (8.3) | 0.40% | — | Paloaltonetworks GlobalprotectAIPaloaltonetworks Pan-osAIPaloaltonetworks Prisma AccessAIPaloaltonetworks Cloud NgfwAI | 11/4/2025 | 17/6/2026 | When configured using SAML, a session fixation vulnerability in the GlobalProtect™ login enables an attacker to impersonate a legitimate authorized user and perform actions as that GlobalProtect user. This requires the legitimate user to first click on a malicious link provided by the attacker. The SAML login for the… | |
| Aplazada | Media (6.9) | 0.42% | — | Paloaltonetworks Pan-osAI | 11/4/2025 | 17/6/2026 | An improper input neutralization vulnerability in the management web interface of the Palo Alto Networks PAN-OS® software enables a malicious authenticated read-write administrator to impersonate another legitimate authenticated PAN-OS administrator. The attacker must have network access to the management web… | |
| Analizada | Media (5.1) | 0.34% | — | Paloaltonetworks Pan-os | 11/4/2025 | 17/6/2026 | An authenticated file deletion vulnerability in the Palo Alto Networks PAN-OS® software enables an authenticated attacker with network access to the management web interface to delete certain files as the “nobody” user; this includes limited logs and configuration files but does not include system files. The attacker… | |
| Aplazada | Media (5.1) | 0.27% | — | Paloaltonetworks Prisma Sd-wan IONAI | 11/4/2025 | 17/6/2026 | A denial-of-service (DoS) vulnerability in Palo Alto Networks Prisma® SD-WAN ION devices enables an unauthenticated attacker in a network adjacent to a Prisma SD-WAN ION device to disrupt the packet processing capabilities of the device by sending a burst of crafted packets to that device. | |
| Aplazada | Media (6.8) | 0.17% | — | Paloaltonetworks Cortex XDRAI | 11/4/2025 | 17/6/2026 | A null pointer dereference vulnerability in the Palo Alto Networks Cortex® XDR agent on Windows devices allows a low-privileged local Windows user to crash the agent. Additionally, malware can use this vulnerability to perform malicious activity without Cortex XDR being able to detect it. | |
| Analizada | Alta (7.1) | 0.16% | — | Paloaltonetworks Globalprotect | 11/4/2025 | 17/6/2026 | A vulnerability with a privilege management mechanism in the Palo Alto Networks GlobalProtect™ app on Windows devices allows a locally authenticated non-administrative Windows user to escalate their privileges to NT AUTHORITY\SYSTEM. However, execution requires that the local user can also successfully exploit a race… | |
| Analizada | Media (4.9) | 0.61% | — | Arubanetworks Arubaos | 8/4/2025 | 17/6/2026 | Multiple vulnerabilities exist in the web-based management interface of AOS-10 GW and AOS-8 Controller/Mobility Conductor. Successful exploitation of these vulnerabilities could allow an authenticated, remote attacker to download arbitrary files from the filesystem of an affected device. | |
| Analizada | Media (6.1) | 0.27% | — | Arubanetworks Arubaos | 8/4/2025 | 17/6/2026 | A vulnerability in the Captive Portal of an AOS-10 GW and AOS-8 Controller/Mobility Conductor could allow a remote attacker to conduct a reflected cross-site scripting (XSS) attack. Successful exploitation could enable the attacker to execute arbitrary script code in the victim's browser within the context of the… | |
| Analizada | Alta (7.2) | 1.2% | — | Arubanetworks Arubaos | 8/4/2025 | 17/6/2026 | Authenticated command injection vulnerabilities exist in the AOS-10 GW and AOS-8 Controller/Mobility Conductor web-based management interface. Successful exploitation of these vulnerabilities allows an Authenticated attacker to execute arbitrary commands as a privileged user on the underlying operating system. | |
| Analizada | Alta (7.2) | 0.55% | — | Arubanetworks Arubaos | 8/4/2025 | 17/6/2026 | Arbitrary File Write vulnerabilities exist in the web-based management interface of both the AOS-10 GW and AOS-8 Controller/Mobility Conductor operating systems. Successful exploitation could allow an Authenticated attacker to upload arbitrary files and execute arbitrary commands on the underlying host operating… | |
| Aplazada | Alta (7.1) | 0.36% | — | Rhizome Networks CG ButtonAI | 26/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rhizome Networks CG Button content-glass-button allows Reflected XSS.This issue affects CG Button: from n/a through <= 1.0.5.6. | |
| Aplazada | Alta (8.7) | 0.39% | — | Optigo Networks Visual Bacnet Capture ToolAIOptigo Networks Visual Networks Capture ToolAI | 13/3/2025 | 17/6/2026 | Optigo Networks Visual BACnet Capture Tool and Optigo Visual Networks Capture Tool version 3.1.2rc11 are vulnerable to an attacker impersonating the web application service and mislead victim clients. | |
| Aplazada | Crítica (9.3) | 0.45% | — | Optigo Networks Visual Bacnet Capture ToolAIOptigo Networks Visual Networks Capture ToolAI | 13/3/2025 | 17/6/2026 | Optigo Networks Visual BACnet Capture Tool and Optigo Visual Networks Capture Tool version 3.1.2rc11 contain an exposed web management service that could allow an attacker to bypass authentication measures and gain controls over utilities within the products. | |
| Aplazada | Alta (8.7) | 0.39% | — | Optigo Networks Visual Bacnet Capture ToolAIOptigo Networks Visual Networks Capture ToolAI | 13/3/2025 | 17/6/2026 | Optigo Networks Visual BACnet Capture Tool and Optigo Visual Networks Capture Tool version 3.1.2rc11 contain a hard coded secret key. This could allow an attacker to generate valid JWT (JSON Web Token) sessions. | |
| Analizada | Media (6) | 0.46% | — | Paloaltonetworks Globalprotect | 12/3/2025 | 17/6/2026 | A vulnerability in the Palo Alto Networks GlobalProtect app on Windows allows a remote attacker to run ActiveX controls within the context of an authenticated Windows user. This enables the attacker to run commands as if they are a legitimate authenticated user. However, to exploit this vulnerability, the… | |
| Aplazada | Alta (7.1) | 0.16% | 💥 PoC | Paloaltonetworks GlobalprotectAI | 12/3/2025 | 17/6/2026 | A reliance on untrusted input for a security decision in the GlobalProtect app on Windows devices potentially enables a locally authenticated non-administrative Windows user to escalate their privileges to NT AUTHORITY\SYSTEM. GlobalProtect App on macOS, Linux, iOS, Android, Chrome OS and GlobalProtect UWP App are not… | |
| Aplazada | Media (6.8) | 0.24% | — | Paloaltonetworks Pan-osAI | 12/3/2025 | 17/6/2026 | A Denial of Service (DoS) vulnerability in Palo Alto Networks PAN-OS software causes the firewall to unexpectedly reboot when processing a specially crafted LLDP frame sent by an unauthenticated adjacent attacker. Repeated attempts to initiate this condition causes the firewall to enter maintenance mode. This issue… | |
| Aplazada | Media (6.8) | 0.19% | — | Paloaltonetworks Pan-osAI | 12/3/2025 | 17/6/2026 | A vulnerability in the Palo Alto Networks PAN-OS software enables an authenticated admin on the PAN-OS CLI to read arbitrary files. The attacker must have network access to the management interface (web, SSH, console, or telnet) and successfully authenticate to exploit this issue. You can greatly reduce the risk of… |