Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

1845 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.5)0.33%—R-fx Networks Linux Malware DetectAI6/5/202517/6/2026
An issue in the component /internals/functions of R-fx Networks Linux Malware Detect v1.6.5 allows attackers to escalate privileges and execute arbitrary code via supplying a file that contains a crafted filename.
AnalizadaMedia (5.7)0.25%—Catonetworks Cato Client27/4/202517/6/2026
An issue in CatoNetworks CatoClient before v.5.8.0 allows attackers to escalate privileges and achieve a race condition (TOCTOU) via the PrivilegedHelperTool component.
AplazadaCrítica (9.3)0.18%—Paloaltonetworks Prisma Access BrowserAI11/4/202517/6/2026
An improper exception check in Palo Alto Networks Prisma Access Browser allows a low privileged user to prevent Prisma Access Browser from applying it's Policy Rules. This enables the user to use Prisma Access Browser without any restrictions.
AplazadaMedia (5.9)0.12%—Paloaltonetworks Pan-osAI11/4/202517/6/2026
A vulnerability in the Palo Alto Networks PAN-OS® software enables unlicensed administrators to view clear-text data captured using the packet capture feature https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-admin/monitoring/take-packet-captures/take-a-custom-packet-capture in decrypted HTTP/2 data streams…
AplazadaMedia (6.3)0.56%—Paloaltonetworks Cortex XDR Broker VMAI11/4/202517/6/2026
A command injection vulnerability in the Palo Alto Networks Cortex XDR® Broker VM allows an authenticated user to execute arbitrary OS commands with root privileges on the host operating system running Broker VM.
AplazadaAlta (8.7)0.32%—Paloaltonetworks Pan-osAI11/4/202517/6/2026
A denial-of-service (DoS) vulnerability in the Simple Certificate Enrollment Protocol (SCEP) authentication feature of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker to initiate system reboots using a maliciously crafted packet. Repeated attempts to initiate a reboot causes the firewall to…
AplazadaAlta (7.1)0.57%—Paloaltonetworks Pan-osAIPaloaltonetworks Vm-seriesAI11/4/202517/6/2026
A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as a root user. This issue is only applicable to PAN-OS VM-Series. This issue does not affect firewalls that are already deployed. Cloud NGFW and…
AplazadaAlta (8.3)0.40%—Paloaltonetworks GlobalprotectAIPaloaltonetworks Pan-osAIPaloaltonetworks Prisma AccessAIPaloaltonetworks Cloud NgfwAI11/4/202517/6/2026
When configured using SAML, a session fixation vulnerability in the GlobalProtect™ login enables an attacker to impersonate a legitimate authorized user and perform actions as that GlobalProtect user. This requires the legitimate user to first click on a malicious link provided by the attacker. The SAML login for the…
AplazadaMedia (6.9)0.42%—Paloaltonetworks Pan-osAI11/4/202517/6/2026
An improper input neutralization vulnerability in the management web interface of the Palo Alto Networks PAN-OS® software enables a malicious authenticated read-write administrator to impersonate another legitimate authenticated PAN-OS administrator. The attacker must have network access to the management web…
AnalizadaMedia (5.1)0.34%—Paloaltonetworks Pan-os11/4/202517/6/2026
An authenticated file deletion vulnerability in the Palo Alto Networks PAN-OS® software enables an authenticated attacker with network access to the management web interface to delete certain files as the “nobody” user; this includes limited logs and configuration files but does not include system files. The attacker…
AplazadaMedia (5.1)0.27%—Paloaltonetworks Prisma Sd-wan IONAI11/4/202517/6/2026
A denial-of-service (DoS) vulnerability in Palo Alto Networks Prisma® SD-WAN ION devices enables an unauthenticated attacker in a network adjacent to a Prisma SD-WAN ION device to disrupt the packet processing capabilities of the device by sending a burst of crafted packets to that device.
AplazadaMedia (6.8)0.17%—Paloaltonetworks Cortex XDRAI11/4/202517/6/2026
A null pointer dereference vulnerability in the Palo Alto Networks Cortex® XDR agent on Windows devices allows a low-privileged local Windows user to crash the agent. Additionally, malware can use this vulnerability to perform malicious activity without Cortex XDR being able to detect it.
AnalizadaAlta (7.1)0.16%—Paloaltonetworks Globalprotect11/4/202517/6/2026
A vulnerability with a privilege management mechanism in the Palo Alto Networks GlobalProtect™ app on Windows devices allows a locally authenticated non-administrative Windows user to escalate their privileges to NT AUTHORITY\SYSTEM. However, execution requires that the local user can also successfully exploit a race…
AnalizadaMedia (4.9)0.61%—Arubanetworks Arubaos8/4/202517/6/2026
Multiple vulnerabilities exist in the web-based management interface of AOS-10 GW and AOS-8 Controller/Mobility Conductor. Successful exploitation of these vulnerabilities could allow an authenticated, remote attacker to download arbitrary files from the filesystem of an affected device.
AnalizadaMedia (6.1)0.27%—Arubanetworks Arubaos8/4/202517/6/2026
A vulnerability in the Captive Portal of an AOS-10 GW and AOS-8 Controller/Mobility Conductor could allow a remote attacker to conduct a reflected cross-site scripting (XSS) attack. Successful exploitation could enable the attacker to execute arbitrary script code in the victim's browser within the context of the…
AnalizadaAlta (7.2)1.2%—Arubanetworks Arubaos8/4/202517/6/2026
Authenticated command injection vulnerabilities exist in the AOS-10 GW and AOS-8 Controller/Mobility Conductor web-based management interface. Successful exploitation of these vulnerabilities allows an Authenticated attacker to execute arbitrary commands as a privileged user on the underlying operating system.
AnalizadaAlta (7.2)0.55%—Arubanetworks Arubaos8/4/202517/6/2026
Arbitrary File Write vulnerabilities exist in the web-based management interface of both the AOS-10 GW and AOS-8 Controller/Mobility Conductor operating systems. Successful exploitation could allow an Authenticated attacker to upload arbitrary files and execute arbitrary commands on the underlying host operating…
AplazadaAlta (7.1)0.36%—Rhizome Networks CG ButtonAI26/3/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rhizome Networks CG Button content-glass-button allows Reflected XSS.This issue affects CG Button: from n/a through <= 1.0.5.6.
AplazadaAlta (8.7)0.39%—Optigo Networks Visual Bacnet Capture ToolAIOptigo Networks Visual Networks Capture ToolAI13/3/202517/6/2026
Optigo Networks Visual BACnet Capture Tool and Optigo Visual Networks Capture Tool version 3.1.2rc11 are vulnerable to an attacker impersonating the web application service and mislead victim clients.
AplazadaCrítica (9.3)0.45%—Optigo Networks Visual Bacnet Capture ToolAIOptigo Networks Visual Networks Capture ToolAI13/3/202517/6/2026
Optigo Networks Visual BACnet Capture Tool and Optigo Visual Networks Capture Tool version 3.1.2rc11 contain an exposed web management service that could allow an attacker to bypass authentication measures and gain controls over utilities within the products.
AplazadaAlta (8.7)0.39%—Optigo Networks Visual Bacnet Capture ToolAIOptigo Networks Visual Networks Capture ToolAI13/3/202517/6/2026
Optigo Networks Visual BACnet Capture Tool and Optigo Visual Networks Capture Tool version 3.1.2rc11 contain a hard coded secret key. This could allow an attacker to generate valid JWT (JSON Web Token) sessions.
AnalizadaMedia (6)0.46%—Paloaltonetworks Globalprotect12/3/202517/6/2026
A vulnerability in the Palo Alto Networks GlobalProtect app on Windows allows a remote attacker to run ActiveX controls within the context of an authenticated Windows user. This enables the attacker to run commands as if they are a legitimate authenticated user. However, to exploit this vulnerability, the…
AplazadaAlta (7.1)0.16%💥 PoCPaloaltonetworks GlobalprotectAI12/3/202517/6/2026
A reliance on untrusted input for a security decision in the GlobalProtect app on Windows devices potentially enables a locally authenticated non-administrative Windows user to escalate their privileges to NT AUTHORITY\SYSTEM. GlobalProtect App on macOS, Linux, iOS, Android, Chrome OS and GlobalProtect UWP App are not…
AplazadaMedia (6.8)0.24%—Paloaltonetworks Pan-osAI12/3/202517/6/2026
A Denial of Service (DoS) vulnerability in Palo Alto Networks PAN-OS software causes the firewall to unexpectedly reboot when processing a specially crafted LLDP frame sent by an unauthenticated adjacent attacker. Repeated attempts to initiate this condition causes the firewall to enter maintenance mode. This issue…
AplazadaMedia (6.8)0.19%—Paloaltonetworks Pan-osAI12/3/202517/6/2026
A vulnerability in the Palo Alto Networks PAN-OS software enables an authenticated admin on the PAN-OS CLI to read arbitrary files. The attacker must have network access to the management interface (web, SSH, console, or telnet) and successfully authenticate to exploit this issue. You can greatly reduce the risk of…