Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2811▼ 173 respecto a la semana anterior
Críticas / altas1356▲ 48 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)267▼ 256 respecto a la semana anterior
83 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 0.56% | — | ARM Cortex-a710 FirmwareARM Cortex-a77 FirmwareARM Cortex-a78 FirmwareARM Cortex-a78ae Firmware+12 | 10/12/2024 | 17/6/2026 | Use of Hardware Page Aggregation (HPA) and Stage-1 and/or Stage-2 translation on Cortex-A77, Cortex-A78, Cortex-A78C, Cortex-A78AE, Cortex-A710, Cortex-X1, Cortex-X1C, Cortex-X2, Cortex-X3, Cortex-X4, Cortex-X925, Neoverse V1, Neoverse V2, Neoverse V3, Neoverse V3AE, Neoverse N2 may permit bypass of Stage-2… | |
| Aplazada | Media (5.3) | 0.38% | — | Paloaltonetworks Cortex XsoarAI | 9/10/2024 | 17/6/2026 | A vulnerability in Cortex XSOAR allows the disclosure of incident data to users who do not have the privilege to view the data. | |
| Analizada | Media (5.7) | 0.21% | — | Paloaltonetworks Cortex XDR Agent | 9/10/2024 | 17/6/2026 | A problem with a detection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices enables a user with Windows non-administrative privileges to disable the agent. This issue may be leveraged by malware to disable the Cortex XDR agent and then to perform malicious activity. | |
| Analizada | Media (5.6) | 0.19% | — | Paloaltonetworks Cortex XDR Agent | 11/9/2024 | 17/6/2026 | A problem with a detection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices enables a user with Windows administrator privileges to disable the agent. This issue may be leveraged by malware to disable the Cortex XDR agent and then to perform malicious activity. | |
| Aplazada | Media (6) | 0.22% | — | Paloaltonetworks Cortex XsoarAIPaloaltonetworks Cortex XsiamAIApache ActivemqAI | 11/9/2024 | 17/6/2026 | A problem with the ActiveMQ integration for both Cortex XSOAR and Cortex XSIAM can result in the cleartext exposure of the configured ActiveMQ credentials in log bundles. | |
| Analizada | Alta (7) | 1.2% | — | Paloaltonetworks Cortex Xsoar Commonscripts | 14/8/2024 | 17/6/2026 | A command injection issue in Palo Alto Networks Cortex XSOAR CommonScripts Pack allows an unauthenticated attacker to execute arbitrary commands within the context of an integration container. | |
| Aplazada | Alta (7.5) | 0.26% | — | CortexAI | 1/8/2024 | 17/6/2026 | A TLS certificate verification issue discovered in cortex v0.42.1 allows attackers to obtain sensitive information via the makeOperatorRequest function. | |
| Aplazada | Media (6.8) | 0.13% | — | Paloaltonetworks Cortex XDR AgentAI | 10/7/2024 | 17/6/2026 | An improper file signature check in Palo Alto Networks Cortex XDR agent may allow an attacker to bypass the Cortex XDR agent's executable blocking capabilities and run untrusted executables on the device. This issue can be leveraged to execute untrusted software without being detected or blocked. | |
| Modificada | Media (6.8) | 0.41% | — | Paloaltonetworks Cortex XDR Agent | 12/6/2024 | 17/6/2026 | A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices allows a low privileged local Windows user to disable the agent. This issue may be leveraged by malware to disable the Cortex XDR agent and then to perform malicious activity. | |
| Modificada | Media (5.2) | 0.13% | — | Paloaltonetworks Cortex XDR Agent | 12/6/2024 | 17/6/2026 | A privilege escalation (PE) vulnerability in the Palo Alto Networks Cortex XDR agent on Windows devices enables a local user to execute programs with elevated privileges. However, execution does require the local user to successfully exploit a race condition, which makes this vulnerability difficult to exploit. | |
| Modificada | Baja (2) | 0.09% | — | Paloaltonetworks Cortex XDR Agent | 12/6/2024 | 17/6/2026 | A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local low privileged Windows user to disrupt some functionality of the agent. However, they are not able to disrupt Cortex XDR agent protection mechanisms using this vulnerability. | |
| Aplazada | Media (6.5) | 0.45% | — | ARM Cortex-m Security ExtensionsAI | 24/4/2024 | 17/6/2026 | Insufficient argument checking in Secure state Entry functions in software using Cortex-M Security Extensions (CMSE), that has been compiled using toolchains that implement 'Arm v8-M Security Extensions Requirements on Development Tools' prior to version 1.4, allows an attacker to pass values to Secure state that are… | |
| Modificada | Media (5.5) | 0.24% | — | ARM Cortex-a77 FirmwareXEN | 8/12/2023 | 17/6/2026 | Cortex-A77 cores (r0p0 and r1p0) are affected by erratum 1508412 where software, under certain circumstances, could deadlock a core due to the execution of either a load to device or non-cacheable memory, and either a store exclusive or register read of the Physical Address Register (PAR_EL1) in close proximity. | |
| Modificada | Media (6.7) | 0.17% | — | Paloaltonetworks Cortex Xsoar | 8/11/2023 | 17/6/2026 | A local privilege escalation (PE) vulnerability in the Palo Alto Networks Cortex XSOAR engine software running on a Linux operating system enables a local attacker to execute programs with elevated privileges if the attacker has shell access to the engine. | |
| Modificada | Media (5.5) | 0.32% | — | Paloaltonetworks Cortex XDR Agent | 13/9/2023 | 17/6/2026 | A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local user to disable the agent. | |
| Modificada | Crítica (9.8) | 0.93% | — | Strangebee CortexStrangebee Thehive | 11/9/2023 | 17/6/2026 | An issue in StrangeBee TheHive v.5.0.8, v.4.1.21 and Cortex v.3.1.6 allows a remote attacker to gain privileges via Active Directory authentication mechanism. | |
| Modificada | Media (6.5) | 1.3% | — | Paloaltonetworks Cortex XsoarFedoraproject Fedora | 8/2/2023 | 17/6/2026 | A file disclosure vulnerability in the Palo Alto Networks Cortex XSOAR server software enables an authenticated user with access to the web interface to read local files from the server. | |
| Modificada | Alta (7.8) | 0.29% | — | Paloaltonetworks Cortex XDR Agent | 8/2/2023 | 17/6/2026 | A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local user to execute privileged cytool commands that disable or uninstall the agent. | |
| Modificada | Media (6.7) | 0.21% | — | Paloaltonetworks Cortex XDR Agent | 8/2/2023 | 17/6/2026 | An information exposure vulnerability in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local system administrator to disclose the admin password for the agent in cleartext, which bad actors can then use to execute privileged cytool commands that disable or uninstall the agent. | |
| Modificada | Alta (7.5) | 0.83% | — | ARM Cortex-a53 FirmwareARM Cortex-a55 FirmwareARM Cortex-a57 FirmwareARM Cortex-a72 Firmware+6 | 10/1/2023 | 17/6/2026 | The AES instructions on the ARMv8 platform do not have an algorithm that is "intrinsically resistant" to side-channel attacks. NOTE: the vendor reportedly offers the position "while power side channel attacks ... are possible, they are not directly caused by or related to the Arm architecture." | |
| Modificada | Media (6.5) | 0.79% | — | Linuxfoundation Cortex | 19/12/2022 | 17/6/2026 | Cortex provides multi-tenant, long term storage for Prometheus. A local file inclusion vulnerability exists in Cortex versions 1.13.0, 1.13.1 and 1.14.0, where a malicious actor could remotely read local files as a result of parsing maliciously crafted Alertmanager configurations when submitted to the Alertmanager Set… | |
| Modificada | Media (6.7) | 0.12% | — | Paloaltonetworks Cortex Xsoar | 9/11/2022 | 17/6/2026 | A local privilege escalation (PE) vulnerability in the Palo Alto Networks Cortex XSOAR engine software running on a Linux operating system allows a local attacker with shell access to the engine to execute programs with elevated privileges. | |
| Modificada | Media (5.5) | 0.22% | — | Paloaltonetworks Cortex XDR Agent | 14/9/2022 | 17/6/2026 | An improper link resolution vulnerability in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local attacker to read files on the system with elevated privileges when generating a tech support file. | |
| Modificada | Media (4.3) | 0.55% | — | Paloaltonetworks Cortex Xsoar | 11/5/2022 | 17/6/2026 | An improper authorization vulnerability in Palo Alto Network Cortex XSOAR software enables authenticated users in non-Read-Only groups to generate an email report that contains summary information about all incidents in the Cortex XSOAR instance, including incidents to which the user does not have access. This issue… | |
| Modificada | Media (6.7) | 0.23% | — | Paloaltonetworks Cortex XDR Agent | 11/5/2022 | 17/6/2026 | A local privilege escalation (PE) vulnerability exists in Palo Alto Networks Cortex XDR agent software on Windows that enables an authenticated local user with file creation privilege in the Windows root directory (such as C:\) to execute a program with elevated privileges. This issue impacts all versions of Cortex… |