Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2853▼ 343 respecto a la semana anterior
Críticas / altas1376▼ 50 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
124 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 0.29% | — | Pandasecurity Panda Dome | 22/11/2024 | 17/6/2026 | Panda Security Dome VPN DLL Hijacking Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Panda Security Dome. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this… | |
| Analizada | Alta (7.8) | 0.34% | — | Pandasecurity Panda Dome | 22/11/2024 | 17/6/2026 | Panda Security Dome Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Panda Security Dome. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this… | |
| Analizada | Alta (7.8) | 0.34% | — | Pandasecurity Panda Dome | 22/11/2024 | 17/6/2026 | Panda Security Dome Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Panda Security Dome. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this… | |
| Analizada | Alta (7.8) | 0.34% | — | Pandasecurity Panda Dome | 22/11/2024 | 17/6/2026 | Panda Security Dome Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Panda Security Dome. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this… | |
| Aplazada | Alta (8.5) | 0.19% | — | Watchguard EpdrAIPanda Ad360AIPanda DomeAI | 8/11/2024 | 8/8/2026 | Improper Privilege Management vulnerability in WatchGuard EPDR, Panda AD360 and Panda Dome on Windows (PSANHost.exe module) allows arbitrary file delete with SYSTEM permissions. | |
| Analizada | Media (4.3) | 0.32% | — | Giuliopanda Bulk Images Optimizer | 18/10/2024 | 17/6/2026 | The Bulk images optimizer: Resize, optimize, convert to webp, rename … plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'save_configuration' function in all versions up to, and including, 2.0.1. This makes it possible for authenticated attackers, with… | |
| Modificada | Media (5.4) | 0.35% | — | Pandavideo Panda Video | 9/7/2024 | 17/6/2026 | The Panda Video plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 1.4.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject… | |
| Aplazada | Alta (8.8) | 0.87% | — | Pandavideo Panda VideoAI | 9/7/2024 | 17/6/2026 | The Panda Video plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.4.0 via the 'selected_button' parameter. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary files on the server, allowing the… | |
| Analizada | Crítica (9.8) | 0.60% | — | Pandax | 17/3/2024 | 17/6/2026 | A vulnerability was found in PandaXGO PandaX up to 20240310. It has been classified as critical. Affected is an unknown function of the file /apps/system/router/upload.go of the component File Extension Handler. The manipulation of the argument file leads to unrestricted upload. It is possible to launch the attack… | |
| Analizada | Alta (7.3) | 0.51% | — | Pandax | 17/3/2024 | 17/6/2026 | A vulnerability was found in PandaXGO PandaX up to 20240310 and classified as critical. This issue affects the function ExportUser of the file /apps/system/api/user.go. The manipulation of the argument filename leads to path traversal: '../filedir'. The attack may be initiated remotely. The exploit has been disclosed… | |
| Analizada | Crítica (9.8) | 0.85% | — | Pandax | 17/3/2024 | 17/6/2026 | A vulnerability has been found in PandaXGO PandaX up to 20240310 and classified as critical. This vulnerability affects the function DeleteImage of the file /apps/system/router/upload.go. The manipulation of the argument fileName with the input ../../../../../../../../../tmp/1.txt leads to path traversal:… | |
| Analizada | Crítica (9.8) | 0.51% | — | Pandax | 17/3/2024 | 17/6/2026 | A vulnerability, which was classified as critical, was found in PandaXGO PandaX up to 20240310. This affects the function InsertRole of the file /apps/system/services/role_menu.go. The manipulation of the argument roleKey leads to sql injection. It is possible to initiate the attack remotely. The exploit has been… | |
| Modificada | Crítica (9.8) | 1.0% | — | Gabrieleventuri Pandasai | 22/1/2024 | 17/6/2026 | GenerateSDFPipeline in synthetic_dataframe in PandasAI (aka pandas-ai) through 1.5.17 allows attackers to trigger the generation of arbitrary Python code that is executed by SDFCodeExecutor. An attacker can create a dataframe that provides an English language specification of this Python code. NOTE: the vendor… | |
| Modificada | Crítica (9.8) | 0.99% | — | Redpanda | 18/12/2023 | 17/6/2026 | Redpanda before 23.1.21 and 23.2.x before 23.2.18 has missing authorization checks in the Transactions API. | |
| Modificada | Media (5.5) | 0.16% | — | Watchguard EPP FirmwareWatchguard EDR FirmwareWatchguard Epdr FirmwareWatchguard Panda Ad360 Firmware | 5/10/2023 | 17/6/2026 | An issue was discovered in WatchGuard EPDR 8.0.21.0002. Due to a weak implementation of a password check, it is possible to obtain credentials to access the management console as a non-privileged user. | |
| Modificada | Media (5.5) | 0.17% | — | Watchguard EPP FirmwareWatchguard EDR FirmwareWatchguard Epdr FirmwareWatchguard Panda Ad360 Firmware | 5/10/2023 | 17/6/2026 | An issue was discovered in WatchGuard EPDR 8.0.21.0002. It is possible to enable or disable defensive capabilities by sending a crafted message to a named pipe. | |
| Modificada | Media (6.7) | 0.18% | — | Watchguard EPP FirmwareWatchguard EDR FirmwareWatchguard Epdr FirmwareWatchguard Panda Ad360 Firmware | 5/10/2023 | 17/6/2026 | An issue was discovered in WatchGuard EPDR 8.0.21.0002. It is possible to bypass the defensive capabilities by adding a registry key as SYSTEM. | |
| Modificada | Alta (7.8) | 0.16% | — | Watchguard EPP FirmwareWatchguard EDR FirmwareWatchguard Epdr FirmwareWatchguard Panda Ad360 Firmware | 5/10/2023 | 17/6/2026 | An issue was discovered in WatchGuard EPDR 8.0.21.0002. Due to a weak implementation of message handling between WatchGuard EPDR processes, it is possible to perform a Local Privilege Escalation on Windows by sending a crafted message to a named pipe. | |
| Modificada | Crítica (9.8) | 1.5% | — | Gabrieleventuri Pandasai | 21/8/2023 | 17/6/2026 | An issue in Gaberiele Venturi pandasai v.0.8.0 and before allows a remote attacker to execute arbitrary code via a crafted request to the prompt function. | |
| Modificada | Crítica (9.8) | 1.4% | — | Gabrieleventuri Pandasai | 15/8/2023 | 17/6/2026 | An issue in pandas-ai v.0.9.1 and before allows a remote attacker to execute arbitrary code via the _is_jailbreak function. | |
| Modificada | Media (6.5) | 0.40% | — | Watchguard Panda Security VPN | 13/7/2023 | 17/6/2026 | A DLL hijacking vulnerability in Panda Security VPN for Windows prior to version v15.14.8 allows attackers to execute arbitrary code via placing a crafted DLL file in the same directory as PANDAVPN.exe. | |
| Modificada | Media (6.1) | 0.41% | — | Ipandao Editor.md | 8/5/2023 | 17/6/2026 | Cross Site Scripting (XSS) pandao editor.md 1.5.0 allows attackers to execute arbitrary code via crafted linked url values. | |
| Modificada | Media (6.1) | 0.43% | — | Ipandao Editor.md | 1/5/2023 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in pandao editor.md thru 1.5.0 allows attackers to inject arbitrary web script or HTML via crafted markdown text. | |
| Modificada | Media (4.3) | 0.59% | — | Redpanda | 8/4/2023 | 17/6/2026 | rpk in Redpanda before 23.1.2 mishandles the redpanda.rpc_server_tls field, leading to (for example) situations in which there is a data type mismatch that cannot be automatically fixed by rpk, and instead a user must reconfigure (while a cluster is turned off) in order to have TLS on broker RPC ports. NOTE: the fix… | |
| Modificada | Media (6.1) | 0.66% | — | Ipandao Editor.md | 4/4/2023 | 17/6/2026 | Cross Site Scripting vulnerability found in Pandao Editor.md v.1.5.0 allows a remote attacker to execute arbitrary code via a crafted script to the editor parameter. |