Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
91 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.3) | 0.14% | — | Paloaltonetworks Prisma Access Agent | 13/5/2026 | 14/7/2026 | Multiple information disclosure vulnerabilities in Prisma Access Agent® allow a local user to access sensitive configuration data and credentials. The Prisma Access Agent on Linux, ChromeOS, Android, and iOS are not affected. | |
| Analizada | Media (5.2) | 0.22% | — | Paloaltonetworks Prisma Sd-wan | 13/5/2026 | 14/7/2026 | An improper certificate validation vulnerability in the Palo Alto Networks Prisma SD-WAN ION enables man-in-the-middle (MitM) attacker to impersonate the controller. | |
| Analizada | Alta (7.3) | 0.16% | — | Paloaltonetworks Prisma Browser | 13/5/2026 | 13/7/2026 | A code injection vulnerability in Palo Alto Networks Prisma® Browser on macOS fails to properly restrict access to its AppleScript interface allowing a locally authenticated non-admin user to leverage this exposed Apple Event handler to send unauthorized commands to the browser. | |
| Analizada | Media (5.8) | 0.11% | — | Paloaltonetworks Prisma Browser | 13/5/2026 | 14/7/2026 | A race condition vulnerability in Palo Alto Networks Prisma® Browser enables a locally authenticated non-admin user to bypass certain access and data control policies. | |
| Analizada | Alta (7.3) | 0.15% | — | Paloaltonetworks Prisma Browser | 13/5/2026 | 14/7/2026 | An improper protection of alternate path vulnerability in Palo Alto Networks Prisma® Browser on macOS fails to properly restrict access to an internal automation bridge. This allows a locally authenticated non-admin user to leverage an exposed communication channel to send unauthorized commands to the browser,… | |
| Aplazada | Alta (7.2) | 0.32% | — | Plugin-planet PrismaticAI | 16/4/2026 | 17/6/2026 | The Prismatic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'prismatic_encoded' pseudo-shortcode in all versions up to, and including, 3.7.3. This is due to insufficient input sanitization and output escaping on user-supplied attributes within the 'prismatic_decode' function. This makes it… | |
| Analizada | Crítica (9.6) | 0.48% | — | Pebblepower Pebble Prism Ultra Firmware | 4/3/2026 | 17/6/2026 | A lack of authentication and authorization mechanisms in the Bluetooth Low Energy (BLE) communication protocol of SRK Powertech Pvt Ltd Pebble Prism Ultra v2.9.2 allows attackers to reverse engineer the protocol and execute arbitrary commands on the device without establishing a connection. This is exploitable over… | |
| Aplazada | Media (6.9) | 0.42% | — | Browan Communications Prismx Mx100AI | 20/1/2026 | 17/6/2026 | PrismX MX100 AP controller developed by BROWAN COMMUNICATIONS has an Insufficiently Protected Credentials vulnerability, allowing privileged remote attackers to allowing authenticated remote attackers to obtain SMTP plaintext passwords through the web frontend. | |
| Aplazada | Alta (8.6) | 0.65% | — | Browan Communications Prismx Mx100AI | 20/1/2026 | 17/6/2026 | PrismX MX100 AP controller developed by BROWAN COMMUNICATIONS has an Arbitrary File Upload vulnerability, allowing privileged remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server. | |
| Aplazada | Crítica (9.3) | 0.50% | — | Browan Communications Prismx Mx100AI | 20/1/2026 | 17/6/2026 | PrismX MX100 AP controller developed by BROWAN COMMUNICATIONS has a Use of Hard-coded Credentials vulnerability, allowing unauthenticated remote attackers to log in to the database using hardcoded database credentials stored in the firmware. | |
| Analizada | Media (6.6) | 0.75% | — | Paloaltonetworks Pan-osPaloaltonetworks Prisma Access | 15/1/2026 | 17/6/2026 | A vulnerability in Palo Alto Networks PAN-OS software enables an unauthenticated attacker to cause a denial of service (DoS) to the firewall. Repeated attempts to trigger this issue results in the firewall entering into maintenance mode. | |
| Modificada | Alta (8.1) | 0.50% | — | Axiomthemes Prisma | 18/12/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Prisma prisma allows PHP Local File Inclusion.This issue affects Prisma: from n/a through <= 1.10. | |
| Aplazada | Media (4.4) | 0.09% | — | Paloaltonetworks Prisma BrowserAI | 14/11/2025 | 17/6/2026 | A sensitive information disclosure vulnerability in Palo Alto Networks Prisma® Browser allows a locally authenticated non-admin user to retrieve sensitive data from Prisma Browser. Browser self-protection should be enabled to mitigate this issue. | |
| Aplazada | Baja (1.1) | 0.11% | — | Paloaltonetworks Prisma BrowserAI | 14/11/2025 | 17/6/2026 | An insufficient validation of an untrusted input vulnerability in Palo Alto Networks Prisma® Browser allows a locally authenticated non-admin user to revert the browser’s security controls. | |
| Aplazada | Baja (1.1) | 0.13% | — | Paloaltonetworks Prisma BrowserAI | 14/11/2025 | 30/9/2026 | An insufficient policy enforcement vulnerability in Palo Alto Networks Prisma® Browser on Windows allows a locally authenticated non-admin user to bypass the screenshot control feature of the browser. Browser self-protection should be enabled to mitigate this issue. | |
| Aplazada | Media (6.6) | 0.56% | — | Paloaltonetworks Pan-osAIPaloaltonetworks Pa-seriesAIPaloaltonetworks Vm-seriesAIPaloaltonetworks Prisma AccessAI | 13/11/2025 | 17/6/2026 | A denial-of-service (DoS) vulnerability in Palo Alto Networks PAN-OS software enables an unauthenticated attacker to reboot a firewall by sending a specially crafted packet through the dataplane. Repeated attempts to initiate a reboot causes the firewall to enter maintenance mode. This issue is applicable to the… | |
| Aplazada | Crítica (9.3) | 0.33% | — | Nutanix Prism CentralAI | 20/8/2025 | 17/6/2026 | Prism Central versions prior to 2024.3.1 are vulnerable to a stored cross-site scripting attack via the Events component, allowing an attacker to hijack a victim user’s session and perform actions in their security context. | |
| Aplazada | Media (6.5) | 0.23% | — | Prismtechstudios Modern-footnotesAI | 20/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in prismtechstudios Modern Footnotes modern-footnotes allows Stored XSS.This issue affects Modern Footnotes: from n/a through <= 1.4.19. | |
| Aplazada | Media (5.1) | 0.19% | — | Paloaltonetworks Prisma Access BrowserAI | 12/6/2025 | 17/6/2026 | An insufficient implementation of cache vulnerability in Palo Alto Networks Prisma® Access Browser enables users to bypass certain data control policies. | |
| Aplazada | Baja (2) | 0.35% | — | Paloaltonetworks Prisma Cloud Compute EditionAI | 14/5/2025 | 17/6/2026 | Web sessions in the web interface of Palo Alto Networks Prisma® Cloud Compute Edition do not expire when users are deleted, which makes Prisma Cloud Compute Edition susceptible to unauthorized access. Compute in Prisma Cloud Enterprise Edition is not affected by this issue. | |
| Aplazada | Crítica (9.3) | 0.18% | — | Paloaltonetworks Prisma Access BrowserAI | 11/4/2025 | 17/6/2026 | An improper exception check in Palo Alto Networks Prisma Access Browser allows a low privileged user to prevent Prisma Access Browser from applying it's Policy Rules. This enables the user to use Prisma Access Browser without any restrictions. | |
| Aplazada | Alta (8.3) | 0.40% | — | Paloaltonetworks GlobalprotectAIPaloaltonetworks Pan-osAIPaloaltonetworks Prisma AccessAIPaloaltonetworks Cloud NgfwAI | 11/4/2025 | 17/6/2026 | When configured using SAML, a session fixation vulnerability in the GlobalProtect™ login enables an attacker to impersonate a legitimate authorized user and perform actions as that GlobalProtect user. This requires the legitimate user to first click on a malicious link provided by the attacker. The SAML login for the… | |
| Aplazada | Media (5.1) | 0.27% | — | Paloaltonetworks Prisma Sd-wan IONAI | 11/4/2025 | 17/6/2026 | A denial-of-service (DoS) vulnerability in Palo Alto Networks Prisma® SD-WAN ION devices enables an unauthenticated attacker in a network adjacent to a Prisma SD-WAN ION device to disrupt the packet processing capabilities of the device by sending a burst of crafted packets to that device. | |
| Analizada | Media (5.4) | 0.34% | — | Prismjs Prism | 3/3/2025 | 17/6/2026 | Prism (aka PrismJS) through 1.29.0 allows DOM Clobbering (with resultant XSS for untrusted input that contains HTML but does not directly contain JavaScript), because document.currentScript lookup can be shadowed by attacker-injected HTML elements. | |
| Analizada | Alta (8.7) | 29% | ⚠ Explotación activa | Paloaltonetworks Pan-osPaloaltonetworks Prisma Access | 27/12/2024 | 17/6/2026 | A Denial of Service vulnerability in the DNS Security feature of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to send a malicious packet through the data plane of the firewall that reboots the firewall. Repeated attempts to trigger this condition will cause the firewall to enter maintenance… |