Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3017▼ 66 respecto a la semana anterior
Críticas / altas1412▲ 56 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)381▼ 129 respecto a la semana anterior
–

58 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.8)0.11%—Paloaltonetworks Prisma Browser13/5/202614/7/2026
A race condition vulnerability in Palo Alto Networks Prisma® Browser enables a locally authenticated non-admin user to bypass certain access and data control policies.
AnalizadaAlta (7.3)0.15%—Paloaltonetworks Prisma Browser13/5/202614/7/2026
An improper protection of alternate path vulnerability in Palo Alto Networks Prisma® Browser on macOS fails to properly restrict access to an internal automation bridge. This allows a locally authenticated non-admin user to leverage an exposed communication channel to send unauthorized commands to the browser,…
AplazadaAlta (7.2)0.32%—Plugin-planet PrismaticAI16/4/202617/6/2026
The Prismatic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'prismatic_encoded' pseudo-shortcode in all versions up to, and including, 3.7.3. This is due to insufficient input sanitization and output escaping on user-supplied attributes within the 'prismatic_decode' function. This makes it…
AnalizadaMedia (6.6)0.75%—Paloaltonetworks Pan-osPaloaltonetworks Prisma Access15/1/202617/6/2026
A vulnerability in Palo Alto Networks PAN-OS software enables an unauthenticated attacker to cause a denial of service (DoS) to the firewall. Repeated attempts to trigger this issue results in the firewall entering into maintenance mode.
ModificadaAlta (8.1)0.50%—Axiomthemes Prisma18/12/202517/6/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Prisma prisma allows PHP Local File Inclusion.This issue affects Prisma: from n/a through <= 1.10.
AplazadaMedia (4.4)0.09%—Paloaltonetworks Prisma BrowserAI14/11/202517/6/2026
A sensitive information disclosure vulnerability in Palo Alto Networks Prisma® Browser allows a locally authenticated non-admin user to retrieve sensitive data from Prisma Browser. Browser self-protection should be enabled to mitigate this issue.
AplazadaBaja (1.1)0.11%—Paloaltonetworks Prisma BrowserAI14/11/202517/6/2026
An insufficient validation of an untrusted input vulnerability in Palo Alto Networks Prisma® Browser allows a locally authenticated non-admin user to revert the browser’s security controls.
AplazadaBaja (1.1)0.13%—Paloaltonetworks Prisma BrowserAI14/11/202530/9/2026
An insufficient policy enforcement vulnerability in Palo Alto Networks Prisma® Browser on Windows allows a locally authenticated non-admin user to bypass the screenshot control feature of the browser. Browser self-protection should be enabled to mitigate this issue.
AplazadaMedia (6.6)0.56%—Paloaltonetworks Pan-osAIPaloaltonetworks Pa-seriesAIPaloaltonetworks Vm-seriesAIPaloaltonetworks Prisma AccessAI13/11/202517/6/2026
A denial-of-service (DoS) vulnerability in Palo Alto Networks PAN-OS software enables an unauthenticated attacker to reboot a firewall by sending a specially crafted packet through the dataplane. Repeated attempts to initiate a reboot causes the firewall to enter maintenance mode. This issue is applicable to the…
AplazadaMedia (5.1)0.19%—Paloaltonetworks Prisma Access BrowserAI12/6/202517/6/2026
An insufficient implementation of cache vulnerability in Palo Alto Networks Prisma® Access Browser enables users to bypass certain data control policies.
AplazadaBaja (2)0.35%—Paloaltonetworks Prisma Cloud Compute EditionAI14/5/202517/6/2026
Web sessions in the web interface of Palo Alto Networks Prisma® Cloud Compute Edition do not expire when users are deleted, which makes Prisma Cloud Compute Edition susceptible to unauthorized access. Compute in Prisma Cloud Enterprise Edition is not affected by this issue.
AplazadaCrítica (9.3)0.18%—Paloaltonetworks Prisma Access BrowserAI11/4/202517/6/2026
An improper exception check in Palo Alto Networks Prisma Access Browser allows a low privileged user to prevent Prisma Access Browser from applying it's Policy Rules. This enables the user to use Prisma Access Browser without any restrictions.
AplazadaAlta (8.3)0.40%—Paloaltonetworks GlobalprotectAIPaloaltonetworks Pan-osAIPaloaltonetworks Prisma AccessAIPaloaltonetworks Cloud NgfwAI11/4/202517/6/2026
When configured using SAML, a session fixation vulnerability in the GlobalProtect™ login enables an attacker to impersonate a legitimate authorized user and perform actions as that GlobalProtect user. This requires the legitimate user to first click on a malicious link provided by the attacker. The SAML login for the…
AplazadaMedia (5.1)0.27%—Paloaltonetworks Prisma Sd-wan IONAI11/4/202517/6/2026
A denial-of-service (DoS) vulnerability in Palo Alto Networks Prisma® SD-WAN ION devices enables an unauthenticated attacker in a network adjacent to a Prisma SD-WAN ION device to disrupt the packet processing capabilities of the device by sending a burst of crafted packets to that device.
AnalizadaAlta (8.7)29%⚠ Explotación activaPaloaltonetworks Pan-osPaloaltonetworks Prisma Access27/12/202417/6/2026
A Denial of Service vulnerability in the DNS Security feature of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to send a malicious packet through the data plane of the firewall that reboots the firewall. Repeated attempts to trigger this condition will cause the firewall to enter maintenance…
AnalizadaMedia (6.9)0.41%—Paloaltonetworks Pan-osPaloaltonetworks GlobalprotectPaloaltonetworks Prisma Access11/9/202417/6/2026
An information exposure vulnerability exists in Palo Alto Networks PAN-OS software that enables a GlobalProtect end user to learn both the configured GlobalProtect uninstall password and the configured disable or disconnect passcode. After the password or passcode is known, end users can uninstall, disable, or…
ModificadaMedia (4.8)0.25%—Paloaltonetworks Prisma Cloud12/6/202417/6/2026
A cross-site scripting (XSS) vulnerability in Palo Alto Networks Prisma Cloud Compute software enables a malicious administrator with add/edit permissions for identity providers to store a JavaScript payload using the web interface on Prisma Cloud Compute. This enables a malicious administrator to perform actions in…
AnalizadaMedia (5)0.35%—Paloaltonetworks Pan-osPaloaltonetworks Prisma Access10/4/202417/6/2026
A vulnerability in the GlobalProtect Gateway in Palo Alto Networks PAN-OS software enables an authenticated attacker to impersonate another user and send network packets to internal assets. However, this vulnerability does not allow the attacker to receive response packets from those internal assets.
ModificadaMedia (6.5)0.66%—Paloaltonetworks Pan-osPaloaltonetworks Prisma Access10/2/202217/6/2026
PAN-OS software provides options to exclude specific websites from URL category enforcement and those websites are blocked or allowed (depending on your rules) regardless of their associated URL category. This is done by creating a custom URL category list or by using an external dynamic list (EDL) in a URL Filtering…
ModificadaAlta (7.2)0.86%—Paloaltonetworks Prisma AccessPaloaltonetworks Pan-os10/11/202117/6/2026
An OS command injection vulnerability in the Palo Alto Networks PAN-OS command line interface (CLI) enables an authenticated administrator with access to the CLI to execute arbitrary OS commands to escalate privileges. This issue impacts: PAN-OS 8.1 versions earlier than PAN-OS 8.1.20-h1; PAN-OS 9.0 versions earlier…
ModificadaAlta (8.1)33%—Paloaltonetworks Prisma AccessPaloaltonetworks Pan-os10/11/202117/6/2026
An OS command injection vulnerability in the Simple Certificate Enrollment Protocol (SCEP) feature of PAN-OS software allows an unauthenticated network-based attacker with specific knowledge of the firewall configuration to execute arbitrary code with root user privileges. The attacker must have network access to the…
ModificadaMedia (4.8)0.63%—Paloaltonetworks Prisma Cloud15/7/202117/6/2026
A reflected cross-site scripting (XSS) vulnerability exists in the Prisma Cloud Compute web console that enables a remote attacker to execute arbitrary JavaScript code in the browser-based web console while an authenticated administrator is using that web interface. Prisma Cloud Compute SaaS versions were…
ModificadaMedia (6.1)1.7%—Plugin-planet Prismatic12/7/202117/6/2026
The Prismatic WordPress plugin before 2.8 does not escape the 'tab' GET parameter before outputting it back in an attribute, leading to a reflected Cross-Site Scripting issue which will be executed in the context of a logged in administrator
ModificadaMedia (5.4)0.62%—Plugin-planet Prismatic12/7/202117/6/2026
The Prismatic WordPress plugin before 2.8 does not sanitise or validate some of its shortcode parameters, allowing users with a role as low as Contributor to set Cross-Site payload in them. A post made by a contributor would still have to be approved by an admin to have the XSS trigger able in the frontend, however,…
ModificadaBaja (3.8)0.54%—Paloaltonetworks Prisma Cloud10/6/202117/6/2026
An information exposure through log file vulnerability exists in the Palo Alto Networks Prisma Cloud Compute Console where a secret used to authorize the role of the authenticated user is logged to a debug log file. Authenticated Operator role and Auditor role users with access to the debug log files can use this…