Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
1845 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 0.71% | — | Dcnetworks Dcme-720 FirmwareDcnetworks Dcme-320-l FirmwareDcnetworks Dcme-320 FirmwareDcnetworks Dcme-520 Firmware | 29/11/2024 | 17/6/2026 | DCME-320 <=7.4.12.90, DCME-520 <=9.25.5.11, DCME-320-L <=9.3.5.26, and DCME-720 <=9.1.5.11 are vulnerable to Remote Code Execution via /function/system/basic/mgmt_edit.php. | |
| Analizada | Crítica (9.8) | 0.71% | — | Dcnetworks Dcme-720 FirmwareDcnetworks Dcme-320-l FirmwareDcnetworks Dcme-320 FirmwareDcnetworks Dcme-520 Firmware | 29/11/2024 | 17/6/2026 | DCME-320 <=7.4.12.90, DCME-520 <=9.25.5.11, DCME-320-L <=9.3.5.26, and DCME-720 <=9.1.5.11 are vulnerable to Remote Code Execution via /function/audit/newstatistics/mon_stat_top10.php. | |
| Analizada | Crítica (9.8) | 0.71% | — | Dcnetworks Dcme-720 FirmwareDcnetworks Dcme-320-l FirmwareDcnetworks Dcme-320 FirmwareDcnetworks Dcme-520 Firmware | 29/11/2024 | 17/6/2026 | DCME-320 <=7.4.12.90, DCME-520 <=9.25.5.11, DCME-320-L <=9.3.5.26, and DCME-720 <=9.1.5.11 are vulnerable to Remote Code Execution via /function/audit/newstatistics/mon_stat_hist.php. | |
| Analizada | Crítica (9.8) | 0.75% | — | Dcnetworks Dcme-720 FirmwareDcnetworks Dcme-320-l FirmwareDcnetworks Dcme-320 FirmwareDcnetworks Dcme-520 Firmware | 29/11/2024 | 17/6/2026 | DCME-320 <=7.4.12.90, DCME-520 <=9.25.5.11, DCME-320-L, <=9.3.5.26, and DCME-720 <=9.1.5.11 are vulnerable to Remote Code Execution via /function/system/basic/license_update.php. | |
| Analizada | Alta (7.1) | 1.5% | — | Paloaltonetworks Globalprotect | 27/11/2024 | 17/6/2026 | An insufficient certification validation issue in the Palo Alto Networks GlobalProtect app enables attackers to connect the GlobalProtect app to arbitrary servers. This can enable a local non-administrative operating system user or an attacker on the same subnet to install malicious root certificates on the endpoint… | |
| Analizada | Crítica (10) | 0.58% | — | Versa-networks Versa Director | 19/11/2024 | 3/9/2026 | The Versa Director uses PostgreSQL (Postgres) to store operational and configuration data. It is also needed for High Availability function of the Versa Director. The default configuration has a common password across all instances of Versa Director. By default, Versa Director configures Postgres to listen on all… | |
| Aplazada | Media (6.5) | 0.39% | — | Holanetworks Hola Free Video PlayerAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in holanetworks Hola Free Video Player hola-free-video-player allows DOM-Based XSS.This issue affects Hola Free Video Player: from n/a through <= 1.3.9. | |
| Analizada | Media (6.9) | 95% | ⚠ Explotación activa💥 Exploit | Paloaltonetworks Pan-os | 18/11/2024 | 4/8/2026 | A privilege escalation vulnerability in Palo Alto Networks PAN-OS software allows a PAN-OS administrator with access to the management web interface to perform actions on the firewall with root privileges. Cloud NGFW and Prisma Access are not impacted by this vulnerability. | |
| Analizada | Crítica (9.3) | 100% | ⚠ Explotación activa💥 Exploit | Paloaltonetworks Pan-os | 18/11/2024 | 4/8/2026 | An authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to gain PAN-OS administrator privileges to perform administrative actions, tamper with the configuration, or exploit other authenticated privilege escalation… | |
| Aplazada | Alta (8.7) | 0.43% | — | Paloaltonetworks Pan-osAI | 14/11/2024 | 17/6/2026 | A null pointer dereference in Palo Alto Networks PAN-OS software on PA-800 Series, PA-3200 Series, PA-5200 Series, and PA-7000 Series hardware platforms when Decryption policy is enabled allows an unauthenticated attacker to crash PAN-OS by sending specific traffic through the data plane, resulting in a denial of… | |
| Analizada | Media (4.6) | 0.34% | — | Paloaltonetworks Pan-os | 14/11/2024 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software enables an authenticated read-write Panorama administrator to push a specially crafted configuration to a PAN-OS node. This enables impersonation of a legitimate PAN-OS administrator who can perform restricted actions on the PAN-OS node… | |
| Analizada | Media (5.1) | 0.34% | — | Paloaltonetworks Pan-os | 14/11/2024 | 17/6/2026 | A blind XML External Entities (XXE) injection vulnerability in the Palo Alto Networks PAN-OS software enables an authenticated attacker to exfiltrate arbitrary files from firewalls to an attacker controlled server. This attack requires network access to the firewall management interface. | |
| Analizada | Media (5.3) | 0.18% | — | Paloaltonetworks Pan-os | 14/11/2024 | 17/6/2026 | An improper certificate validation vulnerability in Palo Alto Networks PAN-OS software enables an authorized user with a specially crafted client certificate to connect to an impacted GlobalProtect portal or GlobalProtect gateway as a different legitimate user. This attack is possible only if you "Allow Authentication… | |
| Analizada | Baja (2.1) | 0.47% | — | Paloaltonetworks Pan-os | 14/11/2024 | 17/6/2026 | A server-side request forgery in PAN-OS software enables an authenticated attacker with administrative privileges to use the administrative web interface as a proxy, which enables the attacker to view internal network resources not otherwise accessible. | |
| Analizada | Media (6.8) | 0.47% | — | Paloaltonetworks Pan-os | 14/11/2024 | 17/6/2026 | A command injection vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to bypass system restrictions in the management plane and delete files on the firewall. | |
| Analizada | Alta (8.7) | 0.48% | — | Paloaltonetworks Pan-os | 14/11/2024 | 17/6/2026 | A null pointer dereference vulnerability in Palo Alto Networks PAN-OS software enables an unauthenticated attacker to stop a core system service on the firewall by sending a crafted packet through the data plane that causes a denial of service (DoS) condition. Repeated attempts to trigger this condition result in the… | |
| Analizada | Alta (8.7) | 0.51% | — | Paloaltonetworks Pan-os | 14/11/2024 | 17/6/2026 | A null pointer dereference vulnerability in the GlobalProtect gateway in Palo Alto Networks PAN-OS software enables an unauthenticated attacker to stop the GlobalProtect service on the firewall by sending a specially crafted packet that causes a denial of service (DoS) condition. Repeated attempts to trigger this… | |
| Aplazada | Sin puntuar | 0.30% | — | Extremenetworks ExtremexosAI | 11/11/2024 | 17/6/2026 | The BGP daemon in Extreme Networks ExtremeXOS (aka EXOS) 30.7.1.1 allows an attacker (who is not on a directly connected network) to cause a denial of service (BGP session reset) because of BGP attribute error mishandling (for attribute 21 and 25). NOTE: the vendor disputes this because it is "evaluating support for… | |
| Analizada | Crítica (9.8) | 1.7% | — | Dcnetworks Dcme-320 Firmware | 5/11/2024 | 17/6/2026 | DCME-320 v7.4.12.90 was discovered to contain a command injection vulnerability. | |
| Analizada | Crítica (9.8) | 1.1% | — | Dcnetworks Dcme-320-l Firmware | 21/10/2024 | 17/6/2026 | An issue in DCME-320-L <=9.3.2.114 allows a remote attacker to execute arbitrary code via the log_u_umount.php component. | |
| Analizada | Media (6.5) | 0.50% | — | Nextscripts Social Networks Auto Poster | 16/10/2024 | 17/6/2026 | The NextScripts: Social Networks Auto-Poster plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on multiple user privilege/security functions provided in versions up to, and including 4.3.17. This makes it possible for low-privileged attackers, like subscribers, to perform… | |
| Modificada | Media (5.2) | 0.29% | — | Paloaltonetworks Globalprotect | 9/10/2024 | 17/6/2026 | A privilege escalation vulnerability in the Palo Alto Networks GlobalProtect app on Windows allows a locally authenticated non-administrative Windows user to escalate their privileges to NT AUTHORITY/SYSTEM through the use of the repair functionality offered by the .msi file used to install GlobalProtect. | |
| Analizada | Media (5.1) | 0.29% | — | Paloaltonetworks Pan-os | 9/10/2024 | 17/6/2026 | A privilege escalation (PE) vulnerability in the XML API of Palo Alto Networks PAN-OS software enables an authenticated PAN-OS administrator with restricted privileges to use a compromised XML API key to perform actions as a higher privileged PAN-OS administrator. For example, an administrator with "Virtual system… | |
| Aplazada | Media (5.3) | 0.38% | — | Paloaltonetworks Cortex XsoarAI | 9/10/2024 | 17/6/2026 | A vulnerability in Cortex XSOAR allows the disclosure of incident data to users who do not have the privilege to view the data. | |
| Analizada | Media (5.7) | 0.21% | — | Paloaltonetworks Cortex XDR Agent | 9/10/2024 | 17/6/2026 | A problem with a detection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices enables a user with Windows non-administrative privileges to disable the agent. This issue may be leveraged by malware to disable the Cortex XDR agent and then to perform malicious activity. |