Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

1845 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.8)0.71%—Dcnetworks Dcme-720 FirmwareDcnetworks Dcme-320-l FirmwareDcnetworks Dcme-320 FirmwareDcnetworks Dcme-520 Firmware29/11/202417/6/2026
DCME-320 <=7.4.12.90, DCME-520 <=9.25.5.11, DCME-320-L <=9.3.5.26, and DCME-720 <=9.1.5.11 are vulnerable to Remote Code Execution via /function/system/basic/mgmt_edit.php.
AnalizadaCrítica (9.8)0.71%—Dcnetworks Dcme-720 FirmwareDcnetworks Dcme-320-l FirmwareDcnetworks Dcme-320 FirmwareDcnetworks Dcme-520 Firmware29/11/202417/6/2026
DCME-320 <=7.4.12.90, DCME-520 <=9.25.5.11, DCME-320-L <=9.3.5.26, and DCME-720 <=9.1.5.11 are vulnerable to Remote Code Execution via /function/audit/newstatistics/mon_stat_top10.php.
AnalizadaCrítica (9.8)0.71%—Dcnetworks Dcme-720 FirmwareDcnetworks Dcme-320-l FirmwareDcnetworks Dcme-320 FirmwareDcnetworks Dcme-520 Firmware29/11/202417/6/2026
DCME-320 <=7.4.12.90, DCME-520 <=9.25.5.11, DCME-320-L <=9.3.5.26, and DCME-720 <=9.1.5.11 are vulnerable to Remote Code Execution via /function/audit/newstatistics/mon_stat_hist.php.
AnalizadaCrítica (9.8)0.75%—Dcnetworks Dcme-720 FirmwareDcnetworks Dcme-320-l FirmwareDcnetworks Dcme-320 FirmwareDcnetworks Dcme-520 Firmware29/11/202417/6/2026
DCME-320 <=7.4.12.90, DCME-520 <=9.25.5.11, DCME-320-L, <=9.3.5.26, and DCME-720 <=9.1.5.11 are vulnerable to Remote Code Execution via /function/system/basic/license_update.php.
AnalizadaAlta (7.1)1.5%—Paloaltonetworks Globalprotect27/11/202417/6/2026
An insufficient certification validation issue in the Palo Alto Networks GlobalProtect app enables attackers to connect the GlobalProtect app to arbitrary servers. This can enable a local non-administrative operating system user or an attacker on the same subnet to install malicious root certificates on the endpoint…
AnalizadaCrítica (10)0.58%—Versa-networks Versa Director19/11/20243/9/2026
The Versa Director uses PostgreSQL (Postgres) to store operational and configuration data. It is also needed for High Availability function of the Versa Director. The default configuration has a common password across all instances of Versa Director. By default, Versa Director configures Postgres to listen on all…
AplazadaMedia (6.5)0.39%—Holanetworks Hola Free Video PlayerAI19/11/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in holanetworks Hola Free Video Player hola-free-video-player allows DOM-Based XSS.This issue affects Hola Free Video Player: from n/a through <= 1.3.9.
AnalizadaMedia (6.9)95%⚠ Explotación activa💥 ExploitPaloaltonetworks Pan-os18/11/20244/8/2026
A privilege escalation vulnerability in Palo Alto Networks PAN-OS software allows a PAN-OS administrator with access to the management web interface to perform actions on the firewall with root privileges. Cloud NGFW and Prisma Access are not impacted by this vulnerability.
AnalizadaCrítica (9.3)100%⚠ Explotación activa💥 ExploitPaloaltonetworks Pan-os18/11/20244/8/2026
An authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to gain PAN-OS administrator privileges to perform administrative actions, tamper with the configuration, or exploit other authenticated privilege escalation…
AplazadaAlta (8.7)0.43%—Paloaltonetworks Pan-osAI14/11/202417/6/2026
A null pointer dereference in Palo Alto Networks PAN-OS software on PA-800 Series, PA-3200 Series, PA-5200 Series, and PA-7000 Series hardware platforms when Decryption policy is enabled allows an unauthenticated attacker to crash PAN-OS by sending specific traffic through the data plane, resulting in a denial of…
AnalizadaMedia (4.6)0.34%—Paloaltonetworks Pan-os14/11/202417/6/2026
A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software enables an authenticated read-write Panorama administrator to push a specially crafted configuration to a PAN-OS node. This enables impersonation of a legitimate PAN-OS administrator who can perform restricted actions on the PAN-OS node…
AnalizadaMedia (5.1)0.34%—Paloaltonetworks Pan-os14/11/202417/6/2026
A blind XML External Entities (XXE) injection vulnerability in the Palo Alto Networks PAN-OS software enables an authenticated attacker to exfiltrate arbitrary files from firewalls to an attacker controlled server. This attack requires network access to the firewall management interface.
AnalizadaMedia (5.3)0.18%—Paloaltonetworks Pan-os14/11/202417/6/2026
An improper certificate validation vulnerability in Palo Alto Networks PAN-OS software enables an authorized user with a specially crafted client certificate to connect to an impacted GlobalProtect portal or GlobalProtect gateway as a different legitimate user. This attack is possible only if you "Allow Authentication…
AnalizadaBaja (2.1)0.47%—Paloaltonetworks Pan-os14/11/202417/6/2026
A server-side request forgery in PAN-OS software enables an authenticated attacker with administrative privileges to use the administrative web interface as a proxy, which enables the attacker to view internal network resources not otherwise accessible.
AnalizadaMedia (6.8)0.47%—Paloaltonetworks Pan-os14/11/202417/6/2026
A command injection vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to bypass system restrictions in the management plane and delete files on the firewall.
AnalizadaAlta (8.7)0.48%—Paloaltonetworks Pan-os14/11/202417/6/2026
A null pointer dereference vulnerability in Palo Alto Networks PAN-OS software enables an unauthenticated attacker to stop a core system service on the firewall by sending a crafted packet through the data plane that causes a denial of service (DoS) condition. Repeated attempts to trigger this condition result in the…
AnalizadaAlta (8.7)0.51%—Paloaltonetworks Pan-os14/11/202417/6/2026
A null pointer dereference vulnerability in the GlobalProtect gateway in Palo Alto Networks PAN-OS software enables an unauthenticated attacker to stop the GlobalProtect service on the firewall by sending a specially crafted packet that causes a denial of service (DoS) condition. Repeated attempts to trigger this…
AplazadaSin puntuar0.30%—Extremenetworks ExtremexosAI11/11/202417/6/2026
The BGP daemon in Extreme Networks ExtremeXOS (aka EXOS) 30.7.1.1 allows an attacker (who is not on a directly connected network) to cause a denial of service (BGP session reset) because of BGP attribute error mishandling (for attribute 21 and 25). NOTE: the vendor disputes this because it is "evaluating support for…
AnalizadaCrítica (9.8)1.7%—Dcnetworks Dcme-320 Firmware5/11/202417/6/2026
DCME-320 v7.4.12.90 was discovered to contain a command injection vulnerability.
AnalizadaCrítica (9.8)1.1%—Dcnetworks Dcme-320-l Firmware21/10/202417/6/2026
An issue in DCME-320-L <=9.3.2.114 allows a remote attacker to execute arbitrary code via the log_u_umount.php component.
AnalizadaMedia (6.5)0.50%—Nextscripts Social Networks Auto Poster16/10/202417/6/2026
The NextScripts: Social Networks Auto-Poster plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on multiple user privilege/security functions provided in versions up to, and including 4.3.17. This makes it possible for low-privileged attackers, like subscribers, to perform…
ModificadaMedia (5.2)0.29%—Paloaltonetworks Globalprotect9/10/202417/6/2026
A privilege escalation vulnerability in the Palo Alto Networks GlobalProtect app on Windows allows a locally authenticated non-administrative Windows user to escalate their privileges to NT AUTHORITY/SYSTEM through the use of the repair functionality offered by the .msi file used to install GlobalProtect.
AnalizadaMedia (5.1)0.29%—Paloaltonetworks Pan-os9/10/202417/6/2026
A privilege escalation (PE) vulnerability in the XML API of Palo Alto Networks PAN-OS software enables an authenticated PAN-OS administrator with restricted privileges to use a compromised XML API key to perform actions as a higher privileged PAN-OS administrator. For example, an administrator with "Virtual system…
AplazadaMedia (5.3)0.38%—Paloaltonetworks Cortex XsoarAI9/10/202417/6/2026
A vulnerability in Cortex XSOAR allows the disclosure of incident data to users who do not have the privilege to view the data.
AnalizadaMedia (5.7)0.21%—Paloaltonetworks Cortex XDR Agent9/10/202417/6/2026
A problem with a detection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices enables a user with Windows non-administrative privileges to disable the agent. This issue may be leveraged by malware to disable the Cortex XDR agent and then to perform malicious activity.
Orbitaley — Vulnerabilidades