Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

5318 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.1)0.19%—Accellion Kiteworks Managed File Transfer29/11/20257/10/2026
Kiteworks MFT orchestrates end-to-end file transfer workflows. Prior to version 9.1.0, a bug in Kiteworks MFT could cause under certain circumstances that a user's active session would not properly time out due to inactivity. This issue has been patched in version 9.1.0.
AplazadaMedia (5.5)0.10%—Mitsubishi GX Works2AI27/11/202517/6/2026
Cleartext Storage of Sensitive Information Vulnerability in GX Works2 all versions allows an attacker to disclose credential information stored in plaintext from project files. As a result, the attacker may be able to open project files protected by user authentication using disclosed credential information, and…
AplazadaBaja (2.7)0.22%—Splunk Add-on FOR Palo Alto NetworksAI26/11/202517/6/2026
In Splunk Add-on for Palo Alto Networks versions below 2.0.2, the add-on exposes client secrets in plain text in the _internal index during the addition of new “Data Security Accounts“. The vulnerability would require either local access to the log files or administrative access to internal indexes, which by default…
AnalizadaCrítica (9.8)0.54%—Millensys Vision Tools Workspace24/11/202517/6/2026
MILLENSYS Vision Tools Workspace 6.5.0.2585 exposes a sensitive configuration endpoint (/MILLENSYS/settings) that is accessible without authentication. This page leaks plaintext database credentials, file share paths, internal license server configuration, and software update parameters. An unauthenticated attacker…
AplazadaMedia (6.5)0.15%—Bqworks Accordion SliderAI21/11/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bqworks Accordion Slider accordion-slider allows Stored XSS.This issue affects Accordion Slider: from n/a through <= 1.9.13.
AnalizadaCrítica (9.8)0.53%—Dasannetworks Ds2924 Firmware19/11/202517/6/2026
An authentication bypass issue was discovered in Dasan Switch DS2924 web based interface, firmware versions 1.01.18 and 1.02.00, allowing attackers to gain escalated privileges via storing crafted cookies in the web browser.
AnalizadaAlta (8.8)0.89%—Arubanetworks Arubaos18/11/202517/6/2026
A vulnerability in the command line interface of affected devices could allow an authenticated remote attacker to conduct a command injection attack. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system.
AnalizadaAlta (7.5)0.39%—Arubanetworks Arubaos18/11/202517/6/2026
A vulnerability in the web-based management interface of affected products could allow an unauthenticated remote attacker to cause a denial of service. Successful exploitation could allow an attacker to crash the system, preventing it from rebooting without manual intervention and disrupting network operations.
AnalizadaAlta (7.2)0.99%—Arubanetworks Airwave18/11/202517/6/2026
A command injection vulnerability has been identified in the command line interface of the HPE Aruba Networking Airwave Platform. An authenticated attacker could exploit this vulnerability to execute arbitrary operating system commands with elevated privileges on the underlying operating system.
AnalizadaAlta (8)0.82%—IBM Planning Analytics LocalIBM Planning Analytics Workspace17/11/20257/10/2026
IBM Planning Analytics Local 2.1.0 through 2.1.14 could allow a remote authenticated user to traverse directories on the system. An attacker could send a specially crafted URL request containing absolute path sequences to view, read, or write arbitrary files on the system.
AnalizadaMedia (4.3)0.21%—IBM Planning Analytics LocalIBM Planning Analytics Workspace17/11/20257/10/2026
IBM Planning Analytics Local 2.1.0 through 2.1.14 stores sensitive information in source code could be used in further attacks against the system.
AplazadaMedia (4.4)0.09%—Paloaltonetworks Prisma BrowserAI14/11/20257/10/2026
A sensitive information disclosure vulnerability in Palo Alto Networks Prisma® Browser allows a locally authenticated non-admin user to retrieve sensitive data from Prisma Browser. Browser self-protection should be enabled to mitigate this issue.
AplazadaBaja (1.1)0.13%—Paloaltonetworks Prisma BrowserAI14/11/20257/10/2026
An insufficient policy enforcement vulnerability in Palo Alto Networks Prisma® Browser on Windows allows a locally authenticated non-admin user to bypass the screenshot control feature of the browser. Browser self-protection should be enabled to mitigate this issue.
AplazadaBaja (1.1)0.11%—Paloaltonetworks Prisma BrowserAI14/11/20257/10/2026
An insufficient validation of an untrusted input vulnerability in Palo Alto Networks Prisma® Browser allows a locally authenticated non-admin user to revert the browser’s security controls.
AplazadaMedia (6.6)0.56%—Paloaltonetworks Pan-osAIPaloaltonetworks Pa-seriesAIPaloaltonetworks Vm-seriesAIPaloaltonetworks Prisma AccessAI13/11/202517/6/2026
A denial-of-service (DoS) vulnerability in Palo Alto Networks PAN-OS software enables an unauthenticated attacker to reboot a firewall by sending a specially crafted packet through the dataplane. Repeated attempts to initiate a reboot causes the firewall to enter maintenance mode. This issue is applicable to the…
AplazadaMedia (5.3)0.24%—Omnissa Workspace ONE UEMAI12/11/202517/6/2026
Omnissa Workspace ONE UEM contains an observable response discrepancy vulnerability. A malicious actor may be able to enumerate sensitive information such as tenant ID and user accounts that could facilitate brute-force, password-spraying or credential-stuffing attacks.
AplazadaMedia (4.4)0.23%—MembershipworksAI12/11/202517/6/2026
The MembershipWorks – Membership, Events & Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 6.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level…
AplazadaAlta (8.8)0.20%—Amazon Workspaces Client LinuxAI5/11/202517/6/2026
Improper handling of the authentication token in the Amazon WorkSpaces client for Linux, versions 2023.0 through 2024.8, may expose the authentication token for DCV-based WorkSpaces to other local users on the same client machine. Under certain circumstances, a local user may be able to extract another local user's…
AplazadaAlta (7.1)0.25%—Purethemes Workscout-coreAI22/10/20258/10/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in purethemes WorkScout-Core workscout-core allows Reflected XSS.This issue affects WorkScout-Core: from n/a through < 1.7.06.
AplazadaAlta (8.6)0.60%—Ruijienetworks Rg-est300AI16/10/20258/10/2026
Multiple versions of RG-EST300 provided by Ruijie Networks provide SSH server functionality. It is not documented in the manual, and enabled in the initial configuration. Anyone with the knowledge of the related credentials can log in to the affected device, leading to information disclosure, altering the system…
AnalizadaMedia (4.9)0.45%—Arubanetworks Arubaos14/10/20258/10/2026
Arbitrary file download vulnerabilities exist in a low-level interface library in AOS-10 GW and AOS-8 Controller/Mobility Conductor operating systems. Successful exploitation could allow an authenticated malicious actor to download arbitrary files through carefully constructed exploits.
AnalizadaMedia (4.9)0.45%—Arubanetworks Arubaos14/10/20258/10/2026
Arbitrary file download vulnerabilities exist in a low-level interface library in AOS-10 GW and AOS-8 Controller/Mobility Conductor operating systems. Successful exploitation could allow an authenticated malicious actor to download arbitrary files through carefully constructed exploits.
AnalizadaMedia (4.9)0.38%—Arubanetworks Arubaos14/10/20258/10/2026
An arbitrary file download vulnerability exists in the web-based management interface of AOS-10 GW and AOS-8 Controller/Mobility Conductor operating systems. Successful exploitation could allow an Authenticated malicious actor to download arbitrary files through carefully constructed exploits.
AnalizadaMedia (4.9)0.35%—Arubanetworks Arubaos14/10/20258/10/2026
Arbitrary file download vulnerabilities exist in the CLI binary of AOS-10 GW and AOS-8 Controller/Mobility Conductor operating systems. Successful exploitation could allow an authenticated malicious actor to download arbitrary files through carefully constructed exploits.
AnalizadaMedia (4.9)0.35%—Arubanetworks Arubaos14/10/20258/10/2026
Arbitrary file download vulnerabilities exist in the CLI binary of AOS-10 GW and AOS-8 Controller/Mobility Conductor operating systems. Successful exploitation could allow an authenticated malicious actor to download arbitrary files through carefully constructed exploits.