Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
1845 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.2) | 0.41% | — | Paloaltonetworks Pan-os | 9/10/2024 | 17/6/2026 | A memory corruption vulnerability in Palo Alto Networks PAN-OS software allows an unauthenticated attacker to crash PAN-OS due to a crafted packet through the data plane, resulting in a denial of service (DoS) condition. Repeated attempts to trigger this condition will result in PAN-OS entering maintenance mode. | |
| Analizada | Alta (7) | 0.67% | — | Paloaltonetworks Expedition | 9/10/2024 | 17/6/2026 | A reflected XSS vulnerability in Palo Alto Networks Expedition enables execution of malicious JavaScript in the context of an authenticated Expedition user's browser if that user clicks on a malicious link, allowing phishing attacks that could lead to Expedition browser session theft. | |
| Modificada | Alta (8.2) | 14% | 💥 PoC | Paloaltonetworks Expedition | 9/10/2024 | 17/6/2026 | A cleartext storage of sensitive information vulnerability in Palo Alto Networks Expedition allows an authenticated attacker to reveal firewall usernames, passwords, and API keys generated using those credentials. | |
| Analizada | Crítica (9.2) | 100% | ⚠ Explotación activa💥 Exploit | Paloaltonetworks Expedition | 9/10/2024 | 17/6/2026 | An SQL injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to reveal Expedition database contents, such as password hashes, usernames, device configurations, and device API keys. With this, attackers can also create and read arbitrary files on the Expedition system. | |
| Modificada | Crítica (9.3) | 83% | 💥 PoC | Paloaltonetworks Expedition | 9/10/2024 | 17/6/2026 | An OS command injection vulnerability in Palo Alto Networks Expedition allows an authenticated attacker to run arbitrary OS commands as root in Expedition, resulting in disclosure of usernames, cleartext passwords, device configurations, and device API keys of PAN-OS firewalls. | |
| Analizada | Crítica (9.9) | 99% | ⚠ Explotación activa💥 Exploit | Paloaltonetworks Expedition | 9/10/2024 | 17/6/2026 | An OS command injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to run arbitrary OS commands as root in Expedition, resulting in disclosure of usernames, cleartext passwords, device configurations, and device API keys of PAN-OS firewalls. | |
| Analizada | Media (6.6) | 0.51% | — | Versa-networks Versa Director | 20/9/2024 | 25/8/2026 | The Versa Director offers REST APIs for orchestration and management. By design, certain APIs, such as the login screen, banner display, and device registration, do not require authentication. However, it was discovered that for Directors directly connected to the Internet, one of these APIs can be exploited by… | |
| Analizada | Media (5.3) | 0.32% | — | Paloaltonetworks Pan-os | 11/9/2024 | 17/6/2026 | A vulnerability in the GlobalProtect portal in Palo Alto Networks PAN-OS software enables a malicious authenticated GlobalProtect user to impersonate another GlobalProtect user. Active GlobalProtect users impersonated by an attacker who is exploiting this vulnerability are disconnected from GlobalProtect. Upon… | |
| Analizada | Media (5.6) | 0.19% | — | Paloaltonetworks Cortex XDR Agent | 11/9/2024 | 17/6/2026 | A problem with a detection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices enables a user with Windows administrator privileges to disable the agent. This issue may be leveraged by malware to disable the Cortex XDR agent and then to perform malicious activity. | |
| Aplazada | Media (6) | 0.22% | — | Paloaltonetworks Cortex XsoarAIPaloaltonetworks Cortex XsiamAIApache ActivemqAI | 11/9/2024 | 17/6/2026 | A problem with the ActiveMQ integration for both Cortex XSOAR and Cortex XSIAM can result in the cleartext exposure of the configured ActiveMQ credentials in log bundles. | |
| Analizada | Media (6.7) | 0.24% | — | Paloaltonetworks Pan-os | 11/9/2024 | 17/6/2026 | An improper neutralization of matching symbols vulnerability in the Palo Alto Networks PAN-OS command line interface (CLI) enables authenticated administrators (including read-only administrators) with access to the CLI to to read arbitrary files on the firewall. | |
| Analizada | Media (6.9) | 0.41% | — | Paloaltonetworks Pan-osPaloaltonetworks GlobalprotectPaloaltonetworks Prisma Access | 11/9/2024 | 17/6/2026 | An information exposure vulnerability exists in Palo Alto Networks PAN-OS software that enables a GlobalProtect end user to learn both the configured GlobalProtect uninstall password and the configured disable or disconnect passcode. After the password or passcode is known, end users can uninstall, disable, or… | |
| Analizada | Alta (8.6) | 1.4% | — | Paloaltonetworks Pan-os | 11/9/2024 | 17/6/2026 | A command injection vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as root on the firewall. | |
| Modificada | Media (5.8) | 0.22% | — | Nozominetworks CMCNozominetworks Guardian | 11/9/2024 | 17/6/2026 | An access control vulnerability was discovered in the Reports section due to a specific access restriction not being properly enforced for users with limited privileges. If a logged-in user with reporting privileges learns how to create a specific application request, they might be able to make limited changes to the… | |
| Analizada | Alta (7.2) | 4.0% | ⚠ Explotación activa | Versa-networks Versa Director | 22/8/2024 | 17/6/2026 | The Versa Director GUI provides an option to customize the look and feel of the user interface. This option is only available for a user logged with Provider-Data-Center-Admin or Provider-Data-Center-System-Admin. (Tenant level users do not have this privilege). The “Change Favicon” (Favorite Icon) option can be… | |
| Analizada | Media (6) | 0.25% | — | Paloaltonetworks Pan-os | 14/8/2024 | 17/6/2026 | An information exposure vulnerability in Palo Alto Networks PAN-OS software enables a local system administrator to unintentionally disclose secrets, passwords, and tokens of external systems. A read-only administrator who has access to the config log, can read secrets, passwords, and tokens to external systems. | |
| Analizada | Media (5.2) | 0.21% | — | Paloaltonetworks Globalprotect | 14/8/2024 | 17/6/2026 | A privilege escalation (PE) vulnerability in the Palo Alto Networks GlobalProtect app on Windows devices enables a local user to execute programs with elevated privileges. | |
| Analizada | Alta (7) | 1.2% | — | Paloaltonetworks Cortex Xsoar Commonscripts | 14/8/2024 | 17/6/2026 | A command injection issue in Palo Alto Networks Cortex XSOAR CommonScripts Pack allows an unauthenticated attacker to execute arbitrary commands within the context of an integration container. | |
| Analizada | Media (5.3) | 0.43% | — | Arubanetworks ArubaosHP Instantos | 6/8/2024 | 17/6/2026 | Multiple unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the Soft AP daemon accessed via the PAPI protocol. Successful exploitation of these vulnerabilities results in the ability to interrupt the normal operation of the affected Access Point. | |
| Modificada | Media (5.3) | 0.43% | — | Arubanetworks ArubaosHP Instantos | 6/8/2024 | 17/6/2026 | Multiple unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the Soft AP daemon accessed via the PAPI protocol. Successful exploitation of these vulnerabilities results in the ability to interrupt the normal operation of the affected Access Point. | |
| Modificada | Media (5.3) | 0.43% | — | Arubanetworks ArubaosHP Instantos | 6/8/2024 | 17/6/2026 | Multiple unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the Soft AP daemon accessed via the PAPI protocol. Successful exploitation of these vulnerabilities results in the ability to interrupt the normal operation of the affected Access Point. | |
| Analizada | Crítica (9.8) | 0.39% | — | Arubanetworks ArubaosHP Instantos | 6/8/2024 | 17/6/2026 | There is a vulnerability in the AP Certificate Management Service which could allow a threat actor to execute an unauthenticated RCE attack. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system leading to complete system compromise. | |
| Analizada | Crítica (9.8) | 0.60% | — | Arubanetworks ArubaosHP Instantos | 6/8/2024 | 17/6/2026 | There are vulnerabilities in the Soft AP Daemon Service which could allow a threat actor to execute an unauthenticated RCE attack. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system leading to complete system compromise. | |
| Analizada | Crítica (9.8) | 0.63% | — | Arubanetworks ArubaosHP Instantos | 6/8/2024 | 17/6/2026 | There are vulnerabilities in the Soft AP Daemon Service which could allow a threat actor to execute an unauthenticated RCE attack. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system leading to complete system compromise. | |
| Modificada | Crítica (9.1) | 0.66% | — | Hms-networks Ewon Cosy+ Firmware | 6/8/2024 | 17/6/2026 | A compromised HMS Networks Cosy+ device could be used to request a Certificate Signing Request from Talk2m for another device, resulting in an availability issue. The issue was patched on the Talk2m production server on April 18, 2024. |