Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

4192 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaBaja (3.6)0.14%—Linuxfoundation CNI Network Plugins10/12/202517/6/2026
The CNI portmap plugin allows containers to emulate opening a host port, forwarding that traffic to the container. Versions 1.6.0 through 1.8.0 inadvertently forward all traffic with the same destination port as the host port when the portmap plugin is configured with the nftables backend, thus ignoring the…
AnalizadaCrítica (9.8)3.4%⚠ Explotación activaArraynetworks Arrayos AG5/12/202517/6/2026
Array Networks ArrayOS AG before 9.4.5.9 allows command injection, as exploited in the wild in August through December 2025.
AplazadaAlta (8.7)0.43%—R Radio Network FM TransmitterAI4/12/202526/9/2026
R Radio Network FM Transmitter 1.07 allows unauthenticated attackers to access the admin user's password through the system.cgi endpoint, enabling authentication bypass and FM station setup access.
AnalizadaBaja (3.1)0.18%—Medtronic Carelink Network4/12/202525/9/2026
Insecure Direct Object Reference vulnerability in Medtronic CareLink Network which allows an authenticated attacker with access to specific device and user information to submit web requests to an API endpoint that would expose sensitive user information. This issue affects CareLink Network: before December 4, 2025.
AnalizadaMedia (4.1)0.11%—Medtronic Carelink Network4/12/202525/9/2026
Medtronic CareLink Network allows a local attacker with access to log files on an internal API server to view plaintext passwords from errors logged under certain circumstances. This issue affects CareLink Network: before December 4, 2025.
AnalizadaCrítica (9.8)0.33%—Medtronic Carelink Network4/12/202525/9/2026
Medtronic CareLink Network allows an unauthenticated remote attacker to perform a brute force attack on an API endpoint that could be used to determine a valid password under certain circumstances. This issue affects CareLink Network: before December 4, 2025.
AnalizadaMedia (5.3)0.30%—Medtronic Carelink Network4/12/202525/9/2026
Medtronic CareLink Network allows an unauthenticated remote attacker to initiate a request for security questions to an API endpoint that could be used to determine a valid user account. This issue affects CareLink Network: before December 4, 2025.
AplazadaBaja (2.7)0.22%—Splunk Add-on FOR Palo Alto NetworksAI26/11/202517/6/2026
In Splunk Add-on for Palo Alto Networks versions below 2.0.2, the add-on exposes client secrets in plain text in the _internal index during the addition of new “Data Security Accounts“. The vulnerability would require either local access to the log files or administrative access to internal indexes, which by default…
AnalizadaCrítica (9.8)0.53%—Dasannetworks Ds2924 Firmware19/11/202517/6/2026
An authentication bypass issue was discovered in Dasan Switch DS2924 web based interface, firmware versions 1.01.18 and 1.02.00, allowing attackers to gain escalated privileges via storing crafted cookies in the web browser.
AnalizadaAlta (8.8)0.89%—Arubanetworks Arubaos18/11/202517/6/2026
A vulnerability in the command line interface of affected devices could allow an authenticated remote attacker to conduct a command injection attack. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system.
AnalizadaAlta (7.5)0.39%—Arubanetworks Arubaos18/11/202517/6/2026
A vulnerability in the web-based management interface of affected products could allow an unauthenticated remote attacker to cause a denial of service. Successful exploitation could allow an attacker to crash the system, preventing it from rebooting without manual intervention and disrupting network operations.
AnalizadaAlta (7.2)0.99%—Arubanetworks Airwave18/11/202517/6/2026
A command injection vulnerability has been identified in the command line interface of the HPE Aruba Networking Airwave Platform. An authenticated attacker could exploit this vulnerability to execute arbitrary operating system commands with elevated privileges on the underlying operating system.
AnalizadaBaja (2.1)0.35%—Fabian Nero Social Networking Site17/11/20257/10/2026
A vulnerability was found in code-projects Nero Social Networking Site 1.0. The affected element is an unknown function of the file /profilefriends.php. Performing manipulation of the argument ID results in sql injection. The attack may be initiated remotely. The exploit has been made public and could be used.
AnalizadaMedia (5.5)0.44%—Fabian Nero Social Networking Site17/11/20257/10/2026
A flaw has been found in code-projects Nero Social Networking Site 1.0. This issue affects some unknown processing of the file /friendsphoto.php. This manipulation of the argument ID causes sql injection. The attack can be initiated remotely. The exploit has been published and may be used.
AplazadaMedia (4.4)0.09%—Paloaltonetworks Prisma BrowserAI14/11/20257/10/2026
A sensitive information disclosure vulnerability in Palo Alto Networks Prisma® Browser allows a locally authenticated non-admin user to retrieve sensitive data from Prisma Browser. Browser self-protection should be enabled to mitigate this issue.
AplazadaBaja (1.1)0.13%—Paloaltonetworks Prisma BrowserAI14/11/20257/10/2026
An insufficient policy enforcement vulnerability in Palo Alto Networks Prisma® Browser on Windows allows a locally authenticated non-admin user to bypass the screenshot control feature of the browser. Browser self-protection should be enabled to mitigate this issue.
AplazadaBaja (1.1)0.11%—Paloaltonetworks Prisma BrowserAI14/11/20257/10/2026
An insufficient validation of an untrusted input vulnerability in Palo Alto Networks Prisma® Browser allows a locally authenticated non-admin user to revert the browser’s security controls.
AplazadaMedia (6.6)0.56%—Paloaltonetworks Pan-osAIPaloaltonetworks Pa-seriesAIPaloaltonetworks Vm-seriesAIPaloaltonetworks Prisma AccessAI13/11/202517/6/2026
A denial-of-service (DoS) vulnerability in Palo Alto Networks PAN-OS software enables an unauthenticated attacker to reboot a firewall by sending a specially crafted packet through the dataplane. Repeated attempts to initiate a reboot causes the firewall to enter maintenance mode. This issue is applicable to the…
AnalizadaMedia (6.5)0.21%💥 PoCOpensource-socialnetwork Open Source Social Network5/11/202517/6/2026
OSSN (Open Source Social Network) 8.6 is vulnerable to SQL Injection in /action/rtcomments/status via the timestamp parameter.
AnalizadaAlta (7.3)0.29%💥 PoCOpensource-socialnetwork Open Source Social Network3/11/202517/6/2026
Open Source Social Network (OSSN) 8.6 is vulnerable to Cross Site Scripting (XSS) via the parameter param` at endpoint u/administrator/friends.
ModificadaMedia (5.1)0.51%—Nagios Network Analyzer30/10/202517/6/2026
Nagios Network Analyzer versions prior to 2024R1 are vulnerable to cross-site scripting (XSS) via the Percentile Calculator menu. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser.
AnalizadaAlta (8.6)1.4%—Nagios Network Analyzer30/10/20257/10/2026
Nagios Network Analyzer versions prior to 2024R2.0.1 contain a vulnerability in the LDAP certificate management functionality whereby the certificate removal operation fails to apply adequate input sanitation. An authenticated administrator can trigger command execution on the underlying host in the context of the web…
AnalizadaMedia (5.1)0.76%—Nagios Network Analyzer30/10/20257/10/2026
Nagios Network Analyzer versions prior to 2024R1 contain a stored cross-site scripting (XSS) vulnerability in the Source Groups page (percentile calculator menu). An attacker can supply a malicious payload which is stored by the application and later rendered in the context of other users. When a victim views the…
AnalizadaMedia (5.5)0.48%—Fabian Nero Social Networking Site27/10/202517/6/2026
A weakness has been identified in code-projects Nero Social Networking Site 1.0. This affects an unknown part of the file /friendprofile.php. Executing manipulation of the argument ID can lead to sql injection. It is possible to launch the attack remotely. The exploit has been made available to the public and could be…
AnalizadaMedia (5.5)0.48%—Fabian Nero Social Networking Site27/10/202517/6/2026
A security flaw has been discovered in code-projects Nero Social Networking Site 1.0. Affected by this issue is some unknown functionality of the file /deletemessage.php. Performing manipulation of the argument message_id results in sql injection. It is possible to initiate the attack remotely. The exploit has been…