Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
–

4192 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.3)0.17%—Paloaltonetworks Cortex XDR Broker VMAI13/8/202517/6/2026
A credential management flaw in Palo Alto Networks Cortex XDR® Broker VM causes different Broker VM images to share identical default credentials for internal services. Users knowing these default credentials could access internal services on other Broker VM installations. The attacker must have network access to the…
AplazadaMedia (5.3)0.12%—Paloaltonetworks GlobalprotectAI13/8/202517/6/2026
An insufficient certificate validation issue in the Palo Alto Networks GlobalProtect™ app enables attackers to connect the GlobalProtect app to arbitrary servers. This can enable a local non-administrative operating system user or an attacker on the same subnet to install malicious root certificates on the endpoint…
AplazadaMedia (5.6)0.12%—Paloaltonetworks Pan-osAIPaloaltonetworks Pa-7500AI13/8/202517/6/2026
A problem with the implementation of the MACsec protocol in Palo Alto Networks PAN-OS® results in the cleartext exposure of the connectivity association key (CAK). This issue is only applicable to PA-7500 Series devices which are in an NGFW cluster. A user who possesses this key can read messages being sent between…
AplazadaMedia (5.9)0.16%—Paloaltonetworks CheckovAI13/8/202517/6/2026
A sensitive information disclosure vulnerability in Palo Alto Networks Checkov by Prisma® Cloud can result in the cleartext exposure of Prisma Cloud access keys in Checkov's output.
AplazadaMedia (4.8)0.18%—Paloaltonetworks CheckovAI13/8/202517/6/2026
An unsafe deserialization vulnerability in Palo Alto Networks Checkov by Prisma® Cloud allows an authenticated user to execute arbitrary code as a non administrative user by scanning a malicious terraform file when using Checkov in Prisma® Cloud. This issue impacts Checkov 3.0 versions earlier than Checkov 3.2.415.
AnalizadaMedia (6.9)0.50%—F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+2213/8/202517/6/2026
An HTTP/2 implementation flaw allows a denial-of-service (DoS) that uses malformed HTTP/2 control frames in order to break the max concurrent streams limit (HTTP/2 MadeYouReset Attack). Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
AplazadaAlta (8.6)3.6%💥 ExploitNagios XI Network MonitorAI5/8/202516/6/2026
Nagios XI Network Monitor prior to Graph Explorer component version 1.3 contains a command injection vulnerability in `visApi.php`. An authenticated user can inject system commands via unsanitized parameters such as `host`, resulting in remote code execution.
ModificadaAlta (8.1)0.63%—Commscope Ruckus Network Director4/8/202517/6/2026
RUCKUS Network Director (RND) before 4.5 allows spoofing of an administrator JWT by an attacker who knows the hardcoded value of a certain secret key.
ModificadaMedia (4.3)0.82%—Commscope Ruckus Smartzone FirmwareCommscope Ruckus Network Director4/8/202517/6/2026
RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build allows ../ directory traversal to read files.
ModificadaAlta (8.8)2.1%—Commscope Ruckus Smartzone FirmwareCommscope Ruckus Network Director4/8/202517/6/2026
In RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build, OS command injection can occur via an IP address field provided by an authenticated user.
ModificadaAlta (8.8)1.8%—Commscope Ruckus Smartzone FirmwareCommscope Ruckus Network Director4/8/202517/6/2026
RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build allows OS command injection via a certain parameter in an API route.
ModificadaAlta (7.5)0.34%—Commscope Ruckus Network Director4/8/202517/6/2026
RUCKUS Network Director (RND) before 4.5 stores passwords in a recoverable format.
ModificadaAlta (8.8)0.98%—Commscope Ruckus Smartzone FirmwareCommscope Ruckus Network Director4/8/202517/6/2026
Ruckus SmartZone (SZ) before 6.1.2p3 Refresh Build allows authentication bypass via a valid API key and crafted HTTP headers.
ModificadaAlta (8.8)0.48%—Commscope Ruckus Network Director4/8/202517/6/2026
RUCKUS Network Director (RND) before 4.5 allows jailed users to obtain root access vis a weak, hardcoded password.
AplazadaMedia (6)0.08%—HPE Telco Network Function Virtual OrchestratorAI31/7/202517/6/2026
A vulnerability was discovered in the storage policy for certain sets of encryption keys in the HPE Telco Network Function Virtual Orchestrator. Successful Exploitation could lead to unauthorized parties gaining access to sensitive system information.
AplazadaMedia (6)0.15%—HPE Telco Network Function Virtual OrchestratorAI31/7/202517/6/2026
A vulnerability was discovered in the storage policy for certain sets of authentication keys in the HPE Telco Network Function Virtual Orchestrator. Successful Exploitation could lead to unauthorized parties gaining access to sensitive system information.
AplazadaMedia (6)0.14%—HPE Telco Network Function Virtual OrchestratorAI31/7/202517/6/2026
A vulnerability was discovered in the storage policy for certain sets of sensitive credential information in the HPE Telco Network Function Virtual Orchestrator. Successful Exploitation could lead to unauthorized parties gaining access to sensitive system information.
AplazadaAlta (8.8)3.0%—A10networks AX LoadbalancerAI31/7/202517/6/2026
A path traversal vulnerability exists in A10 Networks AX Loadbalancer versions 2.6.1-GR1-P5, 2.7.0, and earlier. The vulnerability resides in the handling of the filename parameter in the /xml/downloads endpoint, which fails to properly sanitize user input. An unauthenticated attacker can exploit this flaw by sending…
AplazadaCrítica (10)1.3%💥 ExploitArraynetworks VapvAIArraynetworks VxagAI31/7/202517/6/2026
Array Networks vAPV (version 8.3.2.17) and vxAG (version 9.2.0.34) appliances are affected by a privilege escalation vulnerability caused by a combination of hardcoded SSH credentials (or SSH private key) and insecure permissions on a startup script. The devices ship with a default SSH login or a hardcoded DSA private…
AplazadaMedia (6.8)0.13%—Paloaltonetworks Globalprotect APPAI29/7/202517/6/2026
An incorrect privilege assignment vulnerability in the Palo Alto Networks GlobalProtect™ App on Linux devices enables a locally authenticated non administrative user to disable the app even if the GlobalProtect app configuration would not normally permit them to do so. The GlobalProtect app on Windows, macOS, iOS,…
AnalizadaMedia (4.5)0.18%—IBM Qradar Network Threat Analytics22/7/202517/6/2026
IBM Security QRadar Network Threat Analytics 1.0.0 through 1.3.1 could allow a privileged user to cause a denial of service due to improper allocation of resources.
AnalizadaMedia (5.3)0.22%—Extremenetworks Extremecontrol21/7/202517/6/2026
In ExtremeControl before 25.5.12, a cross-site scripting (XSS) vulnerability was discovered in a login interface of the affected application. The issue stems from improper handling of user-supplied input within HTML attributes, allowing an attacker to inject script code that may execute in a user's browser under…
AnalizadaMedia (4.3)0.34%—Cisco Prime InfrastructureCisco Evolved Programmable Network Manager16/7/202529/6/2026
A vulnerability in a subset of REST APIs of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, low-privileged, remote attacker to conduct a blind SQL injection attack. This vulnerability is due to insufficient validation of user-supplied input. An attacker…
AplazadaAlta (7.5)0.08%—Kaseya Rapid Fire Tools Network DetectiveAI16/7/202517/6/2026
An issue was discovered in Kaseya Rapid Fire Tools Network Detective through 2.0.16.0. A vulnerability exists in the EncryptionUtil class because symmetric encryption is implemented in a deterministic and non-randomized fashion. The method Encrypt(byte[] clearData) derives both the encryption key and the IV from a…
AplazadaAlta (8.2)0.13%—Kaseya Rapid Fire Tools Network DetectiveAI16/7/202517/6/2026
Kaseya Rapid Fire Tools Network Detective 2.0.16.0 has Unencrypted Credentials (for privileged access) stored in the collector.txt configuration file.