Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
4192 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.17% | — | Paloaltonetworks Cortex XDR Broker VMAI | 13/8/2025 | 17/6/2026 | A credential management flaw in Palo Alto Networks Cortex XDR® Broker VM causes different Broker VM images to share identical default credentials for internal services. Users knowing these default credentials could access internal services on other Broker VM installations. The attacker must have network access to the… | |
| Aplazada | Media (5.3) | 0.12% | — | Paloaltonetworks GlobalprotectAI | 13/8/2025 | 17/6/2026 | An insufficient certificate validation issue in the Palo Alto Networks GlobalProtect™ app enables attackers to connect the GlobalProtect app to arbitrary servers. This can enable a local non-administrative operating system user or an attacker on the same subnet to install malicious root certificates on the endpoint… | |
| Aplazada | Media (5.6) | 0.12% | — | Paloaltonetworks Pan-osAIPaloaltonetworks Pa-7500AI | 13/8/2025 | 17/6/2026 | A problem with the implementation of the MACsec protocol in Palo Alto Networks PAN-OS® results in the cleartext exposure of the connectivity association key (CAK). This issue is only applicable to PA-7500 Series devices which are in an NGFW cluster. A user who possesses this key can read messages being sent between… | |
| Aplazada | Media (5.9) | 0.16% | — | Paloaltonetworks CheckovAI | 13/8/2025 | 17/6/2026 | A sensitive information disclosure vulnerability in Palo Alto Networks Checkov by Prisma® Cloud can result in the cleartext exposure of Prisma Cloud access keys in Checkov's output. | |
| Aplazada | Media (4.8) | 0.18% | — | Paloaltonetworks CheckovAI | 13/8/2025 | 17/6/2026 | An unsafe deserialization vulnerability in Palo Alto Networks Checkov by Prisma® Cloud allows an authenticated user to execute arbitrary code as a non administrative user by scanning a malicious terraform file when using Checkov in Prisma® Cloud. This issue impacts Checkov 3.0 versions earlier than Checkov 3.2.415. | |
| Analizada | Media (6.9) | 0.50% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+22 | 13/8/2025 | 17/6/2026 | An HTTP/2 implementation flaw allows a denial-of-service (DoS) that uses malformed HTTP/2 control frames in order to break the max concurrent streams limit (HTTP/2 MadeYouReset Attack). Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Aplazada | Alta (8.6) | 3.6% | 💥 Exploit | Nagios XI Network MonitorAI | 5/8/2025 | 16/6/2026 | Nagios XI Network Monitor prior to Graph Explorer component version 1.3 contains a command injection vulnerability in `visApi.php`. An authenticated user can inject system commands via unsanitized parameters such as `host`, resulting in remote code execution. | |
| Modificada | Alta (8.1) | 0.63% | — | Commscope Ruckus Network Director | 4/8/2025 | 17/6/2026 | RUCKUS Network Director (RND) before 4.5 allows spoofing of an administrator JWT by an attacker who knows the hardcoded value of a certain secret key. | |
| Modificada | Media (4.3) | 0.82% | — | Commscope Ruckus Smartzone FirmwareCommscope Ruckus Network Director | 4/8/2025 | 17/6/2026 | RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build allows ../ directory traversal to read files. | |
| Modificada | Alta (8.8) | 2.1% | — | Commscope Ruckus Smartzone FirmwareCommscope Ruckus Network Director | 4/8/2025 | 17/6/2026 | In RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build, OS command injection can occur via an IP address field provided by an authenticated user. | |
| Modificada | Alta (8.8) | 1.8% | — | Commscope Ruckus Smartzone FirmwareCommscope Ruckus Network Director | 4/8/2025 | 17/6/2026 | RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build allows OS command injection via a certain parameter in an API route. | |
| Modificada | Alta (7.5) | 0.34% | — | Commscope Ruckus Network Director | 4/8/2025 | 17/6/2026 | RUCKUS Network Director (RND) before 4.5 stores passwords in a recoverable format. | |
| Modificada | Alta (8.8) | 0.98% | — | Commscope Ruckus Smartzone FirmwareCommscope Ruckus Network Director | 4/8/2025 | 17/6/2026 | Ruckus SmartZone (SZ) before 6.1.2p3 Refresh Build allows authentication bypass via a valid API key and crafted HTTP headers. | |
| Modificada | Alta (8.8) | 0.48% | — | Commscope Ruckus Network Director | 4/8/2025 | 17/6/2026 | RUCKUS Network Director (RND) before 4.5 allows jailed users to obtain root access vis a weak, hardcoded password. | |
| Aplazada | Media (6) | 0.08% | — | HPE Telco Network Function Virtual OrchestratorAI | 31/7/2025 | 17/6/2026 | A vulnerability was discovered in the storage policy for certain sets of encryption keys in the HPE Telco Network Function Virtual Orchestrator. Successful Exploitation could lead to unauthorized parties gaining access to sensitive system information. | |
| Aplazada | Media (6) | 0.15% | — | HPE Telco Network Function Virtual OrchestratorAI | 31/7/2025 | 17/6/2026 | A vulnerability was discovered in the storage policy for certain sets of authentication keys in the HPE Telco Network Function Virtual Orchestrator. Successful Exploitation could lead to unauthorized parties gaining access to sensitive system information. | |
| Aplazada | Media (6) | 0.14% | — | HPE Telco Network Function Virtual OrchestratorAI | 31/7/2025 | 17/6/2026 | A vulnerability was discovered in the storage policy for certain sets of sensitive credential information in the HPE Telco Network Function Virtual Orchestrator. Successful Exploitation could lead to unauthorized parties gaining access to sensitive system information. | |
| Aplazada | Alta (8.8) | 3.0% | — | A10networks AX LoadbalancerAI | 31/7/2025 | 17/6/2026 | A path traversal vulnerability exists in A10 Networks AX Loadbalancer versions 2.6.1-GR1-P5, 2.7.0, and earlier. The vulnerability resides in the handling of the filename parameter in the /xml/downloads endpoint, which fails to properly sanitize user input. An unauthenticated attacker can exploit this flaw by sending… | |
| Aplazada | Crítica (10) | 1.3% | 💥 Exploit | Arraynetworks VapvAIArraynetworks VxagAI | 31/7/2025 | 17/6/2026 | Array Networks vAPV (version 8.3.2.17) and vxAG (version 9.2.0.34) appliances are affected by a privilege escalation vulnerability caused by a combination of hardcoded SSH credentials (or SSH private key) and insecure permissions on a startup script. The devices ship with a default SSH login or a hardcoded DSA private… | |
| Aplazada | Media (6.8) | 0.13% | — | Paloaltonetworks Globalprotect APPAI | 29/7/2025 | 17/6/2026 | An incorrect privilege assignment vulnerability in the Palo Alto Networks GlobalProtect™ App on Linux devices enables a locally authenticated non administrative user to disable the app even if the GlobalProtect app configuration would not normally permit them to do so. The GlobalProtect app on Windows, macOS, iOS,… | |
| Analizada | Media (4.5) | 0.18% | — | IBM Qradar Network Threat Analytics | 22/7/2025 | 17/6/2026 | IBM Security QRadar Network Threat Analytics 1.0.0 through 1.3.1 could allow a privileged user to cause a denial of service due to improper allocation of resources. | |
| Analizada | Media (5.3) | 0.22% | — | Extremenetworks Extremecontrol | 21/7/2025 | 17/6/2026 | In ExtremeControl before 25.5.12, a cross-site scripting (XSS) vulnerability was discovered in a login interface of the affected application. The issue stems from improper handling of user-supplied input within HTML attributes, allowing an attacker to inject script code that may execute in a user's browser under… | |
| Analizada | Media (4.3) | 0.34% | — | Cisco Prime InfrastructureCisco Evolved Programmable Network Manager | 16/7/2025 | 29/6/2026 | A vulnerability in a subset of REST APIs of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, low-privileged, remote attacker to conduct a blind SQL injection attack. This vulnerability is due to insufficient validation of user-supplied input. An attacker… | |
| Aplazada | Alta (7.5) | 0.08% | — | Kaseya Rapid Fire Tools Network DetectiveAI | 16/7/2025 | 17/6/2026 | An issue was discovered in Kaseya Rapid Fire Tools Network Detective through 2.0.16.0. A vulnerability exists in the EncryptionUtil class because symmetric encryption is implemented in a deterministic and non-randomized fashion. The method Encrypt(byte[] clearData) derives both the encryption key and the IV from a… | |
| Aplazada | Alta (8.2) | 0.13% | — | Kaseya Rapid Fire Tools Network DetectiveAI | 16/7/2025 | 17/6/2026 | Kaseya Rapid Fire Tools Network Detective 2.0.16.0 has Unencrypted Credentials (for privileged access) stored in the collector.txt configuration file. |