Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2676▼ 422 respecto a la semana anterior
Críticas / altas1295▼ 73 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 274 respecto a la semana anterior
–

83 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.7)0.24%—Paloaltonetworks Cortex XDR Agent11/5/202217/6/2026
A local privilege escalation (PE) vulnerability exists in Palo Alto Networks Cortex XDR agent software on Windows that enables an authenticated local user with file creation privilege in the Windows root directory (such as C:\) to execute a program with elevated privileges. This issue impacts: All versions of the…
ModificadaMedia (5.6)0.50%—XENARM Cortex-r7 FirmwareARM Cortex-r8 FirmwareARM Cortex-a57 Firmware+1813/3/202217/6/2026
Certain Arm Cortex and Neoverse processors through 2022-03-08 do not properly restrict cache speculation, aka Spectre-BHB. An attacker can leverage the shared branch history in the Branch History Buffer (BHB) to influence mispredicted branches. Then, cache allocation can allow the attacker to obtain sensitive…
ModificadaMedia (4.7)0.30%—Amperecomputing Ampere Altra MAX FirmwareAmperecomputing Ampere Altra FirmwareARM Neoverse-e1 FirmwareARM Neoverse-v1 Firmware+1810/3/202217/6/2026
Spectre BHB is a variant of Spectre-v2 in which malicious code uses the shared branch history (stored in the CPU BHB) to influence mispredicted branches in the victim's hardware context. Speculation caused by these mispredicted branches can then potentially be used to cause cache allocation, which can then be used to…
ModificadaMedia (5.4)1.7%—Paloaltonetworks Cortex Xsoar10/2/202217/6/2026
A stored cross-site scripting (XSS) vulnerability in Palo Alto Network Cortex XSOAR web interface enables an authenticated network-based attacker to store a persistent javascript payload that will perform arbitrary actions in the Cortex XSOAR web interface on behalf of authenticated administrators who encounter the…
ModificadaAlta (7.8)0.23%—Paloaltonetworks Cortex XDR Agent12/1/202217/6/2026
A local privilege escalation (PE) vulnerability exists in the Palo Alto Networks Cortex XDR agent that enables an authenticated local user to execute programs with elevated privileges. This issue impacts: Cortex XDR agent 5.0 versions earlier than Cortex XDR agent 5.0.12; Cortex XDR agent 6.1 versions earlier than…
ModificadaAlta (7.3)0.25%—Paloaltonetworks Cortex XDR Agent12/1/202217/6/2026
An untrusted search path vulnerability exists in the Palo Alto Networks Cortex XDR agent that enables a local attacker with file creation privilege in the Windows root directory (such as C:\) to store a program that can then be unintentionally executed by another local user when that user utilizes a Live Terminal…
ModificadaMedia (5.5)0.22%—Paloaltonetworks Cortex XDR Agent12/1/202217/6/2026
A file information exposure vulnerability exists in the Palo Alto Networks Cortex XDR agent that enables a local attacker to read the contents of arbitrary files on the system with elevated privileges when generating a support file. This issue impacts: Cortex XDR agent 5.0 versions earlier than Cortex XDR agent…
ModificadaAlta (7.1)0.24%—Paloaltonetworks Cortex XDR Agent12/1/202217/6/2026
An improper link resolution before file access vulnerability exists in the Palo Alto Networks Cortex XDR agent on Windows platforms that enables a local user to delete arbitrary system files and impact the system integrity or cause a denial of service condition. This issue impacts: Cortex XDR agent 5.0 versions…
ModificadaAlta (8.1)0.58%—Paloaltonetworks Cortex Xsoar8/9/202117/6/2026
An improper verification of cryptographic signature vulnerability exists in Cortex XSOAR SAML authentication that enables an unauthenticated network-based attacker with specific knowledge of the Cortex XSOAR instance to access protected resources and perform unauthorized actions on the Cortex XSOAR server. This issue…
ModificadaMedia (4.3)0.49%—Paloaltonetworks Cortex Xsoar8/9/202117/6/2026
An improper authorization vulnerability in the Palo Alto Networks Cortex XSOAR server enables an authenticated network-based attacker with investigation read permissions to download files from incident investigations of which they are aware but are not a part of. This issue impacts: All Cortex XSOAR 5.5.0 builds;…
ModificadaBaja (3.4)0.30%—ARM Cortex-m33 FirmwareARM Cortex-m35p FirmwareARM Cortex-m55 FirmwareARM China Star-mc1 Firmware23/8/202117/6/2026
Certain Arm products before 2021-08-23 do not properly consider the effect of exceptions on a VLLDM instruction. A Non-secure handler may have read or write access to part of a Secure context. This affects Arm Cortex-M33 r0p0 through r1p0, Arm Cortex-M35P r0, Arm Cortex-M55 r0p0 through r1p0, and Arm China STAR-MC1…
ModificadaMedia (5.3)1.4%—Linuxfoundation Cortex3/8/202117/6/2026
An issue was discovered in Grafana Cortex through 1.9.0. The header value X-Scope-OrgID is used to construct file paths for rules files, and if crafted to conduct directory traversal such as ae ../../sensitive/path/in/deployment pathname, then Cortex will attempt to parse a rules file at that location and include some…
ModificadaAlta (7.8)0.25%—Paloaltonetworks Cortex XDR Agent15/7/202117/6/2026
A local privilege escalation (PE) vulnerability exists in the Palo Alto Networks Cortex XDR agent on Windows platforms that enables an authenticated local Windows user to execute programs with SYSTEM privileges. Exploiting this vulnerability requires the user to have file creation privilege in the Windows root…
ModificadaCrítica (9.8)1.4%—Paloaltonetworks Cortex Xsoar22/6/202117/6/2026
An improper authorization vulnerability in Palo Alto Networks Cortex XSOAR enables a remote unauthenticated attacker with network access to the Cortex XSOAR server to perform unauthorized actions through the REST API. This issue impacts: Cortex XSOAR 6.1.0 builds later than 1016923 and earlier than 1271064; Cortex…
ModificadaAlta (7.8)0.25%—Paloaltonetworks Cortex XDR Agent10/6/202117/6/2026
A local privilege escalation vulnerability exists in the Palo Alto Networks Cortex XDR agent on Windows platforms that enables an authenticated local Windows user to execute programs with SYSTEM privileges. This requires the user to have the privilege to create files in the Windows root directory or to manipulate key…
ModificadaMedia (5.5)0.61%—XENARM Cortex-a72Broadcom Bcm2711Intel Core I7-10700k+49/6/202117/6/2026
Potential floating point value injection in all supported CPU products, in conjunction with software vulnerabilities relating to speculative execution with incorrect floating point results, may cause the use of incorrect data from FPVI and may result in data leakage.
ModificadaMedia (5.5)0.33%—XENARM Cortex-a72Broadcom Bcm2711Intel Core I7-10700k+49/6/202117/6/2026
Potential speculative code store bypass in all supported CPU products, in conjunction with software vulnerabilities relating to speculative execution of overwritten instructions, may cause an incorrect speculation and could result in data leakage.
ModificadaMedia (5.5)0.37%—Linuxfoundation Cortex30/4/202117/6/2026
The Alertmanager in CNCF Cortex before 1.8.1 has a local file disclosure vulnerability when -experimental.alertmanager.enable-api is used. The HTTP basic auth password_file can be used as an attack vector to send any file content via a webhook. The alertmanager templates can be used as an attack vector to send any…
ModificadaMedia (5.1)0.17%—Paloaltonetworks Cortex Xsoar10/3/202117/6/2026
An information exposure through log file vulnerability exists in Cortex XSOAR software where the secrets configured for the SAML single sign-on (SSO) integration can be logged to the '/var/log/demisto/' server logs when testing the integration during setup. This logged information includes the private key and identity…
ModificadaAlta (7.8)0.34%—Paloaltonetworks Cortex XDR Agent9/12/202017/6/2026
A local privilege escalation vulnerability exists in Palo Alto Networks Cortex XDR Agent on the Windows platform that allows an authenticated local Windows user to execute programs with SYSTEM privileges. This requires the user to have the privilege to create files in the Windows root directory. This issue impacts:…
ModificadaMedia (5.5)0.31%—Paloaltonetworks Cortex XDR Agent9/12/202017/6/2026
An improper handling of exceptional conditions vulnerability in Cortex XDR Agent allows a local authenticated Windows user to create files in the software's internal program directory that prevents the Cortex XDR Agent from starting. The exceptional condition is persistent and prevents Cortex XDR Agent from starting…
ModificadaMedia (5.5)0.49%—ARM Cortex-a32 FirmwareARM Cortex-a35 FirmwareARM Cortex-a53 FirmwareARM Cortex-a57 Firmware+48/6/202017/6/2026
Arm Armv8-A core implementations utilizing speculative execution past unconditional changes in control flow may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis, aka "straight-line speculation."
ModificadaAlta (7.7)5.1%—Thehive-project Cortex-analyzers9/5/201917/6/2026
TheHive Project UnshortenLink analyzer before 1.1, included in Cortex-Analyzers before 1.15.2, has SSRF. To exploit the vulnerability, an attacker must create a new analysis, select URL for Data Type, and provide an SSRF payload like "http://127.0.0.1:22" in the Data parameter. The result can be seen in the main…
ModificadaAlta (7.2)1.7%—Thehive-project Cortex21/12/201817/6/2026
An organization administrator can add a super administrator in THEHIVE PROJECT Cortex before 2.1.3 due to the lack of overriding the Role.toString method.
ModificadaMedia (5.6)8.6%—Intel Atom CIntel Atom EIntel Atom X3Intel Atom Z+22110/7/201817/6/2026
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a speculative buffer overflow and side-channel analysis.