Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
–

124 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.66%—Ipandao Editor.md4/4/202317/6/2026
Cross Site Scripting vulnerability found in Pandao Editor.md v.1.5.0 allows a remote attacker to execute arbitrary code via a crafted script in the <iframe>src parameter.
ModificadaMedia (5.5)0.27%—Redpanda13/2/202317/6/2026
Redpanda before 22.3.12 discloses cleartext AWS credentials. The import functionality in the rpk binary logs an AWS Access Key ID and Secret in cleartext to standard output, allowing a local user to view the key in the console, or in Kubernetes logs if stdout output is collected. The fixed versions are 22.3.12,…
ModificadaMedia (5.4)0.84%💥 ExploitPanda Pods Repeater Field Project Panda Pods Repeater Field30/1/202317/6/2026
The Panda Pods Repeater Field WordPress plugin before 1.5.4 does not sanitize and escapes a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against a user having at least Contributor permission.
ModificadaMedia (5.3)0.39%—Jenkins Bigpanda Notifier21/9/202217/6/2026
Jenkins BigPanda Notifier Plugin 1.4.0 and earlier does not mask the BigPanda API key on the global configuration form, increasing the potential for attackers to observe and capture it.
ModificadaMedia (4.3)0.50%—Jenkins Bigpanda Notifier21/9/202217/6/2026
Jenkins BigPanda Notifier Plugin 1.4.0 and earlier stores the BigPanda API key unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system.
ModificadaAlta (7.5)1.7%—Pandatix Go-cvss15/9/202217/6/2026
go-cvss is a Go module to manipulate Common Vulnerability Scoring System (CVSS). In affected versions when a full CVSS v2.0 vector string is parsed using `ParseVector`, an Out-of-Bounds Read is possible due to a lack of tests. The Go module will then panic. The problem is patched in tag `v0.4.0`, by the commit…
ModificadaAlta (7.8)0.37%—Watchguard Panda Antivirus13/1/202217/6/2026
This vulnerability allows local attackers to escalate privileges on affected installations of Panda Security Free Antivirus 20.2.0.0. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the use of named…
ModificadaAlta (7.8)0.26%—Pandasecurity Panda Adaptive Defense 360Pandasecurity Panda Devices Agent23/9/202117/6/2026
DLL hijacking in Panda Agent <=1.16.11 in Panda Security, S.L.U. Panda Adaptive Defense 360 <= 8.0.17 allows attacker to escalate privileges via maliciously crafted DLL file.
ModificadaCrítica (9.8)3.6%—Numfocus Pandas15/5/202017/6/2026
pandas through 1.0.3 can unserialize and execute commands from an untrusted file that is passed to the read_pickle() function, if __reduce__ makes an os.system call. NOTE: third parties dispute this issue because the read_pickle() function is documented as unsafe and it is the user's responsibility to use the function…
ModificadaMedia (6.1)0.79%—Ipandao Editor.md3/8/201917/6/2026
pandao Editor.md 1.5.0 allows XSS via an attribute of an ABBR or SUP element.
ModificadaCrítica (9.8)3.5%—Pandasecurity Panda AntivirusPandasecurity Panda Antivirus PROPandasecurity Panda DomePandasecurity Panda Global Protection+223/5/201917/6/2026
Insecure permissions of the section object Global\PandaDevicesAgentSharedMemory and the event Global\PandaDevicesAgentSharedMemoryChange in Panda products before 18.07.03 allow attackers to queue an event (as an encrypted JSON string) to the system service AgentSvc.exe, which leads to privilege escalation when the…
ModificadaMedia (6.1)0.86%—Ipandao Editor.md13/3/201917/6/2026
Editor.md 1.5.0 has DOM-based XSS via vectors involving the '<EMBED SRC="data:image/svg+xml' substring.
ModificadaMedia (6.1)0.79%—Ipandao Editor.md7/11/201817/6/2026
pandao Editor.md 1.5.0 has DOM XSS via input starting with a "<<" substring, which is mishandled during construction of an A element.
ModificadaMedia (6.1)0.86%—Ipandao Editor.md2/9/201817/6/2026
Pandao Editor.md 1.5.0 allows XSS via crafted attributes of an invalid IMG element.
ModificadaAlta (7.8)0.29%—Pandasecurity Panda Global Protection12/3/201817/6/2026
Panda Global Protection 17.0.1 allows local users to gain privileges or cause a denial of service by impersonating all the pipes through a use of \.\pipe\PSANMSrvcPpal -- an "insecurely created named pipe." Ensures full access to Everyone users group.
ModificadaAlta (7.8)0.33%—Pandasecurity Panda Global Protection12/3/201817/6/2026
Unquoted Windows search path vulnerability in the panda_url_filtering service in Panda Global Protection 17.0.1 allows local users to gain privileges via a malicious artefact.
ModificadaAlta (7.5)1.1%—Pandasecurity Panda Global Protection14/12/201717/6/2026
Panda Global Protection 17.0.1 allows a system crash via a 0xb3702c04 \\.\PSMEMDriver DeviceIoControl request.
ModificadaAlta (7.5)1.1%—Pandasecurity Panda Global Protection14/12/201717/6/2026
Panda Global Protection 17.0.1 allows a system crash via a 0xb3702c44 \\.\PSMEMDriver DeviceIoControl request.
ModificadaCrítica (9.8)3.0%💥 ExploitFoodpanda Clone Project Foodpanda Clone13/12/201717/6/2026
FS Foodpanda Clone 1.0 has SQL Injection via the /food keywords parameter.
ModificadaAlta (7.8)0.74%—Panda Security Panda Antivirus PRO 2015Panda Security Panda Global Protection 2015Panda Security Panda Gold Protection 2015Panda Security Panda Internet Security 201525/7/201717/6/2026
Heap-based buffer overflow in Panda Security Kernel Memory Access Driver 1.0.0.13 allows attackers to execute arbitrary code with kernel privileges via a crafted size input for allocated kernel paged pool and allocated non-paged pool buffers.
ModificadaMedia (5.9)0.66%—Watchguard Panda Mobile Security5/5/201717/6/2026
Acceptance of invalid/self-signed TLS certificates in "Panda Mobile Security" 1.1 for iOS allows a man-in-the-middle and/or physically proximate attacker to silently intercept information sent during the login API call.
ModificadaMedia (5.5)0.45%—Watchguard Panda Antivirus30/4/201717/6/2026
PSKMAD.sys in Panda Free Antivirus 18.0 allows local users to cause a denial of service (BSoD) via a crafted DeviceIoControl request to \\.\PSMEMDriver.
ModificadaAlta (7.8)1.2%💥 ExploitWatchguard Panda Endpoint Administration Agent18/4/201617/6/2026
Panda Endpoint Administration Agent before 7.50.00, as used in Panda Security for Business products for Windows, uses a weak ACL for the Panda Security/WaAgent directory and sub-directories, which allows local users to gain SYSTEM privileges by modifying an executable module.
ModificadaAlta (7.8)0.85%💥 ExploitWatchguard Panda URL Filtering18/4/201617/6/2026
Panda Security URL Filtering before 4.3.1.9 uses a weak ACL for the "Panda Security URL Filtering" directory and installed files, which allows local users to gain SYSTEM privileges by modifying Panda_URL_Filteringb.exe.
ModificadaAlta (7.2)0.57%—Pandasecurity Panda AV PRO 2014Pandasecurity Panda Global Protection 2014Pandasecurity Panda Internet Security 201426/8/201417/6/2026
Heap-based buffer overflow in the PavTPK.sys kernel mode driver of Panda Security 2014 products before hft131306s24_r1 allows local users to gain privileges via a crafted argument to a 0x222008 IOCTL call.