Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
91 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.26% | — | Prism I.t. Systems Multilevel Referral Affiliate Plugin FOR WoocommerceAI | 1/12/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Prism I.T. Systems Multilevel Referral Affiliate Plugin for WooCommerce multilevel-referral-plugin-for-woocommerce allows Reflected XSS.This issue affects Multilevel Referral Affiliate Plugin for WooCommerce: from n/a… | |
| Aplazada | Media (6.5) | 0.50% | — | Prism IT Systems User Rights Access ManagerAI | 1/11/2024 | 17/6/2026 | Access Control vulnerability in Prism IT Systems User Rights Access Manager allows . This issue affects User Rights Access Manager: from n/a through 1.1.2. | |
| Analizada | Media (6.9) | 0.41% | — | Paloaltonetworks Pan-osPaloaltonetworks GlobalprotectPaloaltonetworks Prisma Access | 11/9/2024 | 17/6/2026 | An information exposure vulnerability exists in Palo Alto Networks PAN-OS software that enables a GlobalProtect end user to learn both the configured GlobalProtect uninstall password and the configured disable or disconnect passcode. After the password or passcode is known, end users can uninstall, disable, or… | |
| Modificada | Media (4.8) | 0.25% | — | Paloaltonetworks Prisma Cloud | 12/6/2024 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in Palo Alto Networks Prisma Cloud Compute software enables a malicious administrator with add/edit permissions for identity providers to store a JavaScript payload using the web interface on Prisma Cloud Compute. This enables a malicious administrator to perform actions in… | |
| Analizada | Media (5) | 0.35% | — | Paloaltonetworks Pan-osPaloaltonetworks Prisma Access | 10/4/2024 | 17/6/2026 | A vulnerability in the GlobalProtect Gateway in Palo Alto Networks PAN-OS software enables an authenticated attacker to impersonate another user and send network packets to internal assets. However, this vulnerability does not allow the attacker to receive response packets from those internal assets. | |
| Aplazada | Media (5.8) | 0.31% | — | Prism IT Systems User Rights Access ManagerAI | 31/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Prism IT Systems User Rights Access Manager allows Reflected XSS.This issue affects User Rights Access Manager: from n/a through 1.1.2. | |
| Modificada | Media (5.4) | 0.40% | — | Prismtechstudios Modern Footnotes | 20/10/2023 | 17/6/2026 | The Modern Footnotes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode in versions up to, and including, 1.4.16 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level… | |
| Modificada | Media (4.8) | 0.39% | — | Prismtechstudios Modern Footnotes | 22/6/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Prism Tech Studios Modern Footnotes plugin <= 1.4.15 versions. | |
| Modificada | Alta (7.8) | 0.44% | — | Prismlauncher Prism Launcher | 6/3/2023 | 17/6/2026 | An issue in Prism Launcher up to v6.1 allows attackers to perform a directory traversal via importing a crafted .mrpack file. | |
| Modificada | Media (5.3) | 0.78% | — | Ssctech Blue Prism Enterprise | 26/8/2022 | 17/6/2026 | An issue was discovered in Blue Prism Enterprise 6.0 through 7.01. In a misconfigured environment that exposes the Blue Prism Application server, it is possible for an authenticated user to reverse engineer the Blue Prism software and circumvent access controls for the UpdateOfflineHelpData administrative function.… | |
| Modificada | Alta (8.1) | 1.0% | — | Ssctech Blue Prism Enterprise | 26/8/2022 | 17/6/2026 | An issue was discovered in Blue Prism Enterprise 6.0 through 7.01. In a misconfigured environment that exposes the Blue Prism Application server, it is possible for an authenticated user to reverse engineer the Blue Prism software and circumvent access controls for the getChartData administrative function. Using a… | |
| Modificada | Alta (8.8) | 2.0% | — | Ssctech Blue Prism | 25/8/2022 | 17/6/2026 | An issue was discovered in Blue Prism Enterprise 6.0 through 7.01. In a misconfigured environment that exposes the Blue Prism Application server, it is possible for a domain authenticated user to send a crafted message to the Blue Prism Server and accomplish a remote code execution attack that is possible because of… | |
| Modificada | Media (5.3) | 0.78% | — | Ssctech Blue Prism | 25/8/2022 | 17/6/2026 | An issue was discovered in Blue Prism Enterprise 6.0 through 7.01. In a misconfigured environment that exposes the Blue Prism Application server, it is possible for an authenticated user to reverse engineer the Blue Prism software and circumvent access controls for the SetProcessAttributes administrative function.… | |
| Modificada | Baja (3.1) | 0.69% | — | Ssctech Blue Prism | 25/8/2022 | 17/6/2026 | An issue was discovered in Blue Prism Enterprise 6.0 through 7.01. In a misconfigured environment that exposes the Blue Prism Application server, it is possible for an authenticated user to reverse engineer the Blue Prism software and circumvent access controls for an administrative function. If credential access is… | |
| Modificada | Media (5.3) | 0.86% | — | Ssctech Blue Prism | 25/8/2022 | 17/6/2026 | An issue was discovered in Blue Prism Enterprise 6.0 through 7.01. In a misconfigured environment that exposes the Blue Prism Application server, it is possible for an authenticated user to reverse engineer the Blue Prism software and circumvent access controls for the setValidationInfo administrative function.… | |
| Modificada | Alta (7.1) | 0.94% | — | Ssctech Blue Prism | 25/8/2022 | 17/6/2026 | An issue was discovered in Blue Prism Enterprise 6.0 through 7.01. In a misconfigured environment that exposes the Blue Prism Application server, it is possible for an authenticated user to reverse engineer the Blue Prism software and circumvent access controls for unintended functionality. An attacker can abuse the… | |
| Modificada | Media (6.1) | 1.5% | — | Prismjs Prism | 18/2/2022 | 17/6/2026 | Prism is a syntax highlighting library. Starting with version 1.14.0 and prior to version 1.27.0, Prism's command line plugin can be used by attackers to achieve a cross-site scripting attack. The command line plugin did not properly escape its output, leading to the input text being inserted into the DOM as HTML… | |
| Modificada | Media (6.5) | 0.66% | — | Paloaltonetworks Pan-osPaloaltonetworks Prisma Access | 10/2/2022 | 17/6/2026 | PAN-OS software provides options to exclude specific websites from URL category enforcement and those websites are blocked or allowed (depending on your rules) regardless of their associated URL category. This is done by creating a custom URL category list or by using an external dynamic list (EDL) in a URL Filtering… | |
| Modificada | Alta (7.2) | 0.86% | — | Paloaltonetworks Prisma AccessPaloaltonetworks Pan-os | 10/11/2021 | 17/6/2026 | An OS command injection vulnerability in the Palo Alto Networks PAN-OS command line interface (CLI) enables an authenticated administrator with access to the CLI to execute arbitrary OS commands to escalate privileges. This issue impacts: PAN-OS 8.1 versions earlier than PAN-OS 8.1.20-h1; PAN-OS 9.0 versions earlier… | |
| Modificada | Alta (8.1) | 33% | 💥 PoC | Paloaltonetworks Prisma AccessPaloaltonetworks Pan-os | 10/11/2021 | 17/6/2026 | An OS command injection vulnerability in the Simple Certificate Enrollment Protocol (SCEP) feature of PAN-OS software allows an unauthenticated network-based attacker with specific knowledge of the firewall configuration to execute arbitrary code with root user privileges. The attacker must have network access to the… | |
| Modificada | Media (6.5) | 1.0% | — | Prismjs Prism | 15/9/2021 | 17/6/2026 | prism is vulnerable to Inefficient Regular Expression Complexity | |
| Modificada | Media (4.8) | 0.63% | — | Paloaltonetworks Prisma Cloud | 15/7/2021 | 17/6/2026 | A reflected cross-site scripting (XSS) vulnerability exists in the Prisma Cloud Compute web console that enables a remote attacker to execute arbitrary JavaScript code in the browser-based web console while an authenticated administrator is using that web interface. Prisma Cloud Compute SaaS versions were… | |
| Modificada | Media (6.1) | 1.7% | 💥 Exploit | Plugin-planet Prismatic | 12/7/2021 | 17/6/2026 | The Prismatic WordPress plugin before 2.8 does not escape the 'tab' GET parameter before outputting it back in an attribute, leading to a reflected Cross-Site Scripting issue which will be executed in the context of a logged in administrator | |
| Modificada | Media (5.4) | 0.62% | — | Plugin-planet Prismatic | 12/7/2021 | 17/6/2026 | The Prismatic WordPress plugin before 2.8 does not sanitise or validate some of its shortcode parameters, allowing users with a role as low as Contributor to set Cross-Site payload in them. A post made by a contributor would still have to be approved by an admin to have the XSS trigger able in the frontend, however,… | |
| Modificada | Media (6.5) | 1.4% | — | Prismjs PrismOracle Application Express | 28/6/2021 | 17/6/2026 | Prism is a syntax highlighting library. Some languages before 1.24.0 are vulnerable to Regular Expression Denial of Service (ReDoS). When Prism is used to highlight untrusted (user-given) text, an attacker can craft a string that will take a very very long time to highlight. This problem has been fixed in Prism v1.24.… |