Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
–

91 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.1)0.26%—Prism I.t. Systems Multilevel Referral Affiliate Plugin FOR WoocommerceAI1/12/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Prism I.T. Systems Multilevel Referral Affiliate Plugin for WooCommerce multilevel-referral-plugin-for-woocommerce allows Reflected XSS.This issue affects Multilevel Referral Affiliate Plugin for WooCommerce: from n/a…
AplazadaMedia (6.5)0.50%—Prism IT Systems User Rights Access ManagerAI1/11/202417/6/2026
Access Control vulnerability in Prism IT Systems User Rights Access Manager allows . This issue affects User Rights Access Manager: from n/a through 1.1.2.
AnalizadaMedia (6.9)0.41%—Paloaltonetworks Pan-osPaloaltonetworks GlobalprotectPaloaltonetworks Prisma Access11/9/202417/6/2026
An information exposure vulnerability exists in Palo Alto Networks PAN-OS software that enables a GlobalProtect end user to learn both the configured GlobalProtect uninstall password and the configured disable or disconnect passcode. After the password or passcode is known, end users can uninstall, disable, or…
ModificadaMedia (4.8)0.25%—Paloaltonetworks Prisma Cloud12/6/202417/6/2026
A cross-site scripting (XSS) vulnerability in Palo Alto Networks Prisma Cloud Compute software enables a malicious administrator with add/edit permissions for identity providers to store a JavaScript payload using the web interface on Prisma Cloud Compute. This enables a malicious administrator to perform actions in…
AnalizadaMedia (5)0.35%—Paloaltonetworks Pan-osPaloaltonetworks Prisma Access10/4/202417/6/2026
A vulnerability in the GlobalProtect Gateway in Palo Alto Networks PAN-OS software enables an authenticated attacker to impersonate another user and send network packets to internal assets. However, this vulnerability does not allow the attacker to receive response packets from those internal assets.
AplazadaMedia (5.8)0.31%—Prism IT Systems User Rights Access ManagerAI31/3/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Prism IT Systems User Rights Access Manager allows Reflected XSS.This issue affects User Rights Access Manager: from n/a through 1.1.2.
ModificadaMedia (5.4)0.40%—Prismtechstudios Modern Footnotes20/10/202317/6/2026
The Modern Footnotes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode in versions up to, and including, 1.4.16 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level…
ModificadaMedia (4.8)0.39%—Prismtechstudios Modern Footnotes22/6/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Prism Tech Studios Modern Footnotes plugin <= 1.4.15 versions.
ModificadaAlta (7.8)0.44%—Prismlauncher Prism Launcher6/3/202317/6/2026
An issue in Prism Launcher up to v6.1 allows attackers to perform a directory traversal via importing a crafted .mrpack file.
ModificadaMedia (5.3)0.78%—Ssctech Blue Prism Enterprise26/8/202217/6/2026
An issue was discovered in Blue Prism Enterprise 6.0 through 7.01. In a misconfigured environment that exposes the Blue Prism Application server, it is possible for an authenticated user to reverse engineer the Blue Prism software and circumvent access controls for the UpdateOfflineHelpData administrative function.…
ModificadaAlta (8.1)1.0%—Ssctech Blue Prism Enterprise26/8/202217/6/2026
An issue was discovered in Blue Prism Enterprise 6.0 through 7.01. In a misconfigured environment that exposes the Blue Prism Application server, it is possible for an authenticated user to reverse engineer the Blue Prism software and circumvent access controls for the getChartData administrative function. Using a…
ModificadaAlta (8.8)2.0%—Ssctech Blue Prism25/8/202217/6/2026
An issue was discovered in Blue Prism Enterprise 6.0 through 7.01. In a misconfigured environment that exposes the Blue Prism Application server, it is possible for a domain authenticated user to send a crafted message to the Blue Prism Server and accomplish a remote code execution attack that is possible because of…
ModificadaMedia (5.3)0.78%—Ssctech Blue Prism25/8/202217/6/2026
An issue was discovered in Blue Prism Enterprise 6.0 through 7.01. In a misconfigured environment that exposes the Blue Prism Application server, it is possible for an authenticated user to reverse engineer the Blue Prism software and circumvent access controls for the SetProcessAttributes administrative function.…
ModificadaBaja (3.1)0.69%—Ssctech Blue Prism25/8/202217/6/2026
An issue was discovered in Blue Prism Enterprise 6.0 through 7.01. In a misconfigured environment that exposes the Blue Prism Application server, it is possible for an authenticated user to reverse engineer the Blue Prism software and circumvent access controls for an administrative function. If credential access is…
ModificadaMedia (5.3)0.86%—Ssctech Blue Prism25/8/202217/6/2026
An issue was discovered in Blue Prism Enterprise 6.0 through 7.01. In a misconfigured environment that exposes the Blue Prism Application server, it is possible for an authenticated user to reverse engineer the Blue Prism software and circumvent access controls for the setValidationInfo administrative function.…
ModificadaAlta (7.1)0.94%—Ssctech Blue Prism25/8/202217/6/2026
An issue was discovered in Blue Prism Enterprise 6.0 through 7.01. In a misconfigured environment that exposes the Blue Prism Application server, it is possible for an authenticated user to reverse engineer the Blue Prism software and circumvent access controls for unintended functionality. An attacker can abuse the…
ModificadaMedia (6.1)1.5%—Prismjs Prism18/2/202217/6/2026
Prism is a syntax highlighting library. Starting with version 1.14.0 and prior to version 1.27.0, Prism's command line plugin can be used by attackers to achieve a cross-site scripting attack. The command line plugin did not properly escape its output, leading to the input text being inserted into the DOM as HTML…
ModificadaMedia (6.5)0.66%—Paloaltonetworks Pan-osPaloaltonetworks Prisma Access10/2/202217/6/2026
PAN-OS software provides options to exclude specific websites from URL category enforcement and those websites are blocked or allowed (depending on your rules) regardless of their associated URL category. This is done by creating a custom URL category list or by using an external dynamic list (EDL) in a URL Filtering…
ModificadaAlta (7.2)0.86%—Paloaltonetworks Prisma AccessPaloaltonetworks Pan-os10/11/202117/6/2026
An OS command injection vulnerability in the Palo Alto Networks PAN-OS command line interface (CLI) enables an authenticated administrator with access to the CLI to execute arbitrary OS commands to escalate privileges. This issue impacts: PAN-OS 8.1 versions earlier than PAN-OS 8.1.20-h1; PAN-OS 9.0 versions earlier…
ModificadaAlta (8.1)33%💥 PoCPaloaltonetworks Prisma AccessPaloaltonetworks Pan-os10/11/202117/6/2026
An OS command injection vulnerability in the Simple Certificate Enrollment Protocol (SCEP) feature of PAN-OS software allows an unauthenticated network-based attacker with specific knowledge of the firewall configuration to execute arbitrary code with root user privileges. The attacker must have network access to the…
ModificadaMedia (6.5)1.0%—Prismjs Prism15/9/202117/6/2026
prism is vulnerable to Inefficient Regular Expression Complexity
ModificadaMedia (4.8)0.63%—Paloaltonetworks Prisma Cloud15/7/202117/6/2026
A reflected cross-site scripting (XSS) vulnerability exists in the Prisma Cloud Compute web console that enables a remote attacker to execute arbitrary JavaScript code in the browser-based web console while an authenticated administrator is using that web interface. Prisma Cloud Compute SaaS versions were…
ModificadaMedia (6.1)1.7%💥 ExploitPlugin-planet Prismatic12/7/202117/6/2026
The Prismatic WordPress plugin before 2.8 does not escape the 'tab' GET parameter before outputting it back in an attribute, leading to a reflected Cross-Site Scripting issue which will be executed in the context of a logged in administrator
ModificadaMedia (5.4)0.62%—Plugin-planet Prismatic12/7/202117/6/2026
The Prismatic WordPress plugin before 2.8 does not sanitise or validate some of its shortcode parameters, allowing users with a role as low as Contributor to set Cross-Site payload in them. A post made by a contributor would still have to be approved by an admin to have the XSS trigger able in the frontend, however,…
ModificadaMedia (6.5)1.4%—Prismjs PrismOracle Application Express28/6/202117/6/2026
Prism is a syntax highlighting library. Some languages before 1.24.0 are vulnerable to Regular Expression Denial of Service (ReDoS). When Prism is used to highlight untrusted (user-given) text, an attacker can craft a string that will take a very very long time to highlight. This problem has been fixed in Prism v1.24.…
Orbitaley — Vulnerabilidades