Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
100 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.6) | 0.33% | — | Google Security Operations Soar | 9/12/2025 | 30/9/2026 | A vulnerability exists in the SecOps SOAR server. The custom integrations feature allowed an authenticated user with an "IDE role" to achieve Remote Code Execution (RCE) in the server. The flaw stemmed from weak validation of uploaded Python package code. An attacker could upload a package containing a malicious… | |
| Analizada | Alta (7) | 0.45% | — | Fortinet Fortisoar | 14/10/2025 | 17/6/2026 | An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] in FortiSOAR 7.6.0 through 7.6.1, 7.5.0 through 7.5.1, 7.4 all versions, 7.3 all versions may allow an attacker who has already obtained a non-login low privileged shell access (via another hypothetical… | |
| Aplazada | Alta (8.7) | 0.63% | — | Google Secops Soar ServerAI | 11/9/2025 | 17/6/2026 | A Path Traversal vulnerability in the archive extraction component in Google SecOps SOAR Server (versions 6.3.54.0, 6.3.53.2, and all prior versions) allows an authenticated attacker with permissions to import Use Cases to achieve Remote Code Execution (RCE) via uploading a malicious ZIP archive containing path… | |
| Analizada | Alta (7.5) | 0.50% | — | IBM Soar Qradar Plugin APP | 20/8/2025 | 17/6/2026 | IBM QRadar SOAR Plugin App 1.0.0 through 5.6.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. | |
| Analizada | Media (5.4) | 0.20% | — | Fortinet Fortisoar | 12/8/2025 | 17/6/2026 | An Improper neutralization of input during web page generation ('cross-site scripting') vulnerability [CWE-79] in FortiSOAR version 7.6.1 and below, version 7.5.1 and below, 7.4 all versions, 7.3 all versions, 7.2 all versions, 7.0 all versions, 6.4 all versions WEB UI may allow an authenticated remote attacker to… | |
| Analizada | Media (4.9) | 0.40% | — | Fortinet Fortisoar | 12/8/2025 | 17/6/2026 | A relative path traversal vulnerability [CWE-23] in FortiSOAR 7.6.0, 7.5.0 through 7.5.1, 7.4 all versions, 7.3 all versions may allow an authenticated attacker to read arbitrary files via uploading a malicious solution pack. | |
| Analizada | Alta (8.4) | 0.81% | — | Fortinet Fortisoar | 18/3/2025 | 17/6/2026 | An improper control of generation of code ('Code Injection') vulnerability [CWE-94] in FortiSOAR Connector FortiSOAR 7.4 all versions, 7.3 all versions, 7.2 all versions, 7.0 all versions, 6.4 all versions may allow an authenticated attacker to execute arbitrary code on the host via a playbook code snippet. | |
| Modificada | Media (6.1) | 0.45% | — | Fortinet FortiadcFortinet FortiauthenticatorFortinet FortiddosFortinet Fortiddos-f+10 | 22/1/2025 | 17/6/2026 | A externally controlled reference to a resource in another sphere vulnerability in Fortinet allows attacker to poison web caches via crafted HTTP requests, where the `Host` header points to an arbitrary webserver | |
| Analizada | Media (5.4) | 0.46% | — | Fortinet Fortisoar | 14/1/2025 | 17/6/2026 | An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiSOAR 7.3.0 through 7.3.3, 7.2.1 through 7.2.2 may allow an authenticated attacker to perform a stored cross site scripting (XSS) attack via the creation of malicious playbook. | |
| Analizada | Alta (8.8) | 1.1% | — | Fortinet Fortisoar Imap Connector | 14/1/2025 | 17/6/2026 | An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in FortiSOAR IMAP connector version 3.5.7 and below may allow an authenticated attacker to execute unauthorized code or commands via a specifically crafted playbook | |
| Analizada | Alta (8) | 0.58% | — | Fortinet Fortisoar | 14/1/2025 | 17/6/2026 | An improper neutralization of formula elements in a csv file in Fortinet FortiSOAR 7.2.1 through 7.4.1 allows attacker to execute unauthorized code or commands via manipulating csv file | |
| Analizada | Media (5.3) | 0.73% | — | Fortinet ForticlientemsFortinet Fortisoar | 14/1/2025 | 17/6/2026 | An observable response discrepancy vulnerability [CWE-204] in FortiClientEMS 7.4.0, 7.2.0 through 7.2.4, 7.0 all versions, and FortiSOAR 7.5.0, 7.4.0 through 7.4.4, 7.3.0 through 7.3.2, 7.2 all versions, 7.0 all versions, 6.4 all versions may allow an unauthenticated attacker to enumerate valid users via observing… | |
| Aplazada | Media (6.4) | 0.26% | — | Splunk APP FOR SoarAI | 7/1/2025 | 17/6/2026 | In versions 1.0.67 and lower of the Splunk App for SOAR, the Splunk documentation for that app recommended adding the `admin_all_objects` capability to the `splunk_app_soar` role. This addition could lead to improper access control for a low-privileged user that does not hold the "admin" Splunk roles. | |
| Analizada | Alta (8.1) | 0.33% | — | IBM Soar | 14/11/2024 | 17/6/2026 | IBM Security SOAR 51.0.1.0 and earlier contains a mechanism for users to recover or change their passwords without knowing the original password, but the user account must be compromised prior to the weak recovery mechanism. | |
| Analizada | Media (6.4) | 0.28% | — | Logpoint Soar | 7/11/2024 | 17/6/2026 | An issue was discovered in Logpoint before 7.5.0. SOAR uses a static JWT secret key to generate tokens that allow access to SOAR API endpoints without authentication. This static key vulnerability enables attackers to create custom JWT secret keys for unauthorized access to these endpoints. | |
| Aplazada | Media (5.3) | 0.38% | — | Paloaltonetworks Cortex XsoarAI | 9/10/2024 | 17/6/2026 | A vulnerability in Cortex XSOAR allows the disclosure of incident data to users who do not have the privilege to view the data. | |
| Aplazada | Media (6) | 0.22% | — | Paloaltonetworks Cortex XsoarAIPaloaltonetworks Cortex XsiamAIApache ActivemqAI | 11/9/2024 | 17/6/2026 | A problem with the ActiveMQ integration for both Cortex XSOAR and Cortex XSIAM can result in the cleartext exposure of the configured ActiveMQ credentials in log bundles. | |
| Analizada | Alta (7.5) | 0.34% | — | Fortinet Fortisoar | 11/9/2024 | 17/6/2026 | An improper authorization vulnerability [CWE-285] in FortiSOAR version 7.4.0 through 7.4.3, 7.3.0 through 7.3.2, 7.2.0 through 7.2.2, 7.0.0 through 7.0.3 change password endpoint may allow an authenticated attacker to perform a brute force attack on users and administrators password via crafted HTTP requests. | |
| Analizada | Alta (7) | 1.2% | — | Paloaltonetworks Cortex Xsoar Commonscripts | 14/8/2024 | 17/6/2026 | A command injection issue in Palo Alto Networks Cortex XSOAR CommonScripts Pack allows an unauthenticated attacker to execute arbitrary commands within the context of an integration container. | |
| Analizada | Crítica (9) | 0.71% | — | Fortinet Fortisoar | 13/8/2024 | 17/6/2026 | An improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiSOAR 7.3.0 through 7.3.2 allows an authenticated, remote attacker to inject arbitrary web script or HTML via the Communications module. | |
| Analizada | Alta (8.8) | 0.46% | — | IBM Soar | 22/6/2024 | 17/6/2026 | IBM Security SOAR 51.0.2.0 could allow an authenticated user to execute malicious code loaded from a specially crafted script. IBM X-Force ID: 294830. | |
| Aplazada | Alta (8.8) | 0.37% | — | Soar Cloud HR PortalAI | 14/6/2024 | 17/6/2026 | The notification emails sent by Soar Cloud HR Portal contain a link with a embedded session. The expiration of the session is not properly configured, remaining valid for more than 7 days and can be reused. | |
| Analizada | Alta (8.8) | 0.83% | — | Fortinet Fortisoar | 11/6/2024 | 17/6/2026 | Multiple improper neutralization of special elements used in SQL commands ('SQL Injection') vulnerabilities [CWE-89] in FortiSOAR 7.2.0 and before 7.0.3 may allow an authenticated attacker to execute unauthorized code or commands via specifically crafted strings parameters. | |
| Analizada | Media (6.5) | 0.53% | — | Fortinet Fortisoar | 3/6/2024 | 17/6/2026 | An improper removal of sensitive information before storage or transfer vulnerability [CWE-212] in FortiSOAR version 7.3.0, version 7.2.2 and below, version 7.0.3 and below may allow an authenticated low privileged user to read Connector passwords in plain-text via HTTP responses. | |
| Modificada | Alta (8.8) | 0.49% | — | IBM Soar Qradar Plugin APP | 2/2/2024 | 17/6/2026 | IBM SOAR QRadar Plugin App 1.0 through 5.0.3 could allow an authenticated user to perform unauthorized actions due to improper access controls. IBM X-Force ID: 260577. |