Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2860▼ 336 respecto a la semana anterior
Críticas / altas1383▼ 43 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 214 respecto a la semana anterior
–

100 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)0.38%—IBM Soar Qradar Plugin APP2/2/202417/6/2026
IBM SOAR QRadar Plugin App 1.0 through 5.0.3 could allow an authenticated user to manipulate output written to log files. IBM X-Force ID: 260576.
ModificadaMedia (6.5)1.0%—IBM Soar Qradar Plugin APP2/2/202417/6/2026
IBM SOAR QRadar Plugin App 1.0 through 5.0.3 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 260575.
ModificadaMedia (6.7)0.17%—Paloaltonetworks Cortex Xsoar8/11/202317/6/2026
A local privilege escalation (PE) vulnerability in the Palo Alto Networks Cortex XSOAR engine software running on a Linux operating system enables a local attacker to execute programs with elevated privileges if the attacker has shell access to the engine.
ModificadaAlta (7.8)0.29%—Splunk Soar31/7/202317/6/2026
Splunk SOAR versions lower than 6.1.0 are indirectly affected by a potential vulnerability accessed through the user’s terminal. A third party can send Splunk SOAR a maliciously crafted web request containing special ANSI characters to cause log file poisoning. When a terminal user attempts to view the poisoned logs,…
ModificadaAlta (8.8)1.1%—Fortinet Fortisoar11/4/202317/6/2026
A improper neutralization of special elements used in a template engine vulnerability in Fortinet FortiSOAR 7.3.0 through 7.3.1 allows an authenticated, remote attacker to execute arbitrary code via a crafted payload.
ModificadaAlta (7.2)0.91%—Fortinet Fortisoar7/3/202317/6/2026
A improper access control vulnerability in Fortinet FortiSOAR 7.3.0 - 7.3.1 allows an attacker authenticated on the administrative interface to perform unauthorized actions via crafted HTTP requests.
ModificadaMedia (6.5)1.3%—Paloaltonetworks Cortex XsoarFedoraproject Fedora8/2/202317/6/2026
A file disclosure vulnerability in the Palo Alto Networks Cortex XSOAR server software enables an authenticated user with access to the web interface to read local files from the server.
ModificadaMedia (5.4)0.46%—Fortinet Fortisoar6/12/202217/6/2026
Improper neutralization of input during web page generation [CWE-79] in FortiSOAR 7.0.0 through 7.0.3 and 7.2.0 may allow an authenticated attacker to inject HTML tags via input fields of various components within FortiSOAR.
ModificadaMedia (6.7)0.12%—Paloaltonetworks Cortex Xsoar9/11/202217/6/2026
A local privilege escalation (PE) vulnerability in the Palo Alto Networks Cortex XSOAR engine software running on a Linux operating system allows a local attacker with shell access to the engine to execute programs with elevated privileges.
ModificadaMedia (5.5)0.17%—Fortinet Fortisoar2/11/202217/6/2026
A missing authentication for a critical function vulnerability in Fortinet FortiSOAR 6.4.0 - 6.4.4 and 7.0.0 - 7.0.3 and 7.2.0 allows an attacker to disclose information via logging into the database using a privileged account without a password.
ModificadaAlta (7.2)1.6%—Fortinet Fortisoar9/9/202217/6/2026
An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiSOAR before 7.2.1 allows an authenticated attacker to execute unauthorized code or commands via crafted HTTP GET requests.
ModificadaAlta (8.8)0.84%—Fortinet Fortisoar6/9/202217/6/2026
An improper neutralization of special elements used in a template engine vulnerability [CWE-1336] in FortiSOAR management interface 7.2.0, 7.0.0 through 7.0.3, 6.4.0 through 6.4.4 may allow a remote and authenticated attacker to execute arbitrary code via a crafted payload.
ModificadaAlta (7.8)0.21%—Fortinet Fortisoar6/9/202217/6/2026
An improper privilege management vulnerability [CWE-269] in Fortinet FortiSOAR before 7.2.1 allows a GUI user who has already found a way to modify system files (via another, unrelated and hypothetical exploit) to execute arbitrary Python commands as root.
ModificadaMedia (6.5)0.81%—Fortinet Fortisoar6/9/202217/6/2026
Multiple relative path traversal vulnerabilities [CWE-23] in Fortinet FortiSOAR before 7.2.1 allows an authenticated attacker to write to the underlying filesystem with nginx permissions via crafted HTTP requests.
ModificadaMedia (4.3)0.55%—Paloaltonetworks Cortex Xsoar11/5/202217/6/2026
An improper authorization vulnerability in Palo Alto Network Cortex XSOAR software enables authenticated users in non-Read-Only groups to generate an email report that contains summary information about all incidents in the Cortex XSOAR instance, including incidents to which the user does not have access. This issue…
ModificadaAlta (7.5)1.3%—Fortinet Fortisoar4/5/202217/6/2026
An improper access control in Fortinet FortiSOAR before 7.2.0 allows unauthenticated attackers to access gateway API data via crafted HTTP GET requests.
ModificadaMedia (5.4)1.7%💥 ExploitPaloaltonetworks Cortex Xsoar10/2/202217/6/2026
A stored cross-site scripting (XSS) vulnerability in Palo Alto Network Cortex XSOAR web interface enables an authenticated network-based attacker to store a persistent javascript payload that will perform arbitrary actions in the Cortex XSOAR web interface on behalf of authenticated administrators who encounter the…
ModificadaMedia (5.9)1.3%—IBM Soar20/1/202217/6/2026
IBM Security SOAR V42 and V43could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 203169.
ModificadaAlta (8.1)0.58%—Paloaltonetworks Cortex Xsoar8/9/202117/6/2026
An improper verification of cryptographic signature vulnerability exists in Cortex XSOAR SAML authentication that enables an unauthenticated network-based attacker with specific knowledge of the Cortex XSOAR instance to access protected resources and perform unauthorized actions on the Cortex XSOAR server. This issue…
ModificadaMedia (4.3)0.49%—Paloaltonetworks Cortex Xsoar8/9/202117/6/2026
An improper authorization vulnerability in the Palo Alto Networks Cortex XSOAR server enables an authenticated network-based attacker with investigation read permissions to download files from incident investigations of which they are aware but are not a part of. This issue impacts: All Cortex XSOAR 5.5.0 builds;…
ModificadaCrítica (9.8)1.4%—Paloaltonetworks Cortex Xsoar22/6/202117/6/2026
An improper authorization vulnerability in Palo Alto Networks Cortex XSOAR enables a remote unauthenticated attacker with network access to the Cortex XSOAR server to perform unauthorized actions through the REST API. This issue impacts: Cortex XSOAR 6.1.0 builds later than 1016923 and earlier than 1271064; Cortex…
ModificadaMedia (5.3)0.94%—IBM Soar19/3/202117/6/2026
IBM Resilient SOAR 40 and earlier could disclose sensitive information by allowing a user to enumerate usernames.
ModificadaMedia (5.1)0.17%—Paloaltonetworks Cortex Xsoar10/3/202117/6/2026
An information exposure through log file vulnerability exists in Cortex XSOAR software where the secrets configured for the SAML single sign-on (SSO) integration can be logged to the '/var/log/demisto/' server logs when testing the integration during setup. This logged information includes the private key and identity…
ModificadaAlta (7.5)0.99%—Soarlabs Soarcoin6/6/201817/6/2026
Soar Labs Soar Coin version up to and including git commit 4a2aa71ee21014e2880a3f7aad11091ed6ad434f (latest release as of Sept 2017) contains an intentional backdoor vulnerability in the function zero_fee_transaction() that can result in theft of Soar Coins by the "onlycentralAccount" (Soar Labs) after payment is…
ModificadaAlta (7.5)2.3%💥 ExploitFernando Soares COM Mamboleto12/1/201016/6/2026
PHP remote file inclusion vulnerability in mamboleto.php in the Fernando Soares Mamboleto (com_mamboleto) component 2.0 RC3 for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.
Orbitaley — Vulnerabilidades