Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
–

567 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaBaja (2.4)0.14%—Microsoft 365 DefenderAIPaloaltonetworks Cortex XDRAI12/9/202517/6/2026
A problem with the Palo Alto Networks Cortex XDR Microsoft 365 Defender Pack can result in exposure of user credentials in application logs. Normally, these application logs are only viewable by local users and are included when generating logs for troubleshooting purposes. This means that these credentials are…
AplazadaMedia (5.3)0.17%—Paloaltonetworks Cortex XDR Broker VMAI13/8/202517/6/2026
A credential management flaw in Palo Alto Networks Cortex XDR® Broker VM causes different Broker VM images to share identical default credentials for internal services. Users knowing these default credentials could access internal services on other Broker VM installations. The attacker must have network access to the…
AplazadaMedia (5.3)0.12%—Paloaltonetworks GlobalprotectAI13/8/202517/6/2026
An insufficient certificate validation issue in the Palo Alto Networks GlobalProtect™ app enables attackers to connect the GlobalProtect app to arbitrary servers. This can enable a local non-administrative operating system user or an attacker on the same subnet to install malicious root certificates on the endpoint…
AplazadaMedia (5.6)0.12%—Paloaltonetworks Pan-osAIPaloaltonetworks Pa-7500AI13/8/202517/6/2026
A problem with the implementation of the MACsec protocol in Palo Alto Networks PAN-OS® results in the cleartext exposure of the connectivity association key (CAK). This issue is only applicable to PA-7500 Series devices which are in an NGFW cluster. A user who possesses this key can read messages being sent between…
AplazadaMedia (5.9)0.16%—Paloaltonetworks CheckovAI13/8/202517/6/2026
A sensitive information disclosure vulnerability in Palo Alto Networks Checkov by Prisma® Cloud can result in the cleartext exposure of Prisma Cloud access keys in Checkov's output.
AplazadaMedia (4.8)0.18%—Paloaltonetworks CheckovAI13/8/202517/6/2026
An unsafe deserialization vulnerability in Palo Alto Networks Checkov by Prisma® Cloud allows an authenticated user to execute arbitrary code as a non administrative user by scanning a malicious terraform file when using Checkov in Prisma® Cloud. This issue impacts Checkov 3.0 versions earlier than Checkov 3.2.415.
AplazadaMedia (6.8)0.13%—Paloaltonetworks Globalprotect APPAI29/7/202517/6/2026
An incorrect privilege assignment vulnerability in the Palo Alto Networks GlobalProtect™ App on Linux devices enables a locally authenticated non administrative user to disable the app even if the GlobalProtect app configuration would not normally permit them to do so. The GlobalProtect app on Windows, macOS, iOS,…
AplazadaAlta (8.4)0.17%—Paloaltonetworks Globalprotect APPAI9/7/202517/6/2026
An incorrect privilege assignment vulnerability in the Palo Alto Networks GlobalProtect™ App on enables a locally authenticated non administrative user to escalate their privileges to root on macOS and Linux or NT AUTHORITY\SYSTEM on Windows. The GlobalProtect app on iOS, Android, Chrome OS and GlobalProtect UWP app…
AplazadaMedia (6.8)0.14%—Paloaltonetworks Globalprotect APPAI9/7/202517/6/2026
An incorrect privilege assignment vulnerability in the Palo Alto Networks GlobalProtect™ App on macOS devices enables a locally authenticated non administrative user to disable the app even if the GlobalProtect app configuration would not normally permit them to do so. The GlobalProtect app on Windows, Linux, iOS,…
AplazadaMedia (6.3)0.14%—Paloaltonetworks Autonomous Digital Experience ManagerAI9/7/202517/6/2026
An incorrect privilege assignment vulnerability in Palo Alto Networks Autonomous Digital Experience Manager allows a locally authenticated low privileged user on macOS endpoints to escalate their privileges to root.
AplazadaMedia (6)0.51%—Paloaltonetworks Pan-osAI13/6/202517/6/2026
An information disclosure vulnerability in the SD-WAN feature of Palo Alto Networks PAN-OS® software enables an unauthorized user to view unencrypted data sent from the firewall through the SD-WAN interface. This requires the user to be able to intercept packets sent from the firewall. Cloud NGFW and Prisma® Access…
AnalizadaBaja (1)0.16%—Paloaltonetworks Globalprotect13/6/202517/6/2026
An improper access control vulnerability in the Endpoint Traffic Policy Enforcement https://docs.paloaltonetworks.com/globalprotect/6-0/globalprotect-app-new-features/new-features-released-in-gp-app/endpoint-traffic-policy-enforcement feature of the Palo Alto Networks GlobalProtect™ app allows certain packets to…
AnalizadaAlta (8.5)0.44%—Paloaltonetworks Globalprotect13/6/202517/6/2026
An improper neutralization of wildcards vulnerability in the log collection feature of Palo Alto Networks GlobalProtect™ app on macOS allows a non administrative user to escalate their privileges to root.
AnalizadaAlta (8.6)0.97%—Paloaltonetworks Pan-os13/6/202517/6/2026
A command injection vulnerability in Palo Alto Networks PAN-OS® enables an authenticated administrative user to perform actions as the root user. The attacker must have network access to the management web interface and successfully authenticate to exploit this issue. Cloud NGFW and Prisma Access are not impacted by…
AplazadaAlta (8.4)0.62%—Paloaltonetworks Pan-osAI13/6/202517/6/2026
A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as a root user. To be able to exploit this issue, the user must have access to the PAN-OS CLI. The security risk posed by this issue is significantly…
AplazadaMedia (4.6)0.19%—Paloaltonetworks Cortex XDR BrokerAI13/6/202517/6/2026
An incorrect privilege assignment vulnerability in Palo Alto Networks Cortex® XDR Broker VM allows an authenticated administrative user to execute certain files available within the Broker VM and escalate their privileges to root.
AplazadaMedia (5.1)0.19%—Paloaltonetworks Prisma Access BrowserAI12/6/202517/6/2026
An insufficient implementation of cache vulnerability in Palo Alto Networks Prisma® Access Browser enables users to bypass certain data control policies.
AnalizadaMedia (6.9)0.58%—Lopalopa Responsive Online Learing Platform27/5/202517/6/2026
A vulnerability was found in Kashipara Responsive Online Learing Platform 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /courses/course_detail_user_new.php. The manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The…
AplazadaBaja (2)0.35%—Paloaltonetworks Prisma Cloud Compute EditionAI14/5/202517/6/2026
Web sessions in the web interface of Palo Alto Networks Prisma® Cloud Compute Edition do not expire when users are deleted, which makes Prisma Cloud Compute Edition susceptible to unauthorized access. Compute in Prisma Cloud Enterprise Edition is not affected by this issue.
AplazadaMedia (4.8)0.40%—Paloaltonetworks Pan-osAI14/5/202517/6/2026
An improper input neutralization vulnerability in the management web interface of the Palo Alto Networks PAN-OS® software enables a malicious authenticated read-write administrator to impersonate another legitimate authenticated PAN-OS administrator. The attacker must have network access to the management web…
AplazadaMedia (5.3)0.16%—Paloaltonetworks Pan-osAIPaloaltonetworks Pa-7500AIPaloaltonetworks Pa-5400AIPaloaltonetworks Pa-5400fAI+414/5/202517/6/2026
Using the AES-128-CCM algorithm for IPSec on certain Palo Alto Networks PAN-OS® firewalls (PA-7500, PA-5400, PA-5400f, PA-3400, PA-1600, PA-1400, and PA-400 Series) leads to unencrypted data transfer to devices that are connected to the PAN-OS firewall through IPSec. This issue does not affect Cloud NGFWs, Prisma®…
AnalizadaMedia (5.2)0.13%—Paloaltonetworks Globalprotect14/5/202517/6/2026
An incorrect privilege assignment vulnerability in the Palo Alto Networks GlobalProtect™ App on macOS devices enables a locally authenticated non administrative user to disable the app. The GlobalProtect app on Windows, Linux, iOS, Android, Chrome OS and GlobalProtect UWP app are not affected.
AplazadaMedia (6.5)0.49%—Paloaltonetworks Cortex XDR Broker VMAI14/5/202517/6/2026
A code injection vulnerability in the Palo Alto Networks Cortex XDR® Broker VM allows an authenticated user to execute arbitrary code with root privileges on the host operating system running Broker VM.
AplazadaBaja (2.7)45%💥 ExploitPaloaltonetworks Pan-osAI14/5/202517/6/2026
A reflected cross-site scripting (XSS) vulnerability in the GlobalProtect™ gateway and portal features of Palo Alto Networks PAN-OS® software enables execution of malicious JavaScript in the context of an authenticated Captive Portal user's browser when they click on a specially crafted link. The primary risk is…
AplazadaMedia (6.9)0.44%—Paloaltonetworks Cortex XDR Broker VMAI14/5/202517/6/2026
A missing authentication vulnerability in Palo Alto Networks Cortex XDR® Broker VM allows an unauthenticated user to disable certain internal services on the Broker VM. The attacker must have network access to the Broker VM to exploit this issue.
Orbitaley — Vulnerabilidades