Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
–

567 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.1)0.15%—Opswat Metadefender Endpoint Security SDKAIPaloaltonetworks GlobalprotectAI14/5/202517/6/2026
An incorrect privilege management vulnerability in the OPSWAT MetaDefender Endpoint Security SDK used by the Palo Alto Networks GlobalProtect™ app on Windows devices allows a locally authenticated non-administrative Windows user to escalate their privileges to NT AUTHORITY\SYSTEM. However, execution requires that the…
ModificadaAlta (8.2)0.42%—Paloaltonetworks Pan-os14/5/202517/6/2026
A missing exception check in Palo Alto Networks PAN-OS® software with the web proxy feature enabled allows an unauthenticated attacker to send a burst of maliciously crafted packets that causes the firewall to become unresponsive and eventually reboot. Repeated successful attempts to trigger this condition will cause…
AnalizadaAlta (8.8)0.48%—Lopalopa Online Service Management Portal5/5/202517/6/2026
kashipara Online Service Management Portal V1.0 is vulnerable to SQL Injection in osms/Requester/CheckStatus.php via the checkid parameter.
AnalizadaAlta (8.8)0.48%—Lopalopa Online Service Management Portal5/5/202517/6/2026
kashipara Online Service Management Portal V1.0 is vulnerable to SQL Injection in /osms/Requester/Requesterchangepass.php via the parameter: rPassword.
AnalizadaMedia (5.3)0.40%—Lopalopa Online Service Management Portal5/5/202517/6/2026
A Directory Listing Vulnerability was found in the /osms/Requester/ directory of the Kashipara Online Service Management Portal V1.0.
AplazadaCrítica (9.3)0.18%—Paloaltonetworks Prisma Access BrowserAI11/4/202517/6/2026
An improper exception check in Palo Alto Networks Prisma Access Browser allows a low privileged user to prevent Prisma Access Browser from applying it's Policy Rules. This enables the user to use Prisma Access Browser without any restrictions.
AplazadaMedia (5.9)0.12%—Paloaltonetworks Pan-osAI11/4/202517/6/2026
A vulnerability in the Palo Alto Networks PAN-OS® software enables unlicensed administrators to view clear-text data captured using the packet capture feature https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-admin/monitoring/take-packet-captures/take-a-custom-packet-capture in decrypted HTTP/2 data streams…
AplazadaMedia (6.3)0.56%—Paloaltonetworks Cortex XDR Broker VMAI11/4/202517/6/2026
A command injection vulnerability in the Palo Alto Networks Cortex XDR® Broker VM allows an authenticated user to execute arbitrary OS commands with root privileges on the host operating system running Broker VM.
AplazadaAlta (8.7)0.32%—Paloaltonetworks Pan-osAI11/4/202517/6/2026
A denial-of-service (DoS) vulnerability in the Simple Certificate Enrollment Protocol (SCEP) authentication feature of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker to initiate system reboots using a maliciously crafted packet. Repeated attempts to initiate a reboot causes the firewall to…
AplazadaAlta (7.1)0.57%—Paloaltonetworks Pan-osAIPaloaltonetworks Vm-seriesAI11/4/202517/6/2026
A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as a root user. This issue is only applicable to PAN-OS VM-Series. This issue does not affect firewalls that are already deployed. Cloud NGFW and…
AplazadaAlta (8.3)0.40%—Paloaltonetworks GlobalprotectAIPaloaltonetworks Pan-osAIPaloaltonetworks Prisma AccessAIPaloaltonetworks Cloud NgfwAI11/4/202517/6/2026
When configured using SAML, a session fixation vulnerability in the GlobalProtect™ login enables an attacker to impersonate a legitimate authorized user and perform actions as that GlobalProtect user. This requires the legitimate user to first click on a malicious link provided by the attacker. The SAML login for the…
AplazadaMedia (6.9)0.42%—Paloaltonetworks Pan-osAI11/4/202517/6/2026
An improper input neutralization vulnerability in the management web interface of the Palo Alto Networks PAN-OS® software enables a malicious authenticated read-write administrator to impersonate another legitimate authenticated PAN-OS administrator. The attacker must have network access to the management web…
AnalizadaMedia (5.1)0.34%—Paloaltonetworks Pan-os11/4/202517/6/2026
An authenticated file deletion vulnerability in the Palo Alto Networks PAN-OS® software enables an authenticated attacker with network access to the management web interface to delete certain files as the “nobody” user; this includes limited logs and configuration files but does not include system files. The attacker…
AplazadaMedia (5.1)0.27%—Paloaltonetworks Prisma Sd-wan IONAI11/4/202517/6/2026
A denial-of-service (DoS) vulnerability in Palo Alto Networks Prisma® SD-WAN ION devices enables an unauthenticated attacker in a network adjacent to a Prisma SD-WAN ION device to disrupt the packet processing capabilities of the device by sending a burst of crafted packets to that device.
AplazadaMedia (6.8)0.17%—Paloaltonetworks Cortex XDRAI11/4/202517/6/2026
A null pointer dereference vulnerability in the Palo Alto Networks Cortex® XDR agent on Windows devices allows a low-privileged local Windows user to crash the agent. Additionally, malware can use this vulnerability to perform malicious activity without Cortex XDR being able to detect it.
AnalizadaAlta (7.1)0.16%—Paloaltonetworks Globalprotect11/4/202517/6/2026
A vulnerability with a privilege management mechanism in the Palo Alto Networks GlobalProtect™ app on Windows devices allows a locally authenticated non-administrative Windows user to escalate their privileges to NT AUTHORITY\SYSTEM. However, execution requires that the local user can also successfully exploit a race…
AnalizadaMedia (6)0.46%—Paloaltonetworks Globalprotect12/3/202517/6/2026
A vulnerability in the Palo Alto Networks GlobalProtect app on Windows allows a remote attacker to run ActiveX controls within the context of an authenticated Windows user. This enables the attacker to run commands as if they are a legitimate authenticated user. However, to exploit this vulnerability, the…
AplazadaAlta (7.1)0.16%💥 PoCPaloaltonetworks GlobalprotectAI12/3/202517/6/2026
A reliance on untrusted input for a security decision in the GlobalProtect app on Windows devices potentially enables a locally authenticated non-administrative Windows user to escalate their privileges to NT AUTHORITY\SYSTEM. GlobalProtect App on macOS, Linux, iOS, Android, Chrome OS and GlobalProtect UWP App are not…
AplazadaMedia (6.8)0.24%—Paloaltonetworks Pan-osAI12/3/202517/6/2026
A Denial of Service (DoS) vulnerability in Palo Alto Networks PAN-OS software causes the firewall to unexpectedly reboot when processing a specially crafted LLDP frame sent by an unauthenticated adjacent attacker. Repeated attempts to initiate this condition causes the firewall to enter maintenance mode. This issue…
AplazadaMedia (6.8)0.19%—Paloaltonetworks Pan-osAI12/3/202517/6/2026
A vulnerability in the Palo Alto Networks PAN-OS software enables an authenticated admin on the PAN-OS CLI to read arbitrary files. The attacker must have network access to the management interface (web, SSH, console, or telnet) and successfully authenticate to exploit this issue. You can greatly reduce the risk of…
AnalizadaAlta (8.2)0.41%—Paloaltonetworks Pan-os12/3/202517/6/2026
A Denial of Service (DoS) vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software enables an unauthenticated attacker to render the service unavailable by sending a large number of specially crafted packets over a period of time. This issue affects both the GlobalProtect portal and the…
AplazadaMedia (6.8)0.20%—Paloaltonetworks Cortex XDRAI20/2/202517/6/2026
A problem with a detection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices enables a user with Windows non-administrative privileges to disable the agent. This vulnerability can also be leveraged by malware to disable the Cortex XDR agent and then perform malicious activity.
AplazadaMedia (5.3)0.26%—Paloaltonetworks Cortex XDR Broker VMAI12/2/202517/6/2026
A problem with the network isolation mechanism of the Palo Alto Networks Cortex XDR Broker VM allows attackers unauthorized access to Docker containers from the host network used by Broker VM. This may allow access to read files sent for analysis and logs transmitted by the Cortex XDR Agent to the Cortex XDR server.
AnalizadaAlta (7.1)2.0%⚠ Explotación activaPaloaltonetworks Pan-os12/2/202517/6/2026
An authenticated file read vulnerability in the Palo Alto Networks PAN-OS software enables an authenticated attacker with network access to the management web interface to read files on the PAN-OS filesystem that are readable by the “nobody” user. You can greatly reduce the risk of this issue by restricting access to…
AplazadaAlta (8.6)1.3%—Paloaltonetworks Pan-osAI12/2/202517/6/2026
A command injection vulnerability in the Palo Alto Networks PAN-OS OpenConfig plugin enables an authenticated administrator with the ability to make gNMI requests to the PAN-OS management web interface to bypass system restrictions and run arbitrary commands. The commands are run as the “__openconfig” user (which has…
Orbitaley — Vulnerabilidades