Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
6557 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (4.8) | 0.22% | — | Paloaltonetworks Cortex XDR Broker VMAI | 10/9/2026 | 11/9/2026 | A privilege escalation vulnerability in Palo Alto Networks Cortex XDR Broker VM enables an authenticated low privileged user with man-in-the-middle (MitM) access to execute code with root privileges on the Broker VM. | |
| Pendiente de análisis | Baja (2.4) | 0.19% | 💥 PoC | Paloaltonetworks Checkov BY Prisma CloudAI | 10/9/2026 | 10/9/2026 | A code execution vulnerability in Palo Alto Networks Checkov by Prisma® Cloud can allow arbitrary code execution when Checkov scans a directory that contains an attacker-controlled configuration file. | |
| Pendiente de análisis | Baja (1.1) | 0.82% | — | Paloaltonetworks Checkov BY Prisma CloudAI | 10/9/2026 | 10/9/2026 | An OS command injection vulnerability in Palo Alto Networks Checkov by Prisma® Cloud enables a local user to execute arbitrary commands in the processes running Checkov. | |
| Pendiente de análisis | Alta (7.2) | 0.37% | — | Paloaltonetworks Pan-osAIPaloaltonetworks Vm-seriesAIPaloaltonetworks Pa-seriesAIPaloaltonetworks PanoramaAI | 10/9/2026 | 11/9/2026 | A buffer overflow vulnerability in the XML processing functionality of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to the management web or dataplane interface to cause a denial of service (DoS) condition on VM-Series firewalls or execute arbitrary code with root… | |
| Pendiente de análisis | Media (4) | 0.45% | — | Safenet Luna Hardware Security ModuleAIPaloaltonetworks Pan-osAI | 10/9/2026 | 11/9/2026 | A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as a root user. To be able to exploit this issue, the user must have access to the PAN-OS CLI and the device must be configured with a Luna Hardware… | |
| Pendiente de análisis | Baja (1.1) | 0.27% | — | Paloaltonetworks Pan-osAIPaloaltonetworks PanoramaAI | 10/9/2026 | 10/9/2026 | A stored cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS® software enables a malicious authenticated administrator to store or execute a JavaScript payload using the web interface. This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and… | |
| Pendiente de análisis | Media (5.9) | 0.10% | — | Paloaltonetworks GlobalprotectAI | 10/9/2026 | 11/9/2026 | Multiple local privilege escalation vulnerabilities in the Palo Alto Networks GlobalProtect™ app allows a local user to escalate their privileges to NT AUTHORITY\SYSTEM on Windows and root on macOS and Linux. This enables a non-administrative user to execute arbitrary commands with administrative privileges. This… | |
| Pendiente de análisis | Media (5.8) | 0.10% | — | Paloaltonetworks Prisma Access AgentAI | 10/9/2026 | 10/9/2026 | A vulnerability in the EndPoint Data Loss Prevention (DLP) enforcement of Palo Alto Networks Prisma® Access Agent enables a local user to bypass configured DLP policy enforcement controls and exfiltrate sensitive data. This Prisma Access Agent on macOS, Linux, iOS, Android and Chrome OS is not affected. | |
| Pendiente de análisis | Media (4.3) | 0.10% | — | Paloaltonetworks Prisma Access AgentAI | 10/9/2026 | 10/9/2026 | An information disclosure vulnerability in the Palo Alto Networks Prisma® Access Agent on Linux enables a local user to access sensitive configuration data and credentials. The Prisma Access Agent on macOS, Windows, iOS, Android and Chrome OS is not affected. | |
| Aplazada | Alta (7.5) | 0.68% | — | Direct Download FOR WoocommerceAI | 10/9/2026 | 10/9/2026 | The Direct Download for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.19 via the (top-level include) function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive… | |
| Aplazada | Crítica (9.8) | 1.0% | 💥 PoC | Drag AND Drop File Upload FOR Elementor FormsAI | 10/9/2026 | 10/9/2026 | The Drag and Drop File Upload for Elementor Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.6.0 via the elementor_file_upload function. This is due to insufficient file type validation in the is_file_type_valid() function, which uses the attacker-controlled… | |
| Aplazada | Alta (7.7) | 0.39% | — | Fortra Goanywhere MFTAI | 9/9/2026 | 10/9/2026 | In versions prior to 7.10.2 a path traversal vulnerability in the /attachRemoteFiles endpoint of Fortra's GoAnywhere MFT allows Web Users with both Secure Folders and Secure Mail permissions to escape their sandboxed home directory, achieving arbitrary file read. | |
| Aplazada | Alta (7.1) | 0.47% | — | Lara DashboardAI | 9/9/2026 | 9/9/2026 | Lara Dashboard through 1.3.1 contains a server-side request forgery vulnerability in the POST /api/admin/builder/markdown/fetch endpoint that allows any authenticated user to fetch arbitrary URLs and read the response body. Attackers can read internal HTTP services and cloud metadata including IAM credentials by… | |
| Pendiente de análisis | Media (4.9) | 0.48% | — | Redhat Build OF KeycloakAIRedhat KeycloakAI | 9/9/2026 | 16/9/2026 | A flaw was found in the key provider component of the keycloak-services library, which is the core engine for the Red Hat Build of Keycloak. The issue occurs because a previous fix for path probing was incomplete, allowing a realm administrator to still submit arbitrary filesystem paths as keystore parameters. This… | |
| Aplazada | Crítica (9.9) | 0.55% | — | Eclipse AeriosAIKeycloakAIOpenldapAI | 8/9/2026 | 9/9/2026 | In the current development version of Eclipse aeriOS, for which no official release has yet been published, the Identity Manager (IdM) deployment included insecure default configurations and credentials for security-sensitive services. The Helm chart exposed the Keycloak service and its PostgreSQL backing database… | |
| Pendiente de análisis | Media (6.3) | 0.54% | — | Opensearch DashboardsAI | 8/9/2026 | 9/9/2026 | Improper input validation in the Vega expression function implementation in OpenSearch Dashboards allows a remote authenticated actor with dashboard write permissions to execute arbitrary JavaScript in the context of other users' browser sessions by saving a crafted Vega visualization. The checkForFunctionProperty… | |
| Aplazada | Alta (8.8) | 0.67% | — | CmsimpleAICmsimple CoauthorsAI | 8/9/2026 | 9/9/2026 | A code execution vulnerability exists in CMSimple 5.22 in the CoAuthors plugin. An authenticated low-privileged user who can modify page content and provide controlled imported content can trigger server-side execution by referencing crafted external or uploaded text content through the affected content import feature. | |
| Aplazada | Media (6.3) | 0.37% | — | PimboardsAI | 8/9/2026 | 11/9/2026 | The vulnerability, if exploited, could allow a miscreant to run arbitrary JavaScript code in a browser session of a PIMBoards user who was socially engineered to click on a malicious link. | |
| Aplazada | Alta (8.3) | 0.11% | — | PimboardsAI | 8/9/2026 | 11/9/2026 | The vulnerability, if exploited, could allow a miscreant with read access to PIMBoards project files to reverse engineer PIMBoards users’ app-native passwords through computational brute-forcing of weak hashes, potentially allowing elevation to a PIMBoards administrator user. | |
| Aplazada | Alta (8.3) | 0.15% | — | PimboardsAI | 8/9/2026 | 11/9/2026 | The vulnerability, if exploited, could allow a miscreant with read access to PIMBoards project files to decrypt and view sensitive information. | |
| Pendiente de análisis | Media (5.4) | 0.23% | — | Fortinet FortisoarAI | 8/9/2026 | 10/9/2026 | A improper access control vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.6, FortiSOAR PaaS 7.5.0 through 7.5.3, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.0 through 7.6.6, FortiSOAR on-premise 7.5.0 through 7.5.3, FortiSOAR on-premise 7.4 all versions,… | |
| Aplazada | Media (6.3) | 0.69% | — | Ash-project ASH Authentication Oauth2 ServerAI | 7/9/2026 | 8/9/2026 | Improper Authentication vulnerability in ash-project ash_authentication_oauth2_server allows an unauthenticated attacker to register OAuth clients even when Dynamic Client Registration is gated by an initial access token. resolve_secret/3 in AshAuthentication.Oauth2Server (reached through __resolve_secret__!) treated… | |
| Aplazada | Media (6.3) | 0.66% | — | Ash-project ASH Authentication Oauth2 ServerAI | 7/9/2026 | 8/9/2026 | Server-Side Request Forgery (SSRF) vulnerability in ash-project ash_authentication_oauth2_server allows an attacker who controls a client metadata URL and its DNS to make the server connect to internal or loopback addresses. public_ip?/1 in AshAuthentication.Oauth2Server.CIMD.ReqFetcher enforces the outbound policy… | |
| Aplazada | Media (6.3) | 0.68% | — | Ash-project ASH Authentication Oauth2 ServerAI | 7/9/2026 | 8/9/2026 | Improper Encoding or Escaping of Output vulnerability in ash-project ash_authentication_oauth2_server allows an unauthenticated attacker to inject arbitrary authentication parameters into the WWW-Authenticate challenge header. BearerPlug and RequireScopePlug built the Bearer resource_metadata="..." challenge by… | |
| Aplazada | Media (6.3) | 0.66% | — | Ash-project ASH Authentication Oauth2 ServerAI | 7/9/2026 | 8/9/2026 | Use of Cache Containing Sensitive Information vulnerability in ash-project ash_authentication_oauth2_server allows a shared HTTP cache to serve one tenant's OAuth discovery metadata to another tenant's clients. The RFC 8414 and RFC 9728 metadata endpoints in AshAuthentication.Phoenix.Oauth2Server.ProtocolRouter return… |