Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
–

6557 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisMedia (4.8)0.22%—Paloaltonetworks Cortex XDR Broker VMAI10/9/202611/9/2026
A privilege escalation vulnerability in Palo Alto Networks Cortex XDR Broker VM enables an authenticated low privileged user with man-in-the-middle (MitM) access to execute code with root privileges on the Broker VM.
Pendiente de análisisBaja (2.4)0.19%💥 PoCPaloaltonetworks Checkov BY Prisma CloudAI10/9/202610/9/2026
A code execution vulnerability in Palo Alto Networks Checkov by Prisma® Cloud can allow arbitrary code execution when Checkov scans a directory that contains an attacker-controlled configuration file.
Pendiente de análisisBaja (1.1)0.82%—Paloaltonetworks Checkov BY Prisma CloudAI10/9/202610/9/2026
An OS command injection vulnerability in Palo Alto Networks Checkov by Prisma® Cloud enables a local user to execute arbitrary commands in the processes running Checkov.
Pendiente de análisisAlta (7.2)0.37%—Paloaltonetworks Pan-osAIPaloaltonetworks Vm-seriesAIPaloaltonetworks Pa-seriesAIPaloaltonetworks PanoramaAI10/9/202611/9/2026
A buffer overflow vulnerability in the XML processing functionality of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to the management web or dataplane interface to cause a denial of service (DoS) condition on VM-Series firewalls or execute arbitrary code with root…
Pendiente de análisisMedia (4)0.45%—Safenet Luna Hardware Security ModuleAIPaloaltonetworks Pan-osAI10/9/202611/9/2026
A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as a root user. To be able to exploit this issue, the user must have access to the PAN-OS CLI and the device must be configured with a Luna Hardware…
Pendiente de análisisBaja (1.1)0.27%—Paloaltonetworks Pan-osAIPaloaltonetworks PanoramaAI10/9/202610/9/2026
A stored cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS® software enables a malicious authenticated administrator to store or execute a JavaScript payload using the web interface. This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and…
Pendiente de análisisMedia (5.9)0.10%—Paloaltonetworks GlobalprotectAI10/9/202611/9/2026
Multiple local privilege escalation vulnerabilities in the Palo Alto Networks GlobalProtect™ app allows a local user to escalate their privileges to NT AUTHORITY\SYSTEM on Windows and root on macOS and Linux. This enables a non-administrative user to execute arbitrary commands with administrative privileges. This…
Pendiente de análisisMedia (5.8)0.10%—Paloaltonetworks Prisma Access AgentAI10/9/202610/9/2026
A vulnerability in the EndPoint Data Loss Prevention (DLP) enforcement of Palo Alto Networks Prisma® Access Agent enables a local user to bypass configured DLP policy enforcement controls and exfiltrate sensitive data. This Prisma Access Agent on macOS, Linux, iOS, Android and Chrome OS is not affected.
Pendiente de análisisMedia (4.3)0.10%—Paloaltonetworks Prisma Access AgentAI10/9/202610/9/2026
An information disclosure vulnerability in the Palo Alto Networks Prisma® Access Agent on Linux enables a local user to access sensitive configuration data and credentials. The Prisma Access Agent on macOS, Windows, iOS, Android and Chrome OS is not affected.
AplazadaAlta (7.5)0.68%—Direct Download FOR WoocommerceAI10/9/202610/9/2026
The Direct Download for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.19 via the (top-level include) function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive…
AplazadaCrítica (9.8)1.0%💥 PoCDrag AND Drop File Upload FOR Elementor FormsAI10/9/202610/9/2026
The Drag and Drop File Upload for Elementor Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.6.0 via the elementor_file_upload function. This is due to insufficient file type validation in the is_file_type_valid() function, which uses the attacker-controlled…
AplazadaAlta (7.7)0.39%—Fortra Goanywhere MFTAI9/9/202610/9/2026
In versions prior to 7.10.2 a path traversal vulnerability in the /attachRemoteFiles endpoint of Fortra's GoAnywhere MFT allows Web Users with both Secure Folders and Secure Mail permissions to escape their sandboxed home directory, achieving arbitrary file read.
AplazadaAlta (7.1)0.47%—Lara DashboardAI9/9/20269/9/2026
Lara Dashboard through 1.3.1 contains a server-side request forgery vulnerability in the POST /api/admin/builder/markdown/fetch endpoint that allows any authenticated user to fetch arbitrary URLs and read the response body. Attackers can read internal HTTP services and cloud metadata including IAM credentials by…
Pendiente de análisisMedia (4.9)0.48%—Redhat Build OF KeycloakAIRedhat KeycloakAI9/9/202616/9/2026
A flaw was found in the key provider component of the keycloak-services library, which is the core engine for the Red Hat Build of Keycloak. The issue occurs because a previous fix for path probing was incomplete, allowing a realm administrator to still submit arbitrary filesystem paths as keystore parameters. This…
AplazadaCrítica (9.9)0.55%—Eclipse AeriosAIKeycloakAIOpenldapAI8/9/20269/9/2026
In the current development version of Eclipse aeriOS, for which no official release has yet been published, the Identity Manager (IdM) deployment included insecure default configurations and credentials for security-sensitive services. The Helm chart exposed the Keycloak service and its PostgreSQL backing database…
Pendiente de análisisMedia (6.3)0.54%—Opensearch DashboardsAI8/9/20269/9/2026
Improper input validation in the Vega expression function implementation in OpenSearch Dashboards allows a remote authenticated actor with dashboard write permissions to execute arbitrary JavaScript in the context of other users' browser sessions by saving a crafted Vega visualization. The checkForFunctionProperty…
AplazadaAlta (8.8)0.67%—CmsimpleAICmsimple CoauthorsAI8/9/20269/9/2026
A code execution vulnerability exists in CMSimple 5.22 in the CoAuthors plugin. An authenticated low-privileged user who can modify page content and provide controlled imported content can trigger server-side execution by referencing crafted external or uploaded text content through the affected content import feature.
AplazadaMedia (6.3)0.37%—PimboardsAI8/9/202611/9/2026
The vulnerability, if exploited, could allow a miscreant to run arbitrary JavaScript code in a browser session of a PIMBoards user who was socially engineered to click on a malicious link.
AplazadaAlta (8.3)0.11%—PimboardsAI8/9/202611/9/2026
The vulnerability, if exploited, could allow a miscreant with read access to PIMBoards project files to reverse engineer PIMBoards users’ app-native passwords through computational brute-forcing of weak hashes, potentially allowing elevation to a PIMBoards administrator user.
AplazadaAlta (8.3)0.15%—PimboardsAI8/9/202611/9/2026
The vulnerability, if exploited, could allow a miscreant with read access to PIMBoards project files to decrypt and view sensitive information.
Pendiente de análisisMedia (5.4)0.23%—Fortinet FortisoarAI8/9/202610/9/2026
A improper access control vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.6, FortiSOAR PaaS 7.5.0 through 7.5.3, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.0 through 7.6.6, FortiSOAR on-premise 7.5.0 through 7.5.3, FortiSOAR on-premise 7.4 all versions,…
AplazadaMedia (6.3)0.69%—Ash-project ASH Authentication Oauth2 ServerAI7/9/20268/9/2026
Improper Authentication vulnerability in ash-project ash_authentication_oauth2_server allows an unauthenticated attacker to register OAuth clients even when Dynamic Client Registration is gated by an initial access token. resolve_secret/3 in AshAuthentication.Oauth2Server (reached through __resolve_secret__!) treated…
AplazadaMedia (6.3)0.66%—Ash-project ASH Authentication Oauth2 ServerAI7/9/20268/9/2026
Server-Side Request Forgery (SSRF) vulnerability in ash-project ash_authentication_oauth2_server allows an attacker who controls a client metadata URL and its DNS to make the server connect to internal or loopback addresses. public_ip?/1 in AshAuthentication.Oauth2Server.CIMD.ReqFetcher enforces the outbound policy…
AplazadaMedia (6.3)0.68%—Ash-project ASH Authentication Oauth2 ServerAI7/9/20268/9/2026
Improper Encoding or Escaping of Output vulnerability in ash-project ash_authentication_oauth2_server allows an unauthenticated attacker to inject arbitrary authentication parameters into the WWW-Authenticate challenge header. BearerPlug and RequireScopePlug built the Bearer resource_metadata="..." challenge by…
AplazadaMedia (6.3)0.66%—Ash-project ASH Authentication Oauth2 ServerAI7/9/20268/9/2026
Use of Cache Containing Sensitive Information vulnerability in ash-project ash_authentication_oauth2_server allows a shared HTTP cache to serve one tenant's OAuth discovery metadata to another tenant's clients. The RFC 8414 and RFC 9728 metadata endpoints in AshAuthentication.Phoenix.Oauth2Server.ProtocolRouter return…