Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
567 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.4) | 0.39% | — | Lopalopa E-learning Management System | 14/11/2024 | 17/6/2026 | A Stored Cross-Site Scripting (XSS) vulnerability was found in /admin/calendar_of_events.php in KASHIPARA E-learning Management System Project 1.0. This vulnerability allows remote attackers to execute arbitrary scripts via the date_start, date_end, and title parameters. | |
| Analizada | Media (5.4) | 0.43% | — | Lopalopa E-learning Management System | 14/11/2024 | 17/6/2026 | A Stored Cross-Site Scripting (XSS) vulnerability was found in /admin/class.php in KASHIPARA E-learning Management System Project 1.0. This vulnerability allows remote attackers to execute arbitrary scripts via the class_name parameter. | |
| Analizada | Media (5.4) | 0.39% | — | Lopalopa E-learning Management System | 14/11/2024 | 17/6/2026 | A Stored Cross-Site Scripting (XSS) vulnerability was found in /admin/add_subject.php in KASHIPARA E-learning Management System Project 1.0. This vulnerability allows remote attackers to execute arbitrary scripts via the subject_code and title parameters. | |
| Aplazada | Alta (8.7) | 0.43% | — | Paloaltonetworks Pan-osAI | 14/11/2024 | 17/6/2026 | A null pointer dereference in Palo Alto Networks PAN-OS software on PA-800 Series, PA-3200 Series, PA-5200 Series, and PA-7000 Series hardware platforms when Decryption policy is enabled allows an unauthenticated attacker to crash PAN-OS by sending specific traffic through the data plane, resulting in a denial of… | |
| Analizada | Media (4.6) | 0.34% | — | Paloaltonetworks Pan-os | 14/11/2024 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software enables an authenticated read-write Panorama administrator to push a specially crafted configuration to a PAN-OS node. This enables impersonation of a legitimate PAN-OS administrator who can perform restricted actions on the PAN-OS node… | |
| Analizada | Media (5.1) | 0.34% | — | Paloaltonetworks Pan-os | 14/11/2024 | 17/6/2026 | A blind XML External Entities (XXE) injection vulnerability in the Palo Alto Networks PAN-OS software enables an authenticated attacker to exfiltrate arbitrary files from firewalls to an attacker controlled server. This attack requires network access to the firewall management interface. | |
| Analizada | Media (5.3) | 0.18% | — | Paloaltonetworks Pan-os | 14/11/2024 | 17/6/2026 | An improper certificate validation vulnerability in Palo Alto Networks PAN-OS software enables an authorized user with a specially crafted client certificate to connect to an impacted GlobalProtect portal or GlobalProtect gateway as a different legitimate user. This attack is possible only if you "Allow Authentication… | |
| Analizada | Baja (2.1) | 0.47% | — | Paloaltonetworks Pan-os | 14/11/2024 | 17/6/2026 | A server-side request forgery in PAN-OS software enables an authenticated attacker with administrative privileges to use the administrative web interface as a proxy, which enables the attacker to view internal network resources not otherwise accessible. | |
| Analizada | Media (6.8) | 0.47% | — | Paloaltonetworks Pan-os | 14/11/2024 | 17/6/2026 | A command injection vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to bypass system restrictions in the management plane and delete files on the firewall. | |
| Analizada | Alta (8.7) | 0.48% | — | Paloaltonetworks Pan-os | 14/11/2024 | 17/6/2026 | A null pointer dereference vulnerability in Palo Alto Networks PAN-OS software enables an unauthenticated attacker to stop a core system service on the firewall by sending a crafted packet through the data plane that causes a denial of service (DoS) condition. Repeated attempts to trigger this condition result in the… | |
| Analizada | Alta (8.7) | 0.51% | — | Paloaltonetworks Pan-os | 14/11/2024 | 17/6/2026 | A null pointer dereference vulnerability in the GlobalProtect gateway in Palo Alto Networks PAN-OS software enables an unauthenticated attacker to stop the GlobalProtect service on the firewall by sending a specially crafted packet that causes a denial of service (DoS) condition. Repeated attempts to trigger this… | |
| Modificada | Media (5.2) | 0.29% | — | Paloaltonetworks Globalprotect | 9/10/2024 | 17/6/2026 | A privilege escalation vulnerability in the Palo Alto Networks GlobalProtect app on Windows allows a locally authenticated non-administrative Windows user to escalate their privileges to NT AUTHORITY/SYSTEM through the use of the repair functionality offered by the .msi file used to install GlobalProtect. | |
| Analizada | Media (5.1) | 0.29% | — | Paloaltonetworks Pan-os | 9/10/2024 | 17/6/2026 | A privilege escalation (PE) vulnerability in the XML API of Palo Alto Networks PAN-OS software enables an authenticated PAN-OS administrator with restricted privileges to use a compromised XML API key to perform actions as a higher privileged PAN-OS administrator. For example, an administrator with "Virtual system… | |
| Aplazada | Media (5.3) | 0.38% | — | Paloaltonetworks Cortex XsoarAI | 9/10/2024 | 17/6/2026 | A vulnerability in Cortex XSOAR allows the disclosure of incident data to users who do not have the privilege to view the data. | |
| Analizada | Media (5.7) | 0.21% | — | Paloaltonetworks Cortex XDR Agent | 9/10/2024 | 17/6/2026 | A problem with a detection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices enables a user with Windows non-administrative privileges to disable the agent. This issue may be leveraged by malware to disable the Cortex XDR agent and then to perform malicious activity. | |
| Analizada | Alta (8.2) | 0.41% | — | Paloaltonetworks Pan-os | 9/10/2024 | 17/6/2026 | A memory corruption vulnerability in Palo Alto Networks PAN-OS software allows an unauthenticated attacker to crash PAN-OS due to a crafted packet through the data plane, resulting in a denial of service (DoS) condition. Repeated attempts to trigger this condition will result in PAN-OS entering maintenance mode. | |
| Analizada | Alta (7) | 0.67% | — | Paloaltonetworks Expedition | 9/10/2024 | 17/6/2026 | A reflected XSS vulnerability in Palo Alto Networks Expedition enables execution of malicious JavaScript in the context of an authenticated Expedition user's browser if that user clicks on a malicious link, allowing phishing attacks that could lead to Expedition browser session theft. | |
| Modificada | Alta (8.2) | 14% | 💥 PoC | Paloaltonetworks Expedition | 9/10/2024 | 17/6/2026 | A cleartext storage of sensitive information vulnerability in Palo Alto Networks Expedition allows an authenticated attacker to reveal firewall usernames, passwords, and API keys generated using those credentials. | |
| Analizada | Crítica (9.2) | 100% | ⚠ Explotación activa💥 Exploit | Paloaltonetworks Expedition | 9/10/2024 | 17/6/2026 | An SQL injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to reveal Expedition database contents, such as password hashes, usernames, device configurations, and device API keys. With this, attackers can also create and read arbitrary files on the Expedition system. | |
| Modificada | Crítica (9.3) | 83% | 💥 PoC | Paloaltonetworks Expedition | 9/10/2024 | 17/6/2026 | An OS command injection vulnerability in Palo Alto Networks Expedition allows an authenticated attacker to run arbitrary OS commands as root in Expedition, resulting in disclosure of usernames, cleartext passwords, device configurations, and device API keys of PAN-OS firewalls. | |
| Analizada | Crítica (9.9) | 99% | ⚠ Explotación activa💥 Exploit | Paloaltonetworks Expedition | 9/10/2024 | 17/6/2026 | An OS command injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to run arbitrary OS commands as root in Expedition, resulting in disclosure of usernames, cleartext passwords, device configurations, and device API keys of PAN-OS firewalls. | |
| Analizada | Crítica (9.8) | 0.56% | — | Lopalopa Music Management System | 25/9/2024 | 17/6/2026 | An Incorrect Access Control vulnerability was found in /music/ajax.php?action=delete_playlist in Kashipara Music Management System v1.0. This vulnerability allows an unauthenticated attacker to delete the valid music playlist entries. | |
| Analizada | Alta (7.6) | 0.37% | — | Lopalopa Music Management System | 16/9/2024 | 17/6/2026 | An Incorrect Access Control vulnerability was found in /music/index.php?page=user_list and /music/index.php?page=edit_user in Kashipara Music Management System v1.0. This allows a low privileged attacker to take over the administrator account. | |
| Analizada | Media (5.9) | 0.23% | — | Lopalopa Music Management System | 16/9/2024 | 17/6/2026 | An Incorrect Access Control vulnerability was found in /music/ajax.php?action=delete_genre in Kashipara Music Management System v1.0. This vulnerability allows an unauthenticated attacker to delete the valid music genre entries. | |
| Analizada | Media (4.2) | 0.22% | — | Lopalopa Music Management System | 16/9/2024 | 17/6/2026 | An Incorrect Access Control vulnerability was found in /music/view_user.php?id=3 and /music/controller.php?page=edit_user&id=3 in Kashipara Music Management System v1.0. This vulnerability allows an unauthenticated attacker to view valid user details. |