Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
257 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 1.0% | — | Paloaltonetworks Pan-os | 3/7/2018 | 17/6/2026 | The PAN-OS session browser in PAN-OS 6.1.20 and earlier, PAN-OS 7.1.16 and earlier, PAN-OS 8.0.9 and earlier, and PAN-OS 8.1.1 and earlier may allow an attacker to inject arbitrary JavaScript or HTML. | |
| Modificada | Media (5.5) | 0.36% | — | Paloaltonetworks Pan-os | 3/7/2018 | 17/6/2026 | The PAN-OS management web interface page in PAN-OS 6.1.20 and earlier, PAN-OS 7.1.16 and earlier, PAN-OS 8.0.8 and earlier, and PAN-OS 8.1.0 may allow an attacker to access the GlobalProtect password hashes of local users via manipulation of the HTML markup. | |
| Modificada | Media (5.5) | 0.43% | — | Paloaltonetworks Pan-os | 3/7/2018 | 17/6/2026 | The PAN-OS management web interface page in PAN-OS 6.1.20 and earlier, PAN-OS 7.1.16 and earlier, PAN-OS 8.0.9 and earlier may allow an attacker to delete files in the system via specific request parameters. | |
| Modificada | Media (6.1) | 1.1% | — | Paloaltonetworks Pan-os | 3/7/2018 | 17/6/2026 | The URL filtering "continue page" hosted by PAN-OS 8.0.10 and earlier may allow an attacker to inject arbitrary JavaScript or HTML via specially crafted URLs. | |
| Modificada | Media (5.9) | 2.4% | — | Paloaltonetworks Pan-os | 10/1/2018 | 17/6/2026 | Palo Alto Networks PAN-OS 6.1, 7.1, and 8.0.x before 8.0.7, when an interface implements SSL decryption with RSA enabled or hosts a GlobalProtect portal or gateway, might allow remote attackers to decrypt TLS ciphertext data by leveraging a Bleichenbacher RSA padding oracle, aka a ROBOT attack. | |
| Modificada | Media (6.1) | 1.1% | — | Paloaltonetworks Pan-os | 10/1/2018 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Captive Portal function in Palo Alto Networks PAN-OS before 8.0.7 allows remote attackers to inject arbitrary web script or HTML by leveraging an unspecified configuration. | |
| Modificada | Media (6.1) | 1.2% | — | Paloaltonetworks Pan-os | 10/1/2018 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.7, when the GlobalProtect gateway or portal is configured, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Analizada | Crítica (9.8) | 98% | ⚠ Explotación activa💥 Exploit | Paloaltonetworks Pan-os | 11/12/2017 | 17/6/2026 | Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 allows remote attackers to execute arbitrary code via vectors involving the management interface. | |
| Modificada | Media (5.3) | 1.7% | — | Paloaltonetworks Pan-os | 11/12/2017 | 17/6/2026 | The configuration file import for applications, spyware and vulnerability objects functionality in the web interface in Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, and 7.1.x before 7.1.14 allows remote attackers to conduct server-side request forgery (SSRF) attacks and consequently obtain sensitive… | |
| Modificada | Alta (7.5) | 2.2% | — | Paloaltonetworks Pan-os | 11/12/2017 | 17/6/2026 | Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.13, and 8.0.x before 8.0.6 allows remote attackers to cause a denial of service via vectors related to the management interface. | |
| Modificada | Crítica (9.8) | 4.9% | — | Paloaltonetworks Pan-os | 11/12/2017 | 17/6/2026 | The web interface packet capture management component in Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 allows remote authenticated users to execute arbitrary code via unspecified vectors. | |
| Modificada | Alta (7.5) | 40% | 💥 PoC | OpensslDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+41 | 13/11/2017 | 17/6/2026 | A denial of service flaw was found in OpenSSL 0.9.8, 1.0.1, 1.0.2 through 1.0.2h, and 1.1.0 in the way the TLS/SSL protocol defined processing of ALERT packets during a connection handshake. A remote attacker could use this flaw to make a TLS/SSL server consume an excessive amount of CPU and fail to accept connections… | |
| Modificada | Crítica (9.8) | 2.5% | — | Paloaltonetworks Pan-os | 7/9/2017 | 17/6/2026 | XML external entity (XXE) vulnerability in the GlobalProtect internal and external gateway interface in Palo Alto Networks PAN-OS before 6.1.18, 7.0.x before 7.0.17, 7.1.x before 7.1.12, and 8.0.x before 8.0.3 allows remote attackers to obtain sensitive information, cause a denial of service, or conduct server-side… | |
| Modificada | Media (6.1) | 1.2% | — | Paloaltonetworks Pan-os | 7/9/2017 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the GlobalProtect internal and external gateway interface in Palo Alto Networks PAN-OS before 6.1.18, 7.0.x before 7.0.17, 7.1.x before 7.1.12, and 8.0.x before 8.0.3 allows remote attackers to inject arbitrary web script or HTML via vectors related to improper request… | |
| Modificada | Media (6.1) | 1.2% | — | Paloaltonetworks Pan-os | 2/8/2017 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the GlobalProtect external interface in Palo Alto Networks PAN-OS before 6.1.18, 7.x before 7.0.16, 7.1.x before 7.1.11, and 8.x before 8.0.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (6.1) | 1.2% | — | Paloaltonetworks Pan-os | 2/8/2017 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the management web interface in Palo Alto Networks PAN-OS before 6.1.18, 7.x before 7.0.16, 7.1.x before 7.1.11, and 8.x before 8.0.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Crítica (9.8) | 6.1% | — | Paloaltonetworks Pan-os | 2/8/2017 | 17/6/2026 | The DNS Proxy in Palo Alto Networks PAN-OS before 6.1.18, 7.x before 7.0.16, 7.1.x before 7.1.11, and 8.x before 8.0.3 allows remote attackers to execute arbitrary code via a crafted domain name. | |
| Modificada | Alta (7.8) | 2.9% | — | Paloaltonetworks Pan-os | 1/6/2017 | 17/6/2026 | Palo Alto Networks Panorama VM Appliance with PAN-OS before 6.0.1 might allow remote attackers to execute arbitrary Python code via a crafted firmware image file. | |
| Modificada | Media (6.5) | 1.2% | — | Paloaltonetworks Pan-os | 2/5/2017 | 17/6/2026 | The Management Web Interface in Palo Alto Networks PAN-OS before 7.1.9 allows remote authenticated users to obtain sensitive information via unspecified request parameters. | |
| Modificada | Crítica (9.8) | 1.8% | — | Paloaltonetworks Pan-os | 29/4/2017 | 17/6/2026 | The GlobalProtect external interface in Palo Alto Networks PAN-OS before 6.1.17, 7.x before 7.0.15, 7.1.x before 7.1.9, and 8.x before 8.0.2 provides different error messages for failed login attempts depending on whether the username exists, which allows remote attackers to enumerate account names and conduct… | |
| Modificada | Media (6.5) | 1.0% | — | Paloaltonetworks Pan-os | 29/4/2017 | 17/6/2026 | The Management Web Interface in Palo Alto Networks PAN-OS before 6.1.17, 7.x before 7.0.15, and 7.1.x before 7.1.9 allows remote authenticated users to obtain sensitive information by leveraging incorrect permission validation, aka PAN-SA-2017-0013 and PAN-70541. | |
| Modificada | Media (6.1) | 0.96% | — | Paloaltonetworks Pan-os | 21/4/2017 | 17/6/2026 | Palo Alto Networks PAN-OS before 7.0.15 has XSS in the GlobalProtect external interface via crafted request parameters, aka PAN-SA-2017-0011 and PAN-70674. | |
| Modificada | Alta (7.8) | 0.54% | — | Paloaltonetworks Pan-os | 14/4/2017 | 17/6/2026 | The Management Web Interface in Palo Alto Networks PAN-OS before 7.1.9 allows remote authenticated users to gain privileges via unspecified request parameters. | |
| Modificada | Media (4.3) | 1.1% | — | Paloaltonetworks Pan-os | 14/4/2017 | 17/6/2026 | The Management Web Interface in Palo Alto Networks PAN-OS before 7.0.14 and 7.1.x before 7.1.9 allows remote attackers to write to export files via unspecified parameters. | |
| Modificada | Media (5.4) | 0.84% | — | Paloaltonetworks Pan-os | 15/3/2017 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Management Web Interface in Palo Alto Networks PAN-OS 5.1, 6.x before 6.1.16, 7.0.x before 7.0.13, and 7.1.x before 7.1.8 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. |