Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
52 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.2) | 0.37% | — | Paloaltonetworks Pan-osAIPaloaltonetworks Vm-seriesAIPaloaltonetworks Pa-seriesAIPaloaltonetworks PanoramaAI | 10/9/2026 | 11/9/2026 | A buffer overflow vulnerability in the XML processing functionality of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to the management web or dataplane interface to cause a denial of service (DoS) condition on VM-Series firewalls or execute arbitrary code with root… | |
| Pendiente de análisis | Baja (1.1) | 0.27% | — | Paloaltonetworks Pan-osAIPaloaltonetworks PanoramaAI | 10/9/2026 | 10/9/2026 | A stored cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS® software enables a malicious authenticated administrator to store or execute a JavaScript payload using the web interface. This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and… | |
| Aplazada | Alta (8.2) | 0.41% | — | Kepano DefuddleAI | 21/8/2026 | 30/9/2026 | Defuddle cleans up HTML pages. Prior to 0.19.1, site extractors interpolate page-derived image alt and src values, og:image values, and video descriptions into HTML strings without context-appropriate escaping, and buildExtractorResponse() returns this contentHtml without the main pipeline's DOM-based sanitization.… | |
| Aplazada | Alta (7.5) | 0.43% | — | Panorama Viewer 360 Degree Image AND Video ViewerAI | 26/6/2026 | 26/6/2026 | Contributor Local File Inclusion in Panorama Viewer – 360 Degree Image + Video Viewer <= 1.6.1 versions. | |
| En análisis | Baja (3.3) | 0.19% | — | Codra Panorama Collaborative Operation & ExecutionCodra Panorama COMCodra Panorama E2Codra Panorama H2 | 25/3/2026 | 17/6/2026 | Please refer to security bulletin BS-036, available on the Panorama CSIRT website: https://my.codra.net/en-gb/csirt. | |
| Pendiente de análisis | Alta (7.7) | 0.53% | — | Codra Panorama SuiteAI | 25/3/2026 | 17/6/2026 | Please refer to security bulletin BS-035, available on the Panorama CSIRT website: https://my.codra.net/en-gb/csirt . | |
| Analizada | Baja (2.1) | 0.28% | — | Kepano Defuddle | 7/3/2026 | 17/6/2026 | Defuddle cleans up HTML pages. Prior to version 0.9.0, the _findContentBySchemaText method in src/defuddle.ts interpolates image src and alt attributes directly into an HTML string without escaping. An attacker can use a " in the alt attribute to break out of the attribute context and inject event handler. This issue… | |
| Aplazada | Media (6.1) | 0.29% | — | Wethink Technology INC 720yun Pano-sdkAI | 2/3/2026 | 17/6/2026 | Cross Site Scripting vulnerability in Wethink Technology Inc 720yun pano-sdk 0.5.877 allows a remote attacker to execute arbitrary code via the LoginComp (Module 2093) and SignupComp (Module 2094) modules. | |
| Analizada | Media (6.1) | 0.23% | — | Krpano | 29/11/2025 | 17/6/2026 | Reflected Cross-Site Scripting (rXSS) in krpano before version 1.23.2 allows a remote unauthenticated attacker to execute arbitrary JavaScript in the victim's browser via a crafted URL to the passQueryParameters function with the xml parameter enabled. | |
| Aplazada | Alta (8.6) | 0.44% | — | Akinsoft TaskpanoAI | 4/9/2025 | 17/6/2026 | Improper Restriction of Excessive Authentication Attempts vulnerability in Akinsoft TaskPano allows Authentication Bypass. This issue affects TaskPano: from s1.06.04 before v1.06.06. | |
| Aplazada | Media (4.7) | 0.30% | — | Akinsoft TaskpanoAI | 4/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Akinsoft TaskPano allows Cross-Site Scripting (XSS). This issue affects TaskPano: s1.06.04. | |
| Analizada | Media (4.8) | 0.31% | — | Projectpanorama Panorama | 15/5/2025 | 17/6/2026 | The Panorama WordPress plugin through 1.5.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Aplazada | Media (4.3) | 0.16% | — | Filipstepanov Phees LinkpreviewAI | 24/2/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in filipstepanov Phee's LinkPreview linkpreview allows Cross Site Request Forgery.This issue affects Phee's LinkPreview: from n/a through <= 1.6.7. | |
| Aplazada | Media (6.5) | 0.37% | — | No-nonsense WP Krpano Wp-krpanoAI | 16/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in No-Nonsense WP krpano wp-krpano allows Stored XSS.This issue affects WP krpano: from n/a through <= 1.2.1. | |
| Aplazada | Alta (7.1) | 0.19% | — | WP PanoramioAI | 16/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in ryscript WP Panoramio wp-panoramio allows Stored XSS.This issue affects WP Panoramio: from n/a through <= 1.5.0. | |
| Aplazada | Media (6.5) | 0.23% | — | Andrey Wp-panoAI | 15/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Andrey wp-pano wp-pano allows Stored XSS.This issue affects wp-pano: from n/a through <= 1.17. | |
| Aplazada | Media (5.3) | 0.42% | — | Avirtum Ipanorama 360AI | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in Avirtum iPanorama 360 WordPress Virtual Tour Builder allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects iPanorama 360 WordPress Virtual Tour Builder: from n/a through 1.8.3. | |
| Aplazada | Alta (7.8) | 0.49% | — | Panoramic Corporation Digital Imaging SoftwareAI | 14/5/2024 | 17/6/2026 | An issue in Panoramic Corporation Digital Imaging Software v.9.1.2.7600 allows a local attacker to escalate privileges via the ccsservice.exe component. | |
| Aplazada | Media (5.3) | 0.42% | — | Avirtum Ipanorama 360AI | 3/5/2024 | 17/6/2026 | Missing Authorization vulnerability in Avirtum iPanorama 360 WordPress Virtual Tour Builder.This issue affects iPanorama 360 WordPress Virtual Tour Builder: from n/a through 1.8.1. | |
| Aplazada | Media (4.3) | 0.37% | — | Hidekazu Ishikawa X-t9AIThemeinwp Default MAGAIOUT THE BOX NamahaAIOUT THE BOX CitylogicAI+11 | 10/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Hidekazu Ishikawa X-T9, Hidekazu Ishikawa Lightning, themeinwp Default Mag, Out the Box Namaha, Out the Box CityLogic, Marsian i-max, Jetmonsters Emmet Lite, Macho Themes Decode, Wayneconnor Sliding Door, Out the Box Shopstar!, Modernthemesnet Gridsby, TT Themes… | |
| Modificada | Alta (8.8) | 1.6% | — | Univera Panorama | 28/11/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Univera Computer System Panorama allows Command Injection. This issue affects Panorama: before 8.0. | |
| Modificada | Media (6.5) | 0.62% | — | Ipanorama 360 Wordpress Virtual Tour Builder Project Ipanorama 360 Wordpress Virtual Tour Builder | 19/10/2023 | 17/6/2026 | The iPanorama 360 – WordPress Virtual Tour Builder plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 1.8.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for… | |
| Modificada | Media (6.5) | 0.48% | — | Libpano13 Project Libpano13 | 7/7/2023 | 17/6/2026 | A null pointer dereference was found in libpano13, version libpano13-2.9.20. The flow allows attackers to cause a denial of service and potential code execute via a crafted file. | |
| Modificada | Media (4.8) | 0.39% | — | Snaborbital Panorama | 12/5/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in SnapOrbital Panorama plugin <= 1.5 versions. | |
| Modificada | Media (4.8) | 0.44% | — | Easy Panorama Project Easy Panorama | 7/4/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-site Scripting (XSS) vulnerability in Leonardo Giacone Easy Panorama plugin <= 1.1.4 versions. |