Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3007▼ 68 respecto a la semana anterior
Críticas / altas1421▲ 55 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
21 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.2) | 0.37% | — | Paloaltonetworks Pan-osAIPaloaltonetworks Vm-seriesAIPaloaltonetworks Pa-seriesAIPaloaltonetworks PanoramaAI | 10/9/2026 | 11/9/2026 | A buffer overflow vulnerability in the XML processing functionality of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to the management web or dataplane interface to cause a denial of service (DoS) condition on VM-Series firewalls or execute arbitrary code with root… | |
| Pendiente de análisis | Baja (1.1) | 0.27% | — | Paloaltonetworks Pan-osAIPaloaltonetworks PanoramaAI | 10/9/2026 | 10/9/2026 | A stored cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS® software enables a malicious authenticated administrator to store or execute a JavaScript payload using the web interface. This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and… | |
| Aplazada | Alta (7.5) | 0.43% | — | Panorama Viewer 360 Degree Image AND Video ViewerAI | 26/6/2026 | 26/6/2026 | Contributor Local File Inclusion in Panorama Viewer – 360 Degree Image + Video Viewer <= 1.6.1 versions. | |
| En análisis | Baja (3.3) | 0.19% | — | Codra Panorama Collaborative Operation & ExecutionCodra Panorama COMCodra Panorama E2Codra Panorama H2 | 25/3/2026 | 17/6/2026 | Please refer to security bulletin BS-036, available on the Panorama CSIRT website: https://my.codra.net/en-gb/csirt. | |
| Pendiente de análisis | Alta (7.7) | 0.53% | — | Codra Panorama SuiteAI | 25/3/2026 | 17/6/2026 | Please refer to security bulletin BS-035, available on the Panorama CSIRT website: https://my.codra.net/en-gb/csirt . | |
| Analizada | Media (4.8) | 0.31% | — | Projectpanorama Panorama | 15/5/2025 | 17/6/2026 | The Panorama WordPress plugin through 1.5.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Aplazada | Media (5.3) | 0.42% | — | Avirtum Ipanorama 360AI | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in Avirtum iPanorama 360 WordPress Virtual Tour Builder allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects iPanorama 360 WordPress Virtual Tour Builder: from n/a through 1.8.3. | |
| Aplazada | Media (5.3) | 0.42% | — | Avirtum Ipanorama 360AI | 3/5/2024 | 17/6/2026 | Missing Authorization vulnerability in Avirtum iPanorama 360 WordPress Virtual Tour Builder.This issue affects iPanorama 360 WordPress Virtual Tour Builder: from n/a through 1.8.1. | |
| Modificada | Alta (8.8) | 1.6% | — | Univera Panorama | 28/11/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Univera Computer System Panorama allows Command Injection. This issue affects Panorama: before 8.0. | |
| Modificada | Media (6.5) | 0.62% | — | Ipanorama 360 Wordpress Virtual Tour Builder Project Ipanorama 360 Wordpress Virtual Tour Builder | 19/10/2023 | 17/6/2026 | The iPanorama 360 – WordPress Virtual Tour Builder plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 1.8.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for… | |
| Modificada | Media (4.8) | 0.39% | — | Snaborbital Panorama | 12/5/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in SnapOrbital Panorama plugin <= 1.5 versions. | |
| Modificada | Media (4.8) | 0.44% | — | Easy Panorama Project Easy Panorama | 7/4/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-site Scripting (XSS) vulnerability in Leonardo Giacone Easy Panorama plugin <= 1.1.4 versions. | |
| Modificada | Media (5.4) | 0.47% | — | Ipanorama 360 Wordpress Virtual Tour Builder Project Ipanorama 360 Wordpress Virtual Tour Builder | 9/1/2023 | 17/6/2026 | The iPanorama 360 WordPress Virtual Tour Builder plugin through 1.6.29 does not sanitise and escape some of its settings, which could allow users such as contributor+ to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. | |
| Modificada | Alta (7.4) | 0.97% | — | Panorama Project Nhiservisignadapter | 31/12/2020 | 17/6/2026 | The digest generation function of NHIServiSignAdapter has not been verified for source file path, which leads to the SMB request being redirected to a malicious host, resulting in the leakage of user's credential. | |
| Modificada | Alta (7.4) | 0.97% | — | Panorama Project Nhiservisignadapter | 31/12/2020 | 17/6/2026 | Multiple functions of NHIServiSignAdapter failed to verify the users’ file path, which leads to the SMB request being redirected to a malicious host, resulting in the leakage of user's credential. | |
| Modificada | Crítica (9.8) | 2.0% | — | Panorama Nhiservisignadapter | 31/12/2020 | 17/6/2026 | The digest generation function of NHIServiSignAdapter has not been verified for parameter’s length, which leads to a stack overflow loophole. Remote attackers can use the leak to execute code without privilege. | |
| Modificada | Crítica (9.8) | 2.0% | — | Panorama Nhiservisignadapter | 31/12/2020 | 17/6/2026 | NHIServiSignAdapter fails to verify the length of digital credential files’ path which leads to a heap overflow loophole. Remote attackers can use the leak to execute code without privilege. | |
| Modificada | Alta (7.5) | 0.51% | — | Panorama Nhiservisignadapter | 31/12/2020 | 17/6/2026 | The encryption function of NHIServiSignAdapter fail to verify the file path input by users. Remote attacker can access arbitrary files through the flaw without privilege. | |
| Modificada | Crítica (9.8) | 2.3% | — | Cylan Clever DOG Smart Camera Panorama Dog-2w FirmwareCylan Clever DOG Smart Camera Plus Dog-2w-v4 Firmware | 20/6/2019 | 17/6/2026 | On Shenzhen Cylan Clever Dog Smart Camera DOG-2W and DOG-2W-V4 devices, an attacker on the network can login remotely to the camera and gain root access. The device ships with a hardcoded 12345678 password for the root account, accessible from a TELNET login prompt. | |
| Modificada | Media (5.5) | 0.35% | — | Cylan Clever DOG Smart Camera Panorama Dog-2w FirmwareCylan Clever DOG Smart Camera Plus Dog-2w-v4 Firmware | 20/6/2019 | 17/6/2026 | On Shenzhen Cylan Clever Dog Smart Camera DOG-2W and DOG-2W-V4 devices, an attacker on the local network has unauthenticated access to the internal SD card via the HTTP service on port 8000. The HTTP web server on the camera allows anyone to view or download the video archive recorded and saved on the external memory… | |
| Modificada | Alta (9.3) | 12% | — | Axis 2100 Network CameraAxis 2110 Network CameraAxis 2120 Network CameraAxis 2130 PTZ Network Camera+6 | 7/5/2007 | 16/6/2026 | Stack-based buffer overflow in the SaveBMP method in the AXIS Camera Control (aka CamImage) ActiveX control before 2.40.0.0 in AxisCamControl.ocx in AXIS 2100, 2110, 2120, 2130 PTZ, 2420, 2420-IR, 2400, 2400+, 2401, 2401+, 2411, and Panorama PTZ allows remote attackers to cause a denial of service (Internet Explorer… |