Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2853▼ 343 respecto a la semana anterior
Críticas / altas1376▼ 50 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
15 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.6) | 0.36% | — | Paloaltonetworks Pan-osSiemens Ruggedcom Ape1808 Firmware | 13/5/2026 | 14/7/2026 | Multiple denial of service vulnerabilities in Palo Alto Networks PAN-OS® software allow an unauthenticated attacker with network access to cause a denial of service (DoS) condition by sending specially crafted network traffic. Panorama and Cloud NGFW are not impacted by these vulnerabilities. | |
| Analizada | Media (6.1) | 1.4% | — | Paloaltonetworks Pan-osSiemens Ruggedcom Ape1808 Firmware | 13/5/2026 | 14/7/2026 | Multiple command injection vulnerabilities in Palo Alto Networks PAN-OS® software enable an authenticated administrator to bypass system restrictions and run arbitrary commands as a root user. To be able to exploit this issue, the user must have access to the PAN-OS CLI or Web UI. The security risk posed by this issue… | |
| Analizada | Media (4.8) | 0.33% | — | Paloaltonetworks Pan-osSiemens Ruggedcom Ape1808 Firmware | 13/5/2026 | 14/7/2026 | A server-side request forgery (SSRF) vulnerability in the IKEv2 implementation of Palo Alto Networks PAN-OS® software allows an unauthenticated attacker to cause the firewall to send network requests to unintended destinations or cause a denial of service (DoS) condition. Panorama, Cloud NGFW and Prisma® Access are… | |
| Analizada | Alta (7.8) | 97% | ⚠ Explotación activa💥 Exploit | Paloaltonetworks Pan-osPaloaltonetworks Prisma AccessSiemens Ruggedcom Ape1808 Firmware | 13/5/2026 | 17/6/2026 | Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection. Panorama and Cloud NGFW are not impacted by these issues. | |
| Analizada | Media (4.4) | 0.18% | — | Paloaltonetworks Pan-osSiemens Ruggedcom Ape1808 Firmware | 13/5/2026 | 14/7/2026 | A stored cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS® software enables a malicious authenticated administrator to store a JavaScript payload using the web interface. This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series). Cloud… | |
| Analizada | Alta (7.2) | 1.1% | 💥 PoC | Paloaltonetworks Pan-osSiemens Ruggedcom Ape1808 Firmware | 13/5/2026 | 14/7/2026 | An authentication bypass vulnerability in Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to bypass authentication controls when Cloud Authentication Service (CAS) is enabled. The risk is higher if CAS is enabled on the management interface and lower when any other login… | |
| Analizada | Alta (7.2) | 0.47% | — | Paloaltonetworks Pan-osSiemens Ruggedcom Ape1808 Firmware | 13/5/2026 | 14/7/2026 | A buffer overflow vulnerability in the DNS proxy and DNS Server features of Palo Alto Networks PAN-OS® Software allows an unauthenticated attacker with network access to cause a denial of service (DoS) condition (all PAN-OS platforms except Cloud NGFW and Prisma Access) or potentially execute arbitrary code by sending… | |
| Analizada | Crítica (9.3) | 32% | ⚠ Explotación activa💥 PoC | Paloaltonetworks Pan-osSiemens Ruggedcom Ape1808 Firmware | 6/5/2026 | 17/6/2026 | A buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets. The risk of this… | |
| Analizada | Crítica (9.8) | 86% | ⚠ Explotación activa💥 PoC | Fortinet FortianalyzerFortinet FortimanagerFortinet Fortinac-fFortinet Fortiproxy+3 | 27/1/2026 | 17/6/2026 | An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.5, FortiAnalyzer 7.4.0 through 7.4.9, FortiAnalyzer 7.2.0 through 7.2.11, FortiAnalyzer 7.0.0 through 7.0.15, FortiManager 7.6.0 through 7.6.5, FortiManager 7.4.0 through 7.4.9,… | |
| Analizada | Crítica (9.8) | 3.9% | ⚠ Explotación activa | Fortinet FortiosFortinet FortiswitchmanagerFortinet FortisaseSiemens Ruggedcom Ape1808 Firmware | 13/1/2026 | 10/9/2026 | A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5 allows attacker to execute unauthorized… | |
| Analizada | Crítica (9.8) | 68% | ⚠ Explotación activa💥 PoC | Fortinet FortiproxyFortinet FortiswitchmanagerFortinet FortiosSiemens Ruggedcom Ape1808 Firmware | 9/12/2025 | 17/6/2026 | A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiProxy 7.6.0 through 7.6.3, FortiProxy 7.4.0 through 7.4.10, FortiProxy 7.2.0 through 7.2.14, FortiProxy 7.0.0 through… | |
| Analizada | Alta (7.5) | 100% | ⚠ Explotación activa💥 Exploit | Siemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Sinec INSSiemens Sinec NMSSiemens ST7 Scadaconnect+161 | 10/10/2023 | 11/8/2026 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. | |
| Modificada | Alta (8.2) | 0.33% | — | Insydeh2oSiemens Simatic Field PG M5 FirmwareSiemens Simatic Field PG M6 FirmwareSiemens Simatic Ipc127e Firmware+12 | 3/2/2022 | 11/8/2026 | An issue was discovered in Insyde InsydeH2O with Kernel 5.0 before 05.08.42, Kernel 5.1 before 05.16.42, Kernel 5.2 before 05.26.42, Kernel 5.3 before 05.35.42, Kernel 5.4 before 05.42.51, and Kernel 5.5 before 05.50.51. An SMM memory corruption vulnerability in FvbServicesRuntimeDxe allows a possible attacker to… | |
| Modificada | Alta (7.5) | 0.32% | — | Insydeh2oNetapp Fas/aff BiosSiemens Ruggedcom Ape1808 FirmwareSiemens Simatic Field PG M5 Firmware+14 | 3/2/2022 | 11/8/2026 | An issue was discovered in Kernel 5.x in Insyde InsydeH2O, affecting HddPassword. Software SMI services that use the Communicate() function of the EFI_SMM_COMMUNICATION_PROTOCOL do not check whether the address of the buffer is valid, which allows use of SMRAM, MMIO, or OS kernel addresses. | |
| Modificada | Alta (7.5) | 0.28% | — | Insydeh2oSiemens Ruggedcom Ape1808 FirmwareSiemens Simatic Field PG M6 FirmwareSiemens Simatic Ipc127e Firmware+13 | 3/2/2022 | 11/8/2026 | A vulnerability exists in System Management Interrupt (SWSMI) handler of InsydeH2O UEFI Firmware code located in SWSMI handler that dereferences gRT (EFI_RUNTIME_SERVICES) pointer to call a GetVariable service, which is located outside of SMRAM. This can result in code execution in SMM (escalating privilege from ring… |