Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
576 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.20% | — | Intel Realsense D400 Series Dynamic Calibration Tool | 14/11/2023 | 17/6/2026 | Uncontrolled search path element in some Intel(R) RealSense(TM) Dynamic Calibration software before version 2.13.1.0 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (8.8) | 64% | 💥 PoC | Netgate PfsenseNetgate Pfsense Plus | 14/11/2023 | 17/6/2026 | An issue in Netgate pfSense v.2.7.0 allows a remote attacker to execute arbitrary code via a crafted request to the interfaces_gif_edit.php and interfaces_gre_edit.php components. | |
| Modificada | Media (5.4) | 55% | — | Netgate Pfsense | 14/11/2023 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in Netgate pfSense v.2.7.0 allows a remote attacker to gain privileges via a crafted URL to the getserviceproviders.php page. | |
| Modificada | Media (5.4) | 58% | — | Netgate Pfsense | 14/11/2023 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in Netgate pfSense v.2.7.0 allows a remote attacker to gain privileges via a crafted url to the status_logs_filter_dynamic.php page. | |
| Modificada | Media (6.1) | 0.57% | — | Sensiolabs Symfony | 10/11/2023 | 17/6/2026 | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Starting in version 6.0.0 and prior to version 6.3.8, the error message in `WebhookController` returns unescaped user-submitted input. As of version 6.3.8, `WebhookController` now doesn't return any user-submitted input… | |
| Analizada | Media (6.1) | 0.69% | — | Debian LinuxSensiolabs SymfonySymfony Twig-bridge | 10/11/2023 | 29/7/2026 | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Starting in versions 2.0.0, 5.0.0, and 6.0.0 and prior to versions 4.4.51, 5.4.31, and 6.3.8, some Twig filters in CodeExtension use `is_safe=html` but don't actually ensure their input is safe. As of versions 4.4.51,… | |
| Modificada | Media (6.5) | 0.69% | — | Sensiolabs Symfony | 10/11/2023 | 17/6/2026 | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Starting in versions 5.4.21 and 6.2.7 and prior to versions 5.4.31 and 6.3.8, `SessionStrategyListener` does not migrate the session after every successful login. It does so only in case the logged in user changes by… | |
| Modificada | Alta (7.2) | 1.7% | — | Pfsense | 9/11/2023 | 17/6/2026 | An issue discovered in Pfsense CE version 2.6.0 allows attackers to change the password of any user without verification. | |
| Modificada | Crítica (9.8) | 1.8% | — | Pfsense | 8/11/2023 | 17/6/2026 | An issue discovered in Pfsense CE version 2.6.0 allows attackers to compromise user accounts via weak password requirements. | |
| Modificada | Alta (7.8) | 0.21% | — | Ellipticlabs AI Virtual Presence SensorEllipticlabs Virtual Lock Sensor | 25/10/2023 | 17/6/2026 | A vulnerability was reported in Elliptic Labs Virtual Lock Sensor for ThinkPad T14 Gen 3 that could allow an attacker with local access to execute code with elevated privileges. | |
| Modificada | Media (4.9) | 1.6% | — | Pfsense | 25/10/2023 | 17/6/2026 | Pfsense CE version 2.6.0 is vulnerable to No rate limit which can lead to an attacker creating multiple malicious users in firewall. | |
| Modificada | Crítica (9.8) | 0.89% | — | Opnsense | 23/10/2023 | 17/6/2026 | DECISO OPNsense 23.1 does not impose rate limits for authentication, allowing attackers to perform a brute-force attack to bypass authentication. | |
| Modificada | Media (6.1) | 0.38% | — | Ezoic Ampedsense | 18/10/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Ezoic AmpedSense – AdSense Split Tester plugin <= 4.68 versions. | |
| Modificada | Media (5.5) | 0.23% | — | Consensys Gnark | 9/10/2023 | 17/6/2026 | gnark is a zk-SNARK library that offers a high-level API to design circuits. Prior to version 0.9.0, for some in-circuit values, it is possible to construct two valid decomposition to bits. In addition to the canonical decomposition of `a`, for small values there exists a second decomposition for `a+r` (where `r` is… | |
| Modificada | Media (5.4) | 0.60% | — | Opnsense | 28/9/2023 | 17/6/2026 | OPNsense before 23.7.5 allows XSS via the index.php sequence parameter to the Lobby Dashboard. | |
| Modificada | Media (5.4) | 0.60% | — | Opnsense | 28/9/2023 | 17/6/2026 | OPNsense before 23.7.5 allows XSS via the index.php column_count parameter to the Lobby Dashboard. | |
| Modificada | Crítica (9.8) | 1.1% | — | Consensys Gnark-crypto | 28/9/2023 | 17/6/2026 | Consensys gnark-crypto through 0.11.2 allows Signature Malleability. This occurs because deserialisation of EdDSA and ECDSA signatures does not ensure that the data is in a certain interval. | |
| Analizada | Media (6.5) | 85% | ⚠ Explotación activa💥 Exploit | Qlik Sense | 29/8/2023 | 5/8/2026 | A path traversal vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023 Patch 7 and earlier, November 2022 Patch 10 and earlier, and August 2022 Patch 12 and earlier allows an unauthenticated remote attacker to generate an anonymous session. This allows them… | |
| Analizada | Crítica (9.9) | 88% | ⚠ Explotación activa💥 Exploit | Qlik Sense | 29/8/2023 | 5/8/2026 | An HTTP Request Tunneling vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023 Patch 7 and earlier, November 2022 Patch 10 and earlier, and August 2022 Patch 12 and earlier allows a remote attacker to elevate their privilege by tunneling HTTP requests in the… | |
| Modificada | Crítica (9.8) | 1.6% | — | Myspotcam Sense Firmware | 28/8/2023 | 17/6/2026 | SpotCam Co., Ltd. SpotCam Sense’s hidden Telnet function has a vulnerability of OS command injection. An remote unauthenticated attacker can exploit this vulnerability to execute command injection attack to perform arbitrary system commands or disrupt service. | |
| Modificada | Alta (7.8) | 0.18% | — | Intel Realsense 450 FA Firmware | 11/8/2023 | 17/6/2026 | Protection mechanism failure in some Intel(R) RealSense(TM) ID software for Intel(R) RealSense(TM) 450 FA in version 0.25.0 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.8) | 0.18% | — | Intel Realsense 450 FA Firmware | 11/8/2023 | 17/6/2026 | Out-of-bounds write in some Intel(R) RealSense(TM) ID software for Intel(R) RealSense(TM) 450 FA in version 0.25.0 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.8) | 0.18% | — | Intel Realsense 450 FA Firmware | 11/8/2023 | 17/6/2026 | Improper buffer restrictions in some Intel(R) RealSense(TM) ID software for Intel(R) RealSense(TM) 450 FA in version 0.25.0 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.8) | 0.14% | — | Intel Realsense Software Development KIT | 11/8/2023 | 17/6/2026 | Incorrect default permissions in some Intel(R) RealSense(TM) SDKs in version 2.53.1 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.8) | 0.18% | — | Intel Realsense 450 FA Firmware | 11/8/2023 | 17/6/2026 | Improper buffer restrictions in some Intel(R) RealSense(TM) ID software for Intel(R) RealSense(TM) 450 FA in version 0.25.0 may allow an authenticated user to potentially enable escalation of privilege via local access. |