Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

576 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)0.20%—Intel Realsense D400 Series Dynamic Calibration Tool14/11/202317/6/2026
Uncontrolled search path element in some Intel(R) RealSense(TM) Dynamic Calibration software before version 2.13.1.0 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaAlta (8.8)64%💥 PoCNetgate PfsenseNetgate Pfsense Plus14/11/202317/6/2026
An issue in Netgate pfSense v.2.7.0 allows a remote attacker to execute arbitrary code via a crafted request to the interfaces_gif_edit.php and interfaces_gre_edit.php components.
ModificadaMedia (5.4)55%—Netgate Pfsense14/11/202317/6/2026
Cross Site Scripting (XSS) vulnerability in Netgate pfSense v.2.7.0 allows a remote attacker to gain privileges via a crafted URL to the getserviceproviders.php page.
ModificadaMedia (5.4)58%—Netgate Pfsense14/11/202317/6/2026
Cross Site Scripting (XSS) vulnerability in Netgate pfSense v.2.7.0 allows a remote attacker to gain privileges via a crafted url to the status_logs_filter_dynamic.php page.
ModificadaMedia (6.1)0.57%—Sensiolabs Symfony10/11/202317/6/2026
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Starting in version 6.0.0 and prior to version 6.3.8, the error message in `WebhookController` returns unescaped user-submitted input. As of version 6.3.8, `WebhookController` now doesn't return any user-submitted input…
AnalizadaMedia (6.1)0.69%—Debian LinuxSensiolabs SymfonySymfony Twig-bridge10/11/202329/7/2026
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Starting in versions 2.0.0, 5.0.0, and 6.0.0 and prior to versions 4.4.51, 5.4.31, and 6.3.8, some Twig filters in CodeExtension use `is_safe=html` but don't actually ensure their input is safe. As of versions 4.4.51,…
ModificadaMedia (6.5)0.69%—Sensiolabs Symfony10/11/202317/6/2026
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Starting in versions 5.4.21 and 6.2.7 and prior to versions 5.4.31 and 6.3.8, `SessionStrategyListener` does not migrate the session after every successful login. It does so only in case the logged in user changes by…
ModificadaAlta (7.2)1.7%—Pfsense9/11/202317/6/2026
An issue discovered in Pfsense CE version 2.6.0 allows attackers to change the password of any user without verification.
ModificadaCrítica (9.8)1.8%—Pfsense8/11/202317/6/2026
An issue discovered in Pfsense CE version 2.6.0 allows attackers to compromise user accounts via weak password requirements.
ModificadaAlta (7.8)0.21%—Ellipticlabs AI Virtual Presence SensorEllipticlabs Virtual Lock Sensor25/10/202317/6/2026
A vulnerability was reported in Elliptic Labs Virtual Lock Sensor for ThinkPad T14 Gen 3 that could allow an attacker with local access to execute code with elevated privileges.
ModificadaMedia (4.9)1.6%—Pfsense25/10/202317/6/2026
Pfsense CE version 2.6.0 is vulnerable to No rate limit which can lead to an attacker creating multiple malicious users in firewall.
ModificadaCrítica (9.8)0.89%—Opnsense23/10/202317/6/2026
DECISO OPNsense 23.1 does not impose rate limits for authentication, allowing attackers to perform a brute-force attack to bypass authentication.
ModificadaMedia (6.1)0.38%—Ezoic Ampedsense18/10/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Ezoic AmpedSense – AdSense Split Tester plugin <= 4.68 versions.
ModificadaMedia (5.5)0.23%—Consensys Gnark9/10/202317/6/2026
gnark is a zk-SNARK library that offers a high-level API to design circuits. Prior to version 0.9.0, for some in-circuit values, it is possible to construct two valid decomposition to bits. In addition to the canonical decomposition of `a`, for small values there exists a second decomposition for `a+r` (where `r` is…
ModificadaMedia (5.4)0.60%—Opnsense28/9/202317/6/2026
OPNsense before 23.7.5 allows XSS via the index.php sequence parameter to the Lobby Dashboard.
ModificadaMedia (5.4)0.60%—Opnsense28/9/202317/6/2026
OPNsense before 23.7.5 allows XSS via the index.php column_count parameter to the Lobby Dashboard.
ModificadaCrítica (9.8)1.1%—Consensys Gnark-crypto28/9/202317/6/2026
Consensys gnark-crypto through 0.11.2 allows Signature Malleability. This occurs because deserialisation of EdDSA and ECDSA signatures does not ensure that the data is in a certain interval.
AnalizadaMedia (6.5)85%⚠ Explotación activa💥 ExploitQlik Sense29/8/20235/8/2026
A path traversal vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023 Patch 7 and earlier, November 2022 Patch 10 and earlier, and August 2022 Patch 12 and earlier allows an unauthenticated remote attacker to generate an anonymous session. This allows them…
AnalizadaCrítica (9.9)88%⚠ Explotación activa💥 ExploitQlik Sense29/8/20235/8/2026
An HTTP Request Tunneling vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023 Patch 7 and earlier, November 2022 Patch 10 and earlier, and August 2022 Patch 12 and earlier allows a remote attacker to elevate their privilege by tunneling HTTP requests in the…
ModificadaCrítica (9.8)1.6%—Myspotcam Sense Firmware28/8/202317/6/2026
SpotCam Co., Ltd. SpotCam Sense’s hidden Telnet function has a vulnerability of OS command injection. An remote unauthenticated attacker can exploit this vulnerability to execute command injection attack to perform arbitrary system commands or disrupt service.
ModificadaAlta (7.8)0.18%—Intel Realsense 450 FA Firmware11/8/202317/6/2026
Protection mechanism failure in some Intel(R) RealSense(TM) ID software for Intel(R) RealSense(TM) 450 FA in version 0.25.0 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaAlta (7.8)0.18%—Intel Realsense 450 FA Firmware11/8/202317/6/2026
Out-of-bounds write in some Intel(R) RealSense(TM) ID software for Intel(R) RealSense(TM) 450 FA in version 0.25.0 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaAlta (7.8)0.18%—Intel Realsense 450 FA Firmware11/8/202317/6/2026
Improper buffer restrictions in some Intel(R) RealSense(TM) ID software for Intel(R) RealSense(TM) 450 FA in version 0.25.0 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaAlta (7.8)0.14%—Intel Realsense Software Development KIT11/8/202317/6/2026
Incorrect default permissions in some Intel(R) RealSense(TM) SDKs in version 2.53.1 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaAlta (7.8)0.18%—Intel Realsense 450 FA Firmware11/8/202317/6/2026
Improper buffer restrictions in some Intel(R) RealSense(TM) ID software for Intel(R) RealSense(TM) 450 FA in version 0.25.0 may allow an authenticated user to potentially enable escalation of privilege via local access.
Orbitaley — Vulnerabilidades