Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
576 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 3.5% | — | Oisf SuricataPfsensePfsense Suricata Package | 6/4/2023 | 17/6/2026 | Directory Traversal vulnerability found in Pfsense v.2.1.3 and Pfsense Suricata v.1.4.6 pkg v.1.0.1 allows a remote attacker to obtain sensitive information via the file parameter to suricata/suricata_logs_browser.php. | |
| Modificada | Crítica (9.6) | 0.67% | — | Netgate PfsenseNetgate Pfsense Acme Package | 4/4/2023 | 17/6/2026 | Cross Site Scripting vulnerability found in Netgate pfSense 2.4.4 and ACME package v.0.6.3 allows attackers to execute arbitrary code via the RootFolder field of acme_certificates.php. | |
| Modificada | Crítica (9.8) | 9.8% | 💥 Exploit | Netgate Pfsense PlusPfsense | 22/3/2023 | 17/6/2026 | Improper restriction of excessive authentication attempts in the SSHGuard component of Netgate pfSense Plus software v22.05.1 and pfSense CE software v2.6.0 allows attackers to bypass brute force protection mechanisms via crafted web requests. | |
| Modificada | Alta (8.8) | 90% | 💥 Exploit | Netgate Pfsense | 17/3/2023 | 17/6/2026 | A command injection vulnerability in the function restore_rrddata() of Netgate pfSense v2.7.0 allows authenticated attackers to execute arbitrary commands via manipulating the contents of an XML file supplied to the component config.xml. | |
| Modificada | Media (6.1) | 60% | — | Netgate Pfsense | 22/2/2023 | 17/6/2026 | pfSense CE through 2.6.0 and pfSense Plus before 22.05 allow XSS in the WebGUI via URL Table Alias URL parameters. | |
| Modificada | Media (4.4) | 0.22% | — | Intel Integrated Sensor Solution | 16/2/2023 | 17/6/2026 | Out-of-bounds read in firmware for the Intel(R) Integrated Sensor Solution before versions 5.4.2.4579v3, 5.4.1.4479 and 5.0.0.4143 may allow a privileged user to potentially enable denial of service via local access. | |
| Modificada | Alta (8.8) | 0.79% | — | Sensiolabs Symfony | 3/2/2023 | 17/6/2026 | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. When authenticating users Symfony by default regenerates the session ID upon login, but preserves the rest of session attributes. Because this does not clear CSRF tokens upon login, this might enables same-site attackers… | |
| Analizada | Alta (8.8) | 4.0% | 💥 PoC | Sensiolabs Symfony | 3/2/2023 | 17/6/2026 | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. The Symfony HTTP cache system, acts as a reverse proxy: It caches entire responses (including headers) and returns them to the clients. In a recent change in the `AbstractSessionListener`, the response might contain a… | |
| Modificada | Crítica (9.8) | 17% | 💥 Exploit | Pfsense Pfblockerng | 20/12/2022 | 17/6/2026 | pfSense pfBlockerNG through 2.1.4_27 allows remote attackers to execute arbitrary OS commands as root via the HTTP Host header, a different vulnerability than CVE-2022-31814. | |
| Modificada | Media (6.1) | 0.63% | — | Netgate AcmeNetgate Pfsense | 15/12/2022 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in Netgate pf Sense 2.4.4-Release-p3 and Netgate ACME package 0.6.3 allows remote attackers to to run arbitrary code via the RootFolder field to acme_certificate_edit.php page of the ACME package. | |
| Modificada | Alta (8.8) | 0.57% | — | Sens Project Sens | 12/12/2022 | 17/6/2026 | SENS v1.0 is vulnerable to Incorrect Access Control vulnerability. | |
| Modificada | Alta (8.8) | 0.61% | — | Sens Project Sens | 12/12/2022 | 17/6/2026 | SENS v1.0 has a file upload vulnerability. | |
| Modificada | Media (5.4) | 0.35% | — | Sens Project Sens | 12/12/2022 | 17/6/2026 | SENS v1.0 is vulnerable to Cross Site Scripting (XSS) via com.liuyanzhao.sens.web.controller.admin, getRegister. | |
| Modificada | Media (6.1) | 0.35% | — | Sens Project Sens | 12/12/2022 | 17/6/2026 | SENS v1.0 is vulnerable to Cross Site Scripting (XSS). | |
| Modificada | Media (4.8) | 0.47% | — | Wpadvancedads Advanced ADS - AD Manager & Adsense | 8/11/2022 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Advanced Ads GmbH Advanced Ads – Ad Manager & AdSense plugin <= 1.31.1 on WordPress. | |
| Modificada | Media (6.1) | 3.2% | — | Pfsense | 3/10/2022 | 17/6/2026 | pfSense v2.5.2 was discovered to contain a cross-site scripting (XSS) vulnerability in the browser.php component. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into a file name. | |
| Modificada | Media (4.3) | 0.79% | — | Automattic Sensei LMS | 29/8/2022 | 17/6/2026 | The Sensei LMS WordPress plugin before 4.5.2 does not ensure that the sender of a private message is either the teacher or the original sender, allowing any authenticated user to send messages to arbitrary private conversation via a IDOR attack. Note: Attackers are not able to see responses/messages between the… | |
| Modificada | Media (5.3) | 2.5% | 💥 Exploit | Automattic Sensei LMS | 29/8/2022 | 17/6/2026 | The Sensei LMS WordPress plugin before 4.5.0 does not have proper permissions set in one of its REST endpoint, allowing unauthenticated users to access private messages sent to teachers | |
| Modificada | Crítica (9.8) | 55% | 💥 Exploit | Keysight Sensor Management Server | 10/8/2022 | 17/6/2026 | The com.keysight.tentacle.config.ResourceManager.smsRestoreDatabaseZip() method is used to restore the HSQLDB database used in SMS. It takes the path of the zipped database file as the single parameter. An unauthenticated, remote attacker can specify an UNC path for the database file (i.e.,… | |
| Analizada | Crítica (9.8) | 21% | — | Keysight Sensor Management Server | 10/8/2022 | 17/6/2026 | A path traversal vulnerability exists in the com.keysight.tentacle.licensing.LicenseManager.addLicenseFile() method in the Keysight Sensor Management Server (SMS). This allows an unauthenticated remote attacker to upload arbitrary files to the SMS host. | |
| Modificada | Media (5.3) | 1.2% | — | Qlik Sense | 21/6/2022 | 17/6/2026 | The GeoAnalytics feature in Qlik Sense April 2020 patch 4 allows SSRF. | |
| Modificada | Media (4.3) | 0.43% | — | Tipsandtricks-hq WP Simple Adsense Insertion | 8/6/2022 | 17/6/2026 | The WP Simple Adsense Insertion WordPress plugin before 2.1 does not perform CSRF checks on updates to its admin page, allowing an attacker to trick a logged in user to manipulate ads and inject arbitrary javascript via submitting a form. | |
| Modificada | Media (4.6) | 0.26% | — | Intel Realsense ID F450 Firmware | 12/5/2022 | 17/6/2026 | Insecure default variable initialization of Intel(R) RealSense(TM) ID Solution F450 before version 2.6.0.74 may allow an unauthenticated user to potentially enable information disclosure via physical access. | |
| Modificada | Crítica (10) | 6.2% | — | Swiftsensors Sg3-1010 Firmware | 14/4/2022 | 17/6/2026 | An authentication bypass vulnerability exists in the device password generation functionality of Swift Sensors Gateway SG3-1010. A specially-crafted network request can lead to remote code execution. An attacker can send a sequence of requests to trigger this vulnerability. | |
| Modificada | Alta (8.8) | 4.5% | — | Netgate PfsenseNetgate Pfsense Plus | 31/3/2022 | 17/6/2026 | Improper access control vulnerability in pfSense CE and pfSense Plus (pfSense CE software versions prior to 2.6.0 and pfSense Plus software versions prior to 22.01) allows a remote attacker with the privilege to change NTP GPS settings to rewrite existing files on the file system, which may result in arbitrary command… |