Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

576 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)3.5%—Oisf SuricataPfsensePfsense Suricata Package6/4/202317/6/2026
Directory Traversal vulnerability found in Pfsense v.2.1.3 and Pfsense Suricata v.1.4.6 pkg v.1.0.1 allows a remote attacker to obtain sensitive information via the file parameter to suricata/suricata_logs_browser.php.
ModificadaCrítica (9.6)0.67%—Netgate PfsenseNetgate Pfsense Acme Package4/4/202317/6/2026
Cross Site Scripting vulnerability found in Netgate pfSense 2.4.4 and ACME package v.0.6.3 allows attackers to execute arbitrary code via the RootFolder field of acme_certificates.php.
ModificadaCrítica (9.8)9.8%💥 ExploitNetgate Pfsense PlusPfsense22/3/202317/6/2026
Improper restriction of excessive authentication attempts in the SSHGuard component of Netgate pfSense Plus software v22.05.1 and pfSense CE software v2.6.0 allows attackers to bypass brute force protection mechanisms via crafted web requests.
ModificadaAlta (8.8)90%💥 ExploitNetgate Pfsense17/3/202317/6/2026
A command injection vulnerability in the function restore_rrddata() of Netgate pfSense v2.7.0 allows authenticated attackers to execute arbitrary commands via manipulating the contents of an XML file supplied to the component config.xml.
ModificadaMedia (6.1)60%—Netgate Pfsense22/2/202317/6/2026
pfSense CE through 2.6.0 and pfSense Plus before 22.05 allow XSS in the WebGUI via URL Table Alias URL parameters.
ModificadaMedia (4.4)0.22%—Intel Integrated Sensor Solution16/2/202317/6/2026
Out-of-bounds read in firmware for the Intel(R) Integrated Sensor Solution before versions 5.4.2.4579v3, 5.4.1.4479 and 5.0.0.4143 may allow a privileged user to potentially enable denial of service via local access.
ModificadaAlta (8.8)0.79%—Sensiolabs Symfony3/2/202317/6/2026
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. When authenticating users Symfony by default regenerates the session ID upon login, but preserves the rest of session attributes. Because this does not clear CSRF tokens upon login, this might enables same-site attackers…
AnalizadaAlta (8.8)4.0%💥 PoCSensiolabs Symfony3/2/202317/6/2026
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. The Symfony HTTP cache system, acts as a reverse proxy: It caches entire responses (including headers) and returns them to the clients. In a recent change in the `AbstractSessionListener`, the response might contain a…
ModificadaCrítica (9.8)17%💥 ExploitPfsense Pfblockerng20/12/202217/6/2026
pfSense pfBlockerNG through 2.1.4_27 allows remote attackers to execute arbitrary OS commands as root via the HTTP Host header, a different vulnerability than CVE-2022-31814.
ModificadaMedia (6.1)0.63%—Netgate AcmeNetgate Pfsense15/12/202217/6/2026
Cross Site Scripting (XSS) vulnerability in Netgate pf Sense 2.4.4-Release-p3 and Netgate ACME package 0.6.3 allows remote attackers to to run arbitrary code via the RootFolder field to acme_certificate_edit.php page of the ACME package.
ModificadaAlta (8.8)0.57%—Sens Project Sens12/12/202217/6/2026
SENS v1.0 is vulnerable to Incorrect Access Control vulnerability.
ModificadaAlta (8.8)0.61%—Sens Project Sens12/12/202217/6/2026
SENS v1.0 has a file upload vulnerability.
ModificadaMedia (5.4)0.35%—Sens Project Sens12/12/202217/6/2026
SENS v1.0 is vulnerable to Cross Site Scripting (XSS) via com.liuyanzhao.sens.web.controller.admin, getRegister.
ModificadaMedia (6.1)0.35%—Sens Project Sens12/12/202217/6/2026
SENS v1.0 is vulnerable to Cross Site Scripting (XSS).
ModificadaMedia (4.8)0.47%—Wpadvancedads Advanced ADS - AD Manager & Adsense8/11/202217/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Advanced Ads GmbH Advanced Ads – Ad Manager & AdSense plugin <= 1.31.1 on WordPress.
ModificadaMedia (6.1)3.2%—Pfsense3/10/202217/6/2026
pfSense v2.5.2 was discovered to contain a cross-site scripting (XSS) vulnerability in the browser.php component. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into a file name.
ModificadaMedia (4.3)0.79%—Automattic Sensei LMS29/8/202217/6/2026
The Sensei LMS WordPress plugin before 4.5.2 does not ensure that the sender of a private message is either the teacher or the original sender, allowing any authenticated user to send messages to arbitrary private conversation via a IDOR attack. Note: Attackers are not able to see responses/messages between the…
ModificadaMedia (5.3)2.5%💥 ExploitAutomattic Sensei LMS29/8/202217/6/2026
The Sensei LMS WordPress plugin before 4.5.0 does not have proper permissions set in one of its REST endpoint, allowing unauthenticated users to access private messages sent to teachers
ModificadaCrítica (9.8)55%💥 ExploitKeysight Sensor Management Server10/8/202217/6/2026
The com.keysight.tentacle.config.ResourceManager.smsRestoreDatabaseZip() method is used to restore the HSQLDB database used in SMS. It takes the path of the zipped database file as the single parameter. An unauthenticated, remote attacker can specify an UNC path for the database file (i.e.,…
AnalizadaCrítica (9.8)21%—Keysight Sensor Management Server10/8/202217/6/2026
A path traversal vulnerability exists in the com.keysight.tentacle.licensing.LicenseManager.addLicenseFile() method in the Keysight Sensor Management Server (SMS). This allows an unauthenticated remote attacker to upload arbitrary files to the SMS host.
ModificadaMedia (5.3)1.2%—Qlik Sense21/6/202217/6/2026
The GeoAnalytics feature in Qlik Sense April 2020 patch 4 allows SSRF.
ModificadaMedia (4.3)0.43%—Tipsandtricks-hq WP Simple Adsense Insertion8/6/202217/6/2026
The WP Simple Adsense Insertion WordPress plugin before 2.1 does not perform CSRF checks on updates to its admin page, allowing an attacker to trick a logged in user to manipulate ads and inject arbitrary javascript via submitting a form.
ModificadaMedia (4.6)0.26%—Intel Realsense ID F450 Firmware12/5/202217/6/2026
Insecure default variable initialization of Intel(R) RealSense(TM) ID Solution F450 before version 2.6.0.74 may allow an unauthenticated user to potentially enable information disclosure via physical access.
ModificadaCrítica (10)6.2%—Swiftsensors Sg3-1010 Firmware14/4/202217/6/2026
An authentication bypass vulnerability exists in the device password generation functionality of Swift Sensors Gateway SG3-1010. A specially-crafted network request can lead to remote code execution. An attacker can send a sequence of requests to trigger this vulnerability.
ModificadaAlta (8.8)4.5%—Netgate PfsenseNetgate Pfsense Plus31/3/202217/6/2026
Improper access control vulnerability in pfSense CE and pfSense Plus (pfSense CE software versions prior to 2.6.0 and pfSense Plus software versions prior to 22.01) allows a remote attacker with the privilege to change NTP GPS settings to rewrite existing files on the file system, which may result in arbitrary command…