Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

576 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)1.9%—Netgate PfsenseNetgate Pfsense Plus31/3/202217/6/2026
Improper input validation vulnerability in pfSense CE and pfSense Plus (pfSense CE software versions prior to 2.6.0 and pfSense Plus software versions prior to 22.01) allows a remote attacker with the privilege to change OpenVPN client or server settings to execute an arbitrary command.
ModificadaMedia (6.1)2.9%—Netgate Pfsense PlusPfsense31/3/202217/6/2026
Cross-site scripting vulnerability in pfSense CE and pfSense Plus (pfSense CE software versions 2.5.2 and earlier, and pfSense Plus software versions 21.05 and earlier) allows a remote attacker to inject an arbitrary script via a malicious URL.
ModificadaMedia (6.5)1.8%—Pfsense-pkg-wireguard10/3/202217/6/2026
Directory traversal vulnerability in pfSense-pkg-WireGuard pfSense-pkg-WireGuard 0.1.5 versions prior to 0.1.5_4 and pfSense-pkg-WireGuard 0.1.6 versions prior to 0.1.6_1 allows a remote authenticated attacker to lead a pfSense user to view a file outside the public folder.
ModificadaMedia (5.9)1.9%—Microsoft Defender FOR Endpoint EDR SensorMicrosoft Defender FOR Endpoint9/3/202217/6/2026
Microsoft Defender for Endpoint Spoofing Vulnerability
ModificadaAlta (8.8)87%💥 ExploitPfsense1/3/202217/6/2026
diag_routes.php in pfSense 2.5.2 allows sed data injection. Authenticated users are intended to be able to view data about the routes set in the firewall. The data is retrieved by executing the netstat utility, and then its output is parsed via the sed utility. Although the common protection mechanisms against command…
ModificadaMedia (5.3)1.4%—Qlik Sense21/2/202217/6/2026
A vulnerability in Qlik Sense Enterprise on Windows could allow an remote attacker to enumerate domain user accounts. An attacker could exploit this vulnerability by sending authentication requests to an affected system. A successful exploit could allow the attacker to compare the response time that are returned by…
ModificadaMedia (5.5)0.24%—Intel Realsense Depth Camera Manager9/2/202217/6/2026
Improper access control in the Intel(R) RealSense(TM) DCM before version 20210625 may allow an authenticated user to potentially enable information disclosure via local access.
ModificadaAlta (8.8)0.57%—Sensiolabs Symfony1/2/202217/6/2026
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. The Symfony form component provides a CSRF protection mechanism by using a random token injected in the form and using the session to store and control the token submitted by the user. When using the FrameworkBundle, this…
ModificadaMedia (6.1)1.5%—PfsensePfsense Plus26/1/202217/6/2026
/usr/local/www/pkg.php in pfSense CE before 2.6.0 and pfSense Plus before 22.01 uses $_REQUEST['pkg_filter'] in a PHP echo call, causing XSS.
AnalizadaCrítica (9)100%⚠ Explotación activa💥 ExploitApache Log4jCvat Computer Vision Annotation ToolIntel Audio Development KITIntel Datacenter Manager+5114/12/202117/6/2026
It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows attackers with control over Thread Context Map (MDC) input data when the logging configuration uses a non-default Pattern Layout with either a Context Lookup (for example,…
AnalizadaCrítica (10)100%⚠ Explotación activa💥 ExploitSiemens 6bk1602-0aa12-0tp0 FirmwareSiemens 6bk1602-0aa22-0tp0 FirmwareSiemens 6bk1602-0aa32-0tp0 FirmwareSiemens 6bk1602-0aa42-0tp0 Firmware+13910/12/202111/8/2026
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can…
ModificadaMedia (6.5)1.4%—Sensiolabs SymfonyFedoraproject Fedora24/11/202117/6/2026
Symfony/Serializer handles serializing and deserializing data structures for Symfony, a PHP framework for web and console applications and a set of reusable PHP components. Symfony versions 4.1.0 before 4.4.35 and versions 5.0.0 before 5.3.12 are vulnerable to CSV injection, also known as formula injection. In Symfony…
ModificadaAlta (8.8)1.3%—Sensiolabs Symfony24/11/202117/6/2026
Symfony/SecurityBundle is the security system for Symfony, a PHP framework for web and console applications and a set of reusable PHP components. Since the rework of the Remember me cookie in version 5.3.0, the cookie is not invalidated when the user changes their password. Attackers can therefore maintain their…
ModificadaMedia (6.5)1.3%—Sensiolabs Symfony24/11/202117/6/2026
Symfony/Http-Kernel is the HTTP kernel component for Symfony, a PHP framework for web and console applications and a set of reusable PHP components. Headers that are not part of the "trusted_headers" allowed list are ignored and protect users from "Cache poisoning" attacks. In Symfony 5.2, maintainers added support…
ModificadaAlta (7.8)0.26%—Intel Realsense D400 Series Universal Windows Platform Driver17/11/202117/6/2026
Uncontrolled search path in the Intel(R) RealSense(TM) D400 Series UWP driver for Windows 10 before version 6.1.160.22 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaAlta (7.8)0.23%—Intel NUC M15 Laptop KIT Integrated Sensor HUB Driver Pack17/11/202117/6/2026
Incorrect default permissions in the installer for the Intel(R) NUC M15 Laptop Kit Integrated Sensor Hub driver pack before version 5.4.1.4449 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaMedia (6.1)1.4%—Opnsense8/11/202117/6/2026
A Cross-site scripting (XSS) vulnerability was discovered in OPNsense before 21.7.4 via the LDAP attribute return in the authentication tester.
ModificadaMedia (5.4)1.1%—Netgate Pfsense12/7/202117/6/2026
An authenticated Cross-Site Scripting (XSS) vulnerability was found in widgets/widgets/wake_on_lan_widget.php, a component of the pfSense software WebGUI, on version 2.4.4-p2 and earlier. The widget did not encode the descr (description) parameter of wake-on-LAN entries in its output, leading to a possible stored XSS.
ModificadaMedia (5.4)3.5%—Netgate Pfsense12/7/202117/6/2026
A Stored Cross-Site Scripting (XSS) vulnerability was found in status_filter_reload.php, a page in the pfSense software WebGUI, on Netgate pfSense version 2.4.4-p2 and earlier. The page did not encode output from the filter reload process, and a stored XSS was possible via the descr (description) parameter on NAT…
ModificadaMedia (5.4)3.2%💥 ExploitAkcp Sensorprobe2 FirmwareAkcp Sensorprobe4 FirmwareAkcp Sensorprobe8 FirmwareAkcp Sensorprobe8-x20 Firmware+130/6/202117/6/2026
Stored cross-site scripting (XSS) in the embedded webserver of AKCP sensorProbe before SP480-20210624 enables remote authenticated attackers to introduce arbitrary JavaScript via the Sensor Description, Email (from/to/cc), System Name, and System Location fields.
ModificadaAlta (8.8)1.4%—Sensiolabs Symfony17/6/202117/6/2026
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. A vulnerability related to firewall authentication is in Symfony starting with version 5.3.0 and prior to 5.3.2. When an application defines multiple firewalls, the token authenticated by one of the firewalls was…
ModificadaMedia (6.8)0.26%—Intel Realsense ID F450 FirmwareIntel Realsense ID F455 Firmware9/6/202117/6/2026
Protection mechanism failure in some Intel(R) RealSense(TM) IDs may allow an unauthenticated user to potentially enable escalation of privilege via physical access.
ModificadaMedia (6.8)0.27%—Intel Realsense ID F450 FirmwareIntel Realsense ID F455 Firmware9/6/202117/6/2026
Improper authentication in some Intel(R) RealSense(TM) IDs may allow an unauthenticated user to potentially enable escalation of privilege via physical access.
ModificadaAlta (7.5)1.3%—Sensepost Gowitness9/6/202117/6/2026
A vulnerability exists in gowitness < 2.3.6 that allows an unauthenticated attacker to perform an arbitrary file read using the file:// scheme in the url parameter to get an image of any file.
ModificadaMedia (5.4)88%—Chiyu-tech Bf-631 FirmwareChiyu-tech Bf-630 FirmwareChiyu-tech Semac S2 FirmwareChiyu-tech Semac D1 Firmware+71/6/202117/6/2026
An XSS vulnerability exists in several IoT devices from CHIYU Technology, including SEMAC, Biosense, BF-630, BF-631, and Webpass due to a lack of sanitization on the component if.cgi - username parameter.