Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
576 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 1.9% | — | Netgate PfsenseNetgate Pfsense Plus | 31/3/2022 | 17/6/2026 | Improper input validation vulnerability in pfSense CE and pfSense Plus (pfSense CE software versions prior to 2.6.0 and pfSense Plus software versions prior to 22.01) allows a remote attacker with the privilege to change OpenVPN client or server settings to execute an arbitrary command. | |
| Modificada | Media (6.1) | 2.9% | — | Netgate Pfsense PlusPfsense | 31/3/2022 | 17/6/2026 | Cross-site scripting vulnerability in pfSense CE and pfSense Plus (pfSense CE software versions 2.5.2 and earlier, and pfSense Plus software versions 21.05 and earlier) allows a remote attacker to inject an arbitrary script via a malicious URL. | |
| Modificada | Media (6.5) | 1.8% | — | Pfsense-pkg-wireguard | 10/3/2022 | 17/6/2026 | Directory traversal vulnerability in pfSense-pkg-WireGuard pfSense-pkg-WireGuard 0.1.5 versions prior to 0.1.5_4 and pfSense-pkg-WireGuard 0.1.6 versions prior to 0.1.6_1 allows a remote authenticated attacker to lead a pfSense user to view a file outside the public folder. | |
| Modificada | Media (5.9) | 1.9% | — | Microsoft Defender FOR Endpoint EDR SensorMicrosoft Defender FOR Endpoint | 9/3/2022 | 17/6/2026 | Microsoft Defender for Endpoint Spoofing Vulnerability | |
| Modificada | Alta (8.8) | 87% | 💥 Exploit | Pfsense | 1/3/2022 | 17/6/2026 | diag_routes.php in pfSense 2.5.2 allows sed data injection. Authenticated users are intended to be able to view data about the routes set in the firewall. The data is retrieved by executing the netstat utility, and then its output is parsed via the sed utility. Although the common protection mechanisms against command… | |
| Modificada | Media (5.3) | 1.4% | — | Qlik Sense | 21/2/2022 | 17/6/2026 | A vulnerability in Qlik Sense Enterprise on Windows could allow an remote attacker to enumerate domain user accounts. An attacker could exploit this vulnerability by sending authentication requests to an affected system. A successful exploit could allow the attacker to compare the response time that are returned by… | |
| Modificada | Media (5.5) | 0.24% | — | Intel Realsense Depth Camera Manager | 9/2/2022 | 17/6/2026 | Improper access control in the Intel(R) RealSense(TM) DCM before version 20210625 may allow an authenticated user to potentially enable information disclosure via local access. | |
| Modificada | Alta (8.8) | 0.57% | — | Sensiolabs Symfony | 1/2/2022 | 17/6/2026 | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. The Symfony form component provides a CSRF protection mechanism by using a random token injected in the form and using the session to store and control the token submitted by the user. When using the FrameworkBundle, this… | |
| Modificada | Media (6.1) | 1.5% | — | PfsensePfsense Plus | 26/1/2022 | 17/6/2026 | /usr/local/www/pkg.php in pfSense CE before 2.6.0 and pfSense Plus before 22.01 uses $_REQUEST['pkg_filter'] in a PHP echo call, causing XSS. | |
| Analizada | Crítica (9) | 100% | ⚠ Explotación activa💥 Exploit | Apache Log4jCvat Computer Vision Annotation ToolIntel Audio Development KITIntel Datacenter Manager+51 | 14/12/2021 | 17/6/2026 | It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows attackers with control over Thread Context Map (MDC) input data when the logging configuration uses a non-default Pattern Layout with either a Context Lookup (for example,… | |
| Analizada | Crítica (10) | 100% | ⚠ Explotación activa💥 Exploit | Siemens 6bk1602-0aa12-0tp0 FirmwareSiemens 6bk1602-0aa22-0tp0 FirmwareSiemens 6bk1602-0aa32-0tp0 FirmwareSiemens 6bk1602-0aa42-0tp0 Firmware+139 | 10/12/2021 | 11/8/2026 | Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can… | |
| Modificada | Media (6.5) | 1.4% | — | Sensiolabs SymfonyFedoraproject Fedora | 24/11/2021 | 17/6/2026 | Symfony/Serializer handles serializing and deserializing data structures for Symfony, a PHP framework for web and console applications and a set of reusable PHP components. Symfony versions 4.1.0 before 4.4.35 and versions 5.0.0 before 5.3.12 are vulnerable to CSV injection, also known as formula injection. In Symfony… | |
| Modificada | Alta (8.8) | 1.3% | — | Sensiolabs Symfony | 24/11/2021 | 17/6/2026 | Symfony/SecurityBundle is the security system for Symfony, a PHP framework for web and console applications and a set of reusable PHP components. Since the rework of the Remember me cookie in version 5.3.0, the cookie is not invalidated when the user changes their password. Attackers can therefore maintain their… | |
| Modificada | Media (6.5) | 1.3% | — | Sensiolabs Symfony | 24/11/2021 | 17/6/2026 | Symfony/Http-Kernel is the HTTP kernel component for Symfony, a PHP framework for web and console applications and a set of reusable PHP components. Headers that are not part of the "trusted_headers" allowed list are ignored and protect users from "Cache poisoning" attacks. In Symfony 5.2, maintainers added support… | |
| Modificada | Alta (7.8) | 0.26% | — | Intel Realsense D400 Series Universal Windows Platform Driver | 17/11/2021 | 17/6/2026 | Uncontrolled search path in the Intel(R) RealSense(TM) D400 Series UWP driver for Windows 10 before version 6.1.160.22 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.8) | 0.23% | — | Intel NUC M15 Laptop KIT Integrated Sensor HUB Driver Pack | 17/11/2021 | 17/6/2026 | Incorrect default permissions in the installer for the Intel(R) NUC M15 Laptop Kit Integrated Sensor Hub driver pack before version 5.4.1.4449 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (6.1) | 1.4% | — | Opnsense | 8/11/2021 | 17/6/2026 | A Cross-site scripting (XSS) vulnerability was discovered in OPNsense before 21.7.4 via the LDAP attribute return in the authentication tester. | |
| Modificada | Media (5.4) | 1.1% | — | Netgate Pfsense | 12/7/2021 | 17/6/2026 | An authenticated Cross-Site Scripting (XSS) vulnerability was found in widgets/widgets/wake_on_lan_widget.php, a component of the pfSense software WebGUI, on version 2.4.4-p2 and earlier. The widget did not encode the descr (description) parameter of wake-on-LAN entries in its output, leading to a possible stored XSS. | |
| Modificada | Media (5.4) | 3.5% | — | Netgate Pfsense | 12/7/2021 | 17/6/2026 | A Stored Cross-Site Scripting (XSS) vulnerability was found in status_filter_reload.php, a page in the pfSense software WebGUI, on Netgate pfSense version 2.4.4-p2 and earlier. The page did not encode output from the filter reload process, and a stored XSS was possible via the descr (description) parameter on NAT… | |
| Modificada | Media (5.4) | 3.2% | 💥 Exploit | Akcp Sensorprobe2 FirmwareAkcp Sensorprobe4 FirmwareAkcp Sensorprobe8 FirmwareAkcp Sensorprobe8-x20 Firmware+1 | 30/6/2021 | 17/6/2026 | Stored cross-site scripting (XSS) in the embedded webserver of AKCP sensorProbe before SP480-20210624 enables remote authenticated attackers to introduce arbitrary JavaScript via the Sensor Description, Email (from/to/cc), System Name, and System Location fields. | |
| Modificada | Alta (8.8) | 1.4% | — | Sensiolabs Symfony | 17/6/2021 | 17/6/2026 | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. A vulnerability related to firewall authentication is in Symfony starting with version 5.3.0 and prior to 5.3.2. When an application defines multiple firewalls, the token authenticated by one of the firewalls was… | |
| Modificada | Media (6.8) | 0.26% | — | Intel Realsense ID F450 FirmwareIntel Realsense ID F455 Firmware | 9/6/2021 | 17/6/2026 | Protection mechanism failure in some Intel(R) RealSense(TM) IDs may allow an unauthenticated user to potentially enable escalation of privilege via physical access. | |
| Modificada | Media (6.8) | 0.27% | — | Intel Realsense ID F450 FirmwareIntel Realsense ID F455 Firmware | 9/6/2021 | 17/6/2026 | Improper authentication in some Intel(R) RealSense(TM) IDs may allow an unauthenticated user to potentially enable escalation of privilege via physical access. | |
| Modificada | Alta (7.5) | 1.3% | — | Sensepost Gowitness | 9/6/2021 | 17/6/2026 | A vulnerability exists in gowitness < 2.3.6 that allows an unauthenticated attacker to perform an arbitrary file read using the file:// scheme in the url parameter to get an image of any file. | |
| Modificada | Media (5.4) | 88% | — | Chiyu-tech Bf-631 FirmwareChiyu-tech Bf-630 FirmwareChiyu-tech Semac S2 FirmwareChiyu-tech Semac D1 Firmware+7 | 1/6/2021 | 17/6/2026 | An XSS vulnerability exists in several IoT devices from CHIYU Technology, including SEMAC, Biosense, BF-630, BF-631, and Webpass due to a lack of sanitization on the component if.cgi - username parameter. |