Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
576 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 44% | 💥 Exploit | Chiyu-tech Semac S2 FirmwareChiyu-tech Semac D1 FirmwareChiyu-tech Semac D2 FirmwareChiyu-tech Semac D4 Firmware+7 | 1/6/2021 | 17/6/2026 | A denial of service condition exists after an integer overflow in several IoT devices from CHIYU Technology, including BIOSENSE, Webpass, and BF-630, BF-631, and SEMAC. The vulnerability can be explored by sending an unexpected integer (> 32 bits) on the page parameter that will crash the web portal and making it… | |
| Modificada | Media (5.4) | 5.3% | — | Pfsense | 1/6/2021 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability was discovered in pfSense 2.4.5-p1 which allows an authenticated attacker to execute arbitrary web scripts via exploitation of the load_balancer_monitor.php function. | |
| Modificada | Media (5.3) | 1.7% | 💥 PoC | Sensiolabs SymfonyFedoraproject Fedora | 13/5/2021 | 17/6/2026 | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. The ability to enumerate users was possible without relevant permissions due to different handling depending on whether the user existed or not when attempting to use the switch users functionality. We now ensure that… | |
| Modificada | Media (6.1) | 2.7% | 💥 Exploit | Opnsense | 3/5/2021 | 17/6/2026 | An open redirect issue was discovered in OPNsense through 20.1.5. The redirect parameter "url" in login page was not filtered and can redirect user to any website. | |
| Modificada | Media (6.1) | 27% | — | Pfsense | 28/4/2021 | 17/6/2026 | pfSense 2.5.0 allows XSS via the services_wol_edit.php Description field. | |
| Modificada | Media (5.4) | 0.80% | — | Larsens Calendar Project Larsens Calendar | 9/4/2021 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in the Larsens Calender plugin Version <= 1.2 for WordPress allows remote attackers to execute arbitrary web script via the "titel" column on the "Eintrage hinzufugen" tab. | |
| Modificada | Media (6.7) | 0.28% | — | Intel Realsense Depth Camera Manager | 17/2/2021 | 17/6/2026 | Incorrect default permissions in the installer for the Intel(R) RealSense(TM) DCM may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (4.8) | 0.61% | — | Bosch Praesideo FirmwareBosch Praesensa Firmware | 14/1/2021 | 17/6/2026 | A vulnerability in the web-based management interface of Bosch PRAESIDEO until and including version 4.41 and Bosch PRAESENSA until and including version 1.10 allows an authenticated remote attacker with admin privileges to mount a stored Cross-Site-Scripting (XSS) attack against another user. When the victim logs… | |
| Modificada | Alta (8.8) | 0.55% | — | Bosch Praesideo FirmwareBosch Praesensa Firmware | 14/1/2021 | 17/6/2026 | A vulnerability in the web-based management interface of Bosch PRAESIDEO until and including version 4.41 and Bosch PRAESENSA until and including version 1.10 allows an unauthenticated remote attacker to trigger actions on an affected system on behalf of another user (Cross-Site Request Forgery). This requires the… | |
| Modificada | Alta (7.8) | 0.28% | — | Intel Realsense D400 Series Dynamic Calibration Tool | 12/11/2020 | 17/6/2026 | Incorrect default permissions in the Intel(R) RealSense(TM) D400 Series Dynamic Calibration Tool before version 2.11, may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (8.8) | 3.0% | — | Sensiolabs HttpclientSensiolabs SymfonyFedoraproject Fedora | 2/9/2020 | 17/6/2026 | In Symfony before versions 4.4.13 and 5.1.5, the CachingHttpClient class from the HttpClient Symfony component relies on the HttpCache class to handle requests. HttpCache uses internal headers like X-Body-Eval and X-Body-File to control the restoration of cached responses. The class was initially written with… | |
| Modificada | Alta (8.8) | 2.0% | — | Senstar Symphony | 1/9/2020 | 17/6/2026 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Senstar Symphony 7.3.2.2. Authentication is not required to exploit this vulnerability. The specific flaw exists within the SSOAuth process. The issue results from the lack of proper validation of user-supplied… | |
| Modificada | Alta (7.8) | 0.28% | — | Intel Realsense D415 FirmwareIntel Realsense D435 FirmwareIntel Realsense D435i Firmware | 13/8/2020 | 17/6/2026 | Improper permissions in the installer for the Intel(R) RealSense(TM) D400 Series UWP driver for Windows* 10 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (6.1) | 2.4% | — | Netgate Pfsense | 29/4/2020 | 17/6/2026 | An XSS vulnerability resides in the hostname field of the diag_ping.php page in pfsense before 2.4.5 version. After passing inputs to the command and executing this command, the $result variable is not sanitized before it is printed. | |
| Modificada | Alta (7.5) | 1.2% | — | Sharp Aquos Sh-m02 FirmwareSharp Aquos Sh-rm02 FirmwareSharp Aquos Mini Sh-m03 FirmwareSharp Aquos L2 Firmware+6 | 23/4/2020 | 17/6/2026 | SHARP AQUOS series (AQUOS SH-M02 build number 01.00.05 and earlier, AQUOS SH-RM02 build number 01.00.04 and earlier, AQUOS mini SH-M03 build number 01.00.04 and earlier, AQUOS Keitai SH-N01 build number 01.00.01 and earlier, AQUOS L2 (UQ mobile/J:COM) build number 01.00.05 and earlier, AQUOS sense lite SH-M05 build… | |
| Modificada | Media (5.4) | 9.3% | 💥 Exploit | Netgate Pfsense | 1/4/2020 | 17/6/2026 | pfSense before 2.4.5 has stored XSS in system_usermanager_addprivs.php in the WebGUI via the descr parameter (aka full name) of a user. | |
| Modificada | Alta (8.1) | 1.1% | — | Sensiolabs Symfony | 30/3/2020 | 17/6/2026 | In symfony/security-http before versions 4.4.7 and 5.0.7, when a `Firewall` checks access control rule, it iterate overs each rule's attributes and stops as soon as the accessDecisionManager decides to grant access on the attribute, preventing the check of next attributes that should have been take into account in an… | |
| Modificada | Media (5.4) | 1.2% | — | Sensiolabs Symfony | 30/3/2020 | 17/6/2026 | In Symfony before versions 5.0.5 and 4.4.5, some properties of the Exception were not properly escaped when the `ErrorHandler` rendered it stacktrace. In addition, the stacktrace were displayed even in a non-debug configuration. The ErrorHandler now escape alls properties of the exception, and the stacktrace is only… | |
| Modificada | Media (4.3) | 1.3% | — | Sensiolabs Symfony | 30/3/2020 | 17/6/2026 | In Symfony before versions 4.4.7 and 5.0.7, when a `Response` does not contain a `Content-Type` header, affected versions of Symfony can fallback to the format defined in the `Accept` header of the request, leading to a possible mismatch between the response's content and `Content-Type` header. When the response… | |
| Modificada | Alta (7) | 1.9% | — | Trendmicro Control ManagerTrendmicro Endpoint SensorTrendmicro IM SecurityTrendmicro Mobile Security+4 | 20/2/2020 | 17/6/2026 | Trend Micro has repackaged installers for several Trend Micro products that were found to utilize a version of an install package that had a DLL hijack vulnerability that could be exploited during a new product installation. The vulnerability was found to ONLY be exploitable during an initial product installation by… | |
| Modificada | Crítica (9.8) | 2.9% | — | Netvu Dv-ip Express FirmwareNetvu Sd-advanced - Sdhd FirmwareNetvu Sd-advanced 8/12/16 VGA FirmwareNetvu SD Advanced Closed Iptv (m3u) Firmware+16 | 6/2/2020 | 17/6/2026 | Dedicated Micros DV-IP Express, SD Advanced, SD, EcoSense, and DS2 devices rely on a GUI warning to help ensure that the administrator configures login credentials, which makes it easier for remote attackers to obtain access by leveraging situations in which this warning was not heeded. NOTE: the vendor states "The… | |
| Modificada | Alta (7.4) | 1.2% | — | 77bank 77 BankAshikagabank AshiginHokkaidobank DoginHokugin Hokuriku Bank Portal+5 | 28/1/2020 | 17/6/2026 | Android App 'MyPallete' and some of the Android banking applications based on 'MyPallete' do not verify X.509 certificates from servers, and also do not properly validate certificates with host-mismatch, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted… | |
| Modificada | Media (6.1) | 2.3% | — | Sensiolabs SymfonyFedoraproject Fedora | 2/1/2020 | 16/6/2026 | Symfony 2.0.X before 2.0.24, 2.1.X before 2.1.12, 2.2.X before 2.2.5, and 2.3.X before 2.3.3 have an issue in the HttpFoundation component. The Host header can be manipulated by an attacker when the framework is generating an absolute URL. A remote attacker could exploit this vulnerability to inject malicious content… | |
| Modificada | Crítica (9.8) | 33% | — | Sensiolabs SymfonyFedoraproject Fedora | 21/11/2019 | 17/6/2026 | An issue was discovered in Symfony 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4.3.7. Serializing certain cache adapter interfaces could result in remote code injection. This is related to symfony/cache. | |
| Modificada | Alta (7.5) | 2.2% | — | Sensiolabs SymfonyFedoraproject Fedora | 21/11/2019 | 17/6/2026 | An issue was discovered in Symfony 2.8.0 through 2.8.50, 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4.3.7. If an application passes unvalidated user input as the file for which MIME type validation should occur, then arbitrary arguments are passed to the underlying file command. This is related to… |