Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

576 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.1)1.3%—Sensiolabs SymfonyFedoraproject Fedora21/11/201917/6/2026
An issue was discovered in Symfony 2.8.0 through 2.8.50, 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4.3.7. The UriSigner was subject to timing attacks. This is related to symfony/http-kernel.
ModificadaCrítica (9.8)3.4%—Sensiolabs Symfony21/11/201917/6/2026
An issue was discovered in Symfony before 4.2.12 and 4.3.x before 4.3.8. The VarExport component incorrectly escapes strings, allowing some specially crafted ones to escalate to execution of arbitrary PHP code. This is related to symfony/var-exporter.
ModificadaMedia (5.3)1.6%—Sensiolabs Symfony21/11/201917/6/2026
An issue was discovered in Symfony 4.2.0 to 4.2.11 and 4.3.0 to 4.3.7. The ability to enumerate users was possible due to different handling depending on whether the user existed when making unauthorized attempts to use the switch users functionality. This is related to symfony/security.
ModificadaMedia (5.5)0.29%—Hisense Infinity F17 Firmware14/11/201917/6/2026
The Hisense F17 Android device with a build fingerprint of Hisense/F17_4G/HS6739MT:8.1.0/O11019/Hisense_F17_4G_00_S01:user/release-keys contains a pre-installed app with a package name of com.mediatek.wfo.impl app (versionCode=27, versionName=8.1.0) that allows any app co-located on the device to modify a system…
ModificadaMedia (5.5)0.29%—Hisense Infinity U965 Firmware14/11/201917/6/2026
The Hisense U965 Android device with a build fingerprint of Hisense/U965_4G_10/HS6739MT:8.1.0/O11019/Hisense_U965_4G_10_S01:user/release-keys contains a pre-installed app with a package name of com.mediatek.wfo.impl app (versionCode=27, versionName=8.1.0) that allows any app co-located on the device to modify a system…
ModificadaMedia (6.1)4.0%—Pfsense-pkg-freeradius32/11/201917/6/2026
/usr/local/www/freeradius_view_config.php in the freeradius3 package before 0.15.7_3 for pfSense on FreeBSD allows a user with an XSS payload as password or username to execute arbitrary javascript code on a victim browser.
ModificadaAlta (8.1)1.4%—Sensiolabs SymfonyFedoraproject FedoraRedhat Enterprise Linux1/11/201916/6/2026
php-symfony2-Validator has loss of information during serialization
ModificadaAlta (8.8)55%💥 ExploitNetgate Pfsense26/9/201917/6/2026
diag_command.php in pfSense 2.4.4-p3 allows CSRF via the txtCommand or txtRecallBuffer field, as demonstrated by executing OS commands. This occurs because csrf_callback() produces a "CSRF token expired" error and a Try Again button when a CSRF token is missing.
ModificadaCrítica (9.8)3.7%—Netgate Pfsense26/9/201917/6/2026
An issue was discovered in pfSense through 2.4.4-p3. widgets/widgets/picture.widget.php uses the widgetkey parameter directly without sanitization (e.g., a basename call) for a pathname to file_get_contents or file_put_contents.
ModificadaMedia (6.1)2.0%—Netgate Pfsense26/9/201917/6/2026
An XSS issue was discovered in pfSense through 2.4.4-p3. In services_captiveportal_mac.php, the username and delmac parameters are displayed without sanitization.
ModificadaAlta (8.8)20%💥 ExploitNetgate Pfsense25/9/201917/6/2026
pfSense through 2.3.4 through 2.4.4-p3 allows Remote Code Injection via a methodCall XML document with a pfsense.exec_php call containing shell metacharacters in a parameter value.
ModificadaCrítica (9.8)2.2%—Dynamicpress Neosense13/9/201917/6/2026
The Neosense theme before 1.8 for WordPress has qquploader unrestricted file upload.
ModificadaMedia (6.1)1.5%💥 ExploitGoogle Adsense Project Google Adsense13/8/201917/6/2026
The adsense-plugin (aka Google AdSense) plugin before 1.44 for WordPress has multiple XSS issues.
ModificadaMedia (6.1)3.0%💥 PoCNetgate Pfsense25/6/201917/6/2026
In pfSense 2.4.4-p2 and 2.4.4-p3, if it is possible to trick an authenticated administrator into clicking on a button on a phishing page, an attacker can leverage XSS to upload arbitrary executable code, via diag_command.php and rrd_fetch_json.php (timePeriod parameter), to a server. Then, the remote attacker can run…
ModificadaMedia (6.5)0.64%—Opnsense17/6/201917/6/2026
OPNsense 18.7.x before 18.7.7 has Incorrect Access Control.
ModificadaCrítica (9.8)5.0%—ApcupsdNetgate Pfsense3/6/201917/6/2026
Apcupsd 0.3.91_5, as used in pfSense through 2.4.4-RELEASE-p3 and other products, has an Arbitrary Command Execution issue in apcupsd_status.php.
ModificadaMedia (6.1)2.6%—ApcupsdNetgate Pfsense3/6/201917/6/2026
Apcupsd 0.3.91_5, as used in pfSense through 2.4.4-RELEASE-p3 and other products, has an XSS issue in apcupsd_status.php.
ModificadaMedia (6.1)59%💥 ExploitNetgate Pfsense29/5/201917/6/2026
In pfSense 2.4.4-p3, a stored XSS vulnerability occurs when attackers inject a payload into the Name or Description field via an acme_accountkeys_edit.php action. The vulnerability occurs due to input validation errors.
ModificadaCrítica (9.8)1.9%—Sensiolabs Symfony23/5/201917/6/2026
Certain Symfony products are affected by: Incorrect Access Control. This affects Symfony 2.7.30 and Symfony 2.8.23 and Symfony 3.2.10 and Symfony 3.3.3. The type of exploitation is: remote. The component is: Password validator.
ModificadaAlta (7.2)3.2%—Netgate PfsenseOpnsense20/5/201917/6/2026
Incorrect access control in the WebUI in OPNsense before version 19.1.8, and pfsense before 2.4.4-p3 allows remote authenticated users to escalate privileges to administrator via a specially crafted request.
ModificadaCrítica (9.8)1.9%—Sensiolabs Symfony16/5/201917/6/2026
In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, HTTP Methods provided as verbs or using the override header may be treated as trusted input, but they are not validated, possibly causing SQL injection or XSS. This is related to symfony/http-foundation.
ModificadaAlta (7.1)2.3%—Sensiolabs Symfony16/5/201917/6/2026
In Symfony before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, it is possible to cache objects that may contain bad user input. On serialization or unserialization, this could result in the deletion of files that the current user has access to. This is related to symfony/cache and…
ModificadaAlta (7.5)1.2%—Sensiolabs SymfonyDrupal16/5/201917/6/2026
In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, a vulnerability would allow an attacker to authenticate as a privileged user on sites with user registration and remember me login functionality enabled. This is related to symfony/security.
ModificadaCrítica (9.8)6.0%—Sensiolabs SymfonyDrupal16/5/201917/6/2026
In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, when service ids allow user input, this could allow for SQL Injection and remote code execution. This is related to symfony/dependency-injection.
ModificadaMedia (5.4)1.0%💥 PoCSensiolabs SymfonyDrupal16/5/201917/6/2026
In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, validation messages are not escaped, which can lead to XSS when user input is included. This is related to symfony/framework-bundle.
Orbitaley — Vulnerabilidades