Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
576 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.1) | 1.3% | — | Sensiolabs SymfonyFedoraproject Fedora | 21/11/2019 | 17/6/2026 | An issue was discovered in Symfony 2.8.0 through 2.8.50, 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4.3.7. The UriSigner was subject to timing attacks. This is related to symfony/http-kernel. | |
| Modificada | Crítica (9.8) | 3.4% | — | Sensiolabs Symfony | 21/11/2019 | 17/6/2026 | An issue was discovered in Symfony before 4.2.12 and 4.3.x before 4.3.8. The VarExport component incorrectly escapes strings, allowing some specially crafted ones to escalate to execution of arbitrary PHP code. This is related to symfony/var-exporter. | |
| Modificada | Media (5.3) | 1.6% | — | Sensiolabs Symfony | 21/11/2019 | 17/6/2026 | An issue was discovered in Symfony 4.2.0 to 4.2.11 and 4.3.0 to 4.3.7. The ability to enumerate users was possible due to different handling depending on whether the user existed when making unauthorized attempts to use the switch users functionality. This is related to symfony/security. | |
| Modificada | Media (5.5) | 0.29% | — | Hisense Infinity F17 Firmware | 14/11/2019 | 17/6/2026 | The Hisense F17 Android device with a build fingerprint of Hisense/F17_4G/HS6739MT:8.1.0/O11019/Hisense_F17_4G_00_S01:user/release-keys contains a pre-installed app with a package name of com.mediatek.wfo.impl app (versionCode=27, versionName=8.1.0) that allows any app co-located on the device to modify a system… | |
| Modificada | Media (5.5) | 0.29% | — | Hisense Infinity U965 Firmware | 14/11/2019 | 17/6/2026 | The Hisense U965 Android device with a build fingerprint of Hisense/U965_4G_10/HS6739MT:8.1.0/O11019/Hisense_U965_4G_10_S01:user/release-keys contains a pre-installed app with a package name of com.mediatek.wfo.impl app (versionCode=27, versionName=8.1.0) that allows any app co-located on the device to modify a system… | |
| Modificada | Media (6.1) | 4.0% | — | Pfsense-pkg-freeradius3 | 2/11/2019 | 17/6/2026 | /usr/local/www/freeradius_view_config.php in the freeradius3 package before 0.15.7_3 for pfSense on FreeBSD allows a user with an XSS payload as password or username to execute arbitrary javascript code on a victim browser. | |
| Modificada | Alta (8.1) | 1.4% | — | Sensiolabs SymfonyFedoraproject FedoraRedhat Enterprise Linux | 1/11/2019 | 16/6/2026 | php-symfony2-Validator has loss of information during serialization | |
| Modificada | Alta (8.8) | 55% | 💥 Exploit | Netgate Pfsense | 26/9/2019 | 17/6/2026 | diag_command.php in pfSense 2.4.4-p3 allows CSRF via the txtCommand or txtRecallBuffer field, as demonstrated by executing OS commands. This occurs because csrf_callback() produces a "CSRF token expired" error and a Try Again button when a CSRF token is missing. | |
| Modificada | Crítica (9.8) | 3.7% | — | Netgate Pfsense | 26/9/2019 | 17/6/2026 | An issue was discovered in pfSense through 2.4.4-p3. widgets/widgets/picture.widget.php uses the widgetkey parameter directly without sanitization (e.g., a basename call) for a pathname to file_get_contents or file_put_contents. | |
| Modificada | Media (6.1) | 2.0% | — | Netgate Pfsense | 26/9/2019 | 17/6/2026 | An XSS issue was discovered in pfSense through 2.4.4-p3. In services_captiveportal_mac.php, the username and delmac parameters are displayed without sanitization. | |
| Modificada | Alta (8.8) | 20% | 💥 Exploit | Netgate Pfsense | 25/9/2019 | 17/6/2026 | pfSense through 2.3.4 through 2.4.4-p3 allows Remote Code Injection via a methodCall XML document with a pfsense.exec_php call containing shell metacharacters in a parameter value. | |
| Modificada | Crítica (9.8) | 2.2% | — | Dynamicpress Neosense | 13/9/2019 | 17/6/2026 | The Neosense theme before 1.8 for WordPress has qquploader unrestricted file upload. | |
| Modificada | Media (6.1) | 1.5% | 💥 Exploit | Google Adsense Project Google Adsense | 13/8/2019 | 17/6/2026 | The adsense-plugin (aka Google AdSense) plugin before 1.44 for WordPress has multiple XSS issues. | |
| Modificada | Media (6.1) | 3.0% | 💥 PoC | Netgate Pfsense | 25/6/2019 | 17/6/2026 | In pfSense 2.4.4-p2 and 2.4.4-p3, if it is possible to trick an authenticated administrator into clicking on a button on a phishing page, an attacker can leverage XSS to upload arbitrary executable code, via diag_command.php and rrd_fetch_json.php (timePeriod parameter), to a server. Then, the remote attacker can run… | |
| Modificada | Media (6.5) | 0.64% | — | Opnsense | 17/6/2019 | 17/6/2026 | OPNsense 18.7.x before 18.7.7 has Incorrect Access Control. | |
| Modificada | Crítica (9.8) | 5.0% | — | ApcupsdNetgate Pfsense | 3/6/2019 | 17/6/2026 | Apcupsd 0.3.91_5, as used in pfSense through 2.4.4-RELEASE-p3 and other products, has an Arbitrary Command Execution issue in apcupsd_status.php. | |
| Modificada | Media (6.1) | 2.6% | — | ApcupsdNetgate Pfsense | 3/6/2019 | 17/6/2026 | Apcupsd 0.3.91_5, as used in pfSense through 2.4.4-RELEASE-p3 and other products, has an XSS issue in apcupsd_status.php. | |
| Modificada | Media (6.1) | 59% | 💥 Exploit | Netgate Pfsense | 29/5/2019 | 17/6/2026 | In pfSense 2.4.4-p3, a stored XSS vulnerability occurs when attackers inject a payload into the Name or Description field via an acme_accountkeys_edit.php action. The vulnerability occurs due to input validation errors. | |
| Modificada | Crítica (9.8) | 1.9% | — | Sensiolabs Symfony | 23/5/2019 | 17/6/2026 | Certain Symfony products are affected by: Incorrect Access Control. This affects Symfony 2.7.30 and Symfony 2.8.23 and Symfony 3.2.10 and Symfony 3.3.3. The type of exploitation is: remote. The component is: Password validator. | |
| Modificada | Alta (7.2) | 3.2% | — | Netgate PfsenseOpnsense | 20/5/2019 | 17/6/2026 | Incorrect access control in the WebUI in OPNsense before version 19.1.8, and pfsense before 2.4.4-p3 allows remote authenticated users to escalate privileges to administrator via a specially crafted request. | |
| Modificada | Crítica (9.8) | 1.9% | — | Sensiolabs Symfony | 16/5/2019 | 17/6/2026 | In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, HTTP Methods provided as verbs or using the override header may be treated as trusted input, but they are not validated, possibly causing SQL injection or XSS. This is related to symfony/http-foundation. | |
| Modificada | Alta (7.1) | 2.3% | — | Sensiolabs Symfony | 16/5/2019 | 17/6/2026 | In Symfony before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, it is possible to cache objects that may contain bad user input. On serialization or unserialization, this could result in the deletion of files that the current user has access to. This is related to symfony/cache and… | |
| Modificada | Alta (7.5) | 1.2% | — | Sensiolabs SymfonyDrupal | 16/5/2019 | 17/6/2026 | In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, a vulnerability would allow an attacker to authenticate as a privileged user on sites with user registration and remember me login functionality enabled. This is related to symfony/security. | |
| Modificada | Crítica (9.8) | 6.0% | — | Sensiolabs SymfonyDrupal | 16/5/2019 | 17/6/2026 | In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, when service ids allow user input, this could allow for SQL Injection and remote code execution. This is related to symfony/dependency-injection. | |
| Modificada | Media (5.4) | 1.0% | 💥 PoC | Sensiolabs SymfonyDrupal | 16/5/2019 | 17/6/2026 | In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, validation messages are not escaped, which can lead to XSS when user input is included. This is related to symfony/framework-bundle. |