Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
576 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 0.97% | — | Qlikview ServerQlik AnalyticsQlik Sense | 1/5/2019 | 17/6/2026 | An issue was discovered in QlikView Server before 11.20 SR19, 12.00 and 12.10 before 12.10 SR11, 12.20 before SR9, and 12.30 before SR2; and Qlik Sense Enterprise and Qlik Analytics Platform installations that lack these patch levels: February 2018 Patch 4, April 2018 Patch 3, June 2018 Patch 3, September 2018 Patch… | |
| Modificada | Crítica (9.8) | 3.6% | — | Kentix Multisensor-lan Firmware | 21/3/2019 | 17/6/2026 | Kentix MultiSensor-LAN 5.63.00 devices and previous allow Authentication Bypass via an Alternate Path or Channel. | |
| Modificada | Alta (7.5) | 1.6% | — | Netgate Pfsense | 1/3/2019 | 17/6/2026 | In pfSense 2.4.4_1, blocking of source IP addresses on the basis of failed HTTPS authentication is inconsistent with blocking of source IP addresses on the basis of failed SSH authentication (the behavior does not match the sshguard documentation), which might make it easier for attackers to bypass intended access… | |
| Modificada | Alta (7.5) | 1.4% | — | Netgate Pfsense | 1/3/2019 | 17/6/2026 | The expiretable configuration in pfSense 2.4.4_1 establishes block durations that are incompatible with the block durations implemented by sshguard, which might make it easier for attackers to bypass intended access restrictions. | |
| Modificada | Alta (7.5) | 2.6% | — | Cisco Aironet Active SensorCisco Digital Network Architecture Center | 7/2/2019 | 17/6/2026 | A vulnerability in the default configuration of the Cisco Aironet Active Sensor could allow an unauthenticated, remote attacker to restart the sensor. The vulnerability is due to a default local account with a static password. The account has privileges only to reboot the device. An attacker could exploit this… | |
| Modificada | Media (6.1) | 1.5% | — | Sensiolabs SymfonyFedoraproject FedoraDebian Linux | 18/12/2018 | 17/6/2026 | An open redirect was discovered in Symfony 2.7.x before 2.7.50, 2.8.x before 2.8.49, 3.x before 3.4.20, 4.0.x before 4.0.15, 4.1.x before 4.1.9 and 4.2.x before 4.2.1. By using backslashes in the `_failure_path` input field of login forms, an attacker can work around the redirection target restrictions and effectively… | |
| Modificada | Media (5.3) | 3.6% | — | Sensiolabs SymfonyDebian Linux | 18/12/2018 | 17/6/2026 | An issue was discovered in Symfony 2.7.x before 2.7.50, 2.8.x before 2.8.49, 3.x before 3.4.20, 4.0.x before 4.0.15, 4.1.x before 4.1.9, and 4.2.x before 4.2.1. When using the scalar type hint `string` in a setter method (e.g. `setName(string $name)`) of a class that's the `data_class` of a form, and when a file… | |
| Modificada | Alta (7.2) | 72% | — | Netgate Pfsense | 3/12/2018 | 17/6/2026 | An exploitable command injection vulnerability exists in the way Netgate pfSense CE 2.4.4-RELEASE processes the parameters of a specific POST request. The attacker can exploit this and gain the ability to execute arbitrary commands on the system. An attacker needs to be able to send authenticated POST requests to the… | |
| Modificada | Alta (7.2) | 49% | — | Netgate Pfsense | 3/12/2018 | 17/6/2026 | An exploitable command injection vulnerability exists in the way Netgate pfSense CE 2.4.4-RELEASE processes the parameters of a specific POST request. The attacker can exploit this and gain the ability to execute arbitrary commands on the system. An attacker needs to be able to send authenticated POST requests to the… | |
| Modificada | Alta (7.2) | 49% | — | Netgate Pfsense | 3/12/2018 | 17/6/2026 | An exploitable command injection vulnerability exists in the way Netgate pfSense CE 2.4.4-RELEASE processes the parameters of a specific POST request. The attacker can exploit this and gain the ability to execute arbitrary commands on the system. An attacker needs to be able to send authenticated POST requests to the… | |
| Modificada | Alta (8.8) | 11% | — | Netgate Pfsense | 26/9/2018 | 17/6/2026 | An authenticated command injection vulnerability exists in status_interfaces.php via dhcp_relinquish_lease() in pfSense before 2.4.4 due to its passing user input from the $_POST parameters "ifdescr" and "ipv" to a shell without escaping the contents of the variables. This allows an authenticated WebGUI user with… | |
| Modificada | Media (6.5) | 0.62% | — | Qbeecam Qbee Multi-sensor Camera FirmwareQbeecamSwisscom Home APP | 18/9/2018 | 17/6/2026 | The QBee MultiSensor Camera through 4.16.4 accepts unencrypted network traffic from clients (such as the QBee Cam application through 1.0.5 for Android and the Swisscom Home application up to 10.7.2 for Android), which results in an attacker being able to reuse cookies to bypass authentication and disable the camera. | |
| Modificada | Media (6.5) | 1.6% | — | Sensiolabs SymfonyDebian Linux | 6/8/2018 | 17/6/2026 | An issue was discovered in Symfony before 2.7.38, 2.8.31, 3.2.14, 3.3.13, 3.4-BETA5, and 4.0-BETA5. When a form is submitted by the user, the request handler classes of the Form component merge POST data and uploaded files data into one array. This big array forms the data that are then bound to the form. At this… | |
| Modificada | Alta (7.5) | 2.7% | — | Sensiolabs SymfonyDebian Linux | 6/8/2018 | 17/6/2026 | An issue was discovered in Symfony before 2.7.38, 2.8.31, 3.2.14, 3.3.13, 3.4-BETA5, and 4.0-BETA5. The Intl component includes various bundle readers that are used to read resource bundles from the local filesystem. The read() methods of these classes use a path and a locale to determine the language bundle to… | |
| Modificada | Media (5.9) | 1.5% | — | Sensiolabs SymfonyDebian Linux | 6/8/2018 | 17/6/2026 | An issue was discovered in Symfony before 2.7.38, 2.8.31, 3.2.14, 3.3.13, 3.4-BETA5, and 4.0-BETA5. The current implementation of CSRF protection in Symfony (Version >=2) does not use different tokens for HTTP and HTTPS; therefore the token is subject to MITM attacks on HTTP and can then be used in an HTTPS context to… | |
| Modificada | Alta (7.2) | 1.1% | — | Sensiolabs Symfony | 3/8/2018 | 17/6/2026 | An issue was discovered in HttpKernel in Symfony 2.7.0 through 2.7.48, 2.8.0 through 2.8.43, 3.3.0 through 3.3.17, 3.4.0 through 3.4.13, 4.0.0 through 4.0.13, and 4.1.0 through 4.1.2. When using HttpCache, the values of the X-Forwarded-Host headers are implicitly set as trusted while this should be forbidden, leading… | |
| Modificada | Media (6.5) | 58% | — | Sensiolabs SymfonyDebian LinuxDrupal | 3/8/2018 | 17/6/2026 | An issue was discovered in Http Foundation in Symfony 2.7.0 through 2.7.48, 2.8.0 through 2.8.43, 3.3.0 through 3.3.17, 3.4.0 through 3.4.13, 4.0.0 through 4.0.13, and 4.1.0 through 4.1.2. It arises from support for a (legacy) IIS header that lets users override the path in the request URL via the X-Original-URL or… | |
| Modificada | Media (6.1) | 6.1% | — | Sensiolabs Symfony | 20/7/2018 | 17/6/2026 | The debug handler in Symfony before v2.7.33, 2.8.x before v2.8.26, 3.x before v3.2.13, and 3.3.x before v3.3.6 has XSS via an array key during exception pretty printing in ExceptionHandler.php, as demonstrated by a /_debugbar/open?op=get URI. NOTE: the vendor's position is that this is not a vulnerability because the… | |
| Modificada | Alta (8.8) | 1.2% | — | Sensu Core | 13/7/2018 | 17/6/2026 | Sensu, Inc. Sensu Core version Before version 1.4.2-3 contains a Insecure Permissions vulnerability in Sensu Core on Windows platforms that can result in Unprivileged users may execute code in context of Sensu service account. This attack appear to be exploitable via Unprivileged user may place an arbitrary DLL in the… | |
| Modificada | Media (6.1) | 1.3% | — | Sensiolabs Symfony | 13/6/2018 | 17/6/2026 | Reflected Cross-site scripting (XSS) vulnerability in the web profiler in SensioLabs Symfony 3.3.6 allows remote attackers to inject arbitrary web script or HTML via the "file" parameter, aka an _profiler/open?file= URI. NOTE: The vendor states "The XSS ... is in the web profiler, a tool that should never be deployed… | |
| Modificada | Media (6.1) | 1.1% | — | Sensiolabs SymfonyDebian Linux | 13/6/2018 | 17/6/2026 | The security handlers in the Security component in Symfony in 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and 4.0.x before 4.0.11 have an Open redirect vulnerability when security.http_utils is inlined by a container. NOTE: this issue exists because of an incomplete fix for… | |
| Modificada | Crítica (9.8) | 2.3% | — | Sensiolabs Symfony | 13/6/2018 | 17/6/2026 | An issue was discovered in the Ldap component in Symfony 2.8.x before 2.8.37, 3.3.x before 3.3.17, 3.4.x before 3.4.7, and 4.0.x before 4.0.7. It allows remote attackers to bypass authentication by logging in with a "null" password and valid username, which triggers an unauthenticated bind. NOTE: this issue exists… | |
| Modificada | Alta (8.8) | 0.76% | — | Sensiolabs SymfonyDebian Linux | 13/6/2018 | 17/6/2026 | An issue was discovered in the Security component in Symfony 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and 4.0.x before 4.0.11. By default, a user's session is invalidated when the user is logged out. This behavior can be disabled through the invalidate_session option. In this… | |
| Modificada | Media (5.9) | 1.6% | — | Sensiolabs SymfonyDebian Linux | 13/6/2018 | 17/6/2026 | An issue was discovered in the HttpFoundation component in Symfony 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and 4.0.x before 4.0.11. The PDOSessionHandler class allows storing sessions on a PDO connection. Under some configurations and with a well-crafted payload, it was… | |
| Modificada | Alta (8.1) | 2.0% | — | Sensiolabs SymfonyDebian LinuxFedoraproject Fedora | 13/6/2018 | 17/6/2026 | An issue was discovered in the Security component in Symfony 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and 4.0.x before 4.0.11. A session fixation vulnerability within the "Guard" login feature may allow an attacker to impersonate a victim towards the web application if the… |