Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
43 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.60% | — | Opnsense | 28/9/2023 | 17/6/2026 | OPNsense before 23.7.5 allows XSS via the index.php column_count parameter to the Lobby Dashboard. | |
| Modificada | Crítica (9.8) | 3.1% | — | Opnsense | 9/8/2023 | 17/6/2026 | A command injection vulnerability in the component /api/cron/settings/setJob/ of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows attackers to execute arbitrary system commands. | |
| Modificada | Crítica (9.6) | 2.6% | 💥 Exploit | Opnsense | 9/8/2023 | 17/6/2026 | /ui/cron/item/open in the Cron component of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows XSS via openAction in app/controllers/OPNsense/Cron/ItemController.php. | |
| Modificada | Media (5.4) | 0.48% | — | Opnsense | 9/8/2023 | 17/6/2026 | The Crash Reporter (crash_reporter.php) component of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 mishandles input sanitization. | |
| Modificada | Alta (7.5) | 0.72% | — | Opnsense | 9/8/2023 | 17/6/2026 | Insecure permissions exist for configd.socket in OPNsense Community Edition before 23.7 and Business Edition before 23.4.2. | |
| Modificada | Crítica (9.8) | 0.99% | — | Opnsense | 9/8/2023 | 9/7/2026 | Insecure permissions in the configuration directory (/conf/) of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allow attackers to access sensitive information (e.g., hashed root password) which could lead to privilege escalation. | |
| Modificada | Alta (7.5) | 0.79% | — | Opnsense | 9/8/2023 | 9/7/2026 | OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 was discovered to contain insecure permissions in the directory /tmp. | |
| Modificada | Media (6.1) | 1.2% | 💥 Exploit | Opnsense | 9/8/2023 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in the act parameter of system_certmanager.php in OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. | |
| Modificada | Crítica (9.8) | 3.6% | — | Opnsense | 9/8/2023 | 17/6/2026 | A command injection vulnerability in the component diag_backup.php of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows attackers to execute arbitrary commands via a crafted backup configuration file. | |
| Modificada | Media (6.1) | 0.57% | — | Opnsense | 9/8/2023 | 17/6/2026 | A reflected cross-site scripting (XSS) vulnerability in the component /ui/diagnostics/log/core/ of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows attackers to inject arbitrary JavaScript via the URL path. | |
| Modificada | Media (6.5) | 0.40% | — | Opnsense | 9/8/2023 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) in the System Halt API (/system/halt) of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows attackers to cause a Denial of Service (DoS) via a crafted GET request. | |
| Modificada | Media (6.1) | 0.59% | — | Opnsense | 9/8/2023 | 17/6/2026 | An open redirect in the Login page of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows attackers to redirect a victim user to an arbitrary web site via a crafted URL. | |
| Modificada | Alta (7.2) | 1.4% | — | Opnsense | 9/8/2023 | 17/6/2026 | A directory traversal vulnerability in the Captive Portal templates of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows attackers to execute arbitrary system commands as root via a crafted ZIP archive. | |
| Modificada | Media (6.1) | 1.4% | — | Opnsense | 8/11/2021 | 17/6/2026 | A Cross-site scripting (XSS) vulnerability was discovered in OPNsense before 21.7.4 via the LDAP attribute return in the authentication tester. | |
| Modificada | Media (6.1) | 2.7% | 💥 Exploit | Opnsense | 3/5/2021 | 17/6/2026 | An open redirect issue was discovered in OPNsense through 20.1.5. The redirect parameter "url" in login page was not filtered and can redirect user to any website. | |
| Modificada | Media (6.5) | 0.64% | — | Opnsense | 17/6/2019 | 17/6/2026 | OPNsense 18.7.x before 18.7.7 has Incorrect Access Control. | |
| Modificada | Alta (7.2) | 3.2% | — | Netgate PfsenseOpnsense | 20/5/2019 | 17/6/2026 | Incorrect access control in the WebUI in OPNsense before version 19.1.8, and pfsense before 2.4.4-p3 allows remote authenticated users to escalate privileges to administrator via a specially crafted request. | |
| Modificada | Alta (8.8) | 32% | 💥 Exploit | Netgate PfsenseOpnsense Project Opnsense | 3/1/2018 | 17/6/2026 | pfSense versions 2.4.1 and lower are vulnerable to clickjacking attacks in the CSRF error page resulting in privileged execution of arbitrary code, because the error detection occurs before an X-Frame-Options header is set. This is fixed in 2.4.2-RELEASE. OPNsense, a 2015 fork of pfSense, was not vulnerable since… |