Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2989▼ 73 respecto a la semana anterior
Críticas / altas1415▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
576 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (5.1) | 1.1% | — | Pfsense PlusAIPfsense CEAI | 3/9/2026 | 9/9/2026 | pfSense Plus before 26.07 and CE before 2.9.0 allow authenticated users with the Firewall: Schedules: Edit privilege to inject arbitrary JavaScript via the descr parameter in /firewall_schedule_edit.php. The schedule description is stored without HTML sanitization and subsequently inserted into an HTML attribute value… | |
| Pendiente de análisis | Media (5.1) | 1.1% | — | Pfsense PlusAIPfsense CEAI | 3/9/2026 | 9/9/2026 | pfSense Plus before 26.07 and CE before 2.9.0 allow authenticated users with the Firewall: Rules: Edit privilege to inject arbitrary JavaScript via the descr parameter in /firewall_rules_edit.php. The firewall rule description is stored in the pfSense XML configuration with only backslash-escaping applied and no HTML… | |
| Pendiente de análisis | Media (5.1) | 1.1% | — | Pfsense PlusAIPfsense CEAI | 3/9/2026 | 9/9/2026 | pfSense Plus before 26.07 and CE before 2.9.0 allow authenticated users with the Status: Monitoring privilege to inject arbitrary JavaScript via graph configuration parameters in /status_monitoring.php. Multiple POST parameters including graph-left, graph-right, time-period, resolution, start-date, end-date,… | |
| Pendiente de análisis | Media (5.3) | 1.2% | — | Pfsense PlusAIPfsense CEAI | 19/8/2026 | 23/9/2026 | pfSense Plus before 26.07 and pfSense CE through 2.8.1 contain a stored cross-site scripting vulnerability in the Traffic Graphs top-talkers feature, where PTR records returned by reverse DNS lookups are incorporated without sanitization into AJAX responses and rendered as HTML through a DOM sink in the administrator… | |
| Pendiente de análisis | Crítica (9.3) | 0.72% | — | Tenable Sensor ProxyAI | 3/8/2026 | 18/8/2026 | A vulnerability in Tenable Sensor Proxy allows a remote attacker to execute code with elevated privileges by inducing an operator to connect the sensor to an attacker-controlled host. | |
| Pendiente de análisis | Media (5.1) | 0.18% | — | OpnsenseAI | 3/8/2026 | 16/9/2026 | OPNsense before 26.1.9 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject arbitrary HTML or JavaScript by embedding payloads in the certificate description field via the trust certificate API. The unsanitized description value is persisted and later rendered in the… | |
| Pendiente de análisis | Media (5.1) | 0.29% | — | OpnsenseAI | 3/8/2026 | 16/9/2026 | OPNsense before 26.1.9 contains a stored cross-site scripting vulnerability that allows authenticated attackers with firewall rule management privileges to inject arbitrary HTML or JavaScript by embedding payloads in the firewall rule description field via the filter API endpoint. The unsanitized description value is… | |
| Aplazada | Alta (8.8) | 0.14% | — | Servereye ClientAIServereye SensorhubAIServereye ClientagentcontainerserviceAI | 22/7/2026 | 22/7/2026 | The servereye client (also known as sensorhub, technically ClientAgentContainerService) versions 20.15 and earlier are vulnerable to Local Privilege Escalation. The high-privileged service SE3Recovery (EmergencyRecoveryService.exe), running as SYSTEM, periodically monitors the directory… | |
| Analizada | Media (5.1) | 0.35% | — | Sensiolabs Symfony | 14/7/2026 | 15/7/2026 | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.53, 6.4.41, 7.4.13, and 8.0.13, UrlGenerator::doGenerate() used strtr() dot-segment encoding that skipped every other chained ../ or ./ segment, allowing attacker-controlled route parameters to generate URLs… | |
| Analizada | Media (5.3) | 0.34% | — | Sensiolabs Symfony | 14/7/2026 | 21/7/2026 | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.1.0 until 6.4.41, 7.4.13, and 8.0.13, UrlAttributeSanitizer::getSupportedAttributes() omitted URL-bearing attributes on <object>, <applet>, <iframe>, and <img>, and <meta http-equiv="refresh"> URLs inside content… | |
| Analizada | Media (5.3) | 0.34% | — | Sensiolabs Symfony | 14/7/2026 | 15/7/2026 | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.1.0 until 6.4.41, 7.4.13, and 8.0.13, UrlSanitizer::parse() rejected raw BiDi formatting characters but not percent-encoded forms and used an ASCII-only whitespace check, allowing sanitized URLs to retain… | |
| Analizada | Media (6.3) | 0.25% | — | Sensiolabs Symfony | 14/7/2026 | 15/7/2026 | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 7.4.13 and 8.0.13, MailomatRequestParser::validateSignature() parsed X-MOM-Webhook-Signature as algo=signature and passed the request-selected algorithm to hash_hmac(), allowing a signature algorithm downgrade… | |
| Analizada | Media (6.9) | 0.57% | — | Sensiolabs Symfony | 14/7/2026 | 16/7/2026 | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 5.4.0 to 5.4.53, 6.4.41, 7.4.13, and 8.0.13, NoPrivateNetworkHttpClient and IpUtils::PRIVATE_SUBNETS omitted IPv6 transition prefixes such as 6to4, NAT64, Teredo, and IPv4-compatible IPv6, allowing attacker-supplied… | |
| Analizada | Alta (8.7) | 0.60% | — | Sensiolabs Symfony | 14/7/2026 | 16/7/2026 | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.53, 6.4.41, 7.4.13, and 8.0.13, DefaultAuthenticationFailureHandler honored the request-supplied _failure_path parameter when failure_forward: true was enabled, allowing an unauthenticated failing login… | |
| Analizada | Media (6.9) | 1.5% | — | Sensiolabs Symfony | 14/7/2026 | 15/7/2026 | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 6.4.40, 7.4.12, and 8.0.12, TwilioRequestParser::doParse() received the configured webhook secret but ignored the X-Twilio-Signature HMAC header, allowing unauthenticated POST requests to inject forged Twilio… | |
| Analizada | Alta (8.7) | 0.57% | 💥 PoC | Sensiolabs Symfony | 14/7/2026 | 15/7/2026 | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, Crawler::addXmlContent() set DOMDocument::$validateOnParse = true before loadXML(), re-enabling external entity resolution and allowing attacker-supplied XML to expand file://… | |
| Analizada | Alta (8.7) | 0.52% | — | Sensiolabs Symfony | 14/7/2026 | 15/7/2026 | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, SendmailTransport in -t mode appended recipient addresses to the sendmail command line without a -- end-of-options separator, allowing an address beginning with - to be… | |
| Analizada | Alta (8.3) | 0.72% | — | Sensiolabs Symfony | 14/7/2026 | 16/7/2026 | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 5.4.46 until 5.4.52, 6.4.40, 7.4.12, and 8.0.12, the CVE-2024-50340 fix gated runtime argv parsing on empty($_GET), but parse_str() and the web SAPI can disagree, allowing a crafted query string to leave $_GET empty… | |
| Analizada | Media (6.9) | 0.27% | — | Sensiolabs Symfony | 14/7/2026 | 15/7/2026 | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 7.4.12 and 8.0.12, MailtrapRequestParser::doParse() received the configured webhook secret but ignored the X-Mt-Signature HMAC header, allowing unauthenticated POST requests to inject forged Mailtrap delivery,… | |
| Analizada | Media (6.9) | 0.45% | — | Sensiolabs Symfony | 14/7/2026 | 21/7/2026 | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 6.4.40, 7.4.12, and 8.0.12, the Mailjet mailer bridge and LOX24 notifier bridge webhook parsers received configured webhook secrets but did not verify them, allowing unauthenticated POST requests to inject forged… | |
| Analizada | Baja (2.1) | 0.34% | — | Sensiolabs Symfony | 14/7/2026 | 15/7/2026 | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.1.0-BETA1 until 6.4.40, 7.4.12, and 8.0.12, UrlAttributeSanitizer::getSupportedAttributes() omits URL-valued attributes including action, formaction, poster, and cite, so configurations that admit those attributes… | |
| Analizada | Alta (8.7) | 0.68% | — | Sensiolabs Symfony | 14/7/2026 | 15/7/2026 | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, Symfony\Component\Yaml\Parser::cleanup() used regular expressions with overlapping quantifiers for YAML directive, comment, and document marker cleanup, allowing crafted input… | |
| Analizada | Alta (8.7) | 0.68% | — | Sensiolabs Symfony | 14/7/2026 | 15/7/2026 | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, Symfony\Component\Yaml\Parser resolved YAML collection aliases recursively, allowing a small untrusted YAML input to expand into a multi-gigabyte structure and exhaust memory.… | |
| Analizada | Alta (8.2) | 0.63% | — | Sensiolabs Symfony | 14/7/2026 | 15/7/2026 | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, when the parser is exposed to attacker-controlled input, deeply nested mappings or sequences cause both the block-level (Parser::parseBlock()) and inline… | |
| Analizada | Alta (8.3) | 0.43% | — | Sensiolabs Symfony | 14/7/2026 | 16/7/2026 | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 7.4.12 and 8.0.12, method-scoped #[IsGranted], #[IsSignatureValid], and #[IsCsrfTokenValid] attributes can be configured for GET only, but Symfony routes HEAD requests to the GET handler while the attribute check… |