Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
576 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.3) | 0.46% | — | Sensiolabs Symfony | 14/7/2026 | 15/7/2026 | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, PdoAdapter::doClear() builds a DELETE statement using a namespace derived from the caller-supplied $prefix without binding or escaping it, allowing a caller able to influence… | |
| Analizada | Baja (2) | 0.30% | — | Sensiolabs Symfony | 14/7/2026 | 16/7/2026 | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.4.24 until 6.4.40, 7.4.12, and 8.0.12, the development profiler file_excerpt Twig filter escapes PHP files through highlight_string() but interpolates lines from non-PHP files directly into <code> elements,… | |
| Analizada | Media (6.3) | 0.39% | — | Sensiolabs Symfony | 14/7/2026 | 16/7/2026 | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, Symfony\Component\Mime\Header\ParameterizedHeader validates and encodes parameter values but emits parameter names verbatim, allowing a caller that derives a parameter name… | |
| Analizada | Alta (8.8) | 0.26% | — | Sensiolabs Symfony | 14/7/2026 | 15/7/2026 | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 6.4.40, 7.4.12, and 8.0.12, OidcTokenHandler::verifyClaims() registered audience (aud), issuer (iss), and expiry (exp) checkers but did not pass the mandatory claims list to ClaimCheckerManager::check(), so a… | |
| Analizada | Baja (2.3) | 0.34% | — | Sensiolabs Symfony | 14/7/2026 | 21/7/2026 | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.1.0-BETA1 until 6.4.40, 7.4.12, and 8.0.12, UrlSanitizer::parse() passes Unicode explicit-direction BiDi formatting characters through into sanitized href and src attributes, allowing sanitized content to display a… | |
| Analizada | Crítica (9.1) | 0.37% | — | Sensiolabs Symfony | 14/7/2026 | 15/7/2026 | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, X509Authenticator extracts the user identifier from $_SERVER['SSL_CLIENT_S_DN'] with an unanchored regex that matches emailAddress= anywhere in the distinguished name, allowing… | |
| Analizada | Alta (8.2) | 0.63% | — | Sensiolabs Symfony | 14/7/2026 | 21/7/2026 | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 7.3.0-BETA1 until 7.4.12 and 8.0.12, the JsonPath component compiles attacker-controlled match() and search() filter patterns directly into preg_match() without a length cap, i-regexp restriction, or bounded… | |
| Analizada | Alta (8.3) | 0.67% | — | Sensiolabs Symfony | 14/7/2026 | 15/7/2026 | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, the server:log listener (Symfony\Bridge\Monolog\Command\ServerLogCommand) binds to 0.0.0.0:9911 by default and processes each received frame with… | |
| Analizada | Alta (7.6) | 0.49% | — | Sensiolabs Symfony | 14/7/2026 | 15/7/2026 | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 7.1.0 until 7.4.12 and 8.0.12, Cas2Handler builds the CAS service parameter from Request::getSchemeAndHttpHost(), which reflects an attacker-controlled Host header when framework.trusted_hosts is not configured; an… | |
| Analizada | Baja (2.3) | 0.34% | — | Sensiolabs Symfony | 14/7/2026 | 16/7/2026 | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.1.0-BETA1 until 6.4.40, 7.4.12, and 8.0.12, HtmlSanitizer URL sanitization can allow off-allowlist URLs through allowLinkHosts() or allowMediaHosts() because UrlSanitizer::parse() follows RFC 3986 while browsers… | |
| Analizada | Baja (2.3) | 0.35% | — | Sensiolabs Symfony | 14/7/2026 | 15/7/2026 | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, UrlGenerator validates route parameters against a pattern built as ^ plus the raw requirement plus $; with ungrouped alternations, middle alternatives match as unanchored… | |
| Aplazada | Alta (7.1) | 0.18% | — | Elis Wordcents Adsense Widget With AnalyticsAI | 15/6/2026 | 7/10/2026 | Unauthenticated Cross Site Scripting (XSS) in Eli's WordCents adSense Widget with Analytics <= 1.3.03.27 versions. | |
| Aplazada | Media (6) | 0.38% | — | TypesenseAI | 12/6/2026 | 17/6/2026 | Typesense is a fast, typo-tolerant search engine. Prior to versions 29.1 and 30.2, there is a cache isolation issue affecting search requests that use both server-side search result caching and Scoped Search API Keys. Under specific request ordering, cached search results could be reused across requests with different… | |
| Aplazada | Alta (8.7) | 0.54% | — | TypesenseAI | 12/6/2026 | 17/6/2026 | Typesense is a fast, typo-tolerant search engine. Prior to versions 29.1 and 30.2, there is an unauthenticated denial-of-service vulnerability in the /multi_search endpoint. A specially crafted request can trigger an unhandled exception during request processing, causing the server process to terminate. This issue can… | |
| Aplazada | Alta (8.5) | 0.15% | 💥 PoC | Acer NitrosenseAI | 28/5/2026 | 17/6/2026 | A Local Privilege Escalation (LPE) vulnerability affects Acer NitroSense software versions prior to 3.01.3052. The vulnerability stems from the the PSAdminAgent service, which creates a Named Pipe with a weak Access Control List (ACL). This allows any authenticated local user to connect and send commands. Because the… | |
| Pendiente de análisis | Alta (8.5) | 0.16% | — | Acer NitrosenseAI | 25/5/2026 | 23/7/2026 | NitroSense 3.x before 3.01.3052 contains Local Privilege Escalation (LPE) vulnerability.The program exposes a Windows Named Pipe that uses a custom protocol to invoke internal functions. However, this Named Pipe is misconfigured, allowing any authenticated local user to execute arbitrary code with NT AUTHORITY\SYSTEM… | |
| Pendiente de análisis | Media (6.8) | 0.10% | — | AMD Sensor Fusion HUB DriverAI | 15/5/2026 | 17/6/2026 | A buffer overflow vulnerability within AMD Sensor Fusion Hub Driver can allow a local attacker to write out of bounds, potentially resulting in denial of service or crash | |
| Analizada | Crítica (9.1) | 0.82% | — | Opnsense | 13/5/2026 | 17/6/2026 | OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.8, unsanitized user input is passed to the DHCP configuration of the configured interface, which is processed by a shell script, allowing remote code execution as root on the underlying operating system. This vulnerability is fixed in 26.1.8. | |
| Analizada | Media (6.5) | 0.38% | — | Opnsense | 13/5/2026 | 17/6/2026 | OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.7, a logic flaw in the OPNsense lockout_handler allows an unauthenticated attacker to continuously reset the authentication failure counter for their IP address. By interjecting a crafted username containing a success keyword ("Accepted" or… | |
| Analizada | Crítica (9.1) | 0.82% | — | Opnsense | 13/5/2026 | 17/6/2026 | OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.8, an authenticated Remote Code Execution (RCE) vulnerability in the OPNsense core allows a user with user-management privileges to execute arbitrary system commands as root. An attacker can bypass input validation by formatting their malicious… | |
| Analizada | Crítica (9.1) | 0.86% | — | Opnsense | 13/5/2026 | 17/6/2026 | OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.7, the XMLRPC method opnsense.restore_config_section fails to sanitize user supplied input leading to Remote Code Execution. This vulnerability is fixed in 26.1.7. | |
| Pendiente de análisis | Media (6.2) | 0.11% | — | Ardupilot RoverAIArdupilot AP Inertialsensor Adis1647xAI | 13/5/2026 | 17/6/2026 | Buffer Overflow vulnerability in Ardupilot rover commit v.c56439b045162058df0ff136afea3081fcd06d38 allows a local attacker to cause a denial of service via the AP_InertialSensor_ADIS1647x.cpp, ArduRover, ADIS1647x Sensor component. | |
| Analizada | Alta (8.5) | 0.17% | 💥 PoC | Acer NitrosenseAcer Predatorsense | 8/5/2026 | 12/8/2026 | PredatorSense version 3.00.3136 to 3.00.3196 contain Local Privilege Escalation (LPE) vulnerability.The program exposes a Windows Named Pipe that uses a custom protocol to invoke internal functions. However, this Named Pipe is misconfigured, allowing any authenticated local user to execute arbitrary code with NT… | |
| Analizada | Crítica (9.9) | 0.68% | — | Pfsense | 8/5/2026 | 17/6/2026 | Netgate pfSense CE 2.8.0 allows code execution in the XMLRPC API via pfsense.exec_php. NOTE: the Supplier disputes this because the API call is only available to admins and they are intentionally allowed to execute PHP code. | |
| Analizada | Crítica (9.1) | 0.81% | 💥 PoC | Pfsense | 8/5/2026 | 17/6/2026 | Netgate pfSense CE 2.7.2 allows code execution by using the module installer with a backup file with a serialized PHP object containing the post_reboot_commands property. NOTE: the Supplier disputes this because this installer is only available to admins and they are intentionally allowed to execute PHP code. |