Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
153 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.3) | 0.43% | — | Sensiolabs Symfony | 14/7/2026 | 16/7/2026 | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 7.4.12 and 8.0.12, method-scoped #[IsGranted], #[IsSignatureValid], and #[IsCsrfTokenValid] attributes can be configured for GET only, but Symfony routes HEAD requests to the GET handler while the attribute check… | |
| Analizada | Media (6.3) | 0.46% | — | Sensiolabs Symfony | 14/7/2026 | 15/7/2026 | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, PdoAdapter::doClear() builds a DELETE statement using a namespace derived from the caller-supplied $prefix without binding or escaping it, allowing a caller able to influence… | |
| Analizada | Baja (2) | 0.30% | — | Sensiolabs Symfony | 14/7/2026 | 16/7/2026 | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.4.24 until 6.4.40, 7.4.12, and 8.0.12, the development profiler file_excerpt Twig filter escapes PHP files through highlight_string() but interpolates lines from non-PHP files directly into <code> elements,… | |
| Analizada | Media (6.3) | 0.39% | — | Sensiolabs Symfony | 14/7/2026 | 16/7/2026 | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, Symfony\Component\Mime\Header\ParameterizedHeader validates and encodes parameter values but emits parameter names verbatim, allowing a caller that derives a parameter name… | |
| Analizada | Alta (8.8) | 0.26% | — | Sensiolabs Symfony | 14/7/2026 | 15/7/2026 | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 6.4.40, 7.4.12, and 8.0.12, OidcTokenHandler::verifyClaims() registered audience (aud), issuer (iss), and expiry (exp) checkers but did not pass the mandatory claims list to ClaimCheckerManager::check(), so a… | |
| Analizada | Baja (2.3) | 0.34% | — | Sensiolabs Symfony | 14/7/2026 | 21/7/2026 | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.1.0-BETA1 until 6.4.40, 7.4.12, and 8.0.12, UrlSanitizer::parse() passes Unicode explicit-direction BiDi formatting characters through into sanitized href and src attributes, allowing sanitized content to display a… | |
| Analizada | Crítica (9.1) | 0.37% | — | Sensiolabs Symfony | 14/7/2026 | 15/7/2026 | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, X509Authenticator extracts the user identifier from $_SERVER['SSL_CLIENT_S_DN'] with an unanchored regex that matches emailAddress= anywhere in the distinguished name, allowing… | |
| Analizada | Alta (8.2) | 0.63% | — | Sensiolabs Symfony | 14/7/2026 | 21/7/2026 | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 7.3.0-BETA1 until 7.4.12 and 8.0.12, the JsonPath component compiles attacker-controlled match() and search() filter patterns directly into preg_match() without a length cap, i-regexp restriction, or bounded… | |
| Analizada | Alta (8.3) | 0.67% | — | Sensiolabs Symfony | 14/7/2026 | 15/7/2026 | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, the server:log listener (Symfony\Bridge\Monolog\Command\ServerLogCommand) binds to 0.0.0.0:9911 by default and processes each received frame with… | |
| Analizada | Alta (7.6) | 0.49% | — | Sensiolabs Symfony | 14/7/2026 | 15/7/2026 | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 7.1.0 until 7.4.12 and 8.0.12, Cas2Handler builds the CAS service parameter from Request::getSchemeAndHttpHost(), which reflects an attacker-controlled Host header when framework.trusted_hosts is not configured; an… | |
| Pendiente de análisis | Media (6.3) | 0.60% | 💥 PoC | SymfonyAI | 14/7/2026 | 14/7/2026 | ### Description `Symfony\Component\Mime\Address` is the value-object every Symfony Mailer address (to/cc/bcc/from/reply-to) flows through; its constructor is documented as validating the address and throwing on invalid input, so developers treat it as a security boundary. The constructor accepts email addresses whose… | |
| Analizada | Baja (2.3) | 0.34% | — | Sensiolabs Symfony | 14/7/2026 | 16/7/2026 | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.1.0-BETA1 until 6.4.40, 7.4.12, and 8.0.12, HtmlSanitizer URL sanitization can allow off-allowlist URLs through allowLinkHosts() or allowMediaHosts() because UrlSanitizer::parse() follows RFC 3986 while browsers… | |
| Analizada | Baja (2.3) | 0.35% | — | Sensiolabs Symfony | 14/7/2026 | 15/7/2026 | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, UrlGenerator validates route parameters against a pattern built as ^ plus the raw requirement plus $; with ungrouped alternations, middle alternatives match as unanchored… | |
| Aplazada | Alta (7.8) | 0.19% | — | Symfony UXAI | 8/7/2026 | 10/7/2026 | Symfony UX is a JavaScript ecosystem for Symfony. From 2.32.0 before 2.36.1 and from 3.0.0 before 3.2.0, the ux:install console command installs files from a recipe kit by copying paths listed in a copy-files map, and because Path::isRelative() accepts paths like ../../../etc, a crafted or compromised kit can write… | |
| Analizada | Media (6.1) | 0.34% | — | Symfony UX | 8/7/2026 | 19/8/2026 | Symfony UX is a JavaScript ecosystem for Symfony. From 2.17.0 before 2.36.1 and from 3.0.0 before 3.2.0, the ux_icon() Twig function is marked is_safe=['html'] and Icon::toHtml() inlines SVG source verbatim, allowing unsanitized local SVG files or Iconify on-demand JSON body responses containing nested script… | |
| Aplazada | Alta (8.2) | 0.22% | — | Pontedilana Php-weasyprintAIKnplabs SnappyAISymfony ProcessAI | 19/6/2026 | 22/6/2026 | PhpWeasyPrint is a PHP library allowing PDF generation from a URL or an HTML page. Prior to version 2.5.1, `pontedilana/php-weasyprint` builds the shell command for WeasyPrint by passing the binary path through `escapeshellarg()` first and then checking the *quoted* result with `is_executable()`. On POSIX… | |
| Aplazada | Media (6.9) | 0.32% | — | SuluAISymfonyAI | 1/6/2026 | 22/7/2026 | Sulu is an open-source PHP content management system based on the Symfony framework. Prior to versions 2.6.23 and 3.0.6, the password reset tokenand API key generation uses a weak cryptographical hash algorithm. This issue has been patched in versions 2.6.23 and 3.0.6. | |
| Analizada | Alta (8.7) | 0.76% | — | Symfony Twig | 20/5/2026 | 23/7/2026 | Twig versions 2.16.x and 3.9.0 through 3.25.x contain a sandbox bypass vulnerability when using a SourcePolicyInterface that allows attackers with template rendering capabilities to pass arbitrary PHP callables to sort, filter, map, and reduce filters. Attackers can exploit the runtime check that fails to use the… | |
| Analizada | Media (5.4) | 0.19% | — | Spomky-labs Webauthn-libSpomky-labs Webauthn-symfony-bundleSpomky-labs Webauthn Framwork | 10/3/2026 | 17/6/2026 | web-auth/webauthn-lib is an open source set of PHP libraries and a Symfony bundle to allow developers to integrate that authentication mechanism into their web applications. Prior to 5.2.4, when allowed_origins is configured, CheckAllowedOrigins reduces URL-like values to their host component and accepts on host match… | |
| Analizada | Media (6.3) | 0.23% | — | Sensiolabs Symfony | 28/1/2026 | 17/6/2026 | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to versions 5.4.51, 6.4.33, 7.3.11, 7.4.5, and 8.0.5, the Symfony Process component did not correctly treat some characters (notably `=`) as “special” when escaping arguments on Windows. When PHP is executed from an… | |
| Analizada | Alta (7.5) | 0.43% | — | Auth0-phpLaravel-auth0Auth0 SymfonyWp-auth0 | 17/12/2025 | 30/9/2026 | Auth0-PHP is a PHP SDK for Auth0 Authentication and Management APIs. In applications built with the Auth0-PHP SDK, the audience validation in access tokens is performed improperly. Without proper validation, affected applications may accept ID tokens as Access tokens. Projects are affected if they use Auth0-PHP SDK… | |
| Analizada | Alta (7.3) | 1.3% | 💥 Exploit | Sensiolabs HttpfoundationSensiolabs Symfony | 12/11/2025 | 17/6/2026 | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Symfony's HttpFoundation component defines an object-oriented layer for the HTTP specification. Starting in version 2.0.0 and prior to version 5.4.50, 6.4.29, and 7.3.7, the `Request` class improperly interprets some… | |
| Aplazada | Media (6.1) | 0.24% | — | Symfony Ux-twig-componentAISymfony Ux-live-componentAI | 19/5/2025 | 17/6/2026 | Symfony UX is an initiative and set of libraries to integrate JavaScript tools into applications. Prior to version 2.25.1, rendering `{{ attributes }}` or using any method that returns a `ComponentAttributes` instance (e.g. `only()`, `defaults()`, `without()`) ouputs attribute values directly without escaping. If… | |
| Aplazada | Crítica (9.3) | 0.65% | — | AidexAILaravelAISymfonyAI | 15/4/2025 | 17/6/2026 | In versions prior to Aidex 1.7, an authenticated malicious user, taking advantage of an open registry, could execute unauthorised commands within the system. This includes executing operating system (Unix) commands, interacting with internal services such as PHP or MySQL, and even invoking native functions of the… | |
| Analizada | Alta (8.8) | 0.20% | — | Drupal Symfony Mailer Lite Project Drupal Symfony Mailer Lite | 9/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Drupal Drupal Symfony Mailer Lite allows Cross Site Request Forgery.This issue affects Drupal Symfony Mailer Lite: from 0.0.0 before 1.0.6. |