Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
312 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.1) | 0.24% | — | Endian Firewall Community | 2/4/2026 | 24/7/2026 | Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the mimetypes parameter to /cgi-bin/proxypolicy.cgi. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page. | |
| Analizada | Media (5.1) | 0.24% | — | Endian Firewall Community | 2/4/2026 | 24/7/2026 | Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /cgi-bin/xtaccess.cgi. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page. | |
| Analizada | Media (5.1) | 0.24% | — | Endian Firewall Community | 2/4/2026 | 24/7/2026 | Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /cgi-bin/vpnfw.cgi. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page. | |
| Analizada | Media (5.1) | 0.24% | — | Endian Firewall Community | 2/4/2026 | 24/7/2026 | Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /cgi-bin/zonefw.cgi. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page. | |
| Analizada | Media (5.1) | 0.24% | — | Endian Firewall Community | 2/4/2026 | 24/7/2026 | Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /cgi-bin/outgoingfw.cgi. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page. | |
| Analizada | Media (5.1) | 0.24% | — | Endian Firewall Community | 2/4/2026 | 24/7/2026 | Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /cgi-bin/incoming.cgi. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page. | |
| Analizada | Media (5.1) | 0.24% | — | Endian Firewall Community | 2/4/2026 | 24/7/2026 | Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /cgi-bin/snat.cgi. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page. | |
| Analizada | Media (5.1) | 0.24% | — | Endian Firewall Community | 2/4/2026 | 24/7/2026 | Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /cgi-bin/dnat.cgi. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page. | |
| Analizada | Media (5.1) | 0.24% | — | Endian Firewall Community | 2/4/2026 | 24/7/2026 | Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the dscp parameter to /manage/qos/rules/. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page. | |
| Analizada | Media (5.1) | 0.24% | — | Endian Firewall Community | 2/4/2026 | 24/7/2026 | Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the name parameter to /manage/qos/classes/. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page. | |
| Analizada | Media (5.1) | 0.24% | — | Endian Firewall Community | 2/4/2026 | 24/7/2026 | Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark user ham spam parameter to /cgi-bin/salearn.cgi. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page. | |
| Analizada | Media (5.1) | 0.24% | — | Endian Firewall Community | 2/4/2026 | 24/7/2026 | Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /manage/dhcp/fixed_leases/. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page. | |
| Analizada | Media (5.1) | 0.24% | — | Endian Firewall Community | 2/4/2026 | 24/7/2026 | Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the NAME parameter to /cgi-bin/uplinkeditor.cgi. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page. | |
| Analizada | Media (5.1) | 0.24% | — | Endian Firewall Community | 2/4/2026 | 24/7/2026 | Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /manage/dnsmasq/hosts/. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page. | |
| Analizada | Media (5.1) | 0.24% | — | Endian Firewall Community | 2/4/2026 | 24/7/2026 | Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /cgi-bin/routing.cgi. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page. | |
| Analizada | Alta (8.7) | 1.9% | — | Endian Firewall Community | 2/4/2026 | 24/7/2026 | Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_smtp.cgi. The DATE parameter value is used to construct a file path that is passed to a Perl open() call, which allows command injection due to an incomplete regular expression… | |
| Analizada | Alta (8.7) | 1.9% | — | Endian Firewall Community | 2/4/2026 | 24/7/2026 | Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_openvpn.cgi. The DATE parameter value is used to construct a file path that is passed to a Perl open() call, which allows command injection due to an incomplete regular expression… | |
| Analizada | Alta (8.7) | 1.9% | — | Endian Firewall Community | 2/4/2026 | 24/7/2026 | Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_log.cgi. The DATE parameter value is used to construct a file path that is passed to a Perl open() call, which allows command injection due to an incomplete regular expression… | |
| Analizada | Alta (8.7) | 1.9% | — | Endian Firewall Community | 2/4/2026 | 24/7/2026 | Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_ids.cgi. The DATE parameter value is used to construct a file path that is passed to a Perl open() call, which allows command injection due to an incomplete regular expression… | |
| Analizada | Alta (8.7) | 1.9% | — | Endian Firewall Community | 2/4/2026 | 24/7/2026 | Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_firewall.cgi. The DATE parameter value is used to construct a file path that is passed to a Perl open() call, which allows command injection due to an incomplete regular… | |
| Analizada | Alta (8.7) | 1.9% | — | Endian Firewall Community | 2/4/2026 | 24/7/2026 | Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_clamav.cgi. The DATE parameter value is used to construct a file path that is passed to a Perl open() call, which allows command injection due to an incomplete regular expression… | |
| Analizada | Alta (8.7) | 1.9% | — | Endian Firewall Community | 2/4/2026 | 17/6/2026 | Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_proxy.cgi. The DATE parameter value is used to construct a file path that is passed to a Perl open() call, which allows command injection due to an incomplete regular expression… | |
| Analizada | Alta (7.1) | 0.91% | — | Endian Firewall Community | 2/4/2026 | 17/6/2026 | Endian Firewall version 3.3.25 and prior allow authenticated users to delete arbitrary files via directory traversal in the remove ARCHIVE parameter to /cgi-bin/backup.cgi. The remove ARCHIVE parameter value is used to construct a file path without sanitization of directory traversal sequences, which is then passed to… | |
| Analizada | Baja (1.9) | 0.19% | — | Xlnt-community Xlnt | 7/3/2026 | 17/6/2026 | A vulnerability was identified in xlnt-community xlnt up to 1.6.1. The affected element is the function xlnt::detail::xlsx_consumer::read_office_document of the file source/detail/serialization/xlsx_consumer.cpp of the component XLSX File Parser. The manipulation leads to null pointer dereference. The attack must be… | |
| Analizada | Baja (1.9) | 0.19% | — | Xlnt-community Xlnt | 7/3/2026 | 17/6/2026 | A vulnerability was determined in xlnt-community xlnt up to 1.6.1. Impacted is the function xlnt::detail::compound_document::read_directory of the file source/detail/cryptography/compound_document.cpp of the component Encrypted XLSX File Parser. Executing a manipulation can lead to out-of-bounds read. The attack is… |