Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
153 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 1.4% | — | Sensiolabs Symfony | 17/6/2021 | 17/6/2026 | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. A vulnerability related to firewall authentication is in Symfony starting with version 5.3.0 and prior to 5.3.2. When an application defines multiple firewalls, the token authenticated by one of the firewalls was… | |
| Modificada | Media (5.3) | 1.7% | 💥 PoC | Sensiolabs SymfonyFedoraproject Fedora | 13/5/2021 | 17/6/2026 | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. The ability to enumerate users was possible without relevant permissions due to different handling depending on whether the user existed or not when attempting to use the switch users functionality. We now ensure that… | |
| Modificada | Alta (8.8) | 3.0% | — | Sensiolabs HttpclientSensiolabs SymfonyFedoraproject Fedora | 2/9/2020 | 17/6/2026 | In Symfony before versions 4.4.13 and 5.1.5, the CachingHttpClient class from the HttpClient Symfony component relies on the HttpCache class to handle requests. HttpCache uses internal headers like X-Body-Eval and X-Body-File to control the restoration of cached responses. The class was initially written with… | |
| Modificada | Alta (8.1) | 1.1% | — | Sensiolabs Symfony | 30/3/2020 | 17/6/2026 | In symfony/security-http before versions 4.4.7 and 5.0.7, when a `Firewall` checks access control rule, it iterate overs each rule's attributes and stops as soon as the accessDecisionManager decides to grant access on the attribute, preventing the check of next attributes that should have been take into account in an… | |
| Modificada | Media (5.4) | 1.2% | — | Sensiolabs Symfony | 30/3/2020 | 17/6/2026 | In Symfony before versions 5.0.5 and 4.4.5, some properties of the Exception were not properly escaped when the `ErrorHandler` rendered it stacktrace. In addition, the stacktrace were displayed even in a non-debug configuration. The ErrorHandler now escape alls properties of the exception, and the stacktrace is only… | |
| Modificada | Media (4.3) | 1.3% | — | Sensiolabs Symfony | 30/3/2020 | 17/6/2026 | In Symfony before versions 4.4.7 and 5.0.7, when a `Response` does not contain a `Content-Type` header, affected versions of Symfony can fallback to the format defined in the `Accept` header of the request, leading to a possible mismatch between the response's content and `Content-Type` header. When the response… | |
| Modificada | Media (6.1) | 2.3% | — | Sensiolabs SymfonyFedoraproject Fedora | 2/1/2020 | 16/6/2026 | Symfony 2.0.X before 2.0.24, 2.1.X before 2.1.12, 2.2.X before 2.2.5, and 2.3.X before 2.3.3 have an issue in the HttpFoundation component. The Host header can be manipulated by an attacker when the framework is generating an absolute URL. A remote attacker could exploit this vulnerability to inject malicious content… | |
| Modificada | Crítica (9.8) | 33% | — | Sensiolabs SymfonyFedoraproject Fedora | 21/11/2019 | 17/6/2026 | An issue was discovered in Symfony 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4.3.7. Serializing certain cache adapter interfaces could result in remote code injection. This is related to symfony/cache. | |
| Modificada | Alta (7.5) | 2.2% | — | Sensiolabs SymfonyFedoraproject Fedora | 21/11/2019 | 17/6/2026 | An issue was discovered in Symfony 2.8.0 through 2.8.50, 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4.3.7. If an application passes unvalidated user input as the file for which MIME type validation should occur, then arbitrary arguments are passed to the underlying file command. This is related to… | |
| Modificada | Alta (8.1) | 1.3% | — | Sensiolabs SymfonyFedoraproject Fedora | 21/11/2019 | 17/6/2026 | An issue was discovered in Symfony 2.8.0 through 2.8.50, 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4.3.7. The UriSigner was subject to timing attacks. This is related to symfony/http-kernel. | |
| Modificada | Crítica (9.8) | 3.4% | — | Sensiolabs Symfony | 21/11/2019 | 17/6/2026 | An issue was discovered in Symfony before 4.2.12 and 4.3.x before 4.3.8. The VarExport component incorrectly escapes strings, allowing some specially crafted ones to escalate to execution of arbitrary PHP code. This is related to symfony/var-exporter. | |
| Modificada | Media (5.3) | 1.6% | — | Sensiolabs Symfony | 21/11/2019 | 17/6/2026 | An issue was discovered in Symfony 4.2.0 to 4.2.11 and 4.3.0 to 4.3.7. The ability to enumerate users was possible due to different handling depending on whether the user existed when making unauthorized attempts to use the switch users functionality. This is related to symfony/security. | |
| Modificada | Alta (8.1) | 1.4% | — | Sensiolabs SymfonyFedoraproject FedoraRedhat Enterprise Linux | 1/11/2019 | 16/6/2026 | php-symfony2-Validator has loss of information during serialization | |
| Modificada | Crítica (9.8) | 1.9% | — | Sensiolabs Symfony | 23/5/2019 | 17/6/2026 | Certain Symfony products are affected by: Incorrect Access Control. This affects Symfony 2.7.30 and Symfony 2.8.23 and Symfony 3.2.10 and Symfony 3.3.3. The type of exploitation is: remote. The component is: Password validator. | |
| Modificada | Crítica (9.8) | 1.9% | — | Sensiolabs Symfony | 16/5/2019 | 17/6/2026 | In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, HTTP Methods provided as verbs or using the override header may be treated as trusted input, but they are not validated, possibly causing SQL injection or XSS. This is related to symfony/http-foundation. | |
| Modificada | Alta (7.1) | 2.3% | — | Sensiolabs Symfony | 16/5/2019 | 17/6/2026 | In Symfony before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, it is possible to cache objects that may contain bad user input. On serialization or unserialization, this could result in the deletion of files that the current user has access to. This is related to symfony/cache and… | |
| Modificada | Alta (7.5) | 1.2% | — | Sensiolabs SymfonyDrupal | 16/5/2019 | 17/6/2026 | In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, a vulnerability would allow an attacker to authenticate as a privileged user on sites with user registration and remember me login functionality enabled. This is related to symfony/security. | |
| Modificada | Crítica (9.8) | 6.0% | — | Sensiolabs SymfonyDrupal | 16/5/2019 | 17/6/2026 | In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, when service ids allow user input, this could allow for SQL Injection and remote code execution. This is related to symfony/dependency-injection. | |
| Modificada | Media (5.4) | 1.0% | 💥 PoC | Sensiolabs SymfonyDrupal | 16/5/2019 | 17/6/2026 | In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, validation messages are not escaped, which can lead to XSS when user input is included. This is related to symfony/framework-bundle. | |
| Modificada | Baja (3.7) | 1.4% | — | Symfony TwigDebian Linux | 23/3/2019 | 17/6/2026 | A sandbox information disclosure exists in Twig before 1.38.0 and 2.x before 2.7.0 because, under some circumstances, it is possible to call the __toString() method on an object even if not allowed by the security policy in place. | |
| Modificada | Media (6.1) | 1.5% | — | Sensiolabs SymfonyFedoraproject FedoraDebian Linux | 18/12/2018 | 17/6/2026 | An open redirect was discovered in Symfony 2.7.x before 2.7.50, 2.8.x before 2.8.49, 3.x before 3.4.20, 4.0.x before 4.0.15, 4.1.x before 4.1.9 and 4.2.x before 4.2.1. By using backslashes in the `_failure_path` input field of login forms, an attacker can work around the redirection target restrictions and effectively… | |
| Modificada | Media (5.3) | 3.6% | — | Sensiolabs SymfonyDebian Linux | 18/12/2018 | 17/6/2026 | An issue was discovered in Symfony 2.7.x before 2.7.50, 2.8.x before 2.8.49, 3.x before 3.4.20, 4.0.x before 4.0.15, 4.1.x before 4.1.9, and 4.2.x before 4.2.1. When using the scalar type hint `string` in a setter method (e.g. `setName(string $name)`) of a class that's the `data_class` of a form, and when a file… | |
| Modificada | Media (6.5) | 1.6% | — | Sensiolabs SymfonyDebian Linux | 6/8/2018 | 17/6/2026 | An issue was discovered in Symfony before 2.7.38, 2.8.31, 3.2.14, 3.3.13, 3.4-BETA5, and 4.0-BETA5. When a form is submitted by the user, the request handler classes of the Form component merge POST data and uploaded files data into one array. This big array forms the data that are then bound to the form. At this… | |
| Modificada | Alta (7.5) | 2.7% | — | Sensiolabs SymfonyDebian Linux | 6/8/2018 | 17/6/2026 | An issue was discovered in Symfony before 2.7.38, 2.8.31, 3.2.14, 3.3.13, 3.4-BETA5, and 4.0-BETA5. The Intl component includes various bundle readers that are used to read resource bundles from the local filesystem. The read() methods of these classes use a path and a locale to determine the language bundle to… | |
| Modificada | Media (5.9) | 1.5% | — | Sensiolabs SymfonyDebian Linux | 6/8/2018 | 17/6/2026 | An issue was discovered in Symfony before 2.7.38, 2.8.31, 3.2.14, 3.3.13, 3.4-BETA5, and 4.0-BETA5. The current implementation of CSRF protection in Symfony (Version >=2) does not use different tokens for HTTP and HTTPS; therefore the token is subject to MITM attacks on HTTP and can then be used in an HTTPS context to… |