Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
576 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.2) | 0.19% | — | ABB Coresense HMAIABB Coresense M10AI | 20/10/2025 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ABB CoreSense™ HM, ABB CoreSense™ M10.This issue affects CoreSense™ HM: through 2.3.1; CoreSense™ M10: through 1.4.1.12. | |
| Aplazada | Media (6.5) | 0.17% | — | Crowdstrike Falcon Sensor FOR WindowsAI | 8/10/2025 | 17/6/2026 | A logic error exists in the Falcon sensor for Windows that could allow an attacker, with the prior ability to execute code on a host, to delete arbitrary files. CrowdStrike released a security fix for this issue in Falcon sensor for Windows versions 7.24 and above and all Long Term Visibility (LTV) sensors. There is… | |
| Aplazada | Media (5.6) | 0.12% | — | Crowdstrike Falcon SensorAI | 8/10/2025 | 17/6/2026 | A race condition exists in the Falcon sensor for Windows that could allow an attacker, with the prior ability to execute code on a host, to delete arbitrary files. CrowdStrike released a security fix for this issue in Falcon sensor for Windows versions 7.24 and above and all Long Term Visibility (LTV) sensors. There… | |
| Aplazada | Media (5.1) | 0.33% | — | Deciso OpnsenseAI | 1/10/2025 | 17/6/2026 | In Deciso OPNsense before 25.7.4, when creating an "Interfaces: Devices: Point-to-Point" entry, the value of the parameter ptpid is not sanitized of HTML-related characters/strings. This value is directly displayed when visiting the page/interfaces_assign.php, which can result in stored cross-site scripting. The… | |
| Aplazada | Alta (8.8) | 0.59% | — | Cyrisma SensorAI | 16/9/2025 | 17/6/2026 | CYRISMA Sensor before 444 for Windows has an Insecure Folder and File Permissions vulnerability. A low-privileged user can abuse these issues to escalate privileges and execute arbitrary code in the context of NT AUTHORITY\SYSTEM by replacing DataSpotliteAgent.exe or any other binaries called by the Cyrisma_Agent… | |
| Analizada | Media (5.1) | 3.9% | — | Pfsense | 9/9/2025 | 14/7/2026 | In pfSense CE /suricata/suricata_app_parsers.php, the value of the policy_name parameter is not sanitized of HTML-related strings/characters before being directly displayed. This can result in stored cross-site scripting. The attacker must be authenticated with at least "WebCfg - Services: suricata package"… | |
| Analizada | Media (5.1) | 0.88% | — | Pfsense | 9/9/2025 | 14/7/2026 | In pfSense CE /suricata/suricata_flow_stream.php, the value of the policy_name parameter is not sanitized of HTML-related strings/characters before being directly displayed. This can result in stored cross-site scripting. The attacker must be authenticated with at least "WebCfg - Services: suricata package"… | |
| Analizada | Media (5.3) | 16% | — | Pfsense | 9/9/2025 | 14/7/2026 | In pfSense CE /suricata/suricata_ip_reputation.php, the value of the iplist parameter is not sanitized of directory traversal-related strings/characters. This value is directly used in a file existence check operation. While the contents of the file cannot be read, the server reveals whether the file exists, which… | |
| Analizada | Media (5.1) | 16% | — | Pfsense | 9/9/2025 | 14/7/2026 | In pfSense CE /usr/local/www/suricata/suricata_filecheck.php, the value of the filehash parameter is directly displayed without sanitizing for HTML-related characters/strings. This can result in reflected cross-site scripting if the victim is authenticated. | |
| Analizada | Media (5.1) | 10% | — | Pfsense | 9/9/2025 | 17/6/2026 | In pfSense CE /usr/local/www/status_traffic_totals.php, the value of the start-day parameter is not ensured to be a numeric value or sanitized of HTML-related characters/strings before being directly displayed in the input box. This value can be saved as the default value to be displayed to all users when visiting the… | |
| Analizada | Media (5.3) | 0.92% | — | Pfsense | 9/9/2025 | 14/7/2026 | In pfSense CE /usr/local/www/snort/snort_ip_reputation.php, the value of the iplist parameter is not sanitized of directory traversal-related characters/strings before being used to check if a file exists. While the contents of the file cannot be read, the server reveals whether a file exists, which allows an attacker… | |
| Analizada | Media (4.8) | 1.1% | — | Pfsense | 9/9/2025 | 14/7/2026 | In pfSense CE /usr/local/www/haproxy/haproxy_stats.php, the value of the showsticktablecontent parameter is displayed after being read from HTTP GET requests. This can enable reflected cross-site scripting when the victim is authenticated. | |
| Analizada | Alta (7.5) | 0.52% | — | Consensys Gnark | 29/8/2025 | 17/6/2026 | gnark is a zero-knowledge proof system framework. In version 0.12.0, there is a potential denial of service vulnerability when computing scalar multiplication is using the fake-GLV algorithm. This is because the algorithm didn't converge quickly enough for some of the inputs. This issue has been patched in version… | |
| Analizada | Crítica (9.1) | 9.0% | — | Opnsense | 27/8/2025 | 17/6/2026 | OPNsense before 25.1.8 contains an authenticated command injection vulnerability in its Bridge Interface Edit endpoint (interfaces_bridge_edit.php). The span POST parameter is concatenated into a system-level command without proper sanitization or escaping, allowing an administrator to inject arbitrary shell operators… | |
| Analizada | Alta (8.6) | 0.21% | — | Consensys Gnark | 22/8/2025 | 17/6/2026 | gnark is a zero-knowledge proof system framework. In versions prior to 0.14.0, the Verify function in eddsa.go and ecdsa.go used the S value from a signature without asserting that 0 ≤ S < order, leading to a signature malleability vulnerability. Because gnark’s native EdDSA and ECDSA circuits lack essential… | |
| Aplazada | Crítica (9.8) | 0.48% | — | Brewlabs SensorpressAI | 20/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in brewlabs SensorPress allows Stored XSS. This issue affects SensorPress: from n/a through 1.0. | |
| Aplazada | Media (4.3) | 0.14% | — | Lisensee Netinsight Analytics Implementation PluginAI | 14/8/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in lisensee NetInsight Analytics Implementation Plugin netinsight-analytics-implementation-plugin allows Cross Site Request Forgery.This issue affects NetInsight Analytics Implementation Plugin: from n/a through <= 1.0.3. | |
| Aplazada | Alta (7.1) | 0.13% | — | Lisensee Netinsight Analytics Implementation PluginAI | 14/8/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in lisensee NetInsight Analytics Implementation Plugin netinsight-analytics-implementation-plugin allows Stored XSS.This issue affects NetInsight Analytics Implementation Plugin: from n/a through <= 1.0.3. | |
| Aplazada | Media (5.4) | 0.13% | — | Intel Realsense Dynamic CalibratorAI | 12/8/2025 | 17/6/2026 | Uncontrolled search path for some Intel(R) RealSense(TM) Dynamic Calibrator software before version 2.14.2.0 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Aplazada | Media (5.5) | 0.26% | — | Krasenslavov Featured Image PlusAI | 23/7/2025 | 17/6/2026 | The Featured Image Plus – Quick & Bulk Edit with Unsplash plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.6.6 via the fip_get_image_options() function. This makes it possible for authenticated attackers, with administrator-level access and above, to make web… | |
| Analizada | Media (6.1) | 0.69% | 💥 PoC | Sensaphone Web600 Firmware | 21/7/2025 | 17/6/2026 | Cross Site Scripting vulnerability in Sensaphone WEB600 Monitoring System v.1.6.5.H and before allows a remote attacker to execute arbitrary code via a crafted GET requests to /@.xml, placing payloads in the g7200, g7300, g4601, and g1F02 parameters. | |
| Aplazada | Alta (8.5) | 0.18% | 💥 PoC | Ellipticlabs Virtual Lock SensorAI | 17/7/2025 | 17/6/2026 | An incorrect permissions vulnerability was reported in Elliptic Labs Virtual Lock Sensor that could allow a local, authenticated user to escalate privileges. | |
| Modificada | Media (5.3) | 0.28% | — | Jenkins Sensedia API Platform Tools | 9/7/2025 | 17/6/2026 | Jenkins Sensedia Api Platform tools Plugin 1.0 does not mask the Sensedia API Manager integration token on the global configuration form, increasing the potential for attackers to observe and capture it. | |
| Modificada | Media (6.5) | 0.22% | — | Jenkins Sensedia API Platform Tools | 9/7/2025 | 17/6/2026 | Jenkins Sensedia Api Platform tools Plugin 1.0 stores the Sensedia API Manager integration token unencrypted in its global configuration file on the Jenkins controller, where it can be viewed by users with access to the Jenkins controller file system. | |
| Analizada | Media (6.5) | 1.8% | 💥 PoC | Pfsense | 28/6/2025 | 17/6/2026 | In Netgate pfSense CE 2.8.0, the "WebCfg - Diagnostics: Command" privilege allows reading arbitrary files via diag_command.php dlPath directory traversal. NOTE: the Supplier's perspective is that this is intended behavior for this privilege level, and that system administrators are informed through both the product… |