Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
153 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.2) | 1.1% | — | Sensiolabs Symfony | 3/8/2018 | 17/6/2026 | An issue was discovered in HttpKernel in Symfony 2.7.0 through 2.7.48, 2.8.0 through 2.8.43, 3.3.0 through 3.3.17, 3.4.0 through 3.4.13, 4.0.0 through 4.0.13, and 4.1.0 through 4.1.2. When using HttpCache, the values of the X-Forwarded-Host headers are implicitly set as trusted while this should be forbidden, leading… | |
| Modificada | Media (6.5) | 58% | — | Sensiolabs SymfonyDebian LinuxDrupal | 3/8/2018 | 17/6/2026 | An issue was discovered in Http Foundation in Symfony 2.7.0 through 2.7.48, 2.8.0 through 2.8.43, 3.3.0 through 3.3.17, 3.4.0 through 3.4.13, 4.0.0 through 4.0.13, and 4.1.0 through 4.1.2. It arises from support for a (legacy) IIS header that lets users override the path in the request URL via the X-Original-URL or… | |
| Modificada | Media (6.1) | 6.1% | — | Sensiolabs Symfony | 20/7/2018 | 17/6/2026 | The debug handler in Symfony before v2.7.33, 2.8.x before v2.8.26, 3.x before v3.2.13, and 3.3.x before v3.3.6 has XSS via an array key during exception pretty printing in ExceptionHandler.php, as demonstrated by a /_debugbar/open?op=get URI. NOTE: the vendor's position is that this is not a vulnerability because the… | |
| Modificada | Crítica (9.8) | 6.9% | — | Symfony Twig | 10/7/2018 | 17/6/2026 | Twig before 2.4.4 allows Server-Side Template Injection (SSTI) via the search search_key parameter. NOTE: the vendor points out that Twig itself is not a web application and states that it is the responsibility of web applications using Twig to properly wrap input to it | |
| Modificada | Media (6.1) | 1.3% | — | Sensiolabs Symfony | 13/6/2018 | 17/6/2026 | Reflected Cross-site scripting (XSS) vulnerability in the web profiler in SensioLabs Symfony 3.3.6 allows remote attackers to inject arbitrary web script or HTML via the "file" parameter, aka an _profiler/open?file= URI. NOTE: The vendor states "The XSS ... is in the web profiler, a tool that should never be deployed… | |
| Modificada | Media (6.1) | 1.1% | — | Sensiolabs SymfonyDebian Linux | 13/6/2018 | 17/6/2026 | The security handlers in the Security component in Symfony in 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and 4.0.x before 4.0.11 have an Open redirect vulnerability when security.http_utils is inlined by a container. NOTE: this issue exists because of an incomplete fix for… | |
| Modificada | Crítica (9.8) | 2.3% | — | Sensiolabs Symfony | 13/6/2018 | 17/6/2026 | An issue was discovered in the Ldap component in Symfony 2.8.x before 2.8.37, 3.3.x before 3.3.17, 3.4.x before 3.4.7, and 4.0.x before 4.0.7. It allows remote attackers to bypass authentication by logging in with a "null" password and valid username, which triggers an unauthenticated bind. NOTE: this issue exists… | |
| Modificada | Alta (8.8) | 0.76% | — | Sensiolabs SymfonyDebian Linux | 13/6/2018 | 17/6/2026 | An issue was discovered in the Security component in Symfony 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and 4.0.x before 4.0.11. By default, a user's session is invalidated when the user is logged out. This behavior can be disabled through the invalidate_session option. In this… | |
| Modificada | Media (5.9) | 1.6% | — | Sensiolabs SymfonyDebian Linux | 13/6/2018 | 17/6/2026 | An issue was discovered in the HttpFoundation component in Symfony 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and 4.0.x before 4.0.11. The PDOSessionHandler class allows storing sessions on a PDO connection. Under some configurations and with a well-crafted payload, it was… | |
| Modificada | Alta (8.1) | 2.0% | — | Sensiolabs SymfonyDebian LinuxFedoraproject Fedora | 13/6/2018 | 17/6/2026 | An issue was discovered in the Security component in Symfony 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and 4.0.x before 4.0.11. A session fixation vulnerability within the "Guard" login feature may allow an attacker to impersonate a victim towards the web application if the… | |
| Modificada | Media (6.1) | 0.78% | — | Sensiolabs SymfonyDebian Linux | 13/6/2018 | 17/6/2026 | An issue was discovered in Symfony 2.7.x before 2.7.38, 2.8.x before 2.8.31, 3.2.x before 3.2.14, and 3.3.x before 3.3.13. DefaultAuthenticationSuccessHandler or DefaultAuthenticationFailureHandler takes the content of the _target_path parameter and generates a redirect response, but no check is performed on the path,… | |
| Modificada | Crítica (9.8) | 2.9% | — | Sensiolabs Symfony | 7/2/2017 | 17/6/2026 | Symfony before 2.8.6 and 3.x before 3.0.6 allows remote attackers to bypass authentication by logging in with an empty password and valid username, which triggers an unauthenticated bind. | |
| Modificada | Alta (7.5) | 1.9% | — | Sensiolabs SymfonyDebian Linux | 1/6/2016 | 17/6/2026 | The attemptAuthentication function in Component/Security/Http/Firewall/UsernamePasswordFormAuthenticationListener.php in Symfony before 2.3.41, 2.7.x before 2.7.13, 2.8.x before 2.8.6, and 3.0.x before 3.0.6 does not limit the length of a username stored in a session, which allows remote attackers to cause a denial of… | |
| Modificada | Alta (7.5) | 1.9% | — | Debian LinuxSensiolabs Symfony | 1/6/2016 | 17/6/2026 | The nextBytes function in the SecureRandom class in Symfony before 2.3.37, 2.6.x before 2.6.13, and 2.7.x before 2.7.9 does not properly generate random numbers when used with PHP 5.x without the paragonie/random_compat library and the openssl_random_pseudo_bytes function fails, which makes it easier for attackers to… | |
| Modificada | Alta (7.5) | 2.5% | — | Sensiolabs Symfony | 7/12/2015 | 17/6/2026 | Symfony 2.3.x before 2.3.35, 2.6.x before 2.6.12, and 2.7.x before 2.7.7 might allow remote attackers to have unspecified impact via a timing attack involving the (1) Symfony/Component/Security/Http/RememberMe/PersistentTokenBasedRememberMeServices or (2)… | |
| Modificada | Media (6.8) | 2.7% | — | Sensiolabs Symfony | 7/12/2015 | 17/6/2026 | Session fixation vulnerability in the "Remember Me" login feature in Symfony 2.3.x before 2.3.35, 2.6.x before 2.6.12, and 2.7.x before 2.7.7 allows remote attackers to hijack web sessions via a session id. | |
| Modificada | Media (6.8) | 3.4% | — | Symfony Twig | 6/11/2015 | 17/6/2026 | The displayBlock function Template.php in Sensio Labs Twig before 1.20.0, when Sandbox mode is enabled, allows remote attackers to execute arbitrary code via the _self variable in a template. | |
| Modificada | Media (6.8) | 1.3% | — | Sensiolabs Symfony | 24/6/2015 | 17/6/2026 | Eval injection vulnerability in the HttpCache class in HttpKernel in Symfony 2.x before 2.3.27, 2.4.x and 2.5.x before 2.5.11, and 2.6.x before 2.6.6 allows remote attackers to execute arbitrary PHP code via a language="php" attribute of a SCRIPT element. | |
| Modificada | Media (4.3) | 8.2% | 💥 Exploit | Sensiolabs Symfony | 2/6/2015 | 17/6/2026 | FragmentListener in the HttpKernel component in Symfony 2.3.19 through 2.3.28, 2.4.9 through 2.4.10, 2.5.4 through 2.5.11, and 2.6.0 through 2.6.7, when ESI or SSI support enabled, does not check if the _controller attribute is set, which allows remote attackers to bypass URL signing and security rules by including… | |
| Modificada | Media (5) | 1.9% | — | Sensiolabs Symfony | 27/12/2014 | 16/6/2026 | The Security component in Symfony 2.0.x before 2.0.25, 2.1.x before 2.1.13, 2.2.x before 2.2.9, and 2.3.x before 2.3.6 allows remote attackers to cause a denial of service (CPU consumption) via a long password that triggers an expensive hash computation, as demonstrated by a PBKDF2 computation, a similar issue to… | |
| Modificada | Alta (7.5) | 1.6% | — | Sensiolabs Symfony | 2/6/2014 | 16/6/2026 | Symfony 2.0.x before 2.0.22, 2.1.x before 2.1.7, and 2.2.x remote attackers to execute arbitrary PHP code via a serialized PHP object to the (1) Yaml::parse or (2) Yaml\Parser::parse function, a different vulnerability than CVE-2013-1348. | |
| Modificada | Alta (7.5) | 1.6% | — | Sensiolabs Symfony | 2/6/2014 | 16/6/2026 | The Yaml::parse function in Symfony 2.0.x before 2.0.22 remote attackers to execute arbitrary PHP code via a PHP file, a different vulnerability than CVE-2013-1397. | |
| Modificada | Media (5) | 1.2% | — | Friends OF Symfony Project Fosuserbundle | 25/9/2013 | 16/6/2026 | The login form in the FriendsOfSymfony FOSUserBundle bundle before 1.3.3 for Symfony allows remote attackers to cause a denial of service (CPU consumption) via a long password that triggers an expensive hash computation, as demonstrated by a PBKDF2 computation. | |
| Modificada | Media (6.8) | 1.2% | — | Sensiolabs Symfony | 27/12/2012 | 16/6/2026 | Symfony 2.0.x before 2.0.20, 2.1.x before 2.1.5, and 2.2-dev, when the internal routes configuration is enabled, allows remote attackers to access arbitrary services via vectors involving a URI beginning with a /_internal substring. | |
| Modificada | Media (6.4) | 1.9% | — | Sensiolabs Symfony | 27/12/2012 | 16/6/2026 | Symfony 2.0.x before 2.0.20 does not process URL encoded data consistently within the Routing and Security components, which allows remote attackers to bypass intended URI restrictions via a doubly encoded string. |