Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2570▼ 302 respecto a la semana anterior
Críticas / altas1352▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
9 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Crítica (9.2) | 0.33% | — | Portswigger Burp Suite DastAI | 24/9/2026 | 24/9/2026 | In PortSwigger Burp Suite DAST (formerly Burp Suite Enterprise Edition) before 2026.8, an authentication bypass can occur via an alternate path or channel. | |
| Aplazada | Media (5.3) | 0.47% | — | Shuanx BurpapifinderAI | 13/4/2025 | 17/6/2026 | A vulnerability has been found in shuanx BurpAPIFinder up to 2.0.2 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file BurpApiFinder.db. The manipulation leads to denial of service. The attack can be launched remotely. The exploit has been disclosed to the public and… | |
| Modificada | Media (4.3) | 0.73% | — | Portswigger Burp Suite | 8/7/2022 | 17/6/2026 | A URL disclosure issue was discovered in Burp Suite before 2022.6. If a user views a crafted response in the Repeater or Intruder, it may be incorrectly interpreted as a redirect. | |
| Modificada | Media (6.5) | 1.0% | — | Portswigger Burp Suite | 30/11/2021 | 17/6/2026 | PortSwigger Burp Suite Enterprise Edition before 2021.11 on Windows has weak file permissions for the embedded H2 database, which might lead to privilege escalation. This issue can be exploited by an adversary who has already compromised a valid Windows account on the server via separate means. In this scenario, the… | |
| Modificada | Media (6.5) | 1.1% | — | Portswigger Burp Suite | 29/3/2021 | 17/6/2026 | An issue was discovered in PortSwigger Burp Suite before 2021.2. During viewing of a malicious request, it can be manipulated into issuing a request that does not respect its upstream proxy configuration. This could leak NetNTLM hashes on Windows systems that fail to block outbound SMB. | |
| Modificada | Alta (7.4) | 0.49% | — | Portswigger Burp Suite | 18/6/2018 | 17/6/2026 | Burp Suite Community Edition 1.7.32 and 1.7.33 fail to validate the server certificate in a couple of HTTPS requests which allows a man in the middle to modify or view traffic. | |
| Modificada | Media (5.9) | 0.88% | — | Portswigger Burp Suite | 17/6/2018 | 17/6/2026 | PortSwigger Burp Suite before 1.7.34 has Improper Certificate Validation of the Collaborator server certificate, which might allow man-in-the-middle attackers to obtain interaction data. | |
| Modificada | Alta (7.1) | 0.31% | — | Burp Project Burp | 4/6/2018 | 17/6/2026 | The Gentoo app-backup/burp package before 2.1.32 has incorrect group ownership of the /etc/burp directory, which might allow local users to obtain read and write access to arbitrary files by leveraging access to a certain account for a burp-server.conf change. | |
| Modificada | Alta (7.1) | 0.27% | — | Burp Project Burp | 4/6/2018 | 17/6/2026 | The Gentoo app-backup/burp package before 2.1.32 sets the ownership of the PID file directory to the burp account, which might allow local users to kill arbitrary processes by leveraging access to this account for PID file modification before a root script sends a SIGKILL. |