Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 345 respecto a la semana anterior
Críticas / altas1316▼ 9 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 273 respecto a la semana anterior
35 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.1) | 0.24% | — | Endian Firewall Community | 2/4/2026 | 24/7/2026 | Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /manage/password/web/. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page. | |
| Analizada | Media (5.1) | 0.15% | — | Endian Firewall Community | 2/4/2026 | 24/7/2026 | Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the new_cert_name parameter to /manage/ca/certificate/. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page. | |
| Analizada | Media (5.1) | 0.27% | — | Endian Firewall Community | 2/4/2026 | 24/7/2026 | Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /manage/vpnauthentication/user/. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page. | |
| Analizada | Media (5.1) | 0.24% | — | Endian Firewall Community | 2/4/2026 | 24/7/2026 | Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /manage/ipsec/. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page. | |
| Analizada | Media (5.1) | 0.24% | — | Endian Firewall Community | 2/4/2026 | 24/7/2026 | Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the REMARK parameter to /cgi-bin/openvpnclient.cgi. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page. | |
| Analizada | Media (5.1) | 0.24% | — | Endian Firewall Community | 2/4/2026 | 24/7/2026 | Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /manage/dnsmasq/localdomains/. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page. | |
| Analizada | Media (5.1) | 0.24% | — | Endian Firewall Community | 2/4/2026 | 24/7/2026 | Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the ADDRESS BCC parameter to /cgi-bin/smtprouting.cgi. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page. | |
| Analizada | Media (5.1) | 0.24% | — | Endian Firewall Community | 2/4/2026 | 24/7/2026 | Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the domain parameter to /manage/smtpscan/domainrouting/. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page. | |
| Analizada | Media (5.1) | 0.24% | — | Endian Firewall Community | 2/4/2026 | 24/7/2026 | Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the DOMAIN parameter to /cgi-bin/smtpdomains.cgi. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page. | |
| Analizada | Media (5.1) | 0.24% | — | Endian Firewall Community | 2/4/2026 | 24/7/2026 | Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the group parameter to /cgi-bin/proxygroup.cgi. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page. | |
| Analizada | Media (5.1) | 0.24% | — | Endian Firewall Community | 2/4/2026 | 24/7/2026 | Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the user parameter to /cgi-bin/proxyuser.cgi. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page. | |
| Analizada | Media (5.1) | 0.24% | — | Endian Firewall Community | 2/4/2026 | 24/7/2026 | Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the mimetypes parameter to /cgi-bin/proxypolicy.cgi. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page. | |
| Analizada | Media (5.1) | 0.24% | — | Endian Firewall Community | 2/4/2026 | 24/7/2026 | Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /cgi-bin/xtaccess.cgi. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page. | |
| Analizada | Media (5.1) | 0.24% | — | Endian Firewall Community | 2/4/2026 | 24/7/2026 | Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /cgi-bin/vpnfw.cgi. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page. | |
| Analizada | Media (5.1) | 0.24% | — | Endian Firewall Community | 2/4/2026 | 24/7/2026 | Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /cgi-bin/zonefw.cgi. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page. | |
| Analizada | Media (5.1) | 0.24% | — | Endian Firewall Community | 2/4/2026 | 24/7/2026 | Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /cgi-bin/outgoingfw.cgi. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page. | |
| Analizada | Media (5.1) | 0.24% | — | Endian Firewall Community | 2/4/2026 | 24/7/2026 | Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /cgi-bin/incoming.cgi. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page. | |
| Analizada | Media (5.1) | 0.24% | — | Endian Firewall Community | 2/4/2026 | 24/7/2026 | Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /cgi-bin/snat.cgi. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page. | |
| Analizada | Media (5.1) | 0.24% | — | Endian Firewall Community | 2/4/2026 | 24/7/2026 | Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /cgi-bin/dnat.cgi. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page. | |
| Analizada | Media (5.1) | 0.24% | — | Endian Firewall Community | 2/4/2026 | 24/7/2026 | Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the dscp parameter to /manage/qos/rules/. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page. | |
| Analizada | Media (5.1) | 0.24% | — | Endian Firewall Community | 2/4/2026 | 24/7/2026 | Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the name parameter to /manage/qos/classes/. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page. | |
| Analizada | Media (5.1) | 0.24% | — | Endian Firewall Community | 2/4/2026 | 24/7/2026 | Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark user ham spam parameter to /cgi-bin/salearn.cgi. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page. | |
| Analizada | Media (5.1) | 0.24% | — | Endian Firewall Community | 2/4/2026 | 24/7/2026 | Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /manage/dhcp/fixed_leases/. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page. | |
| Analizada | Media (5.1) | 0.24% | — | Endian Firewall Community | 2/4/2026 | 24/7/2026 | Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the NAME parameter to /cgi-bin/uplinkeditor.cgi. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page. | |
| Analizada | Media (5.1) | 0.24% | — | Endian Firewall Community | 2/4/2026 | 24/7/2026 | Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /manage/dnsmasq/hosts/. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page. |