Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2540▼ 352 respecto a la semana anterior
Críticas / altas1339▲ 68 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 6 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
18 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.5) | 1.0% | — | Netgate Pfsense PlusAINetgate Pfsense CEAI | 25/9/2026 | 30/9/2026 | In Netgate pfSense Plus before 26.07 and pfSense CE before 2.9.0, a Local File Inclusion (LFI) vulnerability in the Dashboard (index.php) widget sequence data handling allows an authenticated attacker to execute arbitrary PHP code. To exploit this, an attacker with privileges to modify Dashboard settings and write… | |
| Aplazada | Media (5.4) | 0.50% | — | Netgate Pfsense PlusAINetgate Pfsense CEAI | 4/9/2026 | 14/9/2026 | Cross Site Scripting vulnerability in Netgate pfSense Plus software versions <= 26.03 pfSense CE software versions <= 2.8.1 allows a remote attacker to execute arbitrary code via the captive_portal_status.widget.php file | |
| Aplazada | Media (5.4) | 0.28% | — | Netgate Pfsense PlusAINetgate Pfsense CEAI | 4/9/2026 | 9/9/2026 | Cross-Site Scripting (XSS) vulnerability in the RSS Widget of Netgate pfSense Plus (versions 26.03, 25.11.1) and pfSense CE (version 2.8.1) allows remote authenticated attackers to inject arbitrary JavaScript via malicious content in an RSS feed title. The injected script executes in the browser of any authenticated… | |
| Pendiente de análisis | Media (5.1) | 1.1% | — | Pfsense PlusAIPfsense CEAI | 3/9/2026 | 9/9/2026 | pfSense Plus before 26.07 and CE before 2.9.0 allow authenticated users with the Firewall: Schedules: Edit privilege to inject arbitrary JavaScript via the descr parameter in /firewall_schedule_edit.php. The schedule description is stored without HTML sanitization and subsequently inserted into an HTML attribute value… | |
| Pendiente de análisis | Media (5.1) | 1.1% | — | Pfsense PlusAIPfsense CEAI | 3/9/2026 | 9/9/2026 | pfSense Plus before 26.07 and CE before 2.9.0 allow authenticated users with the Firewall: Rules: Edit privilege to inject arbitrary JavaScript via the descr parameter in /firewall_rules_edit.php. The firewall rule description is stored in the pfSense XML configuration with only backslash-escaping applied and no HTML… | |
| Pendiente de análisis | Media (5.1) | 1.1% | — | Pfsense PlusAIPfsense CEAI | 3/9/2026 | 9/9/2026 | pfSense Plus before 26.07 and CE before 2.9.0 allow authenticated users with the Status: Monitoring privilege to inject arbitrary JavaScript via graph configuration parameters in /status_monitoring.php. Multiple POST parameters including graph-left, graph-right, time-period, resolution, start-date, end-date,… | |
| Pendiente de análisis | Media (5.3) | 1.2% | — | Pfsense PlusAIPfsense CEAI | 19/8/2026 | 23/9/2026 | pfSense Plus before 26.07 and pfSense CE through 2.8.1 contain a stored cross-site scripting vulnerability in the Traffic Graphs top-talkers feature, where PTR records returned by reverse DNS lookups are incorporated without sanitization into AJAX responses and rendered as HTML through a DOM sink in the administrator… | |
| Modificada | Media (5.4) | 1.3% | — | Netgate Pfsense CENetgate Pfsense Plus | 14/5/2025 | 5/7/2026 | Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds is vulnerable to Cross-site scripting (XSS) in the Automatic Configuration Backup (ACB) service, allowing remote attackers to execute arbitrary JavaScript, delete backups, or leak sensitive information via an unsanitized "reason" field and… | |
| Analizada | Alta (8.8) | 12% | — | Netgate Pfsense CENetgate Pfsense Plus | 14/5/2025 | 17/6/2026 | Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds are vulnerable to command injection in the OpenVPN widget due to improper sanitization of user-supplied input to the OpenVPN management interface. An authenticated attacker can exploit this vulnerability by injecting arbitrary OpenVPN… | |
| Analizada | Media (5.4) | 8.5% | — | Netgate Pfsense CENetgate Pfsense Plus | 14/5/2025 | 17/6/2026 | Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds is vulnerable to Cross Site Scripting (XSS) in widgets/log.widget.php. | |
| Modificada | Media (5.9) | 94% | — | Openbsd OpensshPuttyFilezilla-project Filezilla ClientPanic Transmit 5+64 | 18/12/2023 | 17/6/2026 | The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension negotiation message), and a client and server may consequently end up with a connection for which some… | |
| Modificada | Alta (8.8) | 68% | — | Netgate PfsenseNetgate Pfsense Plus | 6/12/2023 | 17/6/2026 | An issue in Netgate pfSense Plus v.23.05.1 and before and pfSense CE v.2.7.0 allows a remote attacker to execute arbitrary code via a crafted request to the packet_capture.php file. | |
| Modificada | Alta (8.8) | 64% | — | Netgate PfsenseNetgate Pfsense Plus | 14/11/2023 | 17/6/2026 | An issue in Netgate pfSense v.2.7.0 allows a remote attacker to execute arbitrary code via a crafted request to the interfaces_gif_edit.php and interfaces_gre_edit.php components. | |
| Modificada | Crítica (9.8) | 9.8% | — | Netgate Pfsense PlusPfsense | 22/3/2023 | 17/6/2026 | Improper restriction of excessive authentication attempts in the SSHGuard component of Netgate pfSense Plus software v22.05.1 and pfSense CE software v2.6.0 allows attackers to bypass brute force protection mechanisms via crafted web requests. | |
| Modificada | Alta (8.8) | 4.5% | — | Netgate PfsenseNetgate Pfsense Plus | 31/3/2022 | 17/6/2026 | Improper access control vulnerability in pfSense CE and pfSense Plus (pfSense CE software versions prior to 2.6.0 and pfSense Plus software versions prior to 22.01) allows a remote attacker with the privilege to change NTP GPS settings to rewrite existing files on the file system, which may result in arbitrary command… | |
| Modificada | Alta (8.8) | 1.9% | — | Netgate PfsenseNetgate Pfsense Plus | 31/3/2022 | 17/6/2026 | Improper input validation vulnerability in pfSense CE and pfSense Plus (pfSense CE software versions prior to 2.6.0 and pfSense Plus software versions prior to 22.01) allows a remote attacker with the privilege to change OpenVPN client or server settings to execute an arbitrary command. | |
| Modificada | Media (6.1) | 2.9% | — | Netgate Pfsense PlusPfsense | 31/3/2022 | 17/6/2026 | Cross-site scripting vulnerability in pfSense CE and pfSense Plus (pfSense CE software versions 2.5.2 and earlier, and pfSense Plus software versions 21.05 and earlier) allows a remote attacker to inject an arbitrary script via a malicious URL. | |
| Modificada | Media (6.1) | 1.5% | — | PfsensePfsense Plus | 26/1/2022 | 17/6/2026 | /usr/local/www/pkg.php in pfSense CE before 2.6.0 and pfSense Plus before 22.01 uses $_REQUEST['pkg_filter'] in a PHP echo call, causing XSS. |