Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2640▼ 268 respecto a la semana anterior
Críticas / altas1348▲ 90 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)58▼ 468 respecto a la semana anterior
–

9 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisCrítica (9.2)0.33%—Portswigger Burp Suite DastAI24/9/202624/9/2026
In PortSwigger Burp Suite DAST (formerly Burp Suite Enterprise Edition) before 2026.8, an authentication bypass can occur via an alternate path or channel.
ModificadaAlta (7.5)1.0%—Swig-templates Project Swig-templatesSwig Project Swig15/3/202317/6/2026
Directory traversal vulnerability in swig-templates thru 2.0.4 and swig thru 1.4.2, allows attackers to read arbitrary files via the include or extends tags.
ModificadaCrítica (9.8)1.0%—Swig-templates Project Swig-templatesSwig Project Swig15/3/202317/6/2026
An issue was discovered in swig-templates thru 2.0.4 and swig thru 1.4.2, allows attackers to execute arbitrary code via crafted Object.prototype anonymous function.
ModificadaMedia (4.3)0.73%—Portswigger Burp Suite8/7/202217/6/2026
A URL disclosure issue was discovered in Burp Suite before 2022.6. If a user views a crafted response in the Repeater or Intruder, it may be incorrectly interpreted as a redirect.
ModificadaMedia (6.5)1.0%—Portswigger Burp Suite30/11/202117/6/2026
PortSwigger Burp Suite Enterprise Edition before 2021.11 on Windows has weak file permissions for the embedded H2 database, which might lead to privilege escalation. This issue can be exploited by an adversary who has already compromised a valid Windows account on the server via separate means. In this scenario, the…
ModificadaMedia (6.5)1.1%—Portswigger Burp Suite29/3/202117/6/2026
An issue was discovered in PortSwigger Burp Suite before 2021.2. During viewing of a malicious request, it can be manipulated into issuing a request that does not respect its upstream proxy configuration. This could leak NetNTLM hashes on Windows systems that fail to block outbound SMB.
ModificadaAlta (7.4)0.49%—Portswigger Burp Suite18/6/201817/6/2026
Burp Suite Community Edition 1.7.32 and 1.7.33 fail to validate the server certificate in a couple of HTTPS requests which allows a man in the middle to modify or view traffic.
ModificadaMedia (5.9)0.88%—Portswigger Burp Suite17/6/201817/6/2026
PortSwigger Burp Suite before 1.7.34 has Improper Certificate Validation of the Collaborator server certificate, which might allow man-in-the-middle attackers to obtain interaction data.
ModificadaAlta (7.5)1.1%—Walnutstreet Cgswigmore13/3/200916/6/2026
SQL injection vulnerability in the Swigmore institute (cgswigmore) extension before 0.1.2 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.