Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▲ 32 respecto a la semana anterior
Críticas / altas1477▲ 367 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
7 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.8% | — | Untangle Project Untangle | 26/7/2022 | 17/6/2026 | untangle is a python library to convert XML data to python objects. untangle versions 1.2.0 and earlier improperly restricts recursive entity references in DTDs. By exploiting this vulnerability, a remote unauthenticated attacker may cause a denial-of-service (DoS) condition on the server where the product is running. | |
| Modificada | Alta (7.5) | 1.7% | — | Untangle Project Untangle | 26/7/2022 | 17/6/2026 | untangle is a python library to convert XML data to python objects. untangle versions 1.2.0 and earlier improperly restricts XML external entity references. By exploiting this vulnerability, a remote unauthenticated attacker may read the contents of local files. | |
| Modificada | Media (5.3) | 0.81% | — | Untangle Firewall NG | 12/11/2020 | 17/6/2026 | Untangle Firewall NG before 16.0 uses MD5 for passwords. | |
| Modificada | Media (4.8) | 0.52% | — | Untangle NG Firewall | 14/11/2019 | 17/6/2026 | When logged in as an admin user, the Title input field (under Reports) within Untangle NG firewall 14.2.0 is vulnerable to stored XSS. | |
| Modificada | Media (4.8) | 0.52% | — | Untangle NG Firewall | 14/11/2019 | 17/6/2026 | When logged in as an admin user, the Untangle NG firewall 14.2.0 is vulnerable to reflected XSS at multiple places and specific user input fields. | |
| Modificada | Alta (7.2) | 1.9% | — | Untangle NG Firewall | 14/11/2019 | 17/6/2026 | The Untangle NG firewall 14.2.0 is vulnerable to an authenticated command injection when logged in as an admin user. | |
| Modificada | Alta (7.2) | 0.91% | — | Untangle NG Firewall | 14/11/2019 | 17/6/2026 | The Untangle NG firewall 14.2.0 is vulnerable to authenticated inline-query SQL injection within the timeDataDynamicColumn parameter when logged in as an admin user. |