Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2743▲ 32 respecto a la semana anterior
Críticas / altas1477▲ 367 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
–

7 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.8%—Untangle Project Untangle26/7/202217/6/2026
untangle is a python library to convert XML data to python objects. untangle versions 1.2.0 and earlier improperly restricts recursive entity references in DTDs. By exploiting this vulnerability, a remote unauthenticated attacker may cause a denial-of-service (DoS) condition on the server where the product is running.
ModificadaAlta (7.5)1.7%—Untangle Project Untangle26/7/202217/6/2026
untangle is a python library to convert XML data to python objects. untangle versions 1.2.0 and earlier improperly restricts XML external entity references. By exploiting this vulnerability, a remote unauthenticated attacker may read the contents of local files.
ModificadaMedia (5.3)0.81%—Untangle Firewall NG12/11/202017/6/2026
Untangle Firewall NG before 16.0 uses MD5 for passwords.
ModificadaMedia (4.8)0.52%—Untangle NG Firewall14/11/201917/6/2026
When logged in as an admin user, the Title input field (under Reports) within Untangle NG firewall 14.2.0 is vulnerable to stored XSS.
ModificadaMedia (4.8)0.52%—Untangle NG Firewall14/11/201917/6/2026
When logged in as an admin user, the Untangle NG firewall 14.2.0 is vulnerable to reflected XSS at multiple places and specific user input fields.
ModificadaAlta (7.2)1.9%—Untangle NG Firewall14/11/201917/6/2026
The Untangle NG firewall 14.2.0 is vulnerable to an authenticated command injection when logged in as an admin user.
ModificadaAlta (7.2)0.91%—Untangle NG Firewall14/11/201917/6/2026
The Untangle NG firewall 14.2.0 is vulnerable to authenticated inline-query SQL injection within the timeDataDynamicColumn parameter when logged in as an admin user.