Vulnerabilidades em symfony

65 resultados
Análise Vexday

O Symfony apresenta um volume significativo de 65 CVEs catalogadas, com 39 publicadas nos últimos 90 dias, indicando vulnerabilidades recentes e contínuas. A fraqueza dominante é XSS (CWE-79), típica de frameworks web, embora apenas 1 seja crítica e nenhuma esteja sob ataque ativo no momento. O risco atual é moderado, mas demanda atenção ao padrão de descobertas recentes para detecção de novos exploits.

CVE-2024-50340HIGHAbility to change environment from query in symfony/runtimeEPSS 63.4%CVE-2022-24894MEDIUMSymfony storing cookie headers in HttpCacheEPSS 4.0%CVE-2020-15094HIGHRCE in SymfonyEPSS 3.0%CVE-2021-21424MEDIUMPrevent user enumeration using Guard or the new Authenticator-based SecurityEPSS 1.7%CVE-2021-32693MEDIUMAuthentication granted with multiple firewallsEPSS 1.4%CVE-2021-41270MEDIUMCSV Injection in SymfonyEPSS 1.4%CVE-2025-64500HIGHSymfony's incorrect parsing of PATH_INFO can lead to limited authorization bypassEPSS 1.3%CVE-2020-5255LOWPrevent cache poisoning via a Response Content-Type headerEPSS 1.3%CVE-2021-41268MEDIUMCookie persistence in SymfonyEPSS 1.3%CVE-2021-41267MEDIUMWebcache Poisoning in SymfonyEPSS 1.2%CVE-2020-5274MEDIUMExceptions displayed in non-debug configurations in SymfonyEPSS 1.2%CVE-2020-5275HIGHFirewall configured with unanimous strategy was not actually unanimous in symfony/security-httpEPSS 1.1%CVE-2026-45304HIGHSymfony: YAML Parser Exponential Memory Allocation via Recursive Collection-Alias Expansion ("Billion Laughs")EPSS 0.8%CVE-2026-45305HIGHSymfony: YAML Parser ReDoS via Catastrophic Backtracking in Parser::cleanup() RegexEPSS 0.8%CVE-2022-24895MEDIUMSymfony vulnerable to Session Fixation of CSRF tokensEPSS 0.8%CVE-2026-45133HIGHSymfony: [Yaml] Harden the parser when handling untrusted inputEPSS 0.7%CVE-2023-46733MEDIUMSymfony possible session fixation vulnerabilityEPSS 0.7%CVE-2023-46734MEDIUMSymfony potential Cross-site Scripting vulnerabilities in CodeExtension filtersEPSS 0.7%CVE-2024-51996HIGHSymphony has an Authentication Bypass via RememberMeEPSS 0.6%CVE-2026-45067MEDIUMSymfony: Email Header / SMTP Command Injection via CRLF in Symfony\Component\Mime\AddressEPSS 0.6%