Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
494 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.96% | — | Radare2Fedoraproject Fedora | 24/2/2022 | 17/6/2026 | Denial of Service in GitHub repository radareorg/radare2 prior to 5.6.4. | |
| Modificada | Media (5.5) | 1.0% | — | Radare2Fedoraproject Fedora | 23/2/2022 | 17/6/2026 | Denial of Service in GitHub repository radareorg/radare2 prior to 5.6.4. | |
| Modificada | Alta (7.1) | 0.97% | — | Radare2Fedoraproject Fedora | 22/2/2022 | 17/6/2026 | Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.6.4. | |
| Modificada | Media (5.5) | 0.95% | — | Radare2Fedoraproject Fedora | 22/2/2022 | 17/6/2026 | NULL Pointer Dereference in GitHub repository radareorg/radare2 prior to 5.6.4. | |
| Modificada | Alta (7.8) | 1.2% | — | Radare2Fedoraproject Fedora | 22/2/2022 | 17/6/2026 | Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.6.4. | |
| Modificada | Crítica (9.8) | 1.3% | — | Radare2Fedoraproject Fedora | 16/2/2022 | 17/6/2026 | Use After Free in GitHub repository radareorg/radare2 prior to 5.6.2. | |
| Modificada | Alta (7.8) | 1.1% | — | Radare2Fedoraproject Fedora | 8/2/2022 | 17/6/2026 | Use After Free in GitHub repository radareorg/radare2 prior to 5.6.2. | |
| Modificada | Alta (7.1) | 0.97% | — | Radare2Fedoraproject Fedora | 8/2/2022 | 17/6/2026 | Access of Memory Location Before Start of Buffer in NPM radare2.js prior to 5.6.2. | |
| Modificada | Alta (7.1) | 0.95% | — | Radare2Fedoraproject Fedora | 8/2/2022 | 17/6/2026 | Access of Memory Location After End of Buffer in GitHub repository radareorg/radare2 prior to 5.6.2. | |
| Modificada | Alta (7.8) | 1.1% | — | Radare2Fedoraproject Fedora | 8/2/2022 | 17/6/2026 | Use After Free in NPM radare2.js prior to 5.6.2. | |
| Modificada | Alta (7.1) | 0.95% | — | Radare2Fedoraproject Fedora | 8/2/2022 | 17/6/2026 | Buffer Access with Incorrect Length Value in GitHub repository radareorg/radare2 prior to 5.6.2. | |
| Modificada | Alta (7.1) | 1.0% | — | Radare2Fedoraproject Fedora | 8/2/2022 | 17/6/2026 | Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.6.2. | |
| Modificada | Crítica (9.8) | 1.2% | — | Radare2 | 8/2/2022 | 17/6/2026 | Use After Free in GitHub repository radareorg/radare2 prior to 5.6.0. | |
| Modificada | Media (5.5) | 0.93% | — | Radare2Fedoraproject Fedora | 1/2/2022 | 17/6/2026 | NULL Pointer Dereference in GitHub repository radareorg/radare2 prior to 5.6.0. | |
| Modificada | Media (5.5) | 1.1% | — | Radare2Fedoraproject Fedora | 11/1/2022 | 17/6/2026 | radare2 is vulnerable to Out-of-bounds Read | |
| Modificada | Media (4.3) | 0.50% | — | IBM Qradar Security Information AND Event Manager | 1/12/2021 | 17/6/2026 | IBM QRadar SIEM 7.3 and 7.4 is vulnerable to server side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. This vulnerability is due to an incomplete fix for CVE-2020-4786. IBM… | |
| Modificada | Media (6.1) | 0.64% | — | IBM Qradar Security Information AND Event Manager | 1/12/2021 | 17/6/2026 | IBM QRadar SIEM 7.3 and 7.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 205281. | |
| Modificada | Media (5.9) | 1.2% | — | IBM Qradar Security Information AND Event Manager | 1/12/2021 | 17/6/2026 | IBM QRadar SIEM 7.3 and 7.4 could allow an attacker to obtain sensitive information due to the server performing key exchange without entity authentication on inter-host communications using man in the middle techniques. IBM X-Force ID: 203033. | |
| Modificada | Alta (7.5) | 0.69% | — | IBM Qradar Security Information AND Event Manager | 1/12/2021 | 17/6/2026 | IBM QRadar SIEM 7.3 and 7.4 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 196074. | |
| Modificada | Media (5.9) | 1.3% | — | IBM Qradar Network Security | 8/11/2021 | 17/6/2026 | IBM QRadar Network Security 5.4.0 and 5.5.0 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 174340. | |
| Modificada | Media (5.4) | 0.50% | — | IBM Qradar Network Security | 8/11/2021 | 17/6/2026 | IBM QRadar Network Security 5.4.0 and 5.5.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 174269. | |
| Modificada | Media (5.9) | 0.59% | — | IBM Qradar Network Security | 8/11/2021 | 17/6/2026 | IBM QRadar Network Security 5.4.0 and 5.5.0 transmits sensitive or security-critical data in cleartext in a communication channel that can be obtained using man in the middle techniques. IBM X-Force ID: 17467. | |
| Modificada | Media (6.1) | 0.65% | — | IBM Qradar Advisor | 20/10/2021 | 17/6/2026 | IBM QRadar Advisor 2.5 through 2.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 209566. | |
| Modificada | Alta (7.5) | 0.69% | — | IBM Qradar Security Information AND Event Manager | 15/9/2021 | 17/6/2026 | IBM QRadar SIEM 7.3 and 7.4 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 201778. | |
| Modificada | Media (6.1) | 1.0% | — | It-economics Techradar | 15/9/2021 | 17/6/2026 | The TechRadar app 1.1 for Confluence Server allows XSS via the Title field of a Radar. |