Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

2287 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaBaja (2.1)0.31%—Facebook-julykringcadayona Student Information System24/11/202517/6/2026
A vulnerability was identified in itsourcecode Student Information System 1.0. Affected by this vulnerability is an unknown functionality of the file /schedule_edit1.php. Such manipulation of the argument schedule_id leads to sql injection. The attack may be launched remotely. The exploit is publicly available and…
AplazadaBaja (1)0.12%—Xilinx Versal Adaptive SOCAIARM Trusted Firmware FOR Cortex AAIARM Power State Coordination InterfaceAI23/11/202517/6/2026
The Secure Flag passed to Versal™ Adaptive SoC’s Trusted Firmware for Cortex®-A processors (TF-A) for Arm’s Power State Coordination Interface (PSCI) commands were incorrectly set to secure instead of using the processor’s actual security state. This would allow the PSCI requests to appear they were from processors in…
AnalizadaBaja (2.1)0.31%—Facebook-julykringcadayona Student Information System18/11/202517/6/2026
A vulnerability was determined in itsourcecode Student Information System 1.0. The affected element is an unknown function of the file /enrollment_edit1.php. Executing manipulation of the argument en_id can lead to sql injection. The attack may be performed from remote. The exploit has been publicly disclosed and may…
AplazadaAlta (7.3)0.14%—Dell Controlvault3AIDell Controlvault3 PlusAIBroadcom Storage AdapterAI17/11/202517/6/2026
Multiple out-of-bounds read and write vulnerabilities exist in the ControlVault WBDI Driver Broadcom Storage Adapter functionality of Dell ControlVault3 prior to 5.15.14.19 and Dell ControlVault3 Plus prior to 6.2.36.47. A specially crafted WinBioControlUnit call can lead to memory corruption. An attacker can issue an…
AplazadaAlta (7.3)0.16%—Dell Controlvault3AIDell Controlvault3 PlusAIBroadcom Storage AdapterAI17/11/202517/6/2026
Multiple out-of-bounds read and write vulnerabilities exist in the ControlVault WBDI Driver Broadcom Storage Adapter functionality of Dell ControlVault3 prior to 5.15.14.19 and Dell ControlVault3 Plus prior to 6.2.36.47. A specially crafted WinBioControlUnit call can lead to memory corruption. An attacker can issue an…
AnalizadaMedia (5.5)0.15%—Radare214/11/202517/6/2026
A NULL pointer dereference vulnerability was discovered in radare2 6.0.5 and earlier within the info() function of bin_ne.c. A crafted binary input can trigger a segmentation fault, leading to a denial of service when the tool processes malformed data.
AnalizadaMedia (4.3)0.29%—Radare214/11/202517/6/2026
A NULL pointer dereference vulnerability was discovered in radare2 6.0.5 and earlier within the load() function of bin_dyldcache.c. Processing a crafted file can cause a segmentation fault and crash the program.
AplazadaAlta (8.5)0.13%—RadarrAI13/11/202517/6/2026
A vulnerability has been found in Radarr 5.28.0.10274. The affected element is an unknown function of the file C:\ProgramData\Radarr\bin\Radarr.Console.exe of the component Service. Such manipulation leads to incorrect default permissions. The attack can only be performed from a local environment. The vendor was…
AnalizadaMedia (6.5)0.24%—IBM Qradar Security Information AND Event Manager12/11/202517/6/2026
IBM QRadar SIEM 7.5 through 7.5.0 UP14 stores user credentials in configuration files in source control which can be read by an authenticated user.
AplazadaMedia (5.1)0.12%—Intel Ethernet Adapter Complete Driver PackAI11/11/202517/6/2026
Time-of-check time-of-use race condition for some Intel Ethernet Adapter Complete Driver Pack software before version 1.5.1.0 within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable denial of service.…
AplazadaAlta (7.5)0.38%—Kamleshyadav MiraculousAI6/11/202517/6/2026
Missing Authorization vulnerability in kamleshyadav Miraculous miraculous allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Miraculous: from n/a through < 2.0.9.
AplazadaCrítica (9.8)0.45%—Kamleshyadav Miraculous CoreAI6/11/202517/6/2026
Authorization Bypass Through User-Controlled Key vulnerability in kamleshyadav Miraculous Core Plugin miraculouscore allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Miraculous Core Plugin: from n/a through < 2.0.9.
AnalizadaMedia (5.4)0.18%—IBM Qradar Security Information AND Event Manager27/10/202517/6/2026
IBM QRadar SIEM 7.5 through 7.5.0 Update Pack 13 Independent Fix 02 is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted…
AnalizadaMedia (5.4)0.18%—IBM Qradar Security Information AND Event Manager27/10/202517/6/2026
IBM QRadar SIEM 7.5 through 7.5.0 Update Pack 13 Independent Fix 02 is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted…
AnalizadaAlta (7.8)0.13%—IBM Qradar Security Information AND Event Manager27/10/202517/6/2026
IBM QRadar SIEM 7.5 through 7.5.0 Update Pack 13 Independent Fix 02 is vulnerable to privilege escalation due to improper privilege assignment to an update script.
AplazadaMedia (4.3)0.12%—Waituk EntradaAI27/10/202530/9/2026
Cross-Site Request Forgery (CSRF) vulnerability in Waituk Entrada theme allows Cross Site Request Forgery.This issue affects Entrada: from n/a through 5.7.7.
AplazadaAlta (8.7)0.49%—Karmada DashboardAI24/10/202517/6/2026
Karmada Dashboard is a general-purpose, web-based control panel for Karmada which is a multi-cluster management project. Prior to version 0.2.0, there is an authentication bypass vulnerability in the Karmada Dashboard API. The backend API endpoints (e.g., /api/v1/secret, /api/v1/service) did not enforce…
AplazadaAlta (7.1)0.24%—Kamleshyadav CF7 Auto Responder AddonAI22/10/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in kamleshyadav CF7 Auto Responder Addon CF7-autoresponder-addon allows DOM-Based XSS.This issue affects CF7 Auto Responder Addon: from n/a through <= 2.4.
AplazadaAlta (7.1)0.25%—Kamleshyadav RockondjAI22/10/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in kamleshyadav RockON DJ rockon allows Reflected XSS.This issue affects RockON DJ: from n/a through <= 3.3.
AnalizadaBaja (3.3)0.16%—Radare217/10/202517/6/2026
radare2 v5.9.8 and before contains a memory leak in the function bochs_open.
AnalizadaMedia (5.5)0.17%—Radare217/10/202517/6/2026
radare2 v5.9.8 and before contains a memory leak in the function r2r_subprocess_init.
AnalizadaMedia (5.5)0.17%—Radare217/10/202517/6/2026
radare2 v5.9.8 and before contains a memory leak in the function r_bin_object_new.
AnalizadaMedia (5.5)0.16%—Radare216/10/202517/6/2026
radare2 v.5.9.8 and before contains a memory leak in the function _load_relocations.
AplazadaAlta (7.7)0.32%—Allen Bradley 1715 Ethernet IP AdapterAI14/10/202517/6/2026
A denial-of-service security issue exists in the affected product and version. The security issue is caused through CIP communication using crafted payloads. The security issue could result in no CIP communication with 1715 EtherNet/IP Adapter.A restart is required to recover.
ModificadaBaja (1.9)0.28%—Westboy Cicadascms5/10/202517/6/2026
A vulnerability was determined in westboy CicadasCMS up to 2431154dac8d0735e04f1fd2a3c3556668fc8dab. The impacted element is the function Save of the file src/main/java/com/zhiliao/common/template/TemplateFileServiceImpl.java of the component Template Management Page. This manipulation causes cross site scripting. It…