Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
494 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.1) | 0.68% | — | IBM Qradar Security Information AND Event Manager | 22/7/2019 | 17/6/2026 | IBM QRadar SIEM 7.2 and 7.3 specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors. IBM X-Force ID: 155350. | |
| Modificada | Media (5.4) | 0.67% | — | IBM Qradar Security Information AND Event Manager | 17/7/2019 | 17/6/2026 | IBM QRadar SIEM 7.2 and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 159131. | |
| Modificada | Baja (3.3) | 0.33% | — | IBM Qradar Security Information AND Event Manager | 17/7/2019 | 17/6/2026 | IBM QRadar SIEM 7.2 and 7.3 could allow a local user to obtain sensitive information when exporting content that could aid an attacker in further attacks against the system. IBM X-Force ID: 156563. | |
| Modificada | Media (5.3) | 1.3% | — | IBM Qradar Security Information AND Event Manager | 17/7/2019 | 17/6/2026 | IBM QRadar SIEM 7.2 and 7.3 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 155346. | |
| Modificada | Media (6.1) | 0.90% | — | IBM Qradar Security Information AND Event Manager | 17/7/2019 | 17/6/2026 | IBM QRadar SIEM 7.2 and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 155345. | |
| Modificada | Media (5.5) | 0.94% | — | Radare2 | 17/6/2019 | 17/6/2026 | In radare2 through 3.5.1, cmd_mount in libr/core/cmd_mount.c has a double free for the ms command. | |
| Modificada | Alta (7.5) | 1.8% | — | Radare2 | 15/6/2019 | 17/6/2026 | radare2 through 3.5.1 mishandles the RParse API, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact, as demonstrated by newstr buffer overflows during replace operations. This affects libr/asm/asm.c and libr/parse/parse.c. | |
| Modificada | Alta (7.8) | 1.6% | — | Radare2Fedoraproject Fedora | 13/6/2019 | 17/6/2026 | In radare2 through 3.5.1, the rcc_context function of libr/egg/egg_lang.c mishandles changing context. This allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact (invalid memory access in r_egg_lang_parsechar; invalid free in rcc_pusharg). | |
| Modificada | Alta (7.8) | 1.7% | — | Radare2 | 10/6/2019 | 17/6/2026 | In radare2 through 3.5.1, there is a heap-based buffer over-read in the r_egg_lang_parsechar function of egg_lang.c. This allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact because of missing length validation in libr/egg/egg.c. | |
| Modificada | Media (5.9) | 1.0% | — | IBM Qradar Security Information AND Event Manager | 29/5/2019 | 17/6/2026 | IBM QRadar SIEM 7.2.8 WinCollect could allow an attacker to obtain sensitive information by spoofing a trusted entity using man in the middle techniques due to not validating or incorrectly validating a certificate. IBM X-Force ID: 160072. | |
| Modificada | Media (5.3) | 1.8% | — | IBM Qradar Security Information AND Event Manager | 19/4/2019 | 17/6/2026 | IBM QRadar SIEM 7.3 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 147708. | |
| Modificada | Alta (8.1) | 2.2% | — | IBM Qradar Security Information AND Event Manager | 8/4/2019 | 17/6/2026 | IBM QRadar SIEM 7.3.2 could allow a user to bypass authentication exposing certain functionality which could lead to information disclosure or modification of application configuration. IBM X-Force ID: 158986. | |
| Modificada | Alta (7.5) | 1.3% | — | IBM Qradar Security Information AND Event Manager | 15/2/2019 | 17/6/2026 | IBM QRadar SIEM 7.2 and 7.3 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 134177. | |
| Modificada | Media (5.3) | 1.7% | — | IBM Qradar Security Information AND Event Manager | 29/1/2019 | 17/6/2026 | IBM QRadar SIEM 7.2 and 7.3 fails to adequately filter user-controlled input data for syntax that has control-plane implications which could allow an attacker to modify displayed content. IBM X-Force ID: 147811. | |
| Modificada | Media (5.5) | 1.0% | — | Radare2 | 25/12/2018 | 17/6/2026 | In radare2 prior to 3.1.1, core_anal_bytes in libr/core/cmd_anal.c allows attackers to cause a denial-of-service (application crash caused by out-of-bounds read) by crafting a binary file. | |
| Modificada | Media (5.5) | 1.1% | — | Radare2 | 25/12/2018 | 17/6/2026 | In radare2 prior to 3.1.2, the parseOperands function in libr/asm/arch/arm/armass64.c allows attackers to cause a denial-of-service (application crash caused by stack-based buffer overflow) by crafting an input file. | |
| Modificada | Media (5.5) | 0.94% | — | Radare2 | 25/12/2018 | 17/6/2026 | In radare2 through 3.1.3, the armass_assemble function in libr/asm/arch/arm/armass.c allows attackers to cause a denial-of-service (application crash by out-of-bounds read) by crafting an arm assembly input because a loop uses an incorrect index in armass.c and certain length validation is missing in armass64.c, a… | |
| Modificada | Media (5.5) | 0.95% | — | Radare2 | 25/12/2018 | 17/6/2026 | In radare2 prior to 3.1.1, r_bin_dyldcache_extract in libr/bin/format/mach0/dyldcache.c may allow attackers to cause a denial-of-service (application crash caused by out-of-bounds read) by crafting an input file. | |
| Modificada | Media (5.5) | 0.87% | — | Radare2 | 25/12/2018 | 17/6/2026 | In radare2 through 3.1.3, the assemble function inside libr/asm/p/asm_arm_cs.c allows attackers to cause a denial-of-service (application crash via an r_num_calc out-of-bounds read) by crafting an arm assembly input because a loop uses an incorrect index in armass.c and certain length validation is missing in… | |
| Modificada | Media (5.5) | 1.0% | — | Radare2 | 25/12/2018 | 17/6/2026 | In radare2 prior to 3.1.1, the parseOperand function inside libr/asm/p/asm_x86_nz.c may allow attackers to cause a denial of service (application crash in libr/util/strbuf.c via a stack-based buffer over-read) by crafting an input file, a related issue to CVE-2018-20455. | |
| Modificada | Media (5.5) | 1.1% | — | Radare2 | 25/12/2018 | 17/6/2026 | In radare2 prior to 3.1.1, the parseOperand function inside libr/asm/p/asm_x86_nz.c may allow attackers to cause a denial of service (application crash via a stack-based buffer overflow) by crafting an input file, a related issue to CVE-2018-20456. | |
| Modificada | Alta (7.5) | 1.4% | — | IBM Qradar Advisor With Watson | 5/12/2018 | 17/6/2026 | IBM QRadar Advisor with Watson 1.14.0 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 147810. | |
| Modificada | Alta (7.1) | 1.9% | — | IBM Qradar Security Information AND Event Manager | 5/12/2018 | 17/6/2026 | IBM QRadar SIEM 7.2 and 7.3 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 147709. | |
| Modificada | Media (5.4) | 0.66% | — | IBM Qradar Incident Forensics | 5/12/2018 | 17/6/2026 | IBM QRadar SIEM 7.2 and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 147707. | |
| Modificada | Media (5.5) | 0.34% | — | IBM Qradar Incident Forensics | 5/12/2018 | 17/6/2026 | IBM QRadar SIEM 7.2 and 7.3 uses hard-coded credentials which could allow an attacker to bypass the authentication configured by the administrator. IBM X-Force ID: 144656. |