Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
2287 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.9) | 0.33% | — | Pingidentity PingfederateAIGoogle AdapterAI | 15/6/2025 | 17/6/2026 | Improper handling of non-200 http responses in the PingFederate Google Adapter leads to thread exhaustion under normal usage conditions. | |
| Aplazada | Media (6.4) | 0.21% | — | Diot ScadaAI | 14/6/2025 | 17/6/2026 | The DIOT SCADA with MQTT plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'diot' shortcode in all versions up to, and including, 1.0.5.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (6.6) | 0.16% | — | AMD Versal Adaptive SOCAI | 10/6/2025 | 17/6/2026 | In AMD Versal Adaptive SoC devices, the lack of address validation when executing PLM runtime services through the PLM firmware can allow access to isolated or protected memory spaces, resulting in the loss of integrity and confidentiality. | |
| Aplazada | Baja (3.2) | 0.15% | — | AMD Versal Adaptive SOCAI | 10/6/2025 | 17/6/2026 | In AMD Versal Adaptive SoC devices, the incorrect configuration of the SSS during runtime (post-boot) cryptographic operations could cause data to be incorrectly written to and read from invalid locations as well as returning incorrect cryptographic data. | |
| Aplazada | Crítica (9.3) | 0.43% | — | Kamleshyadav WP Lead Capturing PagesAI | 9/6/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in kamleshyadav WP Lead Capturing Pages leadcapture allows Blind SQL Injection.This issue affects WP Lead Capturing Pages: from n/a through < 2.6. | |
| Analizada | Alta (8.3) | 1.6% | — | Zohocorp Manageengine Adaudit Plus | 9/6/2025 | 17/6/2026 | Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection in the alerts module. | |
| Analizada | Alta (8.3) | 1.6% | — | Zohocorp Manageengine Adaudit Plus | 9/6/2025 | 17/6/2026 | Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection in Service Account Auditing reports. | |
| Analizada | Alta (8.3) | 1.6% | — | Zohocorp Manageengine Adaudit Plus | 9/6/2025 | 17/6/2026 | Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection in the Service Account Auditing reports. | |
| Aplazada | Media (6.5) | 0.25% | — | Shahjada Wpdm-premium-packagesAI | 6/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Shahjada WPDM – Premium Packages wpdm-premium-packages allows Stored XSS.This issue affects WPDM – Premium Packages: from n/a through <= 6.0.6. | |
| Aplazada | Alta (7.6) | 0.42% | — | Renzo Tejada Libro DE Reclamaciones Y QuejasAI | 6/6/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Renzo Tejada Libro de Reclamaciones y Quejas libro-de-reclamaciones-y-quejas allows SQL Injection.This issue affects Libro de Reclamaciones y Quejas: from n/a through <= 0.9. | |
| Aplazada | Media (5.9) | 0.33% | — | Shamil Shafeev Dadata RUAI | 6/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Shamil Shafeev «Подсказки» от DaData.ru dadata-ru allows Stored XSS.This issue affects «Подсказки» от DaData.ru: from n/a through <= 1.0.6. | |
| Analizada | Baja (2) | 0.25% | — | Radare2 | 5/6/2025 | 17/6/2026 | A vulnerability was found in Radare2 5.9.9. It has been classified as problematic. Affected is the function r_cons_pal_init in the library /libr/cons/pal.c of the component radiff2. The manipulation of the argument -T leads to memory corruption. An attack has to be approached locally. The complexity of an attack is… | |
| Analizada | Baja (2) | 0.24% | — | Radare2 | 5/6/2025 | 17/6/2026 | A vulnerability was found in Radare2 5.9.9 and classified as problematic. This issue affects the function r_cons_context_break_pop in the library /libr/cons/cons.c of the component radiff2. The manipulation of the argument -T leads to memory corruption. The attack needs to be approached locally. The complexity of an… | |
| Analizada | Baja (2) | 0.22% | — | Radare2 | 5/6/2025 | 17/6/2026 | A vulnerability has been found in Radare2 5.9.9 and classified as problematic. This vulnerability affects the function r_cons_rainbow_free in the library /libr/cons/pal.c of the component radiff2. The manipulation of the argument -T leads to memory corruption. It is possible to launch the attack on the local host. The… | |
| Analizada | Baja (2) | 0.22% | — | Radare2 | 5/6/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in Radare2 5.9.9. This affects the function r_cons_pal_init in the library /libr/cons/pal.c of the component radiff2. The manipulation of the argument -T leads to memory corruption. Attacking locally is a requirement. The complexity of an attack is rather… | |
| Analizada | Baja (2) | 0.23% | — | Radare2 | 5/6/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in Radare2 5.9.9. Affected by this issue is the function r_cons_flush in the library /libr/cons/cons.c of the component radiff2. The manipulation of the argument -T leads to use after free. Local access is required to approach this attack. The… | |
| Analizada | Baja (2) | 0.23% | — | Radare2 | 5/6/2025 | 17/6/2026 | A vulnerability classified as problematic was found in Radare2 5.9.9. Affected by this vulnerability is the function cons_stack_load in the library /libr/cons/cons.c of the component radiff2. The manipulation of the argument -T leads to memory corruption. An attack has to be approached locally. The complexity of an… | |
| Analizada | Baja (2) | 0.23% | — | Radare2 | 5/6/2025 | 17/6/2026 | A vulnerability classified as problematic has been found in Radare2 5.9.9. Affected is the function r_cons_pal_init in the library /libr/cons/pal.c of the component radiff2. The manipulation leads to memory corruption. The attack needs to be approached locally. The complexity of an attack is rather high. The… | |
| Analizada | Baja (2) | 0.22% | — | Radare2 | 5/6/2025 | 17/6/2026 | A vulnerability was found in Radare2 5.9.9. It has been rated as problematic. This issue affects the function r_cons_is_breaked in the library /libr/cons/cons.c of the component radiff2. The manipulation of the argument -T leads to memory corruption. It is possible to launch the attack on the local host. The… | |
| Analizada | Alta (8.8) | 0.32% | — | IBM Cloud PAK FOR SecurityIBM Qradar Suite | 3/6/2025 | 17/6/2026 | IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 could allow an unauthenticated user in the environment to obtain highly sensitive information in configuration files. | |
| Analizada | Alta (7.2) | 0.64% | — | IBM Cloud PAK FOR SecurityIBM Qradar Suite | 3/6/2025 | 17/6/2026 | IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 could allow a privileged execute code in case management script creation due to the improper generation of code. | |
| Analizada | Media (6.5) | 0.43% | — | IBM Cloud PAK FOR SecurityIBM Qradar Suite | 3/6/2025 | 17/6/2026 | IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 could allow an authenticated user to cause a denial of service due to improperly validating API data input. | |
| Analizada | Media (6.5) | 0.26% | — | IBM Cloud PAK FOR SecurityIBM Qradar Suite | 3/6/2025 | 17/6/2026 | IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 does not invalidate session after a logout which could allow a user to impersonate another user on the system. | |
| Analizada | Media (4) | 0.18% | — | IBM Cloud PAK FOR SecurityIBM Qradar Suite | 3/6/2025 | 17/6/2026 | IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 allows web pages to be stored locally which can be read by another user on the system. | |
| Aplazada | Alta (8.5) | 0.20% | — | Realtek Bluetooth HCI AdaptorAI | 2/6/2025 | 17/6/2026 | Bluetooth HCI Adaptor from Realtek has a Link Following vulnerability. Local attackers with regular privileges can create a symbolic link with the same name as a specific file, causing the product to delete arbitrary files pointed to by the link. Subsequently, attackers can leverage arbitrary file deletion to… |