Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
494 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 1.1% | — | Radare2 | 22/5/2018 | 17/6/2026 | The _inst__lds() function in radare2 2.5.0 allows remote attackers to cause a denial of service (heap-based out-of-bounds read and application crash) via a crafted binary file. | |
| Modificada | Alta (8.8) | 51% | 💥 Exploit | IBM Qradar Security Information AND Event Manager | 26/4/2018 | 17/6/2026 | IBM Security QRadar SIEM 7.2 and 7.3 could allow a user to bypass authentication which could lead to code execution. IBM X-Force ID: 138824. | |
| Modificada | Media (6.1) | 0.67% | — | IBM Qradar Security Information AND Event ManagerIBM Qradar Risk ManagerIBM Qradar Vulnerability ManagerIBM Qradar Incident Forensics+1 | 26/4/2018 | 17/6/2026 | IBM Security QRadar SIEM 7.2 and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 134814. | |
| Modificada | Media (6.5) | 2.5% | — | IBM Qradar Security Information AND Event ManagerIBM Qradar Incident ForensicsIBM Qradar Network Insights | 26/4/2018 | 17/6/2026 | IBM Security QRadar SIEM 7.2 and 7.3 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 134812. | |
| Modificada | Media (6.3) | 1.1% | — | IBM Qradar Security Information AND Event Manager | 26/4/2018 | 17/6/2026 | IBM Security QRadar SIEM 7.2 and 7.3 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 134811. | |
| Modificada | Media (5.6) | 1.4% | — | IBM Qradar Security Information AND Event Manager | 26/4/2018 | 17/6/2026 | IBM Security QRadar SIEM 7.2 and 7.3 could allow an unauthenticated user to execute code remotely with lower level privileges under unusual circumstances. IBM X-Force ID: 134810. | |
| Modificada | Media (5.5) | 0.89% | — | Radare2 | 17/4/2018 | 17/6/2026 | In radare2 2.5.0, there is a heap-based buffer over-read in the dalvik_op function (libr/anal/p/anal_dalvik.c). Remote attackers could leverage this vulnerability to cause a denial of service via a crafted DEX file. Note that this issue is different from CVE-2018-8809, which was patched earlier. | |
| Modificada | Media (5.5) | 0.89% | — | Radare2 | 17/4/2018 | 17/6/2026 | In radare2 2.5.0, there is a heap-based buffer over-read in the r_hex_bin2str function (libr/util/hex.c). Remote attackers could leverage this vulnerability to cause a denial of service via a crafted DEX file. This issue is different from CVE-2017-15368. | |
| Modificada | Baja (3.3) | 0.36% | — | IBM Qradar Security Information AND Event Manager | 4/4/2018 | 17/6/2026 | IBM QRadar 7.3 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 134914. | |
| Modificada | Media (5.4) | 0.61% | — | IBM Qradar Security Information AND Event Manager | 4/4/2018 | 17/6/2026 | IBM QRadar 7.3 and 7.3.1 specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors. IBM X-Force ID: 133122. | |
| Modificada | Alta (8.8) | 0.54% | — | IBM Qradar Security Information AND Event Manager | 29/3/2018 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in the xmlrpc.cgi service in IBM QRadar SIEM 7.1 before MR2 Patch 11 Interim Fix 02 and 7.2.x before 7.2.5 Patch 4 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences via vectors related to webmin. IBM X-Force… | |
| Modificada | Media (5.5) | 1.1% | — | Radare2 | 20/3/2018 | 17/6/2026 | In radare2 2.4.0, there is a heap-based buffer over-read in the get_ivar_list_t function of mach0_classes.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted Mach-O file. | |
| Modificada | Media (5.5) | 1.1% | — | Radare2 | 20/3/2018 | 17/6/2026 | In radare2 2.4.0, there is a heap-based buffer over-read in the dalvik_op function of anal_dalvik.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted dex file. | |
| Modificada | Media (5.5) | 1.1% | — | Radare2 | 20/3/2018 | 17/6/2026 | In radare2 2.4.0, there is a heap-based buffer over-read in the r_asm_disassemble function of asm.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted dex file. | |
| Modificada | Media (5.3) | 1.7% | — | IBM Qradar Pulse | 8/3/2018 | 17/6/2026 | IBM Pulse for QRadar 1.0.0 - 1.0.3 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 133123. | |
| Modificada | Media (6.1) | 0.93% | — | F-secure Radar | 16/2/2018 | 17/6/2026 | F-Secure Radar (on-premises) before 2018-02-15 has an Unvalidated Redirect via the ReturnUrl parameter that triggers upon a user login. | |
| Modificada | Media (6.1) | 0.93% | — | F-secure Radar | 16/2/2018 | 17/6/2026 | F-Secure Radar (on-premises) before 2018-02-15 has XSS via vectors involving the Tags parameter in the JSON request body in an outbound request for the /api/latest/vulnerabilityscans/tags/batch resource, aka a "suggested metadata tags for assets" issue. | |
| Modificada | Media (6.1) | 0.98% | — | IBM Qradar Security Information AND Event Manager | 10/1/2018 | 17/6/2026 | IBM QRadar 7.2 and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 133121. | |
| Modificada | Media (4.2) | 12% | 💥 Exploit | IBM Qradar Security Information AND Event Manager | 10/1/2018 | 17/6/2026 | IBM QRadar 7.2 and 7.3 specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors. IBM X-Force ID: 119737. | |
| Modificada | Alta (8.8) | 2.7% | — | IBM Qradar Security Information AND Event Manager | 20/12/2017 | 17/6/2026 | IBM QRadar 7.2 and 7.3 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary commands on the system. IBM X-Force ID: 134178. | |
| Modificada | Media (5.5) | 1.1% | — | Radare2 | 13/11/2017 | 17/6/2026 | In radare2 2.0.1, libr/bin/dwarf.c allows remote attackers to cause a denial of service (invalid read and application crash) via a crafted ELF file, related to r_bin_dwarf_parse_comp_unit in dwarf.c and sdb_set_internal in shlr/sdb/src/sdb.c. | |
| Modificada | Media (5.5) | 1.2% | — | Radare2 | 1/11/2017 | 17/6/2026 | In radare 2.0.1, a pointer wraparound vulnerability exists in store_versioninfo_gnu_verdef() in libr/bin/format/elf/elf.c. | |
| Modificada | Alta (7.8) | 0.98% | — | Radare2 | 1/11/2017 | 17/6/2026 | In radare 2.0.1, an out-of-bounds read vulnerability exists in string_scan_range() in libr/bin/bin.c when doing a string search. | |
| Modificada | Alta (7.8) | 1.0% | — | Radare2 | 1/11/2017 | 17/6/2026 | In radare 2.0.1, a memory corruption vulnerability exists in store_versioninfo_gnu_verdef() and store_versioninfo_gnu_verneed() in libr/bin/format/elf/elf.c, as demonstrated by an invalid free. This error is due to improper sh_size validation when allocating memory. | |
| Modificada | Alta (7.8) | 1.2% | — | Radare2 | 27/10/2017 | 17/6/2026 | In radare2 2.0.1, an integer exception (negative number leading to an invalid memory access) exists in store_versioninfo_gnu_verdef() in libr/bin/format/elf/elf.c via crafted ELF files when parsing the ELF version on 32bit systems. |