Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

494 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.5)1.1%—Radare222/5/201817/6/2026
The _inst__lds() function in radare2 2.5.0 allows remote attackers to cause a denial of service (heap-based out-of-bounds read and application crash) via a crafted binary file.
ModificadaAlta (8.8)51%💥 ExploitIBM Qradar Security Information AND Event Manager26/4/201817/6/2026
IBM Security QRadar SIEM 7.2 and 7.3 could allow a user to bypass authentication which could lead to code execution. IBM X-Force ID: 138824.
ModificadaMedia (6.1)0.67%—IBM Qradar Security Information AND Event ManagerIBM Qradar Risk ManagerIBM Qradar Vulnerability ManagerIBM Qradar Incident Forensics+126/4/201817/6/2026
IBM Security QRadar SIEM 7.2 and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 134814.
ModificadaMedia (6.5)2.5%—IBM Qradar Security Information AND Event ManagerIBM Qradar Incident ForensicsIBM Qradar Network Insights26/4/201817/6/2026
IBM Security QRadar SIEM 7.2 and 7.3 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 134812.
ModificadaMedia (6.3)1.1%—IBM Qradar Security Information AND Event Manager26/4/201817/6/2026
IBM Security QRadar SIEM 7.2 and 7.3 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 134811.
ModificadaMedia (5.6)1.4%—IBM Qradar Security Information AND Event Manager26/4/201817/6/2026
IBM Security QRadar SIEM 7.2 and 7.3 could allow an unauthenticated user to execute code remotely with lower level privileges under unusual circumstances. IBM X-Force ID: 134810.
ModificadaMedia (5.5)0.89%—Radare217/4/201817/6/2026
In radare2 2.5.0, there is a heap-based buffer over-read in the dalvik_op function (libr/anal/p/anal_dalvik.c). Remote attackers could leverage this vulnerability to cause a denial of service via a crafted DEX file. Note that this issue is different from CVE-2018-8809, which was patched earlier.
ModificadaMedia (5.5)0.89%—Radare217/4/201817/6/2026
In radare2 2.5.0, there is a heap-based buffer over-read in the r_hex_bin2str function (libr/util/hex.c). Remote attackers could leverage this vulnerability to cause a denial of service via a crafted DEX file. This issue is different from CVE-2017-15368.
ModificadaBaja (3.3)0.36%—IBM Qradar Security Information AND Event Manager4/4/201817/6/2026
IBM QRadar 7.3 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 134914.
ModificadaMedia (5.4)0.61%—IBM Qradar Security Information AND Event Manager4/4/201817/6/2026
IBM QRadar 7.3 and 7.3.1 specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors. IBM X-Force ID: 133122.
ModificadaAlta (8.8)0.54%—IBM Qradar Security Information AND Event Manager29/3/201817/6/2026
Cross-site request forgery (CSRF) vulnerability in the xmlrpc.cgi service in IBM QRadar SIEM 7.1 before MR2 Patch 11 Interim Fix 02 and 7.2.x before 7.2.5 Patch 4 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences via vectors related to webmin. IBM X-Force…
ModificadaMedia (5.5)1.1%—Radare220/3/201817/6/2026
In radare2 2.4.0, there is a heap-based buffer over-read in the get_ivar_list_t function of mach0_classes.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted Mach-O file.
ModificadaMedia (5.5)1.1%—Radare220/3/201817/6/2026
In radare2 2.4.0, there is a heap-based buffer over-read in the dalvik_op function of anal_dalvik.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted dex file.
ModificadaMedia (5.5)1.1%—Radare220/3/201817/6/2026
In radare2 2.4.0, there is a heap-based buffer over-read in the r_asm_disassemble function of asm.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted dex file.
ModificadaMedia (5.3)1.7%—IBM Qradar Pulse8/3/201817/6/2026
IBM Pulse for QRadar 1.0.0 - 1.0.3 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 133123.
ModificadaMedia (6.1)0.93%—F-secure Radar16/2/201817/6/2026
F-Secure Radar (on-premises) before 2018-02-15 has an Unvalidated Redirect via the ReturnUrl parameter that triggers upon a user login.
ModificadaMedia (6.1)0.93%—F-secure Radar16/2/201817/6/2026
F-Secure Radar (on-premises) before 2018-02-15 has XSS via vectors involving the Tags parameter in the JSON request body in an outbound request for the /api/latest/vulnerabilityscans/tags/batch resource, aka a "suggested metadata tags for assets" issue.
ModificadaMedia (6.1)0.98%—IBM Qradar Security Information AND Event Manager10/1/201817/6/2026
IBM QRadar 7.2 and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 133121.
ModificadaMedia (4.2)12%💥 ExploitIBM Qradar Security Information AND Event Manager10/1/201817/6/2026
IBM QRadar 7.2 and 7.3 specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors. IBM X-Force ID: 119737.
ModificadaAlta (8.8)2.7%—IBM Qradar Security Information AND Event Manager20/12/201717/6/2026
IBM QRadar 7.2 and 7.3 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary commands on the system. IBM X-Force ID: 134178.
ModificadaMedia (5.5)1.1%—Radare213/11/201717/6/2026
In radare2 2.0.1, libr/bin/dwarf.c allows remote attackers to cause a denial of service (invalid read and application crash) via a crafted ELF file, related to r_bin_dwarf_parse_comp_unit in dwarf.c and sdb_set_internal in shlr/sdb/src/sdb.c.
ModificadaMedia (5.5)1.2%—Radare21/11/201717/6/2026
In radare 2.0.1, a pointer wraparound vulnerability exists in store_versioninfo_gnu_verdef() in libr/bin/format/elf/elf.c.
ModificadaAlta (7.8)0.98%—Radare21/11/201717/6/2026
In radare 2.0.1, an out-of-bounds read vulnerability exists in string_scan_range() in libr/bin/bin.c when doing a string search.
ModificadaAlta (7.8)1.0%—Radare21/11/201717/6/2026
In radare 2.0.1, a memory corruption vulnerability exists in store_versioninfo_gnu_verdef() and store_versioninfo_gnu_verneed() in libr/bin/format/elf/elf.c, as demonstrated by an invalid free. This error is due to improper sh_size validation when allocating memory.
ModificadaAlta (7.8)1.2%—Radare227/10/201717/6/2026
In radare2 2.0.1, an integer exception (negative number leading to an invalid memory access) exists in store_versioninfo_gnu_verdef() in libr/bin/format/elf/elf.c via crafted ELF files when parsing the ELF version on 32bit systems.
Orbitaley — Vulnerabilidades