Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

2287 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (4.8)0.32%—Radare217/2/202517/6/2026
A vulnerability, which was classified as problematic, was found in radare2 5.9.9 33286. Affected is an unknown function in the library /libr/main/rasm2.c of the component rasm2. The manipulation leads to memory corruption. An attack has to be approached locally. The exploit has been disclosed to the public and may be…
AnalizadaMedia (4.8)0.23%—IBM Qradar Security Information AND Event Manager14/2/202517/6/2026
IBM QRadar SIEM 7.5 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
AnalizadaCrítica (9.3)1.7%—Myscada Mypro13/2/202517/6/2026
mySCADA myPRO Manager is vulnerable to an OS command injection which could allow a remote attacker to execute arbitrary OS commands.
AnalizadaCrítica (10)7.2%—Myscada Mypro13/2/202517/6/2026
The administrative web interface of mySCADA myPRO Manager can be accessed without authentication which could allow an unauthorized attacker to retrieve sensitive information and upload files without the associated password.
AnalizadaMedia (5.1)0.60%—Myscada Mypro13/2/202517/6/2026
mySCADA myPRO Manager is vulnerable to cross-site request forgery (CSRF), which could allow an attacker to obtain sensitive information. An attacker would need to trick the victim in to visiting an attacker-controlled website.
AnalizadaCrítica (9.2)3.6%—Myscada Mypro13/2/202517/6/2026
mySCADA myPRO Manager stores credentials in cleartext, which could allow an attacker to obtain sensitive information.
AnalizadaCrítica (9.8)2.3%💥 PoCTheme-fusion Avada13/2/202517/6/2026
The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 7.11.13. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it…
AnalizadaCrítica (9.8)0.55%—Theme-fusion Avada Builder13/2/202517/6/2026
The Avada Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.11.13. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers…
AplazadaMedia (5.4)0.20%—Intel Ethernet Adapter Complete Driver PackAI12/2/202517/6/2026
Uncontrolled search path in some Intel(R) Ethernet Adapter Complete Driver Pack install before versions 29.1 may allow an authenticated user to potentially enable escalation of privilege via local access.
AplazadaCrítica (9.3)1.3%—Myscada MyproAI29/1/202517/6/2026
mySCADA myPRO does not properly neutralize POST requests sent to a specific port with email information. This vulnerability could be exploited by an attacker to execute arbitrary commands on the affected system.
AplazadaCrítica (9.3)1.3%—Myscada MyproAI29/1/202517/6/2026
mySCADA myPRO does not properly neutralize POST requests sent to a specific port with version information. This vulnerability could be exploited by an attacker to execute arbitrary commands on the affected system.
AnalizadaMedia (6.5)0.15%—IBM Qradar Security Information AND Event Manager28/1/202517/6/2026
IBM QRadar SIEM 7.5 transmits sensitive or security-critical data in cleartext in a communication channel that could be obtained by an unauthorized actor using man in the middle techniques.
AplazadaAlta (7.6)0.97%💥 PoCShahjada Wpdm-premium-packagesAI24/1/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Shahjada WPDM – Premium Packages wpdm-premium-packages allows Blind SQL Injection.This issue affects WPDM – Premium Packages: from n/a through <= 5.9.6.
AplazadaMedia (4.3)0.43%—JS Morisset JSM Show Post MetadataAI24/1/202517/6/2026
Missing Authorization vulnerability in JS Morisset JSM Show Post Metadata jsm-show-post-meta allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JSM Show Post Metadata: from n/a through <= 4.6.0.
AnalizadaMedia (5.4)0.22%—Theme-fusion Avada Builder22/1/202517/6/2026
The Avada Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including, 3.11.11 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with…
AnalizadaMedia (4.3)0.36%—IBM Security Qradar EDR19/1/202517/6/2026
IBM Security ReaQta 3.12 could allow an authenticated user to perform unauthorized actions due to reliance on untrusted inputs.
AplazadaAlta (7.1)0.17%—Teradata Vantage EditorAI17/1/202517/6/2026
Teradata Vantage Editor 1.0.1 is mostly intended for SQL database access and docs.teradata.com access, but provides unintended functionality (including Chromium Developer Tools) that can result in a client user accessing arbitrary remote websites.
AnalizadaMedia (5.3)0.37%—IBM Qradar Wincollect17/1/202517/6/2026
IBM QRadar WinCollect Agent 10.0.0 through 10.1.12 could allow a remote attacker to inject XML data into parameter values due to improper input validation of assumed immutable data.
AplazadaMedia (5.3)0.41%—Reckcn SppanadadminAI12/1/202517/6/2026
A vulnerability, which was classified as problematic, was found in reckcn SPPanAdmin 1.0. Affected is an unknown function of the file /;/admin/role/edit. The manipulation of the argument name leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and…
AplazadaMedia (6.5)0.21%—Lucia.intelisano Live Flight RadarAI9/1/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in lucia.intelisano Live Flight Radar live-flight-radar allows Stored XSS.This issue affects Live Flight Radar: from n/a through <= 1.0.
AplazadaMedia (6.1)0.36%—Semadatacoop Sema APIAI9/1/202517/6/2026
The SEMA API plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘catid’ parameter in all versions up to, and including, 5.27 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute…
AplazadaMedia (6)0.25%—Teradata DatabaseAISuse Linux Enterprise ServerAI8/1/202517/6/2026
Certain Teradata account-handling code through 2024-11-04, used with SUSE Enterprise Linux Server, mismanages groups. Specifically, when there is an operating system move from SUSE Enterprise Linux Server (SLES) 12 Service Pack (SP) 2 or 3 to SLES 15 SP2 on Teradata Database systems, some service/system user accounts,…
AplazadaMedia (5.3)0.29%—Allada T-shirt Designer FOR WoocommerceAI7/1/202517/6/2026
Missing Authorization vulnerability in Hermann LAHAMI Allada T-shirt Designer for Woocommerce allada-tshirt-designer-for-woocommerce.This issue affects Allada T-shirt Designer for Woocommerce: from n/a through <= 1.1.
AplazadaMedia (6.5)0.35%—Hpinfosys Metadata SEOAI7/1/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hpinfosys Metadata SEO metadata-seo allows Stored XSS.This issue affects Metadata SEO: from n/a through <= 2.3.
AnalizadaMedia (5.3)0.32%—IBM Security Qradar EDR7/1/202517/6/2026
IBM Security ReaQta 3.12 returns sensitive information in an HTTP response that could be used in further attacks against the system.