Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
2287 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.8) | 0.32% | — | Radare2 | 17/2/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in radare2 5.9.9 33286. Affected is an unknown function in the library /libr/main/rasm2.c of the component rasm2. The manipulation leads to memory corruption. An attack has to be approached locally. The exploit has been disclosed to the public and may be… | |
| Analizada | Media (4.8) | 0.23% | — | IBM Qradar Security Information AND Event Manager | 14/2/2025 | 17/6/2026 | IBM QRadar SIEM 7.5 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Analizada | Crítica (9.3) | 1.7% | — | Myscada Mypro | 13/2/2025 | 17/6/2026 | mySCADA myPRO Manager is vulnerable to an OS command injection which could allow a remote attacker to execute arbitrary OS commands. | |
| Analizada | Crítica (10) | 7.2% | — | Myscada Mypro | 13/2/2025 | 17/6/2026 | The administrative web interface of mySCADA myPRO Manager can be accessed without authentication which could allow an unauthorized attacker to retrieve sensitive information and upload files without the associated password. | |
| Analizada | Media (5.1) | 0.60% | — | Myscada Mypro | 13/2/2025 | 17/6/2026 | mySCADA myPRO Manager is vulnerable to cross-site request forgery (CSRF), which could allow an attacker to obtain sensitive information. An attacker would need to trick the victim in to visiting an attacker-controlled website. | |
| Analizada | Crítica (9.2) | 3.6% | — | Myscada Mypro | 13/2/2025 | 17/6/2026 | mySCADA myPRO Manager stores credentials in cleartext, which could allow an attacker to obtain sensitive information. | |
| Analizada | Crítica (9.8) | 2.3% | 💥 PoC | Theme-fusion Avada | 13/2/2025 | 17/6/2026 | The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 7.11.13. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it… | |
| Analizada | Crítica (9.8) | 0.55% | — | Theme-fusion Avada Builder | 13/2/2025 | 17/6/2026 | The Avada Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.11.13. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers… | |
| Aplazada | Media (5.4) | 0.20% | — | Intel Ethernet Adapter Complete Driver PackAI | 12/2/2025 | 17/6/2026 | Uncontrolled search path in some Intel(R) Ethernet Adapter Complete Driver Pack install before versions 29.1 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Aplazada | Crítica (9.3) | 1.3% | — | Myscada MyproAI | 29/1/2025 | 17/6/2026 | mySCADA myPRO does not properly neutralize POST requests sent to a specific port with email information. This vulnerability could be exploited by an attacker to execute arbitrary commands on the affected system. | |
| Aplazada | Crítica (9.3) | 1.3% | — | Myscada MyproAI | 29/1/2025 | 17/6/2026 | mySCADA myPRO does not properly neutralize POST requests sent to a specific port with version information. This vulnerability could be exploited by an attacker to execute arbitrary commands on the affected system. | |
| Analizada | Media (6.5) | 0.15% | — | IBM Qradar Security Information AND Event Manager | 28/1/2025 | 17/6/2026 | IBM QRadar SIEM 7.5 transmits sensitive or security-critical data in cleartext in a communication channel that could be obtained by an unauthorized actor using man in the middle techniques. | |
| Aplazada | Alta (7.6) | 0.97% | 💥 PoC | Shahjada Wpdm-premium-packagesAI | 24/1/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Shahjada WPDM – Premium Packages wpdm-premium-packages allows Blind SQL Injection.This issue affects WPDM – Premium Packages: from n/a through <= 5.9.6. | |
| Aplazada | Media (4.3) | 0.43% | — | JS Morisset JSM Show Post MetadataAI | 24/1/2025 | 17/6/2026 | Missing Authorization vulnerability in JS Morisset JSM Show Post Metadata jsm-show-post-meta allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JSM Show Post Metadata: from n/a through <= 4.6.0. | |
| Analizada | Media (5.4) | 0.22% | — | Theme-fusion Avada Builder | 22/1/2025 | 17/6/2026 | The Avada Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including, 3.11.11 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Analizada | Media (4.3) | 0.36% | — | IBM Security Qradar EDR | 19/1/2025 | 17/6/2026 | IBM Security ReaQta 3.12 could allow an authenticated user to perform unauthorized actions due to reliance on untrusted inputs. | |
| Aplazada | Alta (7.1) | 0.17% | — | Teradata Vantage EditorAI | 17/1/2025 | 17/6/2026 | Teradata Vantage Editor 1.0.1 is mostly intended for SQL database access and docs.teradata.com access, but provides unintended functionality (including Chromium Developer Tools) that can result in a client user accessing arbitrary remote websites. | |
| Analizada | Media (5.3) | 0.37% | — | IBM Qradar Wincollect | 17/1/2025 | 17/6/2026 | IBM QRadar WinCollect Agent 10.0.0 through 10.1.12 could allow a remote attacker to inject XML data into parameter values due to improper input validation of assumed immutable data. | |
| Aplazada | Media (5.3) | 0.41% | — | Reckcn SppanadadminAI | 12/1/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in reckcn SPPanAdmin 1.0. Affected is an unknown function of the file /;/admin/role/edit. The manipulation of the argument name leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and… | |
| Aplazada | Media (6.5) | 0.21% | — | Lucia.intelisano Live Flight RadarAI | 9/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in lucia.intelisano Live Flight Radar live-flight-radar allows Stored XSS.This issue affects Live Flight Radar: from n/a through <= 1.0. | |
| Aplazada | Media (6.1) | 0.36% | — | Semadatacoop Sema APIAI | 9/1/2025 | 17/6/2026 | The SEMA API plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘catid’ parameter in all versions up to, and including, 5.27 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute… | |
| Aplazada | Media (6) | 0.25% | — | Teradata DatabaseAISuse Linux Enterprise ServerAI | 8/1/2025 | 17/6/2026 | Certain Teradata account-handling code through 2024-11-04, used with SUSE Enterprise Linux Server, mismanages groups. Specifically, when there is an operating system move from SUSE Enterprise Linux Server (SLES) 12 Service Pack (SP) 2 or 3 to SLES 15 SP2 on Teradata Database systems, some service/system user accounts,… | |
| Aplazada | Media (5.3) | 0.29% | — | Allada T-shirt Designer FOR WoocommerceAI | 7/1/2025 | 17/6/2026 | Missing Authorization vulnerability in Hermann LAHAMI Allada T-shirt Designer for Woocommerce allada-tshirt-designer-for-woocommerce.This issue affects Allada T-shirt Designer for Woocommerce: from n/a through <= 1.1. | |
| Aplazada | Media (6.5) | 0.35% | — | Hpinfosys Metadata SEOAI | 7/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hpinfosys Metadata SEO metadata-seo allows Stored XSS.This issue affects Metadata SEO: from n/a through <= 2.3. | |
| Analizada | Media (5.3) | 0.32% | — | IBM Security Qradar EDR | 7/1/2025 | 17/6/2026 | IBM Security ReaQta 3.12 returns sensitive information in an HTTP response that could be used in further attacks against the system. |