Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

2287 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (4.9)0.55%—IBM Security Qradar EDR7/1/202517/6/2026
IBM Security ReaQta 3.12 could allow a privileged user to cause a denial of service by sending multiple administration requests due to improper allocation of resources.
AplazadaMedia (5.3)0.72%—KarmadaAIKarmadactlAIKarmada-operatorAI3/1/202517/6/2026
Karmada is a Kubernetes management system that allows users to run cloud-native applications across multiple Kubernetes clusters and clouds. Prior to version 1.12.0, both in karmadactl and karmada-operator, it is possible to supply a filesystem path, or an HTTP(s) URL to retrieve the custom resource definitions(CRDs)…
AplazadaAlta (8.7)0.49%—KarmadaAI3/1/202517/6/2026
Karmada is a Kubernetes management system that allows users to run cloud-native applications across multiple Kubernetes clusters and clouds. Prior to version 1.12.0, the PULL mode clusters registered with the `karmadactl register` command have excessive privileges to access control plane resources. By abusing these…
AplazadaAlta (8.4)0.15%—Smadar SPSAI30/12/202417/6/2026
Smadar SPS – CWE-327: Use of a Broken or Risky Cryptographic Algorithm
AnalizadaMedia (4.3)0.38%—Theme-fusion Avada Builder25/12/202417/6/2026
The Avada (Fusion) Builder plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 3.11.12 via the handle_clone_post() function and the 'fusion_blog' shortcode and due to insufficient restrictions on which posts can be included. This makes it possible for authenticated…
AnalizadaCrítica (9.8)0.92%—Radare217/12/202417/6/2026
Buffer Overflow vulnerability in radarorg radare2 v.5.8.8 allows an attacker to execute arbitrary code via the name, type, or group fields.
AplazadaMedia (6.5)0.39%—Digital Operation Services WifiburadaAI17/12/202417/6/2026
Authentication Bypass by Assumed-Immutable Data vulnerability in Digital Operation Services WiFiBurada allows Manipulating User-Controlled Variables. This issue affects WiFiBurada: before 1.0.5.
AplazadaMedia (4.3)0.40%—Digital Operation Services WifiburadaAI17/12/202417/6/2026
Improper Restriction of Excessive Authentication Attempts vulnerability in Digital Operation Services WiFiBurada allows Use of Known Domain Credentials. This issue affects WiFiBurada: before 1.0.5.
ModificadaMedia (4.3)0.18%—Theme-fusion Avada16/12/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in ThemeFusion Avada avada.This issue affects Avada: from n/a through <= 7.11.10.
AnalizadaAlta (7.8)0.79%—Radare215/12/202417/6/2026
A flaw was found in Radare2, which contains a command injection vulnerability caused by insufficient input validation when handling Pebble Application files. Maliciously crafted inputs can inject shell commands during command parsing, leading to unintended behavior during file processing​
AplazadaMedia (6.1)0.30%—Planaday APIAI12/12/202417/6/2026
The Planaday API plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter in all versions up to, and including, 11.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute…
AnalizadaMedia (5.4)0.23%—IBM Qradar Security Information AND Event Manager7/12/202417/6/2026
IBM QRadar SIEM 7.5 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
AnalizadaAlta (7.8)0.24%—Radare22/12/202417/6/2026
Buffer Overflow vulnerability in radarorg radare2 v.5.8.8 allows an attacker to execute arbitrary code via the parse_die function.
AplazadaAlta (8)1.1%—Omada IdentityAI27/11/202417/6/2026
Stored Cross-Site Scripting in the Access Request History in Omada Identity before version 15 update 1 allows an authenticated attacker to execute arbitrary code in the browser of a victim via a specially crafted link or by viewing a manipulated Access Request History
AplazadaCrítica (9.8)1.6%💥 ExploitAdapt Learning Adapt Authoring ToolAI25/11/202417/6/2026
A NoSQL injection vulnerability in Adapt Learning Adapt Authoring Tool <= 0.11.3 allows unauthenticated attackers to reset user and administrator account passwords via the "Reset password" feature. The vulnerability occurs due to insufficient validation of user input, which is used as a query in Mongoose's find()…
AplazadaMedia (4.3)0.33%—Adapt Learning Adapt Authoring ToolAI25/11/202417/6/2026
Incorrect access control in Adapt Learning Adapt Authoring Tool <= 0.11.3 allows attackers with Authenticated User roles to obtain email addresses via the "Get users" feature. The vulnerability occurs due to a flaw in permission verification logic, where the wildcard character in permitted URLs grants unintended…
AplazadaMedia (5.9)0.39%—Adamskaat Countdown AND ClockAI19/11/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in adamskaat Countdown & Clock countdown-builder allows Stored XSS.This issue affects Countdown & Clock: from n/a through <= 3.0.8.
AplazadaMedia (6.1)0.43%—Cisco Adaptive Security ApplianceAICisco Firepower Threat DefenseAI18/11/202417/6/2026
A vulnerability in the web services interface of Cisco&nbsp;Adaptive Security Appliance (ASA) Software and Cisco&nbsp;Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. This vulnerability is due to…
AnalizadaAlta (8.6)0.92%—Cisco Adaptive Security Appliance Software18/11/202417/6/2026
A vulnerability in the SSL/TLS handler of Cisco&nbsp;Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to cause the affected device to reload unexpectedly, leading to a denial of service (DoS) condition. The vulnerability is due to improper error handling on established SSL/TLS…
AnalizadaAlta (8.8)3.6%—Zohocorp Manageengine Adaudit Plus18/11/202417/6/2026
Zohocorp ManageEngine ADAudit Plus versions below 8123 are vulnerable to SQL Injection in the reports module.
AplazadaMedia (5.3)0.86%—Cisco ATA 190 Series Adaptive Telephone AdapterAI15/11/202417/6/2026
A vulnerability in the Cisco&nbsp;Discovery Protocol functionality of Cisco&nbsp;ATA 190 Series Adaptive Telephone Adapter firmware could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to an out-of-bounds read when processing Cisco&nbsp;Discovery…
AnalizadaMedia (5.3)0.49%—IBM Security Qradar EDR14/11/202417/6/2026
IBM Security ReaQta 3.12 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
AnalizadaMedia (4.8)0.25%—IBM Security Qradar EDR14/11/202417/6/2026
IBM Security ReaQta 3.12 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
AplazadaMedia (6.6)0.14%—Samsung BluetoothadapterAI6/11/202417/6/2026
Improper input validation in BluetoothAdapter prior to SMR Nov-2024 Release 1 allows local attackers to cause local permanent denial of service on Galaxy Watch.
ModificadaAlta (8.8)3.2%—Zohocorp Manageengine Adaudit Plus4/11/202417/6/2026
Zohocorp ManageEngine ADAudit Plus versions below 8121 are vulnerable to SQL Injection in Technician reports option.