Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
292 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.2) | 0.17% | — | IBM Qradar Security Information AND Event Manager | 19/6/2025 | 17/6/2026 | IBM QRadar SIEM 7.5 through 7.5.0 Update Package 12 stores potentially sensitive information in log files that could be read by a local user. | |
| Analizada | Alta (7.1) | 0.48% | — | IBM Qradar Security Information AND Event Manager | 19/6/2025 | 17/6/2026 | IBM QRadar SIEM 7.5 through 7.5.0 Update Package 12 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. | |
| Analizada | Crítica (9.1) | 0.55% | — | IBM Qradar Security Information AND Event Manager | 19/6/2025 | 17/6/2026 | IBM QRadar SIEM 7.5 through 7.5.0 Update Package 12 could allow a privileged user to modify configuration files that would allow the upload of a malicious autoupdate file to execute arbitrary commands. | |
| Analizada | Alta (8.8) | 0.32% | — | IBM Cloud PAK FOR SecurityIBM Qradar Suite | 3/6/2025 | 17/6/2026 | IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 could allow an unauthenticated user in the environment to obtain highly sensitive information in configuration files. | |
| Analizada | Alta (7.2) | 0.64% | — | IBM Cloud PAK FOR SecurityIBM Qradar Suite | 3/6/2025 | 17/6/2026 | IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 could allow a privileged execute code in case management script creation due to the improper generation of code. | |
| Analizada | Media (6.5) | 0.42% | — | IBM Cloud PAK FOR SecurityIBM Qradar Suite | 3/6/2025 | 17/6/2026 | IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 could allow an authenticated user to cause a denial of service due to improperly validating API data input. | |
| Analizada | Media (6.5) | 0.26% | — | IBM Cloud PAK FOR SecurityIBM Qradar Suite | 3/6/2025 | 17/6/2026 | IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 does not invalidate session after a logout which could allow a user to impersonate another user on the system. | |
| Analizada | Media (4) | 0.18% | — | IBM Cloud PAK FOR SecurityIBM Qradar Suite | 3/6/2025 | 17/6/2026 | IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 allows web pages to be stored locally which can be read by another user on the system. | |
| Analizada | Media (6.5) | 0.19% | — | IBM Security Qradar EDR | 20/5/2025 | 17/6/2026 | IBM Security ReaQta EDR 3.12 could allow an attacker to perform unauthorized actions due to improper SSL certificate validation. | |
| Analizada | Media (6.5) | 0.24% | — | IBM Security Qradar EDR | 20/5/2025 | 17/6/2026 | IBM Security ReaQta EDR 3.12 could allow an attacker to spoof a trusted entity by interfering with the communication path between the host and client. | |
| Analizada | Media (6.5) | 0.40% | — | IBM Qradar Wincollect | 11/4/2025 | 17/6/2026 | IBM QRadar WinCollect Agent 10.0 through 10.1.13 could allow a remote attacker to cause a denial of service by interrupting an HTTP request that could consume memory resources. | |
| Analizada | Media (4.7) | 0.27% | — | IBM Security Qradar EDR | 19/3/2025 | 17/6/2026 | IBM Security ReaQta 3.12 allows a privileged user to upload or transfer files of dangerous types that can be automatically processed within the product's environment. | |
| Analizada | Media (4.1) | 0.29% | — | IBM Qradar Advisor | 18/3/2025 | 17/6/2026 | IBM QRadar Advisor 1.0.0 through 2.6.5 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. | |
| Analizada | Alta (7.5) | 0.21% | — | IBM Security Qradar EDR | 14/3/2025 | 17/6/2026 | IBM Security QRadar 3.12 EDR uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt sensitive credential information. | |
| Analizada | Media (4.4) | 0.13% | — | IBM Security Qradar EDR | 14/3/2025 | 17/6/2026 | IBM Security QRadar 3.12 EDR stores user credentials in plain text which can be read by a local privileged user. | |
| Analizada | Media (4.8) | 0.23% | — | IBM Qradar Security Information AND Event Manager | 14/2/2025 | 17/6/2026 | IBM QRadar SIEM 7.5 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Analizada | Media (6.5) | 0.15% | — | IBM Qradar Security Information AND Event Manager | 28/1/2025 | 17/6/2026 | IBM QRadar SIEM 7.5 transmits sensitive or security-critical data in cleartext in a communication channel that could be obtained by an unauthorized actor using man in the middle techniques. | |
| Analizada | Media (4.3) | 0.36% | — | IBM Security Qradar EDR | 19/1/2025 | 17/6/2026 | IBM Security ReaQta 3.12 could allow an authenticated user to perform unauthorized actions due to reliance on untrusted inputs. | |
| Analizada | Media (5.3) | 0.37% | — | IBM Qradar Wincollect | 17/1/2025 | 17/6/2026 | IBM QRadar WinCollect Agent 10.0.0 through 10.1.12 could allow a remote attacker to inject XML data into parameter values due to improper input validation of assumed immutable data. | |
| Analizada | Media (5.3) | 0.32% | — | IBM Security Qradar EDR | 7/1/2025 | 17/6/2026 | IBM Security ReaQta 3.12 returns sensitive information in an HTTP response that could be used in further attacks against the system. | |
| Analizada | Media (4.9) | 0.55% | — | IBM Security Qradar EDR | 7/1/2025 | 17/6/2026 | IBM Security ReaQta 3.12 could allow a privileged user to cause a denial of service by sending multiple administration requests due to improper allocation of resources. | |
| Analizada | Media (5.4) | 0.23% | — | IBM Qradar Security Information AND Event Manager | 7/12/2024 | 17/6/2026 | IBM QRadar SIEM 7.5 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Analizada | Media (5.3) | 0.49% | — | IBM Security Qradar EDR | 14/11/2024 | 17/6/2026 | IBM Security ReaQta 3.12 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Analizada | Media (4.8) | 0.25% | — | IBM Security Qradar EDR | 14/11/2024 | 17/6/2026 | IBM Security ReaQta 3.12 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Modificada | Alta (7.5) | 0.46% | — | IBM Cloud PAK FOR SecurityIBM Qradar Suite | 16/8/2024 | 17/6/2026 | IBM QRadar Suite Software 1.10.12.0 through 1.10.22.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the request. This information could be used in further attacks against the system. IBM… |