Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
183 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.4) | 1.0% | — | Radare2AI | 16/4/2026 | 17/6/2026 | radare2 before 9236f44, when configured on UNIX without SSL, allows command injection via a PDB name to rabin2 -PP. NOTE: although users are supposed to use the latest version from git (not a release), the date range for the vulnerable code was less than a week, occurring after 6.1.2 but before 6.1.3. | |
| Analizada | Alta (8.4) | 1.7% | — | Radare2 | 15/4/2026 | 17/6/2026 | radare2 prior to version 6.1.4 contains a command injection vulnerability in the PDB parser's print_gvars() function that allows attackers to execute arbitrary commands by embedding a newline byte in the PE section header name field. Attackers can craft a malicious PDB file with specially crafted section names to… | |
| Aplazada | Baja (1.9) | 0.16% | — | Radare2AI | 16/3/2026 | 17/6/2026 | A vulnerability has been found in Radare2 5.9.9. This issue affects the function walk_exports_trie of the file libr/bin/format/mach0/mach0.c of the component Mach-O File Parser. Such manipulation leads to resource consumption. The attack can only be performed from a local environment. The exploit has been disclosed to… | |
| Analizada | Media (5.5) | 0.15% | — | Radare2 | 14/11/2025 | 17/6/2026 | A NULL pointer dereference vulnerability was discovered in radare2 6.0.5 and earlier within the info() function of bin_ne.c. A crafted binary input can trigger a segmentation fault, leading to a denial of service when the tool processes malformed data. | |
| Analizada | Media (4.3) | 0.29% | — | Radare2 | 14/11/2025 | 17/6/2026 | A NULL pointer dereference vulnerability was discovered in radare2 6.0.5 and earlier within the load() function of bin_dyldcache.c. Processing a crafted file can cause a segmentation fault and crash the program. | |
| Analizada | Baja (3.3) | 0.16% | — | Radare2 | 17/10/2025 | 17/6/2026 | radare2 v5.9.8 and before contains a memory leak in the function bochs_open. | |
| Analizada | Media (5.5) | 0.17% | — | Radare2 | 17/10/2025 | 17/6/2026 | radare2 v5.9.8 and before contains a memory leak in the function r2r_subprocess_init. | |
| Analizada | Media (5.5) | 0.17% | — | Radare2 | 17/10/2025 | 17/6/2026 | radare2 v5.9.8 and before contains a memory leak in the function r_bin_object_new. | |
| Analizada | Media (5.5) | 0.16% | — | Radare2 | 16/10/2025 | 17/6/2026 | radare2 v.5.9.8 and before contains a memory leak in the function _load_relocations. | |
| Analizada | Baja (2) | 0.25% | — | Radare2 | 5/6/2025 | 17/6/2026 | A vulnerability was found in Radare2 5.9.9. It has been classified as problematic. Affected is the function r_cons_pal_init in the library /libr/cons/pal.c of the component radiff2. The manipulation of the argument -T leads to memory corruption. An attack has to be approached locally. The complexity of an attack is… | |
| Analizada | Baja (2) | 0.24% | — | Radare2 | 5/6/2025 | 17/6/2026 | A vulnerability was found in Radare2 5.9.9 and classified as problematic. This issue affects the function r_cons_context_break_pop in the library /libr/cons/cons.c of the component radiff2. The manipulation of the argument -T leads to memory corruption. The attack needs to be approached locally. The complexity of an… | |
| Analizada | Baja (2) | 0.22% | — | Radare2 | 5/6/2025 | 17/6/2026 | A vulnerability has been found in Radare2 5.9.9 and classified as problematic. This vulnerability affects the function r_cons_rainbow_free in the library /libr/cons/pal.c of the component radiff2. The manipulation of the argument -T leads to memory corruption. It is possible to launch the attack on the local host. The… | |
| Analizada | Baja (2) | 0.22% | — | Radare2 | 5/6/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in Radare2 5.9.9. This affects the function r_cons_pal_init in the library /libr/cons/pal.c of the component radiff2. The manipulation of the argument -T leads to memory corruption. Attacking locally is a requirement. The complexity of an attack is rather… | |
| Analizada | Baja (2) | 0.23% | — | Radare2 | 5/6/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in Radare2 5.9.9. Affected by this issue is the function r_cons_flush in the library /libr/cons/cons.c of the component radiff2. The manipulation of the argument -T leads to use after free. Local access is required to approach this attack. The… | |
| Analizada | Baja (2) | 0.23% | — | Radare2 | 5/6/2025 | 17/6/2026 | A vulnerability classified as problematic was found in Radare2 5.9.9. Affected by this vulnerability is the function cons_stack_load in the library /libr/cons/cons.c of the component radiff2. The manipulation of the argument -T leads to memory corruption. An attack has to be approached locally. The complexity of an… | |
| Analizada | Baja (2) | 0.23% | — | Radare2 | 5/6/2025 | 17/6/2026 | A vulnerability classified as problematic has been found in Radare2 5.9.9. Affected is the function r_cons_pal_init in the library /libr/cons/pal.c of the component radiff2. The manipulation leads to memory corruption. The attack needs to be approached locally. The complexity of an attack is rather high. The… | |
| Analizada | Baja (2) | 0.22% | — | Radare2 | 5/6/2025 | 17/6/2026 | A vulnerability was found in Radare2 5.9.9. It has been rated as problematic. This issue affects the function r_cons_is_breaked in the library /libr/cons/cons.c of the component radiff2. The manipulation of the argument -T leads to memory corruption. It is possible to launch the attack on the local host. The… | |
| Analizada | Crítica (10) | 0.48% | — | Radare2 | 3/3/2025 | 17/6/2026 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in radareorg radare2 allows Overflow Buffers.This issue affects radare2: before <5.9.9. | |
| Analizada | Crítica (10) | 0.51% | — | Radare2 | 28/2/2025 | 17/6/2026 | Out-of-bounds Write vulnerability in radareorg radare2 allows heap-based buffer over-read or buffer overflow.This issue affects radare2: before <5.9.9. | |
| Analizada | Media (4.8) | 0.32% | — | Radare2 | 17/2/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in radare2 5.9.9 33286. Affected is an unknown function in the library /libr/main/rasm2.c of the component rasm2. The manipulation leads to memory corruption. An attack has to be approached locally. The exploit has been disclosed to the public and may be… | |
| Analizada | Crítica (9.8) | 0.92% | — | Radare2 | 17/12/2024 | 17/6/2026 | Buffer Overflow vulnerability in radarorg radare2 v.5.8.8 allows an attacker to execute arbitrary code via the name, type, or group fields. | |
| Analizada | Alta (7.8) | 0.79% | — | Radare2 | 15/12/2024 | 17/6/2026 | A flaw was found in Radare2, which contains a command injection vulnerability caused by insufficient input validation when handling Pebble Application files. Maliciously crafted inputs can inject shell commands during command parsing, leading to unintended behavior during file processing | |
| Analizada | Alta (7.8) | 0.24% | — | Radare2 | 2/12/2024 | 17/6/2026 | Buffer Overflow vulnerability in radarorg radare2 v.5.8.8 allows an attacker to execute arbitrary code via the parse_die function. | |
| Analizada | Media (5.5) | 0.20% | — | Radare2 | 30/10/2024 | 17/6/2026 | An issue in radare2 v5.8.0 through v5.9.4 allows a local attacker to cause a denial of service via the __bf_div function. | |
| Modificada | Media (5.5) | 0.28% | 💥 PoC | Radare2 | 14/3/2024 | 17/6/2026 | An issue in radareorg radare2 v.0.9.7 through v.5.8.6 and fixed in v.5.8.8 allows a local attacker to cause a denial of service via the grub_sfs_read_extent function. |