Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
2287 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 5.3% | — | Zohocorp Manageengine Adaudit Plus | 23/8/2024 | 17/6/2026 | Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in alerts module. | |
| Analizada | Alta (8.8) | 4.4% | — | Zohocorp Manageengine Adaudit Plus | 23/8/2024 | 17/6/2026 | Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in dashboard. Note: This vulnerability is different from another vulnerability (CVE-2024-36515), both of which have affected ADAudit Plus' dashboard. | |
| Analizada | Alta (8.8) | 4.5% | — | Zohocorp Manageengine Adaudit Plus | 23/8/2024 | 17/6/2026 | Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in dashboard. Note: This vulnerability is different from another vulnerability (CVE-2024-36516), both of which have affected ADAudit Plus' dashboard. | |
| Analizada | Alta (8.8) | 4.0% | — | Zohocorp Manageengine Adaudit Plus | 23/8/2024 | 17/6/2026 | Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in file summary option. | |
| Aplazada | Media (6.5) | 0.25% | — | Cryoutcreations BravadaAI | 18/8/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CryoutCreations Bravada bravada allows Stored XSS.This issue affects Bravada: from n/a through 1.1.2. | |
| Analizada | Media (5.3) | 0.36% | — | Scada-lts | 17/8/2024 | 17/6/2026 | A vulnerability has been found in Scada-LTS 2.7.8 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /Scada-LTS/app.shtm#/alarms/Scada of the component Message Handler. The manipulation leads to cross site scripting. The attack can be launched remotely. The exploit… | |
| Modificada | Alta (7.5) | 0.46% | — | IBM Cloud PAK FOR SecurityIBM Qradar Suite | 16/8/2024 | 17/6/2026 | IBM QRadar Suite Software 1.10.12.0 through 1.10.22.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the request. This information could be used in further attacks against the system. IBM… | |
| Modificada | Media (5.9) | 0.30% | — | IBM Qradar Network Packet Capture | 15/8/2024 | 17/6/2026 | IBM QRadar Network Packet Capture 7.5 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. | |
| Modificada | Media (5.5) | 0.12% | — | IBM Cloud PAK FOR SecurityIBM Qradar Suite | 15/8/2024 | 17/6/2026 | IBM QRadar Suite Software 1.10.12.0 through 1.10.23.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 281430. | |
| Modificada | Alta (7.5) | 0.30% | — | IBM Cloud PAK FOR SecurityIBM Qradar Suite | 14/8/2024 | 17/6/2026 | IBM QRadar Suite Software 1.10.12.0 through 1.10.23.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 displays sensitive data improperly to a local privileged user, in non default configurations, during back-end commands which may result in the unexpected disclosure of this information. IBM X-Force ID:… | |
| Aplazada | Media (5.4) | 0.15% | — | Intel Ethernet Adapter Driver PackAI | 14/8/2024 | 17/6/2026 | Uncontrolled search path element in some installation software for Intel(R) Ethernet Adapter Driver Pack before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Aplazada | Alta (7.4) | 0.37% | — | Adacore ADA WEB ServerAI | 13/8/2024 | 17/6/2026 | An issue was discovered in Ada Web Server 20.0. When configured to use SSL (which is not the default setting), the SSL/TLS used to establish connections to external services is done without proper hostname validation. This is exploitable by man-in-the-middle attackers. | |
| Modificada | Media (4.1) | 0.30% | — | IBM Cloud PAK FOR SecurityIBM Qradar Suite | 13/8/2024 | 17/6/2026 | IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.11.0 and IBM QRadar Suite Software 1.10.12.0 through 1.10.23.0 does not invalidate session after logout which could allow another authenticated user to obtain sensitive information. IBM X-Force ID: 233672. | |
| Analizada | Alta (8.8) | 4.7% | — | Zohocorp Manageengine Adaudit Plus | 12/8/2024 | 17/6/2026 | Zohocorp ManageEngine ADAudit Plus versions below 8110 are vulnerable to authenticated SQL Injection in file auditing configuration. | |
| Analizada | Alta (8.8) | 4.7% | — | Zohocorp Manageengine Adaudit Plus | 12/8/2024 | 17/6/2026 | Zohocorp ManageEngine ADAudit Plus versions below 8110 are vulnerable to authenticated SQL Injection in attack surface analyzer's export option. | |
| Analizada | Media (5.4) | 3.1% | — | Zohocorp Manageengine Adaudit Plus | 12/8/2024 | 17/6/2026 | Zohocorp ManageEngine ADAudit Plus versions below 8110 are vulnerable to authenticated SQL Injection in attack surface analyzer's dashboard. | |
| Analizada | Alta (8.8) | 7.4% | — | Zohocorp Manageengine Adaudit Plus | 12/8/2024 | 17/6/2026 | Zohocorp ManageEngine ADAudit Plus versions below 8003 are vulnerable to authenticated SQL Injection in user session recording. | |
| Analizada | Alta (8.8) | 7.4% | — | Zohocorp Manageengine Adaudit Plus | 12/8/2024 | 17/6/2026 | Zohocorp ManageEngine ADAudit Plus versions below 8003 are vulnerable to authenticated SQL Injection in aggregate reports' search option. | |
| Analizada | Alta (7.2) | 0.44% | — | Abinitio Authorization GatewayAbinitio Metadata HUB | 8/8/2024 | 17/6/2026 | An issue discovered in import host feature in Ab Initio Metadata Hub and Authorization Gateway before 4.3.1.1 allows attackers to run arbitrary code via crafted modification of server configuration. | |
| Aplazada | Media (5.9) | 0.27% | — | Marian Kadanka Change From EmailAI | 20/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Marian Kadanka Change From Email allows Stored XSS.This issue affects Change From Email: from n/a through 1.2.1. | |
| Analizada | Alta (8.8) | 0.31% | — | Adamsolymosi Contentlock | 12/7/2024 | 17/6/2026 | The ContentLock WordPress plugin through 1.0.3 does not have CSRF check in place when deleting groups or emails, which could allow attackers to make a logged in admin remove them via a CSRF attack | |
| Modificada | Alta (8.8) | 0.31% | — | Adamsolymosi Contentlock | 12/7/2024 | 17/6/2026 | The ContentLock WordPress plugin through 1.0.3 does not have CSRF check in place when adding emails, which could allow attackers to make a logged in admin perform such action via a CSRF attack | |
| Modificada | Alta (8.8) | 0.31% | — | Adamsolymosi Contentlock | 12/7/2024 | 17/6/2026 | The ContentLock WordPress plugin through 1.0.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack | |
| Modificada | Media (5.4) | 0.31% | — | IBM Security Qradar EDR | 10/7/2024 | 17/6/2026 | IBM Security QRadar EDR 3.12 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. | |
| Modificada | Media (5.3) | 0.24% | — | IBM Security Qradar EDR | 10/7/2024 | 17/6/2026 | IBM Security QRadar EDR 3.12 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then… |