Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2746▼ 296 respecto a la semana anterior
Críticas / altas1284▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)213▼ 109 respecto a la semana anterior
2287 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.46% | — | Uatech Badaso | 25/8/2023 | 17/6/2026 | Una vulnerabilidad de Cross-Site Scripting (XSS) en la función "Edit Category" de Badaso v2.9.7 permite a los atacantes ejecutar scripts web o scripts HTML arbitrarios a través de un payload manipulado inyectado en el parámetro "Title". | |
| Modificada | Media (5.4) | 0.38% | — | Uatech Badaso | 25/8/2023 | 17/6/2026 | Una vulnerabilidad de Cross-Site Scripting (XSS) almacenado existente en la función "Add Tag" de Badaso v2.9.7 permite a los atacantes ejecutar sripts web o scripts HTML arbitrarios a través de un payload manipulado inyectado en el parámetro "Title". | |
| Modificada | Alta (7.5) | 0.92% | — | Radare2 | 22/8/2023 | 17/6/2026 | Un use after free en la función r_reg_set_value en radare2 5.4.2 y 5.4.0. | |
| Modificada | Alta (7.5) | 0.90% | — | Radare2 | 22/8/2023 | 17/6/2026 | Un desbordamiento del búfer del montículo en la función r_read_le32 en radare2 5.4.2 y 5.4.0. | |
| Modificada | Alta (7.5) | 0.92% | — | Radare2 | 22/8/2023 | 17/6/2026 | Un use after free en la función r_reg_get_name_idx en radare2 5.4.2 y 5.4.0. | |
| Modificada | Alta (7.5) | 0.92% | — | Radare2 | 22/8/2023 | 17/6/2026 | Una desreferencia de puntero NULL en la función __core_anal_fcn en radare2 5.4.2 y 5.4.0. | |
| Modificada | Alta (7.5) | 0.90% | — | Radare2 | 22/8/2023 | 17/6/2026 | Un desbordamiento del buffer heap en la función vax_op en radare2 5.4.2 y 5.4.0. | |
| Modificada | Alta (7.5) | 0.91% | — | Radare2 | 22/8/2023 | 17/6/2026 | Un desbordamiento del búfer del montículo en la función r_sleb128 en radare2 5.4.2 y 5.4.0. | |
| Modificada | Media (6.7) | 0.19% | — | Lenovo 13W Yoga FirmwareLenovo 13W Yoga GEN 2 FirmwareLenovo Ideapad 1-11ada05 FirmwareLenovo Ideapad 1-11igl05 Firmware+25 | 17/8/2023 | 17/6/2026 | Se ha identificado un desbordamiento de búfer en el controlador SystemUserMasterHddPwdDxe de algunos productos portátiles de Lenovo que puede permitir a un atacante con acceso local y privilegios elevados ejecutar código arbitrario. | |
| Modificada | Media (5.4) | 0.36% | — | Phpradar Woocommerce Tip/donation | 17/8/2023 | 17/6/2026 | Auth. (shop manager+) Stored Cross-Site Scripting (XSS) vulnerability in PHPRADAR Woocommerce Tip/Donation plugin <= 1.2 versions. | |
| Modificada | Crítica (9.8) | 0.95% | — | Radare2Fedoraproject Fedora | 14/8/2023 | 17/6/2026 | Una vulnerabilidad de desbordamiento de búfer en la región Heap de la memoria en el repositorio de GitHub radareorg/radare2 antes de 5.9.0. | |
| Modificada | Media (5.3) | 0.74% | — | Openzeppelin ContractsOpenzeppelin Contracts-upgradable | 10/8/2023 | 17/6/2026 | OpenZeppelin Contracts is a library for secure smart contract development. Starting in version 4.0.0 and prior to version 4.9.3, contracts using `ERC2771Context` along with a custom trusted forwarder may see `_msgSender` return `address(0)` in calls that originate from the forwarder with calldata shorter than 20… | |
| Modificada | Alta (7.5) | 3.9% | — | Zohocorp Manageengine Adaudit Plus | 7/8/2023 | 17/6/2026 | The event analysis component in Zoho ManageEngine ADAudit Plus 7.1.1 allows an attacker to bypass audit detection by creating or renaming user accounts with a "$" symbol suffix. NOTE: the vendor states "We do not consider this as a security bug and it's an expected behaviour." | |
| Modificada | Alta (7.5) | 1.0% | — | Tel-ster Telwin Scada Webinterface | 3/8/2023 | 17/6/2026 | External input could be used on TEL-STER TelWin SCADA WebInterface to construct paths to files and directories without properly neutralizing special elements within the pathname, which could allow an unauthenticated attacker to read files on the system. | |
| Modificada | Media (6.5) | 1.0% | — | Spidercontrol Scadawebserver | 2/8/2023 | 17/6/2026 | SpiderControl SCADA Webserver versions 2.08 and prior are vulnerable to path traversal. An attacker with administrative privileges could overwrite files on the webserver using the HMI's upload file feature. This could create size zero files anywhere on the webserver, potentially overwriting system files and creating a… | |
| Modificada | Crítica (9.8) | 2.8% | — | Advantech Webaccess/scada | 2/8/2023 | 17/6/2026 | All versions prior to 9.1.4 of Advantech WebAccess/SCADA are vulnerable to use of untrusted pointers. The RPC arguments the client sent could contain raw memory pointers for the server to use as-is. This could allow an attacker to gain access to the remote file system and the ability to execute commands and overwrite… | |
| Modificada | Crítica (9.8) | 0.96% | — | Teleadapt Roomcast Ta-2400 Firmware | 27/7/2023 | 17/6/2026 | TeleAdapt RoomCast TA-2400 1.0 through 3.1 is vulnerable to Improper Privilege Management: from the shell available after an adb connection, simply entering the su command provides root access (without requiring a password). | |
| Modificada | Crítica (9.8) | 0.96% | — | Teleadapt Roomcast Ta-2400 Firmware | 27/7/2023 | 17/6/2026 | TeleAdapt RoomCast TA-2400 1.0 through 3.1 suffers from Use of a Hard-coded Password (PIN): 385521, 843646, and 592671. | |
| Modificada | Crítica (9.8) | 1.0% | — | Teleadapt Roomcast Ta-2400 Firmware | 27/7/2023 | 17/6/2026 | TeleAdapt RoomCast TA-2400 1.0 through 3.1 is vulnerable to Improper Access Control; specifically, Android Debug Bridge (adb) is available. | |
| Modificada | Alta (7.5) | 0.53% | — | Teleadapt Roomcast Ta-2400 Firmware | 27/7/2023 | 17/6/2026 | TeleAdapt RoomCast TA-2400 1.0 through 3.1 suffers from Cleartext Storage of Sensitive Information: RSA private key in Update.exe. | |
| Modificada | Crítica (9.1) | 0.77% | — | Radare2 | 7/7/2023 | 17/6/2026 | Radare2 has a use-after-free vulnerability in pyc parser's get_none_object function. Attacker can read freed memory afterwards. This will allow attackers to cause denial of service. | |
| Modificada | Alta (7.5) | 0.84% | — | Radare2 | 7/7/2023 | 17/6/2026 | Radare2 has a division by zero vulnerability in Mach-O parser's rebase_buffer function. This allow attackers to create malicious inputs that can cause denial of service. | |
| Modificada | Media (5.4) | 1.9% | — | Zohocorp Manageengine Adaudit Plus | 7/7/2023 | 17/6/2026 | Zoho ManageEngine ADAudit Plus before 7100 allows XSS via the username field. | |
| Modificada | Alta (7.5) | 0.93% | — | Cisco Secure Firewall Threat DefenseCisco Adaptive Security Appliance Software | 28/6/2023 | 11/8/2026 | A vulnerability in the hardware-based SSL/TLS cryptography functionality of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 2100 Series Appliances could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly,… | |
| Modificada | Alta (7.5) | 0.39% | — | IBM Qradar Security Information AND Event Manager | 27/6/2023 | 17/6/2026 | IBM QRadar SIEM 7.5.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 248147. |