Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2720▼ 598 respecto a la semana anterior
Críticas / altas1299▼ 202 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
494 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.2) | 0.64% | — | IBM Cloud PAK FOR SecurityIBM Qradar Suite | 3/6/2025 | 17/6/2026 | IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 could allow a privileged execute code in case management script creation due to the improper generation of code. | |
| Analizada | Media (6.5) | 0.43% | — | IBM Cloud PAK FOR SecurityIBM Qradar Suite | 3/6/2025 | 17/6/2026 | IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 could allow an authenticated user to cause a denial of service due to improperly validating API data input. | |
| Analizada | Media (6.5) | 0.26% | — | IBM Cloud PAK FOR SecurityIBM Qradar Suite | 3/6/2025 | 17/6/2026 | IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 does not invalidate session after a logout which could allow a user to impersonate another user on the system. | |
| Analizada | Media (4) | 0.18% | — | IBM Cloud PAK FOR SecurityIBM Qradar Suite | 3/6/2025 | 17/6/2026 | IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 allows web pages to be stored locally which can be read by another user on the system. | |
| Analizada | Media (6.5) | 0.19% | — | IBM Security Qradar EDR | 20/5/2025 | 17/6/2026 | IBM Security ReaQta EDR 3.12 could allow an attacker to perform unauthorized actions due to improper SSL certificate validation. | |
| Analizada | Media (6.5) | 0.24% | — | IBM Security Qradar EDR | 20/5/2025 | 17/6/2026 | IBM Security ReaQta EDR 3.12 could allow an attacker to spoof a trusted entity by interfering with the communication path between the host and client. | |
| Analizada | Media (6.5) | 0.40% | — | IBM Qradar Wincollect | 11/4/2025 | 17/6/2026 | IBM QRadar WinCollect Agent 10.0 through 10.1.13 could allow a remote attacker to cause a denial of service by interrupting an HTTP request that could consume memory resources. | |
| Analizada | Media (4.7) | 0.27% | — | IBM Security Qradar EDR | 19/3/2025 | 17/6/2026 | IBM Security ReaQta 3.12 allows a privileged user to upload or transfer files of dangerous types that can be automatically processed within the product's environment. | |
| Analizada | Media (4.1) | 0.29% | — | IBM Qradar Advisor | 18/3/2025 | 17/6/2026 | IBM QRadar Advisor 1.0.0 through 2.6.5 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. | |
| Analizada | Alta (7.5) | 0.22% | — | IBM Security Qradar EDR | 14/3/2025 | 17/6/2026 | IBM Security QRadar 3.12 EDR uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt sensitive credential information. | |
| Analizada | Media (4.4) | 0.14% | — | IBM Security Qradar EDR | 14/3/2025 | 17/6/2026 | IBM Security QRadar 3.12 EDR stores user credentials in plain text which can be read by a local privileged user. | |
| Analizada | Crítica (10) | 0.48% | — | Radare2 | 3/3/2025 | 17/6/2026 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in radareorg radare2 allows Overflow Buffers.This issue affects radare2: before <5.9.9. | |
| Analizada | Crítica (10) | 0.51% | — | Radare2 | 28/2/2025 | 17/6/2026 | Out-of-bounds Write vulnerability in radareorg radare2 allows heap-based buffer over-read or buffer overflow.This issue affects radare2: before <5.9.9. | |
| Analizada | Media (4.8) | 0.32% | — | Radare2 | 17/2/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in radare2 5.9.9 33286. Affected is an unknown function in the library /libr/main/rasm2.c of the component rasm2. The manipulation leads to memory corruption. An attack has to be approached locally. The exploit has been disclosed to the public and may be… | |
| Analizada | Media (4.8) | 0.23% | — | IBM Qradar Security Information AND Event Manager | 14/2/2025 | 17/6/2026 | IBM QRadar SIEM 7.5 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Analizada | Media (6.5) | 0.15% | — | IBM Qradar Security Information AND Event Manager | 28/1/2025 | 17/6/2026 | IBM QRadar SIEM 7.5 transmits sensitive or security-critical data in cleartext in a communication channel that could be obtained by an unauthorized actor using man in the middle techniques. | |
| Analizada | Media (4.3) | 0.36% | — | IBM Security Qradar EDR | 19/1/2025 | 17/6/2026 | IBM Security ReaQta 3.12 could allow an authenticated user to perform unauthorized actions due to reliance on untrusted inputs. | |
| Analizada | Media (5.3) | 0.37% | — | IBM Qradar Wincollect | 17/1/2025 | 17/6/2026 | IBM QRadar WinCollect Agent 10.0.0 through 10.1.12 could allow a remote attacker to inject XML data into parameter values due to improper input validation of assumed immutable data. | |
| Aplazada | Media (6.5) | 0.21% | — | Lucia.intelisano Live Flight RadarAI | 9/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in lucia.intelisano Live Flight Radar live-flight-radar allows Stored XSS.This issue affects Live Flight Radar: from n/a through <= 1.0. | |
| Analizada | Media (5.3) | 0.32% | — | IBM Security Qradar EDR | 7/1/2025 | 17/6/2026 | IBM Security ReaQta 3.12 returns sensitive information in an HTTP response that could be used in further attacks against the system. | |
| Analizada | Media (4.9) | 0.55% | — | IBM Security Qradar EDR | 7/1/2025 | 17/6/2026 | IBM Security ReaQta 3.12 could allow a privileged user to cause a denial of service by sending multiple administration requests due to improper allocation of resources. | |
| Analizada | Crítica (9.8) | 0.92% | — | Radare2 | 17/12/2024 | 17/6/2026 | Buffer Overflow vulnerability in radarorg radare2 v.5.8.8 allows an attacker to execute arbitrary code via the name, type, or group fields. | |
| Analizada | Alta (7.8) | 0.79% | — | Radare2 | 15/12/2024 | 17/6/2026 | A flaw was found in Radare2, which contains a command injection vulnerability caused by insufficient input validation when handling Pebble Application files. Maliciously crafted inputs can inject shell commands during command parsing, leading to unintended behavior during file processing | |
| Analizada | Media (5.4) | 0.23% | — | IBM Qradar Security Information AND Event Manager | 7/12/2024 | 17/6/2026 | IBM QRadar SIEM 7.5 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Analizada | Alta (7.8) | 0.24% | — | Radare2 | 2/12/2024 | 17/6/2026 | Buffer Overflow vulnerability in radarorg radare2 v.5.8.8 allows an attacker to execute arbitrary code via the parse_die function. |