Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
175 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.38% | — | Radiustheme Variation Images Gallery FOR Woocommerce | 27/7/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in RadiusTheme Variation Images Gallery for WooCommerce plugin <= 2.3.3 versions. | |
| Modificada | Alta (8.8) | 0.25% | — | Radiustheme Classified Listing | 18/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in RadiusTheme Classified Listing plugin <= 2.4.5 versions. | |
| Modificada | Alta (8.8) | 0.26% | — | Radiustheme THE Post Grid | 23/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in RadiusTheme The Post Grid plugin <= 5.0.4 versions. | |
| Modificada | Media (6.5) | 0.52% | — | Pingidentity PingfederatePingidentity Pingid Integration KITPingidentity Radius PCV | 25/4/2023 | 17/6/2026 | The PingID RADIUS PCV adapter for PingFederate, which supports RADIUS authentication with PingID MFA, is vulnerable to MFA bypass under certain configurations. | |
| Modificada | Media (5.4) | 0.36% | — | Radiustheme Portfolio | 4/4/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in RadiusTheme Portfolio – WordPress Portfolio plugin <= 2.8.10 versions. | |
| Modificada | Media (6.5) | 1.1% | — | Freeradius | 17/1/2023 | 17/6/2026 | A flaw was found in freeradius. A malicious RADIUS client or home server can send a malformed abinary attribute which can cause the server to crash. | |
| Modificada | Alta (7.5) | 1.2% | — | Freeradius | 17/1/2023 | 17/6/2026 | In freeradius, when an EAP-SIM supplicant sends an unknown SIM option, the server will try to look that option up in the internal dictionaries. This lookup will fail, but the SIM code will not check for that failure. Instead, it will dereference a NULL pointer, and cause the server to crash. | |
| Modificada | Alta (7.5) | 0.87% | — | Freeradius | 17/1/2023 | 17/6/2026 | In freeradius, the EAP-PWD function compute_password_element() leaks information about the password which allows an attacker to substantially reduce the size of an offline dictionary attack. | |
| Modificada | Media (6.1) | 0.47% | — | Daloradius | 17/1/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Reflected in GitHub repository lirantal/daloradius prior to master-branch. | |
| Modificada | Media (6.1) | 0.47% | — | Daloradius | 17/1/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Reflected in GitHub repository lirantal/daloradius prior to master-branch. | |
| Modificada | Alta (8.8) | 30% | — | Daloradius | 4/1/2023 | 17/6/2026 | Code Injection in GitHub repository lirantal/daloradius prior to master-branch. | |
| Modificada | Alta (7.2) | 1.0% | — | Daloradius | 4/1/2023 | 17/6/2026 | Improper Restriction of Names for Files and Other Resources in GitHub repository lirantal/daloradius prior to master-branch. | |
| Modificada | Media (5.3) | 0.65% | — | Daloradius | 21/12/2022 | 17/6/2026 | Sensitive Cookie Without 'HttpOnly' Flag in GitHub repository lirantal/daloradius prior to master. | |
| Modificada | Alta (7.5) | 0.72% | — | Daloradius | 8/12/2022 | 17/6/2026 | Missing Authorization in GitHub repository lirantal/daloradius prior to master branch. | |
| Modificada | Alta (8.8) | 0.48% | — | Daloradius | 6/12/2022 | 17/6/2026 | daloRADIUS is an open source RADIUS web management application. daloRadius 1.3 and prior are vulnerable to a combination cross site scripting (XSS) and cross site request forgery (CSRF) vulnerability which leads to account takeover in the mng-del.php file because of an unescaped variable reflected in the DOM on line… | |
| Modificada | Media (6.1) | 0.70% | — | Radiustheme Classified Listing | 16/9/2022 | 17/6/2026 | The Classified Listing Pro WordPress plugin before 2.0.20 does not escape a generated URL before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting | |
| Modificada | Media (6.1) | 0.62% | — | Radiustheme Classified ListingRadiustheme Classified Listing Store & MembershipRadiustheme ClassimaRadiustheme Classima Core | 16/9/2022 | 17/6/2026 | The Classima WordPress theme before 2.1.11 and some of its required plugins (Classified Listing before 2.2.14, Classified Listing Pro before 2.0.20, Classified Listing Store & Membership before 1.4.20 and Classima Core before 1.10) do not escape a parameter before outputting it back in attributes, leading to Reflected… | |
| Modificada | Alta (8.8) | 1.6% | — | Radiustheme Team - Wordpress Team Members Showcase | 22/8/2022 | 17/6/2026 | The Team WordPress plugin before 4.1.2 contains a file which could allow any authenticated users to download arbitrary files from the server via a path traversal vector. Furthermore, the file will also be deleted after its content is returned to the user | |
| Modificada | Media (6.5) | 0.86% | — | Radiustheme Logo Slider AND Showcase | 1/11/2021 | 17/6/2026 | The Logo Slider and Showcase WordPress plugin before 1.3.37 allows Editor users to update the plugin's settings via the rtWLSSettings AJAX action because it uses a nonce for authorisation instead of a capability check. | |
| Modificada | Crítica (9.8) | 2.3% | — | Juniper Steel-belted Radius Carrier | 15/7/2021 | 17/6/2026 | A stack-based Buffer Overflow vulnerability in Juniper Networks SBR Carrier with EAP (Extensible Authentication Protocol) authentication configured, allows an attacker sending specific packets causing the radius daemon to crash resulting with a Denial of Service (DoS) or leading to remote code execution (RCE). By… | |
| Modificada | Alta (8.8) | 3.5% | 💥 Exploit | Dmasoftlab Radius Manager | 7/4/2021 | 17/6/2026 | DMA Softlab Radius Manager 4.4.0 allows CSRF with impacts such as adding new manager accounts via admin.php. | |
| Modificada | Crítica (9.8) | 3.2% | — | Dmasoftlab DMA Radius Manager | 2/4/2021 | 17/6/2026 | DMA Softlab Radius Manager 4.4.0 assigns the same session cookie to every admin session. The cookie is valid when the admin is logged in, but is invalid (temporarily) during times when the admin is logged out. In other words, the cookie is functionally equivalent to a static password, and thus provides permanent… | |
| Modificada | Media (6.1) | 1.4% | — | Dmasoftlab DMA Radius Manager | 2/4/2021 | 17/6/2026 | DMA Softlab Radius Manager 4.4.0 is affected by Cross Site Scripting (XSS) via the description, name, or address field (under admin.php). | |
| Modificada | Alta (7.5) | 2.2% | — | FreeradiusOpensuse Leap | 21/3/2020 | 17/6/2026 | In FreeRADIUS 3.0.x before 3.0.20, the EAP-pwd module used a global OpenSSL BN_CTX instance to handle all handshakes. This mean multiple threads use the same BN_CTX instance concurrently, resulting in crashes when concurrent EAP-pwd handshakes are initiated. This can be abused by an adversary as a Denial-of-Service… | |
| Modificada | Alta (7.5) | 3.5% | — | Freeradius PAM RadiusDebian LinuxCanonical Ubuntu Linux | 24/2/2020 | 17/6/2026 | add_password in pam_radius_auth.c in pam_radius 1.4.0 does not correctly check the length of the input password, and is vulnerable to a stack-based buffer overflow during memcpy(). An attacker could send a crafted password to an application (loading the pam_radius library) and crash it. Arbitrary code execution might… |