Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
–

175 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.38%—Radiustheme Variation Images Gallery FOR Woocommerce27/7/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in RadiusTheme Variation Images Gallery for WooCommerce plugin <= 2.3.3 versions.
ModificadaAlta (8.8)0.25%—Radiustheme Classified Listing18/7/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in RadiusTheme Classified Listing plugin <= 2.4.5 versions.
ModificadaAlta (8.8)0.26%—Radiustheme THE Post Grid23/5/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in RadiusTheme The Post Grid plugin <= 5.0.4 versions.
ModificadaMedia (6.5)0.52%—Pingidentity PingfederatePingidentity Pingid Integration KITPingidentity Radius PCV25/4/202317/6/2026
The PingID RADIUS PCV adapter for PingFederate, which supports RADIUS authentication with PingID MFA, is vulnerable to MFA bypass under certain configurations.
ModificadaMedia (5.4)0.36%—Radiustheme Portfolio4/4/202317/6/2026
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in RadiusTheme Portfolio – WordPress Portfolio plugin <= 2.8.10 versions.
ModificadaMedia (6.5)1.1%—Freeradius17/1/202317/6/2026
A flaw was found in freeradius. A malicious RADIUS client or home server can send a malformed abinary attribute which can cause the server to crash.
ModificadaAlta (7.5)1.2%—Freeradius17/1/202317/6/2026
In freeradius, when an EAP-SIM supplicant sends an unknown SIM option, the server will try to look that option up in the internal dictionaries. This lookup will fail, but the SIM code will not check for that failure. Instead, it will dereference a NULL pointer, and cause the server to crash.
ModificadaAlta (7.5)0.87%—Freeradius17/1/202317/6/2026
In freeradius, the EAP-PWD function compute_password_element() leaks information about the password which allows an attacker to substantially reduce the size of an offline dictionary attack.
ModificadaMedia (6.1)0.47%—Daloradius17/1/202317/6/2026
Cross-site Scripting (XSS) - Reflected in GitHub repository lirantal/daloradius prior to master-branch.
ModificadaMedia (6.1)0.47%—Daloradius17/1/202317/6/2026
Cross-site Scripting (XSS) - Reflected in GitHub repository lirantal/daloradius prior to master-branch.
ModificadaAlta (8.8)30%—Daloradius4/1/202317/6/2026
Code Injection in GitHub repository lirantal/daloradius prior to master-branch.
ModificadaAlta (7.2)1.0%—Daloradius4/1/202317/6/2026
Improper Restriction of Names for Files and Other Resources in GitHub repository lirantal/daloradius prior to master-branch.
ModificadaMedia (5.3)0.65%—Daloradius21/12/202217/6/2026
Sensitive Cookie Without 'HttpOnly' Flag in GitHub repository lirantal/daloradius prior to master.
ModificadaAlta (7.5)0.72%—Daloradius8/12/202217/6/2026
Missing Authorization in GitHub repository lirantal/daloradius prior to master branch.
ModificadaAlta (8.8)0.48%—Daloradius6/12/202217/6/2026
daloRADIUS is an open source RADIUS web management application. daloRadius 1.3 and prior are vulnerable to a combination cross site scripting (XSS) and cross site request forgery (CSRF) vulnerability which leads to account takeover in the mng-del.php file because of an unescaped variable reflected in the DOM on line…
ModificadaMedia (6.1)0.70%—Radiustheme Classified Listing16/9/202217/6/2026
The Classified Listing Pro WordPress plugin before 2.0.20 does not escape a generated URL before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting
ModificadaMedia (6.1)0.62%—Radiustheme Classified ListingRadiustheme Classified Listing Store & MembershipRadiustheme ClassimaRadiustheme Classima Core16/9/202217/6/2026
The Classima WordPress theme before 2.1.11 and some of its required plugins (Classified Listing before 2.2.14, Classified Listing Pro before 2.0.20, Classified Listing Store & Membership before 1.4.20 and Classima Core before 1.10) do not escape a parameter before outputting it back in attributes, leading to Reflected…
ModificadaAlta (8.8)1.6%—Radiustheme Team - Wordpress Team Members Showcase22/8/202217/6/2026
The Team WordPress plugin before 4.1.2 contains a file which could allow any authenticated users to download arbitrary files from the server via a path traversal vector. Furthermore, the file will also be deleted after its content is returned to the user
ModificadaMedia (6.5)0.86%—Radiustheme Logo Slider AND Showcase1/11/202117/6/2026
The Logo Slider and Showcase WordPress plugin before 1.3.37 allows Editor users to update the plugin's settings via the rtWLSSettings AJAX action because it uses a nonce for authorisation instead of a capability check.
ModificadaCrítica (9.8)2.3%—Juniper Steel-belted Radius Carrier15/7/202117/6/2026
A stack-based Buffer Overflow vulnerability in Juniper Networks SBR Carrier with EAP (Extensible Authentication Protocol) authentication configured, allows an attacker sending specific packets causing the radius daemon to crash resulting with a Denial of Service (DoS) or leading to remote code execution (RCE). By…
ModificadaAlta (8.8)3.5%💥 ExploitDmasoftlab Radius Manager7/4/202117/6/2026
DMA Softlab Radius Manager 4.4.0 allows CSRF with impacts such as adding new manager accounts via admin.php.
ModificadaCrítica (9.8)3.2%—Dmasoftlab DMA Radius Manager2/4/202117/6/2026
DMA Softlab Radius Manager 4.4.0 assigns the same session cookie to every admin session. The cookie is valid when the admin is logged in, but is invalid (temporarily) during times when the admin is logged out. In other words, the cookie is functionally equivalent to a static password, and thus provides permanent…
ModificadaMedia (6.1)1.4%—Dmasoftlab DMA Radius Manager2/4/202117/6/2026
DMA Softlab Radius Manager 4.4.0 is affected by Cross Site Scripting (XSS) via the description, name, or address field (under admin.php).
ModificadaAlta (7.5)2.2%—FreeradiusOpensuse Leap21/3/202017/6/2026
In FreeRADIUS 3.0.x before 3.0.20, the EAP-pwd module used a global OpenSSL BN_CTX instance to handle all handshakes. This mean multiple threads use the same BN_CTX instance concurrently, resulting in crashes when concurrent EAP-pwd handshakes are initiated. This can be abused by an adversary as a Denial-of-Service…
ModificadaAlta (7.5)3.5%—Freeradius PAM RadiusDebian LinuxCanonical Ubuntu Linux24/2/202017/6/2026
add_password in pam_radius_auth.c in pam_radius 1.4.0 does not correctly check the length of the input password, and is vulnerable to a stack-based buffer overflow during memcpy(). An attacker could send a crafted password to an application (loading the pam_radius library) and crash it. Arbitrary code execution might…
Orbitaley — Vulnerabilidades