Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
–

2287 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaBaja (1.9)0.19%—Radare25/7/20266/7/2026
A security vulnerability has been detected in radareorg radare2 up to 6.1.6. The affected element is the function r_str_ndup/r_str_append of the file libr/util/str.c. The manipulation leads to integer overflow. An attack has to be approached locally. The exploit has been disclosed publicly and may be used. The…
AnalizadaBaja (1.9)0.20%—Radare25/7/20269/7/2026
A weakness has been identified in radareorg radare2 up to 6.1.6. Impacted is the function r_core_seek_arch_bits of the file libr/core/disasm.c of the component regprofile Handler. Executing a manipulation can lead to use after free. The attack requires local access. The exploit has been made available to the public…
AnalizadaBaja (1.9)0.22%—Radare25/7/20269/7/2026
A security flaw has been discovered in radareorg radare2 up to 6.1.6. This issue affects the function r_bin_java_inner_classes_attr_calc_size of the file shlr/java/class.c of the component RBinJava Line Number Table Parser. Performing a manipulation results in heap-based buffer overflow. The attack requires a local…
AnalizadaBaja (1.9)0.19%—Radare25/7/20269/7/2026
A vulnerability was identified in radareorg radare2 up to 6.1.6. This vulnerability affects the function cmd_anal_opcode of the file libr/core/cmd_anal.inc.c of the component hexpairs Parser. Such manipulation leads to integer overflow. The attack needs to be performed locally. The exploit is publicly available and…
AnalizadaBaja (1.9)0.21%—Radare25/7/20267/7/2026
A vulnerability was determined in radareorg radare2 up to 6.1.6. This affects the function core_anal_bytes of the file libr/core/cmd_anal.inc. This manipulation causes integer overflow. The attack needs to be launched locally. The exploit has been publicly disclosed and may be utilized. It is suggested to install a…
AplazadaMedia (6.5)0.22%—Shortpixel Adaptive ImagesAI2/7/20262/7/2026
Subscriber Cross Site Scripting (XSS) in ShortPixel Adaptive Images <= 3.11.3 versions.
AplazadaMedia (5.8)0.47%—Shortpixel Adaptive ImagesAI26/6/202626/6/2026
Unauthenticated Arbitrary File Deletion in ShortPixel Adaptive Images <= 3.11.4 versions.
ModificadaAlta (7.5)0.76%—Faraday Project Faraday24/6/202614/8/2026
Faraday is an HTTP client library abstraction layer that provides a common interface over many adapters. From 1.0.0 until 1.10.6 and 2.14.3, Faraday::NestedParamsEncoder, the default nested query parameter encoder/decoder in Faraday, decodes nested query strings without enforcing a maximum nesting depth. A crafted…
Pendiente de análisisCrítica (9)2.5%💥 PoCManageengine Adselfservice PlusAIManageengine Recoverymanager PlusAIManageengine M365 Manager PlusAIManageengine Adaudit PlusAI23/6/202624/6/2026
In ManageEngine ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus, and ADAudit Plus, the SSO tickets generated to authenticate that session could be predicted by an unauthenticated user, leading to account takeover.
AplazadaCrítica (9.1)2.7%💥 ExploitAvadaAI19/6/202622/6/2026
The Avada (Fusion) Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the maybe_delete_files function in all versions up to, and including, 3.15.3. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can…
AplazadaCrítica (9.3)0.70%—IbapdaAIIbadatcoordinatorAI18/6/202622/6/2026
A remote, unauthenticated attacker may exploit a deserialization of untrusted data vulnerability in ibaPDA or ibaDatCoordinator to gain full access to the affected systems.
AplazadaAlta (7.7)0.47%—Avada Fusion BuilderAI17/6/202617/6/2026
Contributor Arbitrary File Deletion in Fusion Builder <= 3.15.4 versions.
AplazadaAlta (7.2)0.24%—Mitsubishielectric Room AIR ConditionersAIMitsubishielectric Wireless LAN Adapters FOR Room AIR ConditionersAIMitsubishielectric Wireless LAN Adapters FOR Packaged AIR ConditionersAIMitsubishielectric RefrigeratorsAI+1217/6/202617/6/2026
Use of Hard-coded Credentials vulnerability in Mitsubishi Electric Room Air Conditioners (for Japan and outside Japan); Wireless LAN Adapters for Room Air Conditioners (for Japan and outside Japan); Wireless LAN Adapters for Packaged Air Conditioners (for Japan and outside Japan); Refrigerators (for Japan); Heat Pump…
AplazadaAlta (8.8)0.47%—AvadaAI17/6/20261/10/2026
Deserialization of Untrusted Data vulnerability in ThemeFusion Fusion Builder fusion-builder allows Object Injection.This issue affects Fusion Builder: from n/a through 3.15.3.
AnalizadaMedia (4.4)0.09%—IBM Security Qradar EDR11/6/20261/10/2026
IBM Security QRadar EDR 3.12 through 3.12.24 stores user credentials in plain text which can be read by a local privileged user.
AnalizadaAlta (8.2)0.35%—Microsoft Azure Network Adapter9/6/202623/7/2026
Use after free in Linux MANA Driver allows an authorized attacker to elevate privileges locally.
AplazadaAlta (8.3)0.42%—Open-metadata OpenmetadataAI8/6/202623/7/2026
OpenMetadata is a unified metadata platform. Prior to version 1.12.4, a non-admin SSO user can trigger a TEST_CONNECTION workflow for a Database Service and receive, in the HTTP 201 response of POST /api/v1/automations/workflows, both the cleartext database password in request.connection.config.password and the…
AplazadaBaja (1.9)0.21%—Westboy CicadascmsAI2/6/202622/7/2026
A weakness has been identified in westboy CicadasCMS up to 2431154dac8d0735e04f1fd2a3c3556668fc8dab. Impacted is an unknown function of the file src/main/java/com/zhiliao/module/web/system/ScheduleJobController.java of the component Task Scheduling Management Module. Executing a manipulation can lead to cross site…
AplazadaBaja (2.1)0.28%—Westboy CicadascmsAISpringframework CacheAI30/5/202622/7/2026
A flaw has been found in westboy CicadasCMS up to 2431154dac8d0735e04f1fd2a3c3556668fc8dab. Impacted is the function Search of the file org/springframework/cache/support/AbstractCacheManager.java. This manipulation of the argument s causes cross site scripting. Remote exploitation of the attack is possible. The…
AplazadaMedia (4.8)0.18%—ITP Technology ITS Intelligent Scada SystemAI29/5/202621/7/2026
ITS Intelligent SCADA System developed by ITP Technology has a Stored Cross-Site Scripting vulnerability, allowing privileged remote attackers to inject persistent JavaScript codes that are executed in users' browsers upon page load.
AplazadaMedia (4.8)0.18%—ITP Technology ITS Intelligent Scada SystemAI29/5/202621/7/2026
ITS Intelligent SCADA System developed by ITP Technology has a Stored Cross-Site Scripting vulnerability, allowing privileged remote attackers to inject persistent JavaScript codes that are executed in users' browsers upon page load.
AnalizadaMedia (6.1)0.26%—Scadabr28/5/202617/8/2026
A reflected cross-site scripting issue exists in URL handling.
AnalizadaCrítica (9.9)0.52%💥 PoCScadabr28/5/202617/8/2026
Exposed methods allow authenticated users to create and execute arbitrary JavaScript code on the server. The scripts execute with full access, enabling complete system compromise as commands are executed as root.
AnalizadaAlta (8.8)0.46%—IBM Qradar Security Information AND Event Manager27/5/202617/6/2026
IBM QRadar 7.5.0 through 7.5.0 UP15 Interim Fix 002 could allow a privileged user to upload a malicious backup archive that could be restored and used to gain access to the underlying operating system.
AnalizadaMedia (6.5)0.35%💥 PoCAdamhathcock Sharpcompress26/5/202624/7/2026
SharpCompress is a fully managed C# library to deal with many compression types and formats. In 0.47.4 and earlier, a path traversal vulnerability in IArchive.WriteToDirectory() allows a malicious archive to create directories outside the intended extraction root. For TAR archives, this can be escalated to arbitrary…