Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 572 respecto a la semana anterior
Críticas / altas1301▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
494 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.3) | 0.49% | — | IBM Security Qradar EDR | 14/11/2024 | 17/6/2026 | IBM Security ReaQta 3.12 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Analizada | Media (4.8) | 0.25% | — | IBM Security Qradar EDR | 14/11/2024 | 17/6/2026 | IBM Security ReaQta 3.12 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Analizada | Media (5.5) | 0.20% | — | Radare2 | 30/10/2024 | 17/6/2026 | An issue in radare2 v5.8.0 through v5.9.4 allows a local attacker to cause a denial of service via the __bf_div function. | |
| Analizada | Media (6.9) | 0.69% | — | Riskengine Radar | 18/10/2024 | 17/6/2026 | A vulnerability was found in wfh45678 Radar up to 1.0.8 and classified as critical. This issue affects some unknown processing of the component Interface Handler. The manipulation with the input /../ leads to authorization bypass. The attack may be initiated remotely. The exploit has been disclosed to the public and… | |
| Analizada | Media (6.9) | 0.71% | — | Riskengine Radar | 18/10/2024 | 17/6/2026 | A vulnerability has been found in wfh45678 Radar up to 1.0.8 and classified as critical. This vulnerability affects unknown code of the file /services/v1/common/upload. The manipulation of the argument file leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public… | |
| Modificada | Alta (7.5) | 0.46% | — | IBM Cloud PAK FOR SecurityIBM Qradar Suite | 16/8/2024 | 17/6/2026 | IBM QRadar Suite Software 1.10.12.0 through 1.10.22.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the request. This information could be used in further attacks against the system. IBM… | |
| Modificada | Media (5.9) | 0.30% | — | IBM Qradar Network Packet Capture | 15/8/2024 | 17/6/2026 | IBM QRadar Network Packet Capture 7.5 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. | |
| Modificada | Media (5.5) | 0.12% | — | IBM Cloud PAK FOR SecurityIBM Qradar Suite | 15/8/2024 | 17/6/2026 | IBM QRadar Suite Software 1.10.12.0 through 1.10.23.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 281430. | |
| Modificada | Alta (7.5) | 0.30% | — | IBM Cloud PAK FOR SecurityIBM Qradar Suite | 14/8/2024 | 17/6/2026 | IBM QRadar Suite Software 1.10.12.0 through 1.10.23.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 displays sensitive data improperly to a local privileged user, in non default configurations, during back-end commands which may result in the unexpected disclosure of this information. IBM X-Force ID:… | |
| Modificada | Media (4.1) | 0.30% | — | IBM Cloud PAK FOR SecurityIBM Qradar Suite | 13/8/2024 | 17/6/2026 | IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.11.0 and IBM QRadar Suite Software 1.10.12.0 through 1.10.23.0 does not invalidate session after logout which could allow another authenticated user to obtain sensitive information. IBM X-Force ID: 233672. | |
| Modificada | Media (5.4) | 0.31% | — | IBM Security Qradar EDR | 10/7/2024 | 17/6/2026 | IBM Security QRadar EDR 3.12 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. | |
| Modificada | Media (5.3) | 0.24% | — | IBM Security Qradar EDR | 10/7/2024 | 17/6/2026 | IBM Security QRadar EDR 3.12 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then… | |
| Modificada | Media (5.3) | 0.36% | — | IBM Security Qradar EDR | 10/7/2024 | 17/6/2026 | IBM Security QRadar EDR 3.12 could disclose sensitive information due to an observable login response discrepancy. IBM X-Force ID: 257697. | |
| Modificada | Media (5.5) | 0.11% | — | IBM Cloud PAK FOR SecurityIBM Qradar Suite | 10/7/2024 | 17/6/2026 | IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 and IBM QRadar Suite Software 1.10.12.0 through 1.10.22.0 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 281429. | |
| Modificada | Baja (3.3) | 0.17% | — | IBM Cloud PAK FOR SecurityIBM Qradar Suite | 28/6/2024 | 17/6/2026 | IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.11.0 and IBM QRadar Software Suite 1.10.12.0 through 1.10.21.0 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 233673. | |
| Analizada | Alta (8.8) | 0.37% | — | IBM Cloud PAK FOR SecurityIBM Qradar Suite | 18/6/2024 | 17/6/2026 | IBM QRadar Suite Software 1.10.12.0 through 1.10.21.0 and IBM Cloud Pak for Security 1.10.12.0 through 1.10.21.0 could allow an authenticated user to execute certain arbitrary commands due to improper input validation. IBM X-Force ID: 272087. | |
| Analizada | Media (6.8) | 0.43% | — | IBM Qradar Security Information AND Event Manager | 14/5/2024 | 17/6/2026 | IBM QRadar SIEM 7.5 could allow a privileged user to configure user management that would disclose unintended sensitive information across tenants. IBM X-Force ID: 284575. | |
| Analizada | Media (4.3) | 0.35% | — | IBM Cloud PAK FOR SecurityIBM Qradar Suite | 2/5/2024 | 17/6/2026 | IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 and IBM QRadar Suite Software 1.10.12.0 through 1.10.20.0 could allow an authenticated user to modify dashboard parameters due to improper input validation. IBM X-Force ID: 272089. | |
| Analizada | Media (5.9) | 0.46% | — | IBM Cloud PAK FOR SecurityIBM Qradar Suite | 1/5/2024 | 17/6/2026 | IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.11.0 and IBM QRadar Suite for Software 1.10.12.0 through 1.10.19.0 does not set the SameSite attribute for sensitive cookies which could allow an attacker to obtain sensitive information using man-in-the-middle techniques. IBM X-Force ID: 233778. | |
| Analizada | Media (5.4) | 0.30% | — | IBM Cloud PAK FOR SecurityIBM Qradar Suite | 23/4/2024 | 17/6/2026 | IBM QRadar Suite Software 1.10.12.0 through 1.10.19.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials… | |
| Analizada | Alta (8.1) | 0.34% | — | IBM Qradar Security Information AND Event Manager | 11/4/2024 | 17/6/2026 | IBM QRadar SIEM 7.5 could allow an unauthorized user to perform unauthorized actions due to improper certificate validation. IBM X-Force ID: 275706. | |
| Analizada | Media (6.5) | 0.36% | — | IBM Cloud PAK FOR SecurityIBM Qradar Suite | 3/4/2024 | 17/6/2026 | IBM QRadar Suite Software 1.10.12.0 through 1.10.18.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 stores user credentials in plain clear text which can be read by an authenticated user. IBM X-Force ID: 285698. | |
| Analizada | Media (5.4) | 0.34% | 💥 PoC | IBM Qradar Security Information AND Event Manager | 27/3/2024 | 17/6/2026 | IBM QRadar SIEM 7.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 285893. | |
| Analizada | Media (5.4) | 0.34% | — | IBM Qradar Security Information AND Event Manager | 27/3/2024 | 17/6/2026 | IBM QRadar SIEM 7.5 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 275939. | |
| Modificada | Media (5.5) | 0.28% | 💥 PoC | Radare2 | 14/3/2024 | 17/6/2026 | An issue in radareorg radare2 v.0.9.7 through v.5.8.6 and fixed in v.5.8.8 allows a local attacker to cause a denial of service via the grub_sfs_read_extent function. |