Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 554 respecto a la semana anterior
Críticas / altas1325▼ 178 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 242 respecto a la semana anterior
2287 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.5) | 1.5% | — | Radare2 | 17/4/2026 | 14/7/2026 | radare2 prior to commit bc5a890 contains a command injection vulnerability in the afsv/afsvj command path where crafted ELF binaries can embed malicious r2 command sequences as DWARF DW_TAG_formal_parameter names. Attackers can craft a binary with shell commands in DWARF parameter names that execute when radare2… | |
| Pendiente de análisis | Alta (7.4) | 1.0% | — | Radare2AI | 16/4/2026 | 17/6/2026 | radare2 before 9236f44, when configured on UNIX without SSL, allows command injection via a PDB name to rabin2 -PP. NOTE: although users are supposed to use the latest version from git (not a release), the date range for the vulnerable code was less than a week, occurring after 6.1.2 but before 6.1.3. | |
| Analizada | Alta (8.4) | 1.7% | — | Radare2 | 15/4/2026 | 17/6/2026 | radare2 prior to version 6.1.4 contains a command injection vulnerability in the PDB parser's print_gvars() function that allows attackers to execute arbitrary commands by embedding a newline byte in the PE section header name field. Attackers can craft a malicious PDB file with specially crafted section names to… | |
| Aplazada | Media (4.3) | 0.28% | — | AvadaAI | 15/4/2026 | 17/6/2026 | The Avada (Fusion) Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.15.1. This is due to the plugin's `fusion_get_post_custom_field()` function failing to validate whether metadata keys are protected (underscore-prefixed). This makes it possible for… | |
| Aplazada | Media (5.4) | 0.31% | — | AvadaAI | 15/4/2026 | 17/6/2026 | The Avada (Fusion) Builder plugin for WordPress is vulnerable to Arbitrary WordPress Action Execution in all versions up to, and including, 3.15.1. This is due to the plugin's `output_action_hook()` function accepting user-controlled input to trigger any registered WordPress action hook without proper authorization… | |
| Analizada | Alta (7.5) | 0.42% | — | Agentfront @frontmcp/adaptersAgentfront @frontmcp/sdkAgentfront FrontmcpFrontmcp Mcp-from-openapi | 8/4/2026 | 24/7/2026 | FrontMCP is a TypeScript-first framework for the Model Context Protocol (MCP). Prior to 2.3.0, the mcp-from-openapi library uses @apidevtools/json-schema-ref-parser to dereference $ref pointers in OpenAPI specifications without configuring any URL restrictions or custom resolvers. A malicious OpenAPI specification… | |
| Aplazada | Media (5.3) | 0.29% | — | Adastracrypto Cryptocurrency Donation BOXAI | 8/4/2026 | 24/7/2026 | Missing Authorization vulnerability in AdAstraCrypto Cryptocurrency Donation Box – Bitcoin & Crypto Donations cryptocurrency-donation-box allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Cryptocurrency Donation Box – Bitcoin & Crypto Donations: from n/a through <= 2.2.13. | |
| Aplazada | Media (5.3) | 0.26% | 💥 PoC | Shahjada Download ManagerAI | 8/4/2026 | 20/7/2026 | Missing Authorization vulnerability in Shahjada Download Manager download-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Download Manager: from n/a through <= 3.3.52. | |
| Aplazada | Media (5.9) | 0.24% | — | Shahjada Download ManagerAI | 8/4/2026 | 24/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Shahjada Download Manager download-manager allows Stored XSS.This issue affects Download Manager: from n/a through <= 3.3.53. | |
| Aplazada | Alta (8.5) | 0.36% | — | Kamleshyadav Miraculous CoreAI | 25/3/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in kamleshyadav Miraculous Core Plugin miraculouscore allows Blind SQL Injection.This issue affects Miraculous Core Plugin: from n/a through < 2.1.2. | |
| Aplazada | Alta (7.5) | 0.41% | — | Kamleshyadav MiraculousAI | 25/3/2026 | 17/6/2026 | Missing Authorization vulnerability in kamleshyadav Miraculous miraculous allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Miraculous: from n/a through < 2.1.2. | |
| Aplazada | Alta (7.5) | 0.35% | — | Addi Cuotas QUE SE Adaptan A TIAI | 25/3/2026 | 17/6/2026 | Use of Hard-coded Credentials vulnerability in Addi Addi – Cuotas que se adaptan a ti buy-now-pay-later-addi allows Password Recovery Exploitation.This issue affects Addi – Cuotas que se adaptan a ti: from n/a through <= 2.0.4. | |
| Aplazada | Alta (8.1) | 0.52% | — | Ancrathemes VegadaysAI | 25/3/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes VegaDays vegadays allows PHP Local File Inclusion.This issue affects VegaDays: from n/a through <= 1.2.0. | |
| Analizada | Alta (8.6) | 0.35% | — | Cisco Secure Firewall Threat DefenseCisco Adaptive Security Appliance SoftwareCisco IOSCisco IOS XE | 25/3/2026 | 17/9/2026 | A vulnerability in the Internet Key Exchange version 2 (IKEv2) feature of Cisco IOS Software, Cisco IOS XE Software, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a memory leak,… | |
| Analizada | Media (5.4) | 0.14% | — | IBM Qradar Security Information AND Event Manager | 19/3/2026 | 17/6/2026 | IBM QRadar SIEM 7.5.0 through 7.5.0 Update Package 14 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Analizada | Media (5.5) | 0.10% | — | IBM Qradar Security Information AND Event Manager | 19/3/2026 | 17/6/2026 | IBM QRadar SIEM 7.5.0 through 7.5.0 Update Package 14 stores potentially sensitive information in configuration files that could be read by a local user. | |
| Analizada | Media (5.4) | 0.14% | — | IBM Qradar Security Information AND Event Manager | 19/3/2026 | 17/6/2026 | IBM QRadar SIEM 7.5.0 through 7.5.0 Update Package 14 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality. | |
| Analizada | Media (5) | 0.18% | — | IBM Qradar Security Information AND Event Manager | 19/3/2026 | 17/6/2026 | IBM QRadar SIEM 7.5.0 through 7.5.0 Update Package 14 could allow an attacker with access to one tenant to access hostname data from another tenant's account. | |
| Analizada | Alta (7.5) | 0.49% | — | Borewit Music-metadata | 18/3/2026 | 17/6/2026 | music-metadata is a metadata parser for audio and video media files. Prior to version 11.12.3, music-metadata's ASF parser (`parseExtensionObject()` in `lib/asf/AsfParser.ts:112-158`) enters an infinite loop when a sub-object inside the ASF Header Extension Object has `objectSize = 0`. Version 11.12.3 fixes the issue. | |
| Aplazada | Baja (1.9) | 0.16% | — | Radare2AI | 16/3/2026 | 17/6/2026 | A vulnerability has been found in Radare2 5.9.9. This issue affects the function walk_exports_trie of the file libr/bin/format/mach0/mach0.c of the component Mach-O File Parser. Such manipulation leads to resource consumption. The attack can only be performed from a local environment. The exploit has been disclosed to… | |
| Aplazada | Media (6.5) | 0.22% | — | Themefusion Avada CoreAI | 13/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeFusion Avada Core fusion-core allows DOM-Based XSS.This issue affects Avada Core: from n/a through < 5.15.0. | |
| Aplazada | Media (5.3) | 0.29% | — | Themefusion Avada CoreAI | 13/3/2026 | 17/6/2026 | Missing Authorization vulnerability in ThemeFusion Avada Core fusion-core allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Avada Core: from n/a through < 5.15.0. | |
| Analizada | Alta (7.7) | 0.97% | 💥 PoC | Tp-link Omada Sg2005p-pd FirmwareTp-link Omada Sg2008 FirmwareTp-link Omada Sg2008p FirmwareTp-link Omada Sg2016p Firmware+35 | 13/3/2026 | 17/6/2026 | The web interface on multiple Omada switches does not adequately validate certain external inputs, which may lead to out-of-bound memory access when processing crafted requests. Under specific conditions, this flaw may result in unintended command execution.<br>An unauthenticated attacker with network access to the… | |
| Analizada | Media (4.8) | 0.21% | — | Scadabr | 9/3/2026 | 17/6/2026 | ScadaBR 1.12.4 is vulnerable to Session Fixation. The application assigns a JSESSIONID session cookie to unauthenticated users and does not regenerate the session identifier after successful authentication. As a result, a session created prior to login becomes authenticated once the victim logs in, allowing an… | |
| Analizada | Media (6.9) | 0.23% | — | Tp-link Omada Eap610 Firmware | 5/3/2026 | 17/6/2026 | A denial-of-service (DoS) vulnerability was identified in Omada EAP610 v3. An attacker with adjacent network access can send crafted requests to cause the device’s HTTP service to crash. This results in temporary service unavailability until the device is rebooted. This issue affects Omada EAP610 firmware versions… |