Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
494 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.90% | — | Radare2 | 22/8/2023 | 17/6/2026 | A heap buffer overflow in r_read_le32 function in radare25.4.2 and 5.4.0. | |
| Modificada | Alta (7.5) | 0.92% | — | Radare2 | 22/8/2023 | 17/6/2026 | A use after free in r_reg_get_name_idx function in radare2 5.4.2 and 5.4.0. | |
| Modificada | Alta (7.5) | 0.92% | — | Radare2 | 22/8/2023 | 17/6/2026 | A null pointer deference in __core_anal_fcn function in radare2 5.4.2 and 5.4.0. | |
| Modificada | Alta (7.5) | 0.90% | — | Radare2 | 22/8/2023 | 17/6/2026 | A heap buffer overflow in vax_opfunction in radare2 5.4.2 and 5.4.0. | |
| Modificada | Alta (7.5) | 0.91% | — | Radare2 | 22/8/2023 | 17/6/2026 | A heap buffer overflow in r_sleb128 function in radare2 5.4.2 and 5.4.0. | |
| Modificada | Media (5.4) | 0.36% | — | Phpradar Woocommerce Tip/donation | 17/8/2023 | 17/6/2026 | Auth. (shop manager+) Stored Cross-Site Scripting (XSS) vulnerability in PHPRADAR Woocommerce Tip/Donation plugin <= 1.2 versions. | |
| Modificada | Crítica (9.8) | 0.95% | — | Radare2Fedoraproject Fedora | 14/8/2023 | 17/6/2026 | Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.9.0. | |
| Modificada | Crítica (9.1) | 0.77% | — | Radare2 | 7/7/2023 | 17/6/2026 | Radare2 has a use-after-free vulnerability in pyc parser's get_none_object function. Attacker can read freed memory afterwards. This will allow attackers to cause denial of service. | |
| Modificada | Alta (7.5) | 0.84% | — | Radare2 | 7/7/2023 | 17/6/2026 | Radare2 has a division by zero vulnerability in Mach-O parser's rebase_buffer function. This allow attackers to create malicious inputs that can cause denial of service. | |
| Modificada | Alta (7.5) | 0.39% | — | IBM Qradar Security Information AND Event Manager | 27/6/2023 | 17/6/2026 | IBM QRadar SIEM 7.5.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 248147. | |
| Modificada | Media (5.4) | 0.37% | — | IBM Qradar Security Information AND Event Manager | 27/6/2023 | 17/6/2026 | IBM QRadar SIEM 7.5.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 248144. | |
| Modificada | Media (4.3) | 0.44% | — | IBM Qradar Security Information AND Event Manager | 27/6/2023 | 17/6/2026 | IBM QRadar SIEM 7.5.0 could allow an authenticated user to perform unauthorized actions due to hazardous input validation. IBM X-Force ID: 248134. | |
| Modificada | Media (6.5) | 0.63% | — | IBM Qradar Security Information AND Event Manager | 27/6/2023 | 17/6/2026 | IBM QRadar SIEM 7.5.0 is vulnerable to information exposure allowing a delegated Admin tenant user with a specific domain security profile assigned to see data from other domains. IBM X-Force ID: 230403. | |
| Modificada | Alta (7.8) | 0.20% | — | IBM Qradar Wincollect | 31/5/2023 | 17/6/2026 | IBM QRadar WinCollect Agent 10.0 through 10.1.3 could allow a local authenticated attacker to gain elevated privileges on the system. IBM X-Force ID: 248158. | |
| Modificada | Alta (7.8) | 0.19% | — | IBM Qradar Wincollect | 31/5/2023 | 17/6/2026 | IBM QRadar WinCollect Agent 10.0 though 10.1.3 could allow a local user to execute commands on the system due to execution with unnecessary privileges. IBM X-Force ID: 248156. | |
| Modificada | Alta (7.5) | 0.44% | — | IBM Qradar Data Synchronization | 6/5/2023 | 17/6/2026 | IBM QRadar Data Synchronization App 1.0 through 3.0.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 217370. | |
| Modificada | Alta (7.5) | 0.99% | — | Radare2 | 23/3/2023 | 17/6/2026 | Denial of Service in GitHub repository radareorg/radare2 prior to 5.8.6. | |
| Modificada | Alta (7.2) | 0.74% | — | IBM Qradar Security Information AND Event Manager | 22/3/2023 | 17/6/2026 | IBM QRadar SIEM 7.4 and 7.5 is vulnerable to privilege escalation, allowing a user with some admin capabilities to gain additional admin capabilities. IBM X-Force ID: 239425. | |
| Modificada | Media (5.5) | 0.31% | — | Radare2 | 10/3/2023 | 17/6/2026 | radare2 v5.8.3 was discovered to contain a segmentation fault via the component wasm_dis at p/wasm/wasm.c. | |
| Modificada | Alta (7.5) | 0.39% | — | IBM Qradar Security Information AND Event Manager | 17/2/2023 | 17/6/2026 | IBM QRadar SIEM 7.4 and 7.5 is vulnerable to information exposure allowing a non-tenant user with a specific domain security profile assigned to see some data from other domains. IBM X-Force ID: 230402. | |
| Modificada | Alta (7.5) | 0.31% | — | IBM Qradar Security Information AND Event Manager | 17/1/2023 | 17/6/2026 | IBM QRadar SIEM 7.4 and 7.5copies certificate key files used for SSL/TLS in the QRadar web user interface to managed hosts in the deployment that do not require that key. IBM X-Force ID: 244356. | |
| Modificada | Alta (7.8) | 0.36% | — | Radare2 | 15/1/2023 | 17/6/2026 | Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) in GitHub repository radareorg/radare2 prior to 5.8.2. | |
| Modificada | Alta (7.5) | 0.69% | — | Radare2 | 29/12/2022 | 17/6/2026 | NULL Pointer Dereference in GitHub repository radareorg/radare2 prior to 5.8.2. | |
| Modificada | Alta (7.8) | 0.34% | — | Radare2 | 10/12/2022 | 17/6/2026 | Integer Overflow or Wraparound in GitHub repository radareorg/radare2 prior to 5.8.0. | |
| Modificada | Media (5.5) | 0.20% | — | IBM Qradar Security Information AND Event Manager | 7/10/2022 | 17/6/2026 | IBM QRadar SIEM 7.4 and 7.5 could disclose sensitive information via a local service to a privileged user. IBM X-Force ID: 227366. |