Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
–

292 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)0.79%—IBM Qradar Advisor25/2/202017/6/2026
IBM Qradar Advisor 1.1 through 2.5 with Watson uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 166206.
ModificadaMedia (5.3)1.1%—IBM Qradar Security Information AND Event Manager10/1/202017/6/2026
IBM QRadar SIEM 7.3.0 through 7.3.3 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 166355.
ModificadaAlta (7.8)0.26%—IBM Qradar Security Information AND Event Manager10/1/202017/6/2026
IBM QRadar SIEM 7.3.0 through 7.3.3 uses weak credential storage in some instances which could be decrypted by a local attacker. IBM X-Force ID: 164429.
ModificadaMedia (6.1)0.89%—IBM Qradar Security Information AND Event Manager9/11/201917/6/2026
IBM QRadar 7.3.0 to 7.3.2 Patch 4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 167239.
ModificadaMedia (6.5)0.76%—IBM Qradar Advisor With Watson9/11/201917/6/2026
IBM QRadar Advisor 1.0.0 through 2.4.0 uses incomplete blacklisting for input validation which allows attackers to bypass application controls resulting in direct impact to the system and data integrity. IBM X-Force ID: 166205.
ModificadaMedia (4.3)0.71%—IBM Qradar Security Information AND Event Manager9/11/201917/6/2026
IBM QRadar 7.3.0 to 7.3.2 Patch 4 is vulnerable to incorrect authorization in some components which could allow an authenticated user to obtain sensitive information. IBM X-Force ID: 164430.
ModificadaMedia (5.4)0.56%—IBM Qradar Security Information AND Event Manager9/11/201917/6/2026
IBM QRadar 7.3.0 to 7.3.2 Patch 4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 163779.
ModificadaMedia (5.4)0.56%—IBM Qradar Security Information AND Event Manager9/11/201917/6/2026
IBM QRadar 7.3.0 to 7.3.2 Patch 4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 163618.
ModificadaMedia (5.3)0.95%—IBM Qradar Security Information AND Event Manager26/9/201917/6/2026
IBM QRadar SIEM 7.2 and 7.3 is vulnerable to Server Side Request Forgery (SSRF). This may allow an unauthenticated attacker to send unauthorized requests from the QRadar system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 160014.
ModificadaAlta (8.8)0.55%—IBM Qradar Security Information AND Event Manager25/7/201917/6/2026
IBM QRadar SIEM 7.2 and 7.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 159132.
ModificadaAlta (8.1)0.68%—IBM Qradar Security Information AND Event Manager22/7/201917/6/2026
IBM QRadar SIEM 7.2 and 7.3 specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors. IBM X-Force ID: 155350.
ModificadaMedia (5.4)0.67%—IBM Qradar Security Information AND Event Manager17/7/201917/6/2026
IBM QRadar SIEM 7.2 and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 159131.
ModificadaBaja (3.3)0.33%—IBM Qradar Security Information AND Event Manager17/7/201917/6/2026
IBM QRadar SIEM 7.2 and 7.3 could allow a local user to obtain sensitive information when exporting content that could aid an attacker in further attacks against the system. IBM X-Force ID: 156563.
ModificadaMedia (5.3)1.3%—IBM Qradar Security Information AND Event Manager17/7/201917/6/2026
IBM QRadar SIEM 7.2 and 7.3 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 155346.
ModificadaMedia (6.1)0.90%—IBM Qradar Security Information AND Event Manager17/7/201917/6/2026
IBM QRadar SIEM 7.2 and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 155345.
ModificadaMedia (5.9)1.0%—IBM Qradar Security Information AND Event Manager29/5/201917/6/2026
IBM QRadar SIEM 7.2.8 WinCollect could allow an attacker to obtain sensitive information by spoofing a trusted entity using man in the middle techniques due to not validating or incorrectly validating a certificate. IBM X-Force ID: 160072.
ModificadaMedia (5.3)1.8%—IBM Qradar Security Information AND Event Manager19/4/201917/6/2026
IBM QRadar SIEM 7.3 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 147708.
ModificadaAlta (8.1)2.2%—IBM Qradar Security Information AND Event Manager8/4/201917/6/2026
IBM QRadar SIEM 7.3.2 could allow a user to bypass authentication exposing certain functionality which could lead to information disclosure or modification of application configuration. IBM X-Force ID: 158986.
ModificadaAlta (7.5)1.3%—IBM Qradar Security Information AND Event Manager15/2/201917/6/2026
IBM QRadar SIEM 7.2 and 7.3 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 134177.
ModificadaMedia (5.3)1.7%—IBM Qradar Security Information AND Event Manager29/1/201917/6/2026
IBM QRadar SIEM 7.2 and 7.3 fails to adequately filter user-controlled input data for syntax that has control-plane implications which could allow an attacker to modify displayed content. IBM X-Force ID: 147811.
ModificadaAlta (7.5)1.4%—IBM Qradar Advisor With Watson5/12/201817/6/2026
IBM QRadar Advisor with Watson 1.14.0 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 147810.
ModificadaAlta (7.1)1.9%—IBM Qradar Security Information AND Event Manager5/12/201817/6/2026
IBM QRadar SIEM 7.2 and 7.3 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 147709.
ModificadaMedia (5.4)0.66%—IBM Qradar Incident Forensics5/12/201817/6/2026
IBM QRadar SIEM 7.2 and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 147707.
ModificadaMedia (5.5)0.34%—IBM Qradar Incident Forensics5/12/201817/6/2026
IBM QRadar SIEM 7.2 and 7.3 uses hard-coded credentials which could allow an attacker to bypass the authentication configured by the administrator. IBM X-Force ID: 144656.
ModificadaAlta (7.5)1.1%—IBM Qradar Incident Forensics5/12/201817/6/2026
IBM QRadar SIEM 7.2 and 7.3 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 144653.