Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▲ 32 respecto a la semana anterior
Críticas / altas1477▲ 367 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
2280 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.33% | — | Shahjada Download ManagerAI | 2/10/2026 | 2/10/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Shahjada Download Manager allows Retrieve Embedded Sensitive Data. This issue affects Download Manager: from n/a through 3.3.71. | |
| Aplazada | Media (6.1) | 0.17% | — | AvadaAI | 2/10/2026 | 2/10/2026 | The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'lang' parameter in all versions up to, and including, 7.16.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject… | |
| Pendiente de análisis | Baja (1.1) | 0.29% | — | Wikimedia CommonsmetadataAI | 30/9/2026 | 1/10/2026 | Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki CommonsMetadata extension allows Cross-Site Scripting (XSS). This issue affects MediaWiki CommonsMetadata extension: 1.46, 1.45, and 1.43. | |
| Pendiente de análisis | Media (6.3) | 0.39% | — | Apache Airflow Teradata ProviderAI | 29/9/2026 | 29/9/2026 | The Apache Airflow Teradata provider's compute-cluster example Dag declared every one of its Dag Params as unconstrained free text and templated them straight into the compute-cluster operators, which interpolate those values into Teradata DDL. A user who is permitted to trigger that Dag - a lower-trust role than the… | |
| Pendiente de análisis | Media (6.5) | 0.28% | — | Apache Airflow Providers TeradataAI | 29/9/2026 | 29/9/2026 | Apache Airflow's Teradata provider embedded cloud storage credentials directly into SQL statements. `S3ToTeradataOperator` and `AzureBlobStorageToTeradataOperator` interpolate the source bucket's credentials as plain string literals into the `CREATE MULTISET TABLE ... LOCATION` statement whenever the bucket is private… | |
| Aplazada | Media (5.1) | 0.26% | — | Open-metadata OpenmetadataAI | 25/9/2026 | 25/9/2026 | OpenMetadata through 2.0.2 contains a server-side request forgery vulnerability in the URLValidator.validateURL function that fails to properly resolve DNS hostnames and validate internal addresses. Users permitted to create or update EventSubscription can set webhook destinations to internal hosts, allowing the… | |
| Aplazada | Alta (8.4) | 0.40% | — | Rattadan CosmowarpAI | 25/9/2026 | 30/9/2026 | The Rattadan Cosmowarp smart contract before 56c6147 can have a comparison to an unintended value of current_admin. | |
| Aplazada | Media (6.8) | 0.29% | — | JSM Show Post MetadataAI | 23/9/2026 | 23/9/2026 | The JSM Show Post Metadata WordPress plugin before 4.9.1 does not properly escape a post meta key before outputting it into an inline event-handler attribute in an admin-facing meta box, allowing users with contributor-level access and above to inject arbitrary JavaScript that executes in the session of a… | |
| Analizada | Media (5.5) | 0.13% | — | Radare2 | 22/9/2026 | 28/9/2026 | radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's Windows 64-bit crash-dump dmp64 parser was vulnerable because the Windows dmp64 parser used an input-controlled physical-memory-run PageCount directly as the bound of a per-page allocation loop. The vulnerability… | |
| Analizada | Media (5.5) | 0.13% | — | Radare2 | 22/9/2026 | 28/9/2026 | radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's NE relocation fixup-chain parser was vulnerable because the NE relocation parser followed fixup chains without an active iteration limit or cycle detection. The vulnerability is triggered by opening a crafted NE… | |
| Analizada | Baja (3.3) | 0.15% | — | Radare2 | 22/9/2026 | 28/9/2026 | radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's Mach-O LC_DATA_IN_CODE parser was vulnerable because the Mach-O LC_DATA_IN_CODE parser trusted dataoff and datasize and allowed a final partial record to be processed. The vulnerability is triggered by opening a… | |
| Analizada | Baja (3.3) | 0.16% | — | Radare2 | 22/9/2026 | 28/9/2026 | radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's Lua 5.3 bytecode function parser was vulnerable because the Lua 5.3 bytecode function parser read fixed function-metadata fields immediately after a function-name string without checking the remaining buffer… | |
| Analizada | Media (6.1) | 0.13% | — | Radare2 | 22/9/2026 | 28/9/2026 | radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's binary property-list Unicode parser was vulnerable because the binary-property-list Unicode parser underallocated an uninitialized UTF-8 destination and did not guarantee NUL termination. The vulnerability is… | |
| Analizada | Media (4.4) | 0.13% | — | Radare2 | 22/9/2026 | 25/9/2026 | radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's Mach-O Swift field-metadata parser was vulnerable because a relative Swift field pointer could be lower than the field-metadata section base, making subtraction produce a negative logical index. The vulnerability… | |
| Analizada | Media (5.5) | 0.14% | — | Radare2 | 22/9/2026 | 25/9/2026 | radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's Apple Preferred Executable Format loader was vulnerable because the PEF loader accepted relocSecCount values that were not bounded by the number of sections or complete relocation records in the input. The… | |
| Analizada | Media (6.1) | 0.18% | — | Radare2 | 22/9/2026 | 25/9/2026 | radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's ELF PN_XNUM handling was vulnerable because the ELF parser allocated the program-header array using the resolved PN_XNUM count but several consumers still iterated with the original e_phnum value of 65535. The… | |
| Analizada | Media (5.5) | 0.20% | — | Radare2 | 22/9/2026 | 25/9/2026 | radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's CPython bytecode .pyc marshal parser was vulnerable because the CPython marshal readers accepted a 32-bit string length without rejecting values that overflow the size-plus-one allocation. The vulnerability is… | |
| Aplazada | Media (5.5) | 0.54% | — | ScadabrAI | 21/9/2026 | 21/9/2026 | A vulnerability was determined in ScadaBR up to 1.1. Impacted is the function EmportDwr.createExportJSON of the file /ScadaBR/export_project.htm of the component Export Project Endpoint. This manipulation causes information disclosure. The attack can be initiated remotely. The exploit has been publicly disclosed and… | |
| Pendiente de análisis | Media (6.5) | 0.27% | — | IBM QradarAI | 18/9/2026 | 18/9/2026 | IBM QRadar 7.5.0 through 7.5.0 UP15 Interim Fix 006 could allow an authenticated user to obtain sensitive information from backup files due to incorrect permissions assignment. | |
| Pendiente de análisis | Alta (8.2) | 0.46% | — | Cisco Adaptive Security Device ManagerAICisco Secure FMC SoftwareAI | 16/9/2026 | 18/9/2026 | A vulnerability in Cisco Adaptive Security Device Manager (ASDM) single sign-on (SSO) handler for Cisco Secure FMC Software could allow an unauthenticated, remote attacker to log in as the Cisco ASDM administrator user. This vulnerability is due to improper management of the Cisco ASDM SSO token. An attacker could… | |
| Pendiente de análisis | Alta (8.8) | 0.20% | — | Cisco Secure Adaptive Security Appliance SoftwareAICisco Secure Firewall Threat Defense SoftwareAICisco Secure Firewall Management Center SoftwareAI | 16/9/2026 | 18/9/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software and Cisco Secure Firewall Management Center Software engineering team has conducted a comprehensive internal security review. This review… | |
| Pendiente de análisis | Alta (8.1) | 0.28% | — | Cisco Secure Adaptive Security Appliance SoftwareAICisco Secure Firewall Threat Defense SoftwareAICisco Secure Firewall Management Center SoftwareAI | 16/9/2026 | 18/9/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software and Cisco Secure Firewall Management Center Software engineering team has conducted a comprehensive internal security review. This review… | |
| Pendiente de análisis | Alta (8.4) | 0.26% | — | Cisco Secure Adaptive Security Appliance SoftwareAICisco Secure Firewall Threat Defense SoftwareAICisco Secure Firewall Management Center SoftwareAI | 16/9/2026 | 18/9/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software and Cisco Secure Firewall Management Center Software engineering team has conducted a comprehensive internal security review. This review… | |
| Pendiente de análisis | Alta (8.8) | 0.32% | — | Cisco Secure Adaptive Security Appliance SoftwareAICisco Secure Firewall Threat Defense SoftwareAICisco Secure Firewall Management Center SoftwareAI | 16/9/2026 | 18/9/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software and Cisco Secure Firewall Management Center Software engineering team has conducted a comprehensive internal security review. This review… | |
| Pendiente de análisis | Crítica (9.9) | 0.30% | — | Cisco Secure Adaptive Security Appliance SoftwareAICisco Secure Firewall Threat Defense SoftwareAICisco Secure Firewall Management Center SoftwareAI | 16/9/2026 | 18/9/2026 | The vulnerabilities tracked by CVE-2026-20332 are related to improper access control issues that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-284. |