Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2743▲ 32 respecto a la semana anterior
Críticas / altas1477▲ 367 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
–

2280 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.3)0.33%—Shahjada Download ManagerAI2/10/20262/10/2026
Authorization Bypass Through User-Controlled Key vulnerability in Shahjada Download Manager allows Retrieve Embedded Sensitive Data. This issue affects Download Manager: from n/a through 3.3.71.
AplazadaMedia (6.1)0.17%—AvadaAI2/10/20262/10/2026
The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'lang' parameter in all versions up to, and including, 7.16.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject…
Pendiente de análisisBaja (1.1)0.29%—Wikimedia CommonsmetadataAI30/9/20261/10/2026
Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki CommonsMetadata extension allows Cross-Site Scripting (XSS). This issue affects MediaWiki CommonsMetadata extension: 1.46, 1.45, and 1.43.
Pendiente de análisisMedia (6.3)0.39%—Apache Airflow Teradata ProviderAI29/9/202629/9/2026
The Apache Airflow Teradata provider's compute-cluster example Dag declared every one of its Dag Params as unconstrained free text and templated them straight into the compute-cluster operators, which interpolate those values into Teradata DDL. A user who is permitted to trigger that Dag - a lower-trust role than the…
Pendiente de análisisMedia (6.5)0.28%—Apache Airflow Providers TeradataAI29/9/202629/9/2026
Apache Airflow's Teradata provider embedded cloud storage credentials directly into SQL statements. `S3ToTeradataOperator` and `AzureBlobStorageToTeradataOperator` interpolate the source bucket's credentials as plain string literals into the `CREATE MULTISET TABLE ... LOCATION` statement whenever the bucket is private…
AplazadaMedia (5.1)0.26%—Open-metadata OpenmetadataAI25/9/202625/9/2026
OpenMetadata through 2.0.2 contains a server-side request forgery vulnerability in the URLValidator.validateURL function that fails to properly resolve DNS hostnames and validate internal addresses. Users permitted to create or update EventSubscription can set webhook destinations to internal hosts, allowing the…
AplazadaAlta (8.4)0.40%—Rattadan CosmowarpAI25/9/202630/9/2026
The Rattadan Cosmowarp smart contract before 56c6147 can have a comparison to an unintended value of current_admin.
AplazadaMedia (6.8)0.29%—JSM Show Post MetadataAI23/9/202623/9/2026
The JSM Show Post Metadata WordPress plugin before 4.9.1 does not properly escape a post meta key before outputting it into an inline event-handler attribute in an admin-facing meta box, allowing users with contributor-level access and above to inject arbitrary JavaScript that executes in the session of a…
AnalizadaMedia (5.5)0.13%—Radare222/9/202628/9/2026
radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's Windows 64-bit crash-dump dmp64 parser was vulnerable because the Windows dmp64 parser used an input-controlled physical-memory-run PageCount directly as the bound of a per-page allocation loop. The vulnerability…
AnalizadaMedia (5.5)0.13%—Radare222/9/202628/9/2026
radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's NE relocation fixup-chain parser was vulnerable because the NE relocation parser followed fixup chains without an active iteration limit or cycle detection. The vulnerability is triggered by opening a crafted NE…
AnalizadaBaja (3.3)0.15%—Radare222/9/202628/9/2026
radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's Mach-O LC_DATA_IN_CODE parser was vulnerable because the Mach-O LC_DATA_IN_CODE parser trusted dataoff and datasize and allowed a final partial record to be processed. The vulnerability is triggered by opening a…
AnalizadaBaja (3.3)0.16%—Radare222/9/202628/9/2026
radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's Lua 5.3 bytecode function parser was vulnerable because the Lua 5.3 bytecode function parser read fixed function-metadata fields immediately after a function-name string without checking the remaining buffer…
AnalizadaMedia (6.1)0.13%—Radare222/9/202628/9/2026
radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's binary property-list Unicode parser was vulnerable because the binary-property-list Unicode parser underallocated an uninitialized UTF-8 destination and did not guarantee NUL termination. The vulnerability is…
AnalizadaMedia (4.4)0.13%—Radare222/9/202625/9/2026
radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's Mach-O Swift field-metadata parser was vulnerable because a relative Swift field pointer could be lower than the field-metadata section base, making subtraction produce a negative logical index. The vulnerability…
AnalizadaMedia (5.5)0.14%—Radare222/9/202625/9/2026
radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's Apple Preferred Executable Format loader was vulnerable because the PEF loader accepted relocSecCount values that were not bounded by the number of sections or complete relocation records in the input. The…
AnalizadaMedia (6.1)0.18%—Radare222/9/202625/9/2026
radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's ELF PN_XNUM handling was vulnerable because the ELF parser allocated the program-header array using the resolved PN_XNUM count but several consumers still iterated with the original e_phnum value of 65535. The…
AnalizadaMedia (5.5)0.20%—Radare222/9/202625/9/2026
radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's CPython bytecode .pyc marshal parser was vulnerable because the CPython marshal readers accepted a 32-bit string length without rejecting values that overflow the size-plus-one allocation. The vulnerability is…
AplazadaMedia (5.5)0.54%—ScadabrAI21/9/202621/9/2026
A vulnerability was determined in ScadaBR up to 1.1. Impacted is the function EmportDwr.createExportJSON of the file /ScadaBR/export_project.htm of the component Export Project Endpoint. This manipulation causes information disclosure. The attack can be initiated remotely. The exploit has been publicly disclosed and…
Pendiente de análisisMedia (6.5)0.27%—IBM QradarAI18/9/202618/9/2026
IBM QRadar 7.5.0 through 7.5.0 UP15 Interim Fix 006 could allow an authenticated user to obtain sensitive information from backup files due to incorrect permissions assignment.
Pendiente de análisisAlta (8.2)0.46%—Cisco Adaptive Security Device ManagerAICisco Secure FMC SoftwareAI16/9/202618/9/2026
A vulnerability in Cisco Adaptive Security Device Manager (ASDM) single sign-on (SSO) handler for Cisco Secure FMC Software could allow an unauthenticated, remote attacker to log in as the Cisco ASDM administrator user. This vulnerability is due to improper management of the Cisco ASDM SSO token. An attacker could…
Pendiente de análisisAlta (8.8)0.20%—Cisco Secure Adaptive Security Appliance SoftwareAICisco Secure Firewall Threat Defense SoftwareAICisco Secure Firewall Management Center SoftwareAI16/9/202618/9/2026
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software and Cisco Secure Firewall Management Center Software engineering team has conducted a comprehensive internal security review. This review…
Pendiente de análisisAlta (8.1)0.28%—Cisco Secure Adaptive Security Appliance SoftwareAICisco Secure Firewall Threat Defense SoftwareAICisco Secure Firewall Management Center SoftwareAI16/9/202618/9/2026
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software and Cisco Secure Firewall Management Center Software engineering team has conducted a comprehensive internal security review. This review…
Pendiente de análisisAlta (8.4)0.26%—Cisco Secure Adaptive Security Appliance SoftwareAICisco Secure Firewall Threat Defense SoftwareAICisco Secure Firewall Management Center SoftwareAI16/9/202618/9/2026
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software and Cisco Secure Firewall Management Center Software engineering team has conducted a comprehensive internal security review. This review…
Pendiente de análisisAlta (8.8)0.32%—Cisco Secure Adaptive Security Appliance SoftwareAICisco Secure Firewall Threat Defense SoftwareAICisco Secure Firewall Management Center SoftwareAI16/9/202618/9/2026
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software and Cisco Secure Firewall Management Center Software engineering team has conducted a comprehensive internal security review. This review…
Pendiente de análisisCrítica (9.9)0.30%—Cisco Secure Adaptive Security Appliance SoftwareAICisco Secure Firewall Threat Defense SoftwareAICisco Secure Firewall Management Center SoftwareAI16/9/202618/9/2026
The vulnerabilities tracked by CVE-2026-20332 are related to improper access control issues that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-284.