Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3005▼ 85 respecto a la semana anterior
Críticas / altas1403▲ 41 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
17 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.4) | 0.09% | — | IBM Security Qradar EDR | 11/6/2026 | 1/10/2026 | IBM Security QRadar EDR 3.12 through 3.12.24 stores user credentials in plain text which can be read by a local privileged user. | |
| Analizada | Alta (7.5) | 0.15% | — | IBM Qradar EDR | 17/2/2026 | 17/6/2026 | IBM Security QRadar EDR 3.12 through 3.12.23 IBM Security ReaQta uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. | |
| Analizada | Alta (8.8) | 0.20% | — | IBM Qradar EDR | 17/2/2026 | 17/6/2026 | IBM Security QRadar EDR 3.12 through 3.12.23 does not invalidate session after a session expiration which could allow an authenticated user to impersonate another user on the system. | |
| Analizada | Alta (8.8) | 0.20% | — | IBM Security Qradar EDR | 17/2/2026 | 17/6/2026 | IBM Security QRadar EDR 3.12 through 3.12.23 does not invalidate session after a session expiration which could allow an authenticated user to impersonate another user on the system. | |
| Analizada | Media (6.5) | 0.19% | — | IBM Security Qradar EDR | 20/5/2025 | 17/6/2026 | IBM Security ReaQta EDR 3.12 could allow an attacker to perform unauthorized actions due to improper SSL certificate validation. | |
| Analizada | Media (6.5) | 0.24% | — | IBM Security Qradar EDR | 20/5/2025 | 17/6/2026 | IBM Security ReaQta EDR 3.12 could allow an attacker to spoof a trusted entity by interfering with the communication path between the host and client. | |
| Analizada | Media (4.7) | 0.27% | — | IBM Security Qradar EDR | 19/3/2025 | 17/6/2026 | IBM Security ReaQta 3.12 allows a privileged user to upload or transfer files of dangerous types that can be automatically processed within the product's environment. | |
| Analizada | Alta (7.5) | 0.21% | — | IBM Security Qradar EDR | 14/3/2025 | 17/6/2026 | IBM Security QRadar 3.12 EDR uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt sensitive credential information. | |
| Analizada | Media (4.4) | 0.13% | — | IBM Security Qradar EDR | 14/3/2025 | 17/6/2026 | IBM Security QRadar 3.12 EDR stores user credentials in plain text which can be read by a local privileged user. | |
| Analizada | Media (4.3) | 0.36% | — | IBM Security Qradar EDR | 19/1/2025 | 17/6/2026 | IBM Security ReaQta 3.12 could allow an authenticated user to perform unauthorized actions due to reliance on untrusted inputs. | |
| Analizada | Media (5.3) | 0.32% | — | IBM Security Qradar EDR | 7/1/2025 | 17/6/2026 | IBM Security ReaQta 3.12 returns sensitive information in an HTTP response that could be used in further attacks against the system. | |
| Analizada | Media (4.9) | 0.55% | — | IBM Security Qradar EDR | 7/1/2025 | 17/6/2026 | IBM Security ReaQta 3.12 could allow a privileged user to cause a denial of service by sending multiple administration requests due to improper allocation of resources. | |
| Analizada | Media (5.3) | 0.49% | — | IBM Security Qradar EDR | 14/11/2024 | 17/6/2026 | IBM Security ReaQta 3.12 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Analizada | Media (4.8) | 0.25% | — | IBM Security Qradar EDR | 14/11/2024 | 17/6/2026 | IBM Security ReaQta 3.12 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Modificada | Media (5.4) | 0.31% | — | IBM Security Qradar EDR | 10/7/2024 | 17/6/2026 | IBM Security QRadar EDR 3.12 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. | |
| Modificada | Media (5.3) | 0.24% | — | IBM Security Qradar EDR | 10/7/2024 | 17/6/2026 | IBM Security QRadar EDR 3.12 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then… | |
| Modificada | Media (5.3) | 0.36% | — | IBM Security Qradar EDR | 10/7/2024 | 17/6/2026 | IBM Security QRadar EDR 3.12 could disclose sensitive information due to an observable login response discrepancy. IBM X-Force ID: 257697. |