Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 166 respecto a la semana anterior
Críticas / altas1379▲ 45 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 260 respecto a la semana anterior
22 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.17% | — | Hex-rays IDA PROAI | 9/5/2026 | 24/7/2026 | Hex-Rays IDA Pro 9.2 and 9.3 before 9.3sp2 does not block Clang dependency-file generation (via argument injection), which allows attackers to place their code into a plugins directory if the victim uses an attacker-supplied .i64 file. | |
| Pendiente de análisis | Media (5.9) | 0.38% | — | Amazon X-ray Remote SamplerAIOpentelemetry Sampler AWSAI | 23/4/2026 | 17/6/2026 | The AWS X-Ray Remote Sampler package provides a sampler which can get sampling configurations from AWS X-Ray. Prior to 0.1.0-alpha.8, OpenTelemetry.Sampler.AWS reads unbounded HTTP response bodies from a configured AWS X-Ray remote sampling endpoint into memory. AWSXRaySamplerClient.DoRequestAsync called… | |
| Analizada | Alta (7.5) | 0.21% | — | Ixray-team Ix-ray Engine 1.6 | 27/1/2026 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in ixray-team ixray-1.6-stcop.This issue affects ixray-1.6-stcop: before 1.3. | |
| Analizada | Crítica (9.8) | 0.32% | — | Ixray-team Ix-ray Engine 1.6 | 27/1/2026 | 17/6/2026 | Out-of-bounds Write vulnerability in ixray-team ixray-1.6-stcop.This issue affects ixray-1.6-stcop: before 1.3. | |
| Analizada | Alta (7.5) | 0.29% | — | Ixray-team Ix-ray Engine 1.6 | 27/1/2026 | 17/6/2026 | Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in ixray-team ixray-1.6-stcop.This issue affects ixray-1.6-stcop: before 1.3. | |
| Modificada | Alta (7.5) | 1.4% | — | Hex-rays IDA PRO | 19/8/2024 | 17/6/2026 | ida64.dll in Hex-Rays IDA Pro through 8.4 crashes when there is a section that has many jumps linked, and the final jump corresponds to the payload from where the actual entry point will be invoked. NOTE: in many use cases, this is an inconvenience but not a security issue. | |
| Aplazada | Media (4.7) | 0.43% | — | MT Safeline X-ray X3310AI | 4/4/2024 | 17/6/2026 | An HTML injection vulnerability exists in the MT Safeline X-Ray X3310 webserver version NXG 19.05 that enables a remote attacker to render malicious HTML and obtain sensitive information in a victim's browser. | |
| Aplazada | Media (5.4) | 0.34% | — | MT Safeline X-ray X3310AI | 4/4/2024 | 17/6/2026 | A reflected cross-site scripting (XSS) vulnerability exists in the MT Safeline X-Ray X3310 webserver version NXG 19.05 that enables a remote attacker to execute JavaScript code and obtain sensitive information in a victim's browser. | |
| Modificada | Media (5.5) | 0.68% | — | Hex-rays IDA | 7/7/2022 | 17/6/2026 | A memory corruption in Hex Rays Ida Pro v6.6 allows attackers to cause a Denial of Service (DoS) via a crafted file. Related to Data from Faulting Address controls subsequent Write Address starting at msvcrt!memcpy+0x0000000000000056. | |
| Modificada | Alta (10) | 1.9% | — | Hex-rays IDA | 2/1/2015 | 17/6/2026 | Heap-based buffer overflow in the GDB debugger module in Hex-Rays IDA Pro before 6.6 cumulative fix 2014-12-24 allows remote GDB servers to have unspecified impact via unknown vectors. | |
| Modificada | Media (4.3) | 3.2% | — | Xaraya | 5/2/2014 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Xaraya 2.4.0-b1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) id, (2) interface, (3) name, or (4) tabmodule parameter to index.php. | |
| Modificada | Alta (10) | 1.5% | — | Hex-rays IDA | 21/2/2011 | 16/6/2026 | Unspecified vulnerability in the PEF input file loader in Hex-Rays IDA Pro 5.7 and 6.0 has unknown impact and attack vectors. | |
| Modificada | Media (4.3) | 1.2% | — | Hex-rays IDA | 21/2/2011 | 16/6/2026 | Unspecified vulnerability in the Mach-O input file loader in Hex-Rays IDA Pro 5.7 and 6.0 allows user-assisted remote attackers to cause a denial of service (out-of-memory exception and inability to analyze code) via a crafted Mach-O file. | |
| Modificada | Alta (10) | 1.5% | — | Hex-rays IDA | 21/2/2011 | 16/6/2026 | Integer overflow in the PSX/GEOS input file loaders in Hex-Rays IDA Pro 5.7 and 6.0 has unknown impact and attack vectors related to memory allocation. | |
| Modificada | Alta (10) | 1.5% | — | Hex-rays IDA | 21/2/2011 | 16/6/2026 | Integer overflow in the COFF/EPOC/EXPLOAD input file loaders in Hex-Rays IDA Pro 5.7 and 6.0 has unknown impact and attack vectors related to memory allocation. | |
| Modificada | Alta (10) | 1.5% | — | Hex-rays IDA | 21/2/2011 | 16/6/2026 | Unspecified vulnerability in Hex-Rays IDA Pro 5.7 and 6.0 has unknown impact and attack vectors related to "converson of string encodings" and "inconsistencies in the handling of UTF8 sequences by the user interface." | |
| Modificada | Media (6.8) | 3.7% | — | Hex-rays IDA | 21/2/2011 | 16/6/2026 | Buffer overflow in the Mach-O input file loader in Hex-Rays IDA Pro 5.7 and 6.0 allows user-assisted remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted Macho-O file. | |
| Modificada | Alta (9.3) | 1.4% | — | Sourceforge Emule X-ray | 29/5/2008 | 16/6/2026 | Buffer overflow in Uploadlist in eMule X-Ray before 1.4 has unknown impact and remote attack vectors. | |
| Modificada | Alta (7.5) | 1.4% | — | Emule X RAY | 29/5/2008 | 16/6/2026 | Unspecified vulnerability in the web server in eMule X-Ray before 1.4 allows remote attackers to trigger memory corruption via unknown attack vectors. | |
| Modificada | Alta (7.5) | 1.4% | — | Xaraya | 25/4/2007 | 16/6/2026 | Unspecified vulnerability in the Roles module in Xaraya 1.1.2 and earlier allows attackers to gain privileges via unspecified vectors, probably related to incorrect permission checking in xartemplates/user-view.xd. | |
| Modificada | Media (5) | 1.7% | — | Curtis Farnham Files Xaraya Module | 7/2/2006 | 16/6/2026 | Directory traversal vulnerability in Files Xaraya module before 0.5.1, when the Archive Directory field on the Modify Config page is blank, allows remote attackers to access files outside of the web root via ".." (dot dot) sequences. | |
| Modificada | Media (5) | 7.5% | — | Xaraya | 30/11/2005 | 16/6/2026 | Directory traversal vulnerability in the create function in xarMLSXML2PHPBackend.php in Xaraya 1.0 allows remote attackers to create directories and overwrite arbitrary files via ".." sequences in the module parameter to index.php. |