Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
1448 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.1) | 0.52% | — | Mikado-themes EventlyAIPHPAI | 5/3/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Evently evently allows PHP Local File Inclusion.This issue affects Evently: from n/a through <= 1.7. | |
| Analizada | Media (5.8) | 0.43% | — | Cisco SnortCisco Cyber VisionCisco Secure Firewall Threat DefenseCisco Unified Threat Defense Snort Intrusion Prevention System Engine | 4/3/2026 | 18/8/2026 | Multiple Cisco products are affected by a vulnerability in the Snort 3 detection engine that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to restart, resulting in an interruption of packet inspection. This vulnerability is due to incomplete error checking when parsing remote… | |
| Analizada | Media (5.8) | 0.47% | — | Cisco SnortCisco Cyber VisionCisco Secure Firewall Threat DefenseCisco Unified Threat Defense Snort Intrusion Prevention System Engine | 4/3/2026 | 19/8/2026 | This vulnerability is due to incomplete error checking when parsing the Multicast DNS fields of the HTTP header. An attacker could exploit this vulnerability by sending crafted HTTP packets through an established connection to be parsed by Snort 3. A successful exploit could allow the attacker to cause a DoS condition… | |
| Analizada | Media (5.8) | 0.47% | — | Cisco SnortCisco Secure Firewall Threat DefenseCisco Unified Threat Defense Snort Intrusion Prevention System Engine | 4/3/2026 | 19/8/2026 | Multiple Cisco products are affected by a vulnerability in the Snort 3 Detection Engine that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to restart, resulting in an interruption of packet inspection. This vulnerability is due to an error in the JSTokenizer normalization logic… | |
| Analizada | Media (5.8) | 0.38% | — | Cisco SnortCisco Secure Firewall Threat DefenseCisco Unified Threat Defense Snort Intrusion Prevention System Engine | 4/3/2026 | 19/8/2026 | Multiple Cisco products are affected by a vulnerability in the Snort 3 Detection Engine that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to restart, resulting in an interruption of packet inspection. This vulnerability is due to an error in the binder module initialization… | |
| Analizada | Media (5.8) | 0.40% | — | Cisco SnortCisco Secure Firewall Threat DefenseCisco Unified Threat Defense Snort Intrusion Prevention System Engine | 4/3/2026 | 20/8/2026 | Multiple Cisco products are affected by vulnerabilities in the Snort 3 VBA feature that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to crash. These vulnerabilities are due to improper error checking when decompressing VBA data. An attacker could exploit these vulnerabilities… | |
| Analizada | Media (5.8) | 0.45% | — | Cisco SnortCisco Cyber VisionCisco Secure Firewall Threat DefenseCisco Unified Threat Defense Snort Intrusion Prevention System Engine | 4/3/2026 | 20/8/2026 | — | |
| Analizada | Media (5.8) | 0.45% | — | Cisco SnortCisco Cyber VisionCisco Secure Firewall Threat DefenseCisco Unified Threat Defense Snort Intrusion Prevention System Engine | 4/3/2026 | 20/8/2026 | This vulnerability is due to improper error checking when decompressing VBA data. An attacker could exploit this vulnerability by sending crafted VBA data to the Snort 3 Detection Engine on the targeted device. A successful exploit could allow the attacker to cause the Snort 3 Detection Engine to enter an infinite… | |
| Analizada | Media (5.8) | 0.43% | — | Cisco SnortCisco Cyber VisionCisco Secure Firewall Threat DefenseCisco Unified Threat Defense Snort Intrusion Prevention System Engine | 4/3/2026 | 20/8/2026 | Multiple Cisco products are affected by a vulnerability in the Snort 3 VBA feature that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to crash. This vulnerability is due to improper range checking when decompressing VBA data, which is user controlled. An attacker could exploit… | |
| Analizada | Media (5.8) | 0.51% | — | Cisco Cyber VisionCisco Secure Firewall Threat DefenseCisco Unified Threat Defense Snort Intrusion Prevention System EngineCisco Snort | 4/3/2026 | 1/9/2026 | Multiple Cisco products are affected by a vulnerability in the Snort 3 Detection Engine that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to restart, resulting in an interruption of packet inspection. This vulnerability is due to incomplete parsing of the SSL handshake ingress… | |
| Analizada | Media (5.2) | 0.14% | — | HP System Event Utility | 3/3/2026 | 17/6/2026 | — | |
| Aplazada | Media (5.4) | 0.19% | 💥 PoC | Puneethreddy Event Management SystemAI | 26/2/2026 | 17/6/2026 | A reflected Cross-Site Scripting (XSS) vulnerability exists in the register.php backend script of PuneethReddyHC Event Management System 1.0. The mobile POST parameter is improperly validated and echoed back in the HTTP response without sanitization, allowing an attacker to inject and execute arbitrary JavaScript code… | |
| Aplazada | Media (5.4) | 0.42% | — | Moderntribe THE Events CalendarAI | 25/2/2026 | 17/6/2026 | The The Events Calendar plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to an improper capability check on the 'can_edit' and 'can_delete' function in all versions up to, and including, 6.15.16. This makes it possible for authenticated attackers, with Contributor-level… | |
| Analizada | Alta (8.6) | 0.47% | — | Netikus Eventsentry | 24/2/2026 | 17/6/2026 | EventSentry versions prior to 6.0.1.20 contain an unverified password change vulnerability in the account management functionality of the Web Reports interface. The password change mechanism does not require validation of the current password before allowing a new password to be set. An attacker who gains temporary… | |
| Analizada | Baja (2.1) | 0.48% | — | Admerc Event Management System | 24/2/2026 | 17/6/2026 | A flaw has been found in itsourcecode Event Management System 1.0. The impacted element is an unknown function of the file /admin/navbar.php. Executing a manipulation of the argument page can lead to cross site scripting. The attack may be performed from remote. The exploit has been published and may be used. | |
| Analizada | Media (5.5) | 0.59% | — | Admerc Event Management System | 24/2/2026 | 17/6/2026 | A vulnerability was detected in itsourcecode Event Management System 1.0. The affected element is an unknown function of the file /admin/index.php. Performing a manipulation of the argument ID results in sql injection. The attack is possible to be carried out remotely. The exploit is now public and may be used. | |
| Aplazada | Alta (8.1) | 0.42% | — | Axiomthemes SeventreesAI | 20/2/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes SevenTrees seventrees allows PHP Local File Inclusion.This issue affects SevenTrees: from n/a through <=1.0.2. | |
| Aplazada | Alta (7.1) | 0.19% | — | Wpdiscover Timeline Event HistoryAI | 20/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdiscover Timeline Event History timeline-event-history allows Reflected XSS.This issue affects Timeline Event History: from n/a through <= 3.2. | |
| Aplazada | Media (5.3) | 0.25% | — | Metagauss EventprimeAI | 19/2/2026 | 17/6/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Metagauss EventPrime eventprime-event-calendar-management allows Retrieve Embedded Sensitive Data.This issue affects EventPrime: from n/a through <= 4.2.8.3. | |
| Aplazada | Crítica (9.8) | 0.39% | — | Magepeopleteam WpeventlyAI | 19/2/2026 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in magepeopleteam WpEvently mage-eventpress allows Object Injection.This issue affects WpEvently: from n/a through <= 5.1.1. | |
| Analizada | Media (5.5) | 0.59% | — | Admerc Event Management System | 19/2/2026 | 17/6/2026 | A vulnerability has been found in itsourcecode Event Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/manage_register.php. Such manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the… | |
| Analizada | Media (5.5) | 0.59% | — | Admerc Event Management System | 19/2/2026 | 17/6/2026 | A flaw has been found in itsourcecode Event Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/ajax.php?action=login of the component Admin Login. This manipulation of the argument Username causes sql injection. It is possible to initiate the attack remotely. The… | |
| Analizada | Media (5.5) | 0.59% | — | Admerc Event Management System | 19/2/2026 | 17/6/2026 | A vulnerability was detected in itsourcecode Event Management System 1.0. Affected is an unknown function of the file /admin/manage_booking.php. The manipulation of the argument ID results in sql injection. The attack may be performed from remote. The exploit is now public and may be used. | |
| Aplazada | Media (6.4) | 0.32% | — | XO Event CalendarAI | 19/2/2026 | 17/6/2026 | The XO Event Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'xo_event_field' shortcode in all versions up to, and including, 3.2.10 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,… | |
| Aplazada | Media (6.4) | 0.27% | — | Xylusthemes WP Event AggregatorAI | 18/2/2026 | 17/6/2026 | The WP Event Aggregator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wp_events' shortcode in all versions up to, and including, 1.8.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… |