Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2722▼ 518 respecto a la semana anterior
Críticas / altas1296▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
1448 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (2.4) | 0.21% | — | Hcltech Intelliops Event Management | 25/7/2025 | 17/6/2026 | HCL IEM is affected by a cookie attribute not set vulnerability due to inconsistency of certain security-related configurations which could increase exposure to potential vulnerabilities. | |
| Analizada | Media (4.8) | 0.14% | — | Hcltech Intelliops Event Management | 25/7/2025 | 17/6/2026 | HCL IEM is affected by a password in cleartext vulnerability. Sensitive information is transmitted without adequate protection, potentially exposing it to unauthorized access during transit. | |
| Analizada | Media (5.7) | 0.21% | — | Hcltech Intelliops Event Management | 25/7/2025 | 17/6/2026 | HCL IEM is affected by a concurrent login vulnerability. The application allows multiple concurrent sessions using the same user credentials, which may introduce security risks. | |
| Analizada | Media (4.9) | 0.18% | — | Hcltech Intelliops Event Management | 25/7/2025 | 17/6/2026 | HCL IEM is affected by an authorization token sent in cookie vulnerability. A token used for authentication and authorization is being handled in a manner that may increase its exposure to security risks. | |
| Analizada | Media (5.9) | 0.21% | — | Hcltech Intelliops Event Management | 25/7/2025 | 17/6/2026 | HCL IEM is affected by an improper invalidation of access or JWT token vulnerability. A token was not invalidated which may allow attackers to access sensitive data without authorization. | |
| Analizada | Media (6.1) | 0.28% | — | Wp-eventmanager WP Event Manager | 16/7/2025 | 17/6/2026 | The WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘organizer_name' parameter in all versions up to, and including, 3.1.50 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Analizada | Media (4.8) | 0.22% | — | Wp-eventmanager WP Event Manager | 16/7/2025 | 17/6/2026 | The WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘tag-name’ parameter in all versions up to, and including, 3.1.49 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Analizada | Media (5.4) | 0.19% | — | IBM Qradar Security Information AND Event Manager | 15/7/2025 | 17/6/2026 | IBM QRadar SIEM 7.5 - 7.5.0 UP12 IF02 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Analizada | Crítica (9.8) | 0.38% | — | Webnus Modern Events Calendar Lite | 12/7/2025 | 17/6/2026 | The Modern Events Calendar Lite plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter of the 'wp_ajax_mec_load_single_page' AJAX action in all versions up to, and including, 6.3.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL… | |
| Analizada | Media (5.4) | 0.25% | — | Pixelite Events Manager | 9/7/2025 | 17/6/2026 | The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including, 7.0.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Analizada | Media (6.1) | 0.28% | — | Pixelite Events Manager | 9/7/2025 | 17/6/2026 | The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘calendar_header’ parameter in all versions up to, and including, 7.0.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated… | |
| Analizada | Alta (7.5) | 67% | 💥 Exploit | Pixelite Events Manager | 9/7/2025 | 17/6/2026 | The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ parameter in all versions up to, and including, 7.0.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.… | |
| Aplazada | Media (6.3) | 0.27% | — | Myeventon EventonAI | 4/7/2025 | 17/6/2026 | Missing Authorization vulnerability in ashanjay EventON eventon allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects EventON: from n/a through <= 4.9.9. | |
| Analizada | Media (5.6) | 0.25% | — | JLY Campaignevents | 3/7/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - CampaignEvents Extension allows Cross-Site Scripting (XSS).This issue affects Mediawiki - CampaignEvents Extension: from 1.43.X before 1.43.2. | |
| Modificada | Media (6.1) | 0.26% | — | Themewinter Eventin | 27/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Arraytics Eventin wp-event-solution allows Reflected XSS.This issue affects Eventin: from n/a through <= 4.0.28. | |
| Modificada | Media (5.4) | 0.24% | — | Emarketdesign Event Rsvp AND Simple Event Management | 26/6/2025 | 17/6/2026 | The Event RSVP and Simple Event Management Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'emd_mb_meta' shortcode in all versions up to, and including, 4.1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Aplazada | Media (4.3) | 0.28% | — | Wpeventmanager WP User Profile AvatarAI | 20/6/2025 | 17/6/2026 | Missing Authorization vulnerability in WP Event Manager WP User Profile Avatar wp-user-profile-avatar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP User Profile Avatar: from n/a through <= 1.0.6. | |
| Analizada | Media (6.2) | 0.17% | — | IBM Qradar Security Information AND Event Manager | 19/6/2025 | 17/6/2026 | IBM QRadar SIEM 7.5 through 7.5.0 Update Package 12 stores potentially sensitive information in log files that could be read by a local user. | |
| Analizada | Alta (7.1) | 0.48% | — | IBM Qradar Security Information AND Event Manager | 19/6/2025 | 17/6/2026 | IBM QRadar SIEM 7.5 through 7.5.0 Update Package 12 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. | |
| Analizada | Crítica (9.1) | 0.55% | — | IBM Qradar Security Information AND Event Manager | 19/6/2025 | 17/6/2026 | IBM QRadar SIEM 7.5 through 7.5.0 Update Package 12 could allow a privileged user to modify configuration files that would allow the upload of a malicious autoupdate file to execute arbitrary commands. | |
| Aplazada | Crítica (10) | 0.49% | — | Ovatheme Ova-events-managerAI | 17/6/2025 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in ovatheme Ovatheme Events Manager ova-events-manager allows Using Malicious Files.This issue affects Ovatheme Events Manager: from n/a through <= 1.8.4. | |
| Aplazada | Crítica (9.3) | 0.32% | — | JeventsAIJoomlaAI | 12/6/2025 | 17/6/2026 | A SQL injection vulnerability in JEvents component before 3.6.88 and 3.6.82.1 for Joomla was discovered. The extension is vulnerable to SQL injection via publicly accessible actions to list events by date ranges. | |
| Analizada | Media (5.4) | 0.26% | — | Stellarwp THE Events Calendar | 11/6/2025 | 17/6/2026 | The The Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data-date-*’ parameters in all versions up to, and including, 6.13.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and… | |
| Aplazada | Alta (8.1) | 0.64% | — | Wp-eventmanager WP Event ManagerAI | 9/6/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WP Event Manager WP Event Manager wp-event-manager allows PHP Local File Inclusion.This issue affects WP Event Manager: from n/a through <= 3.1.51. | |
| Analizada | Media (5.4) | 0.26% | — | Mage-people Event Manager AND Tickets Selling FOR Woocommerce | 7/6/2025 | 17/6/2026 | The WpEvently plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in all versions up to, and including, 4.4.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject… |