Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2712▼ 359 respecto a la semana anterior
Críticas / altas1261▼ 231 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)213▼ 109 respecto a la semana anterior
1451 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.22% | — | IBM Qradar Security Information AND Event Manager | 14/10/2023 | 17/6/2026 | IBM QRadar SIEM 7.5.0 utiliza algoritmos criptográficos más débiles de lo esperado que podrían permitir a un atacante descifrar información altamente confidencial. IBM X-Force ID: 254138 | |
| Modificada | Crítica (9.8) | 1.7% | — | Fsevents Project Fsevents | 6/10/2023 | 17/6/2026 | fsevents anterior a 1.2.11 depende de la URL https://fsevents-binaries.s3-us-west-2.amazonaws.com, lo que podría permitir a un adversario ejecutar código arbitrario si algún proyecto JavaScript (que depende de fsevents) distribuye código que se obtuvo de esa URL en un momento en que estaba controlada por un adversario. | |
| Modificada | Media (6.5) | 0.22% | — | Multidots Fraud Prevention FOR Woocommerce | 3/10/2023 | 17/6/2026 | Vulnerabilidad de Cross-Site Request Forgery (CSRF) en el complemento Dotstore Fraud Prevention para Woocommerce en versiones <= 2.1.5. | |
| Modificada | Alta (7.8) | 0.17% | — | Dell Common Event Enabler | 29/9/2023 | 17/6/2026 | Dell Common Event Enabler 8.9.8.2 para Windows y versiones anteriores contiene una vulnerabilidad de control de acceso inadecuado. Un usuario malintencionado local con pocos privilegios podría explotar esta vulnerabilidad para obtener privilegios elevados. | |
| Modificada | Media (5.4) | 0.65% | — | Webd Options FOR Twenty Seventeen | 27/9/2023 | 17/6/2026 | El complemento Opciones para Twenty Seventeen para WordPress es vulnerable a Stored Cross-Site Scripting almacenado a través del código corto de 'social-links' en versiones hasta la 2.5.0 inclusive debido a una sanitización de entrada insuficiente y a un escape de salida en los atributos proporcionados por el usuario.… | |
| Modificada | Media (4.8) | 0.60% | — | Wp-eventmanager WP Event Manager | 27/9/2023 | 17/6/2026 | El complemento WP Event Manager – Events Calendar, Registrations, Sell Tickets con WooCommerce para WordPress es vulnerable a Cross-Site Scripting almacenado a través de la configuración de administrador en versiones hasta la 3.1.37.1 inclusive debido a una sanitización de entrada y un escape de salida insuficientes.… | |
| Modificada | Alta (7.2) | 1.6% | — | Miniorange Prevent Files / Folders Access | 25/9/2023 | 17/6/2026 | El complemento Impedir el acceso a archivos/carpetas de WordPress anteriores a 2.5.2 no valida los archivos que se cargarán, lo que podría permitir a los atacantes cargar archivos arbitrarios como PHP en el servidor. | |
| Modificada | Crítica (9.8) | 1.8% | — | Gevent | 25/9/2023 | 17/6/2026 | Un problema en Gevent anterior a la versión 23.9.0 permite a un atacante remoto escalar privilegios mediante un script manipulado al componente WSGIServer. | |
| Modificada | Alta (7.1) | 0.15% | — | Trellix Data Loss Prevention | 14/9/2023 | 17/6/2026 | Existe una vulnerabilidad de escalada de privilegios en Trellix Windows DLP endpoint para Windows de la que se puede abusar para eliminar cualquier archivo/carpeta para el cual el usuario no tiene permiso. | |
| Modificada | Alta (8.1) | 2.4% | — | Zohocorp Manageengine Ad360Zohocorp Manageengine Adaudit PlusZohocorp Manageengine Admanager PlusZohocorp Manageengine Assetexplorer+13 | 28/8/2023 | 17/6/2026 | Zoho ManageEngine Active Directory 360 versiones 4315 e inferiores, ADAudit Plus 7202 e inferiores, ADManager Plus 7200 e inferiores, Asset Explorer 6993 e inferiores y 7xxx 7002 e inferiores, Cloud Security Plus 4161 e inferiores, Data Security Plus 6110 e inferiores, Eventlog Analyzer 12301 y siguientes, Exchange… | |
| Modificada | Crítica (9.8) | 0.89% | — | Phpjabbers Event Booking Calendar | 28/8/2023 | 17/6/2026 | User enumeration is found in PHPJabbers Event Booking Calendar v4.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users. | |
| Modificada | Crítica (9.8) | 1.5% | — | Gabrieleventuri Pandasai | 21/8/2023 | 17/6/2026 | An issue in Gaberiele Venturi pandasai v.0.8.0 and before allows a remote attacker to execute arbitrary code via a crafted request to the prompt function. | |
| Modificada | Crítica (9.8) | 1.4% | — | Gabrieleventuri Pandasai | 15/8/2023 | 17/6/2026 | Un problema en pandas-ai v.0.9.1 y anteriores permite a un atacante remoto ejecutar código arbitrario a través de la función _is_jailbreak. | |
| Modificada | Alta (8.8) | 0.88% | — | Istrong Four Mountain Torrent Disaster Prevention, Control Monitoring AND Early Warning System | 20/7/2023 | 17/6/2026 | A vulnerability, which was classified as critical, was found in Gen Technology Four Mountain Torrent Disaster Prevention and Control of Monitoring and Early Warning System up to 20230712. This affects an unknown part of the file /Duty/AjaxHandle/UploadFloodPlanFileUpdate.ashx. The manipulation of the argument Filedata… | |
| Modificada | Media (5.4) | 0.62% | — | Tiva Events Calendar Project Tiva Events Calendar | 20/7/2023 | 17/6/2026 | A vulnerability classified as problematic was found in Codecanyon Tiva Events Calender 1.4. This vulnerability affects unknown code. The manipulation of the argument name leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-235054 is the… | |
| Modificada | Media (5.4) | 0.33% | — | Mage-people Event Manager AND Tickets Selling FOR Woocommerce | 18/7/2023 | 17/6/2026 | Auth. (editor+) Stored Cross-Site Scripting (XSS) vulnerability in MagePeople Team Event Manager and Tickets Selling Plugin for WooCommerce plugin <= 3.9.5 versions. | |
| Analizada | Crítica (9.8) | 1.3% | — | Apache Eventmesh-connector-rabbitmq | 17/7/2023 | 17/6/2026 | CWE-502 Deserialization of Untrusted Data at the rabbitmq-connector plugin module in Apache EventMesh (incubating) V1.7.0\V1.8.0 on windows\linux\mac os e.g. platforms allows attackers to send controlled message and remote code execute via rabbitmq messages. Users can use the code under the master branch in project… | |
| Modificada | Crítica (9.8) | 0.96% | — | Istrong Mountain Flood Disaster Prevention Monitoring AND Early Warning System | 11/7/2023 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in Suncreate Mountain Flood Disaster Prevention Monitoring and Early Warning System up to 20230706. This issue affects some unknown processing of the file /Duty/AjaxHandle/UpLoadFloodPlanFile.ashx of the component UpLoadFloodPlanFile. The manipulation… | |
| Modificada | Crítica (9.8) | 0.96% | — | Istrong Mountain Flood Disaster Prevention Monitoring AND Early Warning System | 11/7/2023 | 17/6/2026 | A vulnerability classified as critical was found in Suncreate Mountain Flood Disaster Prevention Monitoring and Early Warning System up to 20230706. This vulnerability affects unknown code of the file /Duty/AjaxHandle/Write/UploadFile.ashx of the component Duty Write-UploadFile. The manipulation of the argument… | |
| Modificada | Crítica (9.8) | 0.91% | — | Istrong Mountain Flood Disaster Prevention Monitoring AND Early Warning System | 11/7/2023 | 17/6/2026 | A vulnerability was found in Suncreate Mountain Flood Disaster Prevention Monitoring and Early Warning System up to 20230704. It has been rated as critical. Affected by this issue is some unknown functionality of the file /Duty/AjaxHandle/UploadHandler.ashx of the component Duty Module. The manipulation of the… | |
| Modificada | Media (5.4) | 0.51% | — | Gzscripts Event Booking Calendar | 10/7/2023 | 17/6/2026 | A vulnerability classified as problematic has been found in GZ Scripts Event Booking Calendar 1.8. Affected is an unknown function of the file /load.php. The manipulation of the argument first_name/second_name/phone/address_1/country leads to cross site scripting. It is possible to launch the attack remotely. The… | |
| Modificada | Media (5.3) | 7.5% | 💥 Exploit | Myeventon Eventon | 10/7/2023 | 17/6/2026 | The EventON WordPress plugin before 2.1.2 does not validate that the event_id parameter in its eventon_ics_download ajax action is a valid Event, allowing unauthenticated visitors to access any Post (including unpublished or protected posts) content via the ics export functionality by providing the numeric id of the… | |
| Modificada | Media (5.3) | 43% | 💥 Exploit | Myeventon Eventon | 10/7/2023 | 17/6/2026 | The EventON WordPress plugin before 2.1.2 lacks authentication and authorization in its eventon_ics_download ajax action, allowing unauthenticated visitors to access private and password protected Events by guessing their numeric id. | |
| Modificada | Media (4.3) | 0.39% | — | Eventespresso Event Espresso 4 Decaf | 1/7/2023 | 17/6/2026 | El plugin Event Espresso 4 Decaf para WordPress es vulnerable a ataques de tipo Cross-Site Request Forgery (CSRF) en versiones hasta la 4.10.11 inclusive. Esto es debido a la falta o incorrecta validación nonce en la función "ajaxHandler()". Esto hace posible que los atacantes no autenticados puedan entrar en las… | |
| Modificada | Media (6.1) | 0.39% | — | Simplephpscripts Event Script | 30/6/2023 | 17/6/2026 | A vulnerability was found in SimplePHPscripts Event Script 2.1 and classified as problematic. Affected by this issue is some unknown functionality of the file preview.php of the component URL Parameter Handler. The manipulation leads to cross site scripting. The attack may be launched remotely. It is recommended to… |