Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2976▼ 107 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
246 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 1.2% | 💥 Exploit | Fullworksplugins Quick Event Manager | 20/1/2023 | 17/6/2026 | The Quick Event Manager WordPress Plugin, version < 9.7.5, is affected by a reflected cross-site scripting vulnerability in the 'category' parameter of its 'qem_ajax_calendar' action. | |
| Modificada | Alta (7.5) | 0.31% | — | IBM Qradar Security Information AND Event Manager | 17/1/2023 | 17/6/2026 | IBM QRadar SIEM 7.4 and 7.5copies certificate key files used for SSL/TLS in the QRadar web user interface to managed hosts in the deployment that do not require that key. IBM X-Force ID: 244356. | |
| Modificada | Media (5.3) | 0.70% | — | Solarwinds Security Event Manager | 23/11/2022 | 17/6/2026 | Insecure method vulnerability in which allowed HTTP methods are disclosed. E.g., OPTIONS, DELETE, TRACE, and PUT | |
| Modificada | Media (6.1) | 0.55% | — | Solarwinds Security Event Manager | 23/11/2022 | 17/6/2026 | This vulnerability occurs when a web server fails to correctly process the Content-Length of POST requests. This can lead to HTTP request smuggling or XSS. | |
| Modificada | Media (5.3) | 0.70% | — | Solarwinds Security Event Manager | 23/11/2022 | 17/6/2026 | This vulnerability discloses build and services versions in the server response header. | |
| Modificada | Media (5.5) | 0.20% | — | IBM Qradar Security Information AND Event Manager | 7/10/2022 | 17/6/2026 | IBM QRadar SIEM 7.4 and 7.5 could disclose sensitive information via a local service to a privileged user. IBM X-Force ID: 227366. | |
| Modificada | Alta (7.5) | 0.85% | — | IBM Qradar Security Information AND Event Manager | 7/10/2022 | 17/6/2026 | IBM QRadar SIEM 7.4 and 7.5 data node rebalancing does not function correctly when using encrypted hosts which could result in information disclosure. IBM X-Force ID: 225889. | |
| Modificada | Alta (8.8) | 1.3% | — | Mobileeventsmanager Mobile Events Manager | 16/9/2022 | 17/6/2026 | The Mobile Events Manager WordPress plugin before 1.4.8 does not properly escape the Enquiry source field when exporting events, or the Paid for field when exporting transactions as CSV, leading to a CSV injection vulnerability. | |
| Modificada | Alta (7.8) | 0.19% | — | IBM Qradar Security Information AND Event Manager | 28/7/2022 | 17/6/2026 | IBM QRadar SIEM 7.3, 7.4, and 7.5 is vulnerable to local privilege escalation if this could be combined with other unknown vulnerabilities then privilege escalation could be performed. IBM X-Force ID: 216111. | |
| Modificada | Media (5.5) | 0.18% | — | IBM Qradar Security Information AND Event Manager | 20/7/2022 | 17/6/2026 | IBM QRadar SIEM 7.3, 7.4, and 7.5 could allow a local user to obtain sensitive information from the TLS key file due to incorrect file permissions. IBM X-Force ID: 223597. | |
| Modificada | Media (4.9) | 0.86% | — | IBM Qradar Security Information AND Event Manager | 20/7/2022 | 17/6/2026 | IBM QRadar SIEM 7.3, 7.4, and 7.5 could disclose highly sensitive information to a privileged user. IBM X-Force ID: 210893. | |
| Modificada | Alta (7.5) | 0.51% | — | IBM Qradar Security Information AND Event Manager | 20/7/2022 | 17/6/2026 | IBM QRadar SIEM 7.3, 7.4, and 7.5 does not preform proper certificate validation for some inter-host communications. IBM X-Force ID: 202015. | |
| Modificada | Media (5.3) | 0.99% | — | IBM Qradar Security Information AND Event Manager | 12/7/2022 | 17/6/2026 | IBM QRadar SIEM 7.3, 7.4, and 7.5 may be vulnerable to partial denial of service attack, resulting in some protocols not listening to specified ports. IBM X-Force ID: 214028. | |
| Modificada | Media (6.1) | 0.85% | — | Wp-eventmanager WP Event Manager | 11/7/2022 | 17/6/2026 | The WP Event Manager WordPress plugin before 3.1.28 does not sanitise and escape its search before outputting it back in an attribute on the event dashboard, leading to a Reflected Cross-Site Scripting | |
| Modificada | Media (4.8) | 0.47% | — | IBM Qradar Security Information AND Event Manager | 11/5/2022 | 17/6/2026 | IBM QRadar SIEM 7.3 and 7.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 218367. | |
| Modificada | Media (4.8) | 1.8% | — | IBM Qradar Security Information AND Event Manager | 27/4/2022 | 17/6/2026 | IBM QRadar 7.3, 7.4, and 7.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 220041. | |
| Modificada | Media (5.3) | 0.84% | — | IBM Qradar Security Information AND Event Manager | 27/4/2022 | 17/6/2026 | IBM QRadar SIEM 7.3, 7.4, and 7.5 stores potentially sensitive information in log files that could be read by an user with access to creating domains. IBM X-Force ID: 211037. | |
| Modificada | Alta (7.5) | 1.1% | — | IBM Qradar Security Information AND Event Manager | 27/4/2022 | 17/6/2026 | IBM QRadar SIEM 7.3, 7.4, and 7.5 in some senarios may reveal authorized service tokens to other QRadar users. IBM X-Force ID: 210021 | |
| Modificada | Alta (7.5) | 1.2% | — | IBM Qradar Security Information AND Event Manager | 27/4/2022 | 17/6/2026 | IBM QRadar 7.3, 7.4, and 7.5 could allow a malicious actor to impersonate an actor due to key exchange without entity authentication. IBM X-Force ID: 208756. | |
| Modificada | Media (4.3) | 0.70% | — | IBM Qradar Security Information AND Event Manager | 27/4/2022 | 17/6/2026 | IBM QRadar SIEM 7.3, 7.4, and 7.5 allows for users to access information across tenant and domain boundaries in some situations. IBM X-Force ID: 208397. | |
| Modificada | Crítica (9.8) | 0.89% | — | IBM Qradar Security Information AND Event Manager | 27/4/2022 | 17/6/2026 | IBM QRadar SIEM 7.3, 7.4, and 7.5 in some situations may not automatically log users out after they exceede their idle timeout. IBM X-Force ID: 208341. | |
| Modificada | Media (4.3) | 0.65% | — | IBM Qradar Security Information AND Event Manager | 27/4/2022 | 17/6/2026 | IBM QRadar SIEM 7.3, 7.4, and 7.5 could allow an authenticated user to obtain sensitive information from another user's dashboard providing the dashboard ID of that user. IBM X-Force ID: 203030. | |
| Modificada | Alta (8.8) | 1.5% | — | Mage-people Event Manager AND Tickets Selling FOR Woocommerce | 14/3/2022 | 17/6/2026 | The Event Manager and Tickets Selling for WooCommerce WordPress plugin before 3.5.8 does not validate and escape the post_author_gutenberg parameter before using it in a SQL statement when creating/editing events, which could allow users with a role as low as contributor to perform SQL Injection attacks | |
| Modificada | Media (4.8) | 0.60% | — | Wp-eventmanager WP Event Manager | 7/3/2022 | 17/6/2026 | The WP Event Manager WordPress plugin before 3.1.23 does not escape some of its Field Editor settings when outputting them, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed | |
| Modificada | Media (4.8) | 0.65% | — | Mobileeventsmanager Mobile Events Manager | 24/1/2022 | 17/6/2026 | The Mobile Events Manager WordPress plugin before 1.4.4 does not sanitise and escape various of its settings, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed |