Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2976▼ 107 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

246 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)1.2%💥 ExploitFullworksplugins Quick Event Manager20/1/202317/6/2026
The Quick Event Manager WordPress Plugin, version < 9.7.5, is affected by a reflected cross-site scripting vulnerability in the 'category' parameter of its 'qem_ajax_calendar' action.
ModificadaAlta (7.5)0.31%—IBM Qradar Security Information AND Event Manager17/1/202317/6/2026
IBM QRadar SIEM 7.4 and 7.5copies certificate key files used for SSL/TLS in the QRadar web user interface to managed hosts in the deployment that do not require that key. IBM X-Force ID: 244356.
ModificadaMedia (5.3)0.70%—Solarwinds Security Event Manager23/11/202217/6/2026
Insecure method vulnerability in which allowed HTTP methods are disclosed. E.g., OPTIONS, DELETE, TRACE, and PUT
ModificadaMedia (6.1)0.55%—Solarwinds Security Event Manager23/11/202217/6/2026
This vulnerability occurs when a web server fails to correctly process the Content-Length of POST requests. This can lead to HTTP request smuggling or XSS.
ModificadaMedia (5.3)0.70%—Solarwinds Security Event Manager23/11/202217/6/2026
This vulnerability discloses build and services versions in the server response header.
ModificadaMedia (5.5)0.20%—IBM Qradar Security Information AND Event Manager7/10/202217/6/2026
IBM QRadar SIEM 7.4 and 7.5 could disclose sensitive information via a local service to a privileged user. IBM X-Force ID: 227366.
ModificadaAlta (7.5)0.85%—IBM Qradar Security Information AND Event Manager7/10/202217/6/2026
IBM QRadar SIEM 7.4 and 7.5 data node rebalancing does not function correctly when using encrypted hosts which could result in information disclosure. IBM X-Force ID: 225889.
ModificadaAlta (8.8)1.3%—Mobileeventsmanager Mobile Events Manager16/9/202217/6/2026
The Mobile Events Manager WordPress plugin before 1.4.8 does not properly escape the Enquiry source field when exporting events, or the Paid for field when exporting transactions as CSV, leading to a CSV injection vulnerability.
ModificadaAlta (7.8)0.19%—IBM Qradar Security Information AND Event Manager28/7/202217/6/2026
IBM QRadar SIEM 7.3, 7.4, and 7.5 is vulnerable to local privilege escalation if this could be combined with other unknown vulnerabilities then privilege escalation could be performed. IBM X-Force ID: 216111.
ModificadaMedia (5.5)0.18%—IBM Qradar Security Information AND Event Manager20/7/202217/6/2026
IBM QRadar SIEM 7.3, 7.4, and 7.5 could allow a local user to obtain sensitive information from the TLS key file due to incorrect file permissions. IBM X-Force ID: 223597.
ModificadaMedia (4.9)0.86%—IBM Qradar Security Information AND Event Manager20/7/202217/6/2026
IBM QRadar SIEM 7.3, 7.4, and 7.5 could disclose highly sensitive information to a privileged user. IBM X-Force ID: 210893.
ModificadaAlta (7.5)0.51%—IBM Qradar Security Information AND Event Manager20/7/202217/6/2026
IBM QRadar SIEM 7.3, 7.4, and 7.5 does not preform proper certificate validation for some inter-host communications. IBM X-Force ID: 202015.
ModificadaMedia (5.3)0.99%—IBM Qradar Security Information AND Event Manager12/7/202217/6/2026
IBM QRadar SIEM 7.3, 7.4, and 7.5 may be vulnerable to partial denial of service attack, resulting in some protocols not listening to specified ports. IBM X-Force ID: 214028.
ModificadaMedia (6.1)0.85%—Wp-eventmanager WP Event Manager11/7/202217/6/2026
The WP Event Manager WordPress plugin before 3.1.28 does not sanitise and escape its search before outputting it back in an attribute on the event dashboard, leading to a Reflected Cross-Site Scripting
ModificadaMedia (4.8)0.47%—IBM Qradar Security Information AND Event Manager11/5/202217/6/2026
IBM QRadar SIEM 7.3 and 7.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 218367.
ModificadaMedia (4.8)1.8%—IBM Qradar Security Information AND Event Manager27/4/202217/6/2026
IBM QRadar 7.3, 7.4, and 7.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 220041.
ModificadaMedia (5.3)0.84%—IBM Qradar Security Information AND Event Manager27/4/202217/6/2026
IBM QRadar SIEM 7.3, 7.4, and 7.5 stores potentially sensitive information in log files that could be read by an user with access to creating domains. IBM X-Force ID: 211037.
ModificadaAlta (7.5)1.1%—IBM Qradar Security Information AND Event Manager27/4/202217/6/2026
IBM QRadar SIEM 7.3, 7.4, and 7.5 in some senarios may reveal authorized service tokens to other QRadar users. IBM X-Force ID: 210021
ModificadaAlta (7.5)1.2%—IBM Qradar Security Information AND Event Manager27/4/202217/6/2026
IBM QRadar 7.3, 7.4, and 7.5 could allow a malicious actor to impersonate an actor due to key exchange without entity authentication. IBM X-Force ID: 208756.
ModificadaMedia (4.3)0.70%—IBM Qradar Security Information AND Event Manager27/4/202217/6/2026
IBM QRadar SIEM 7.3, 7.4, and 7.5 allows for users to access information across tenant and domain boundaries in some situations. IBM X-Force ID: 208397.
ModificadaCrítica (9.8)0.89%—IBM Qradar Security Information AND Event Manager27/4/202217/6/2026
IBM QRadar SIEM 7.3, 7.4, and 7.5 in some situations may not automatically log users out after they exceede their idle timeout. IBM X-Force ID: 208341.
ModificadaMedia (4.3)0.65%—IBM Qradar Security Information AND Event Manager27/4/202217/6/2026
IBM QRadar SIEM 7.3, 7.4, and 7.5 could allow an authenticated user to obtain sensitive information from another user's dashboard providing the dashboard ID of that user. IBM X-Force ID: 203030.
ModificadaAlta (8.8)1.5%—Mage-people Event Manager AND Tickets Selling FOR Woocommerce14/3/202217/6/2026
The Event Manager and Tickets Selling for WooCommerce WordPress plugin before 3.5.8 does not validate and escape the post_author_gutenberg parameter before using it in a SQL statement when creating/editing events, which could allow users with a role as low as contributor to perform SQL Injection attacks
ModificadaMedia (4.8)0.60%—Wp-eventmanager WP Event Manager7/3/202217/6/2026
The WP Event Manager WordPress plugin before 3.1.23 does not escape some of its Field Editor settings when outputting them, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
ModificadaMedia (4.8)0.65%—Mobileeventsmanager Mobile Events Manager24/1/202217/6/2026
The Mobile Events Manager WordPress plugin before 1.4.4 does not sanitise and escape various of its settings, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
Orbitaley — Vulnerabilidades