Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▲ 36 respecto a la semana anterior
Críticas / altas1474▲ 366 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 464 respecto a la semana anterior
246 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.40% | — | Mdjm Event ManagementAIMobileeventsmanager Mobile Events ManagerAI | 13/9/2026 | 14/9/2026 | The MDJM Event Management WordPress plugin before 1.7.8.5 and the Mobile Events Manager WordPress plugin through 1.4.8.3 do not check a capability, a nonce or the type of the record before permanently deleting the post identified in a request to their playlist entry removal, allowing unauthenticated attackers to… | |
| Aplazada | Alta (7.1) | 0.25% | — | Fullworksplugins Quick Event ManagerAI | 3/9/2026 | 4/9/2026 | Unauthenticated Cross Site Scripting (XSS) in Quick Event Manager <= 9.17 versions. | |
| Aplazada | Alta (7.5) | 0.35% | — | Fullworksplugins Quick Event ManagerAI | 3/9/2026 | 5/9/2026 | Unauthenticated Broken Access Control in Quick Event Manager <= 9.17 versions. | |
| Aplazada | Crítica (9.4) | 0.64% | — | Joomlaeventmanager Joomla Event ManagerAI | 27/8/2026 | 28/8/2026 | Joomla Extension - joomlaeventmanager.net - Privileged remote code execution in Joomla Event Manager < 5.0.1 - The administrator source model allows to write dangerous file type incl. PHP, leading to remote code execution. | |
| Aplazada | Media (5.3) | 0.35% | — | Joomla Event ManagerAI | 27/8/2026 | 28/8/2026 | Joomla Extension - joomlaeventmanager.net - Attendee lists readable by any logged-in user in Joomla Event Manager < 5.0.1 - A non-manager can therefore read attendee names, usernames, registration dates and statuses for events they do not manage, including lists belonging to unpublished events. | |
| Aplazada | Media (5.1) | 0.39% | — | Joomlaeventmanager Joomla Event ManagerAI | 27/8/2026 | 28/8/2026 | Joomla Extension - joomlaeventmanager.net - Cross-user event and venue takeover through forged form fields in Joomla Event Manager < 5.0.1 - A registered user with edit-own rights (the eventowner=1 setting or core.edit.own) can POST another user's record id together with their own id as created_by and take over that… | |
| Aplazada | Media (6.9) | 0.41% | — | Ezcode Event ManagerAI | 27/8/2026 | 28/8/2026 | Joomla Extension - joomlaeventmanager.net - Unauthenticated article overwrite and force-publish in Joomla Event Manager < 5.0.1 - Any visitor holding their own session token can republish and overwrite an article associated with an event. | |
| Aplazada | Media (5.3) | 0.16% | — | Wpeventsmanager WP Events ManagerAI | 7/8/2026 | 26/8/2026 | The WP Events Manager WordPress plugin before 2.2.5 does not verify that an incoming payment notification originates from the site's configured merchant account, nor that the paid amount matches the booking total, allowing unauthenticated users to mark any booking as paid without a legitimate payment reaching the… | |
| Aplazada | Crítica (9.8) | 0.48% | — | Wpeventsmanager WP Events ManagerAI | 7/8/2026 | 26/8/2026 | The WP Events Manager WordPress plugin before 2.2.5 does not validate the requested quantity when registering for a paid event and computes the price from the attacker-controlled quantity, allowing any authenticated user to create a completed booking for a paid event without making a payment. | |
| Analizada | Alta (8.8) | 0.49% | — | IBM Qradar Security Information AND Event Manager | 5/8/2026 | 10/8/2026 | IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 could allow an authenticated privileged user to execute arbitrary commands with normal user privileges on the system due to improper validation of user supplied input. | |
| Analizada | Crítica (9.8) | 0.65% | — | IBM Qradar Security Information AND Event Manager | 5/8/2026 | 10/8/2026 | IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 has an XML External Entity (XXE) injection vulnerability. The vulnerability resides in the parseXmlPayload() function within the event processing pipeline ( q1labs_core.jar ). When at least one log source type is configured to use… | |
| Analizada | Alta (8.8) | 0.46% | — | IBM Qradar Security Information AND Event Manager | 27/5/2026 | 17/6/2026 | IBM QRadar 7.5.0 through 7.5.0 UP15 Interim Fix 002 could allow a privileged user to upload a malicious backup archive that could be restored and used to gain access to the underlying operating system. | |
| Analizada | Media (5.4) | 0.14% | — | IBM Qradar Security Information AND Event Manager | 19/3/2026 | 17/6/2026 | IBM QRadar SIEM 7.5.0 through 7.5.0 Update Package 14 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Analizada | Media (5.5) | 0.10% | — | IBM Qradar Security Information AND Event Manager | 19/3/2026 | 17/6/2026 | IBM QRadar SIEM 7.5.0 through 7.5.0 Update Package 14 stores potentially sensitive information in configuration files that could be read by a local user. | |
| Analizada | Media (5.4) | 0.14% | — | IBM Qradar Security Information AND Event Manager | 19/3/2026 | 17/6/2026 | IBM QRadar SIEM 7.5.0 through 7.5.0 Update Package 14 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality. | |
| Analizada | Media (5) | 0.18% | — | IBM Qradar Security Information AND Event Manager | 19/3/2026 | 17/6/2026 | IBM QRadar SIEM 7.5.0 through 7.5.0 Update Package 14 could allow an attacker with access to one tenant to access hostname data from another tenant's account. | |
| Aplazada | Media (4.3) | 0.13% | — | Wpeventsmanager Events ManagerAI | 12/12/2025 | 17/6/2026 | The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 7.2.2.2. This is due to missing or incorrect nonce validation on the 'location_delete' action. This makes it possible for unauthenticated attackers to… | |
| Analizada | Baja (2.7) | 0.29% | — | IBM Qradar Security Information AND Event Manager | 9/12/2025 | 1/10/2026 | IBM QRadar SIEM 7.5 - 7.5.0 UP14 IF01 is affected by an information disclosure vulnerability involving exposure of directory information. IBM has addressed this vulnerability in the latest update. | |
| Analizada | Media (6.5) | 0.24% | — | IBM Qradar Security Information AND Event Manager | 12/11/2025 | 17/6/2026 | IBM QRadar SIEM 7.5 through 7.5.0 UP14 stores user credentials in configuration files in source control which can be read by an authenticated user. | |
| Analizada | Media (5.4) | 0.18% | — | IBM Qradar Security Information AND Event Manager | 27/10/2025 | 17/6/2026 | IBM QRadar SIEM 7.5 through 7.5.0 Update Pack 13 Independent Fix 02 is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted… | |
| Analizada | Media (5.4) | 0.18% | — | IBM Qradar Security Information AND Event Manager | 27/10/2025 | 17/6/2026 | IBM QRadar SIEM 7.5 through 7.5.0 Update Pack 13 Independent Fix 02 is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted… | |
| Analizada | Alta (7.8) | 0.13% | — | IBM Qradar Security Information AND Event Manager | 27/10/2025 | 17/6/2026 | IBM QRadar SIEM 7.5 through 7.5.0 Update Pack 13 Independent Fix 02 is vulnerable to privilege escalation due to improper privilege assignment to an update script. | |
| Analizada | Baja (2.3) | 0.12% | — | IBM Qradar Security Information AND Event Manager | 14/9/2025 | 17/6/2026 | IBM QRadar SIEM 7.5 through 7.5 Update Pack 13 Independent Fix 01 could allow a local privileged user to perform unauthorized actions on configuration files due to improper permission assignment. | |
| Analizada | Media (5.4) | 0.18% | — | IBM Qradar Incident ForensicsIBM Qradar Security Information AND Event Manager | 22/8/2025 | 17/6/2026 | IBM QRadar SIEM 7.5 through 7.5.0 Dashboard is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Analizada | Alta (7.8) | 0.15% | — | IBM Qradar Incident ForensicsIBM Qradar Security Information AND Event Manager | 22/8/2025 | 17/6/2026 | IBM QRadar SIEM 7.5 through 7.5.0 UP13 could allow an authenticated user to escalate their privileges via a misconfigured cronjob due to execution with unnecessary privileges. |