Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

1447 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.5)0.21%—WP Event SolutionAI6/10/20266/10/2026
Unauthenticated Broken Access Control in WP Event Solution <= 4.1.25 versions.
AplazadaAlta (8.8)0.36%—Presstigers Simple Event PlannerAI5/10/20266/10/2026
Deserialization of Untrusted Data vulnerability in PressTigers Simple Event Planner simple-event-planner allows Object Injection.This issue affects Simple Event Planner: from n/a through 1.5.7.
Pendiente de análisisMedia (6.3)0.32%—Svenbluege Event GalleryAI5/10/20266/10/2026
Joomla Extension - svenbluege.de - Server-side request forgery in the Google Photos picker in Event Gallery extension < 6.6.0 - The Google Photos picker of the back-end upload page fetches the thumbnails of the picked images through the server, with the OAuth access token of the Google Photos account. The task took…
Pendiente de análisisMedia (5.3)0.15%—Svenbluege.de Event GalleryAI5/10/20266/10/2026
Joomla Extension - svenbluege.de - Cross-site scripting and open redirect on the share mini page in Event Gallery extension < 6.6.0 - The page a shared image link opens (the share mini page of the front end) can link the article the image was shared from when the option "Share article links" is on. It took the address…
Pendiente de análisisMedia (5.1)0.15%—Svenbluege Event GalleryAI5/10/20266/10/2026
Joomla Extension - svenbluege.de - Cross-site request forgery of list tasks of the backend in Event Gallery extension < 6.6.0 - Eight tasks which the buttons of the back-end lists call did not check the form token: setting the default payment method, shipping method, image type set, order status and watermark; putting…
AplazadaMedia (5.3)0.20%—Arraytics WP Event SolutionAI5/10/20266/10/2026
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Arraytics WP Event Solution wp-event-solution allows Retrieve Embedded Sensitive Data.This issue affects WP Event Solution: from n/a through 4.1.25.
AplazadaMedia (5.3)0.18%—Arraytics WP Event SolutionAI5/10/20266/10/2026
Missing Authorization vulnerability in Arraytics WP Event Solution wp-event-solution allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Event Solution: from n/a through 4.1.25.
AplazadaMedia (5.3)0.20%—Pixelite Events ManagerAI5/10/20266/10/2026
Insertion of Sensitive Information Into Sent Data vulnerability in Pixelite Events Manager events-manager allows Retrieve Embedded Sensitive Data.This issue affects Events Manager: from n/a through 7.4.5.
AplazadaMedia (4.3)0.17%—Stellarwp Event TicketsAI5/10/20266/10/2026
Missing Authorization vulnerability in Liquid Web / StellarWP Event Tickets event-tickets allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Event Tickets: from n/a through 5.30.0.
AplazadaMedia (6.5)0.28%—Eventtickets Event Tickets AND RegistrationAI2/10/20262/10/2026
The Event Tickets and Registration plugin for WordPress is vulnerable to generic SQL Injection via the 'orderby' parameter in all versions up to, and including, 5.29.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for…
AplazadaMedia (6.5)0.22%—Theeventscalendar THE Events CalendarAI2/10/20262/10/2026
The Events Calendar WordPress plugin before 6.17.5.1 does not validate or sanitise data submitted to an unauthenticated AJAX action before merging it into its rendering context, allowing unauthenticated users to execute arbitrary shortcodes registered on the site.
AplazadaAlta (8.5)0.25%—Event TicketsAI30/9/20262/10/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Liquid Web / StellarWP Event Tickets event-tickets allows Blind SQL Injection.This issue affects Event Tickets: from n/a through 5.29.5.
AplazadaMedia (5.4)0.20%—Theeventscalendar THE Events CalendarAI30/9/202630/9/2026
Contributor Broken Access Control in The Events Calendar <= 6.17.5 versions.
AplazadaMedia (4.3)0.21%—Prevent Files Folders AccessAI30/9/202630/9/2026
Subscriber Broken Access Control in Prevent files / folders access <= 2.6.7 versions.
Pendiente de análisisAlta (7.5)0.31%—Wikimedia EventbusAI29/9/202630/9/2026
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Mediawiki - EventBus Extension allows Excavation. This issue affects Mediawiki - EventBus Extension: 1.47.0-alpha.
En análisisMedia (5.3)0.24%—Event GalleryAI27/9/202630/9/2026
Joomla Extension - svenbluege.de - Reflected XSS and open redirect in Event Gallery extension < 6.5.0 - The “return” parameter is base64-decoded and written to the “Back” link without being validated.
En análisisAlta (7)0.31%—Svenbluege Event GalleryAI27/9/202629/9/2026
Joomla Extension - svenbluege.de - Authenticated arbitrary path deletion in `clear cache` task in Event Gallery extension < 6.5.0 - Using the `images` parameter of the `cache.process` task, you can recursively delete any directories that the web server is authorized to write to.
En análisisMedia (5.1)0.15%—Svenbluege Event GalleryAI27/9/202630/9/2026
Joomla Extension - svenbluege.de - CSRF in backend cleanup actions in Event Gallery extension < 6.5.0 - Only orphaned file entries and shopping carts that are older than 30 days will be deleted.
En análisisMedia (6.9)0.15%—Svenbluege Event GalleryAI27/9/202629/9/2026
Joomla Extension - svenbluege.de - CSRF in various cart actions in Event Gallery extension < 6.5.0
En análisisMedia (5.1)0.15%—Svenbluege Event GalleryAI27/9/202630/9/2026
Joomla Extension - svenbluege.de - CSRF in image upload in Event Gallery extension < 6.5.0 - Due to lack of an CSRF token check, a third-party site can upload files to an event and overwrite existing files with the same name.
Pendiente de análisisMedia (5.3)0.97%—Zoho Eventlog AnalyzerAIZoho Log360AI24/9/202624/9/2026
ZohoCorp ManageEngine EventLog Analyzer and Log360 before build 13071 were vulnerable to a DoS vulnerability that allowed attackers to crash the log collector using malformed syslog packets.
AplazadaMedia (4.3)0.18%—Events ManagerAI24/9/202624/9/2026
The Events Manager WordPress plugin before 7.4.5 does not force the scope of its logged-in event and location search when a caller supplies their own owner value, letting a low-privileged user read other accounts' unpublished, pending or trashed event and venue content, including full street addresses.
AplazadaBaja (2.7)0.17%—Events ManagerAI24/9/202624/9/2026
The Events Manager WordPress plugin before 7.4.5 does not stop a ticket-update request from replacing the identifiers of the ticket it was authorized against, letting a user who can manage one event's tickets overwrite and reassign any ticket on the site to their own event.
AplazadaAlta (7.1)0.18%—Event TicketsAI23/9/202623/9/2026
Unauthenticated Cross Site Scripting (XSS) in Event Tickets <= 5.29.4 versions.
AplazadaBaja (2.7)0.18%—Event Booking ManagerAI23/9/202623/9/2026
The Event Booking Manager for WooCommerce WordPress plugin before 5.7.3 does not restrict its event listing query to events the requesting user is permitted to read, so users with contributor-level access and above can retrieve other authors' private, draft and trashed events, together with event detail the standard…
Orbitaley — Vulnerabilidades