Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

324 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)1.7%—Fsevents Project Fsevents6/10/202317/6/2026
fsevents before 1.2.11 depends on the https://fsevents-binaries.s3-us-west-2.amazonaws.com URL, which might allow an adversary to execute arbitrary code if any JavaScript project (that depends on fsevents) distributes code that was obtained from that URL at a time when it was controlled by an adversary. NOTE: some…
ModificadaMedia (5.4)0.62%—Tiva Events Calendar Project Tiva Events Calendar20/7/202317/6/2026
A vulnerability classified as problematic was found in Codecanyon Tiva Events Calender 1.4. This vulnerability affects unknown code. The manipulation of the argument name leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-235054 is the…
ModificadaAlta (8.8)1.4%—Coolplugins Cool TimelineCoolplugins Cryptocurrency WidgetsCoolplugins Cryptocurrency Widgets FOR ElementorCoolplugins Event Single Page Builder FOR THE Event Calendar+67/6/202317/6/2026
Several WordPress plugins developed by Cool Plugins are vulnerable to arbitrary plugin installation and activation that can lead to remote code execution by authenticated attackers with minimal permissions, such as a subscriber.
ModificadaMedia (4.8)0.37%—WP Simple Events Project WP Simple Events8/5/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Nico Graff WP Simple Events plugin <= 1.0 versions.
ModificadaMedia (4.8)0.44%—Amr-ical-events-list Project Amr-ical-events-list2/5/202317/6/2026
The amr ical events lists WordPress plugin through 6.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
ModificadaMedia (6.5)0.56%—WP Fevents Book Project WP Fevents Book24/4/202317/6/2026
The WP FEvents Book WordPress plugin through 0.46 does not ensures that bookings to be updated belong to the user making the request, allowing any authenticated user to book, add notes, or cancel booking on behalf of other users.
ModificadaMedia (5.4)0.44%—WP Fevents Book Project WP Fevents Book24/4/202317/6/2026
The WP FEvents Book WordPress plugin through 0.46 does not sanitise and escape some parameters, which could allow any authenticated users, such as subscriber to perform Cross-Site Scripting attacks
ModificadaMedia (4.8)0.50%—Webnus Modern Events Calendar Lite27/3/202317/6/2026
The Modern Events Calendar Lite WordPress plugin before 6.5.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
ModificadaMedia (4.8)0.39%—Community Events Project Community Events23/3/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting vulnerability in Yannick Lefebvre Community Events plugin <= 1.4.8 versions.
ModificadaAlta (8.8)0.87%—E-dynamics Events Made Easy22/3/202317/6/2026
The Events Made Easy WordPress Plugin, version <= 2.3.14 is affected by an authenticated SQL injection vulnerability in the 'search_name' parameter in the eme_recurrences_list action.
ModificadaMedia (5.4)0.51%—E-dynamics Events Made Easy19/1/202317/6/2026
The Events Made Easy plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several functions related to AJAX actions in versions up to, and including, 2.3.16. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to invoke those…
ModificadaMedia (6.1)0.89%💥 ExploitMhsoftware Wordpress Events Calendar Plugin16/1/202317/6/2026
The WordPress Events Calendar WordPress plugin before 1.4.5 does not sanitize and escapes a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against both unauthenticated and authenticated users (such as high-privilege ones like admin).
ModificadaCrítica (9.8)0.67%—Events Project Events16/1/202317/6/2026
A vulnerability classified as critical was found in Events Extension on BigTree. Affected by this vulnerability is the function getRandomFeaturedEventByDate/getUpcomingFeaturedEventsInCategoriesWithSubcategories/recacheEvent/searchResults of the file classes/events.php. The manipulation leads to sql injection. The…
ModificadaAlta (7.5)0.63%—Evolution-events Artaxerxes5/1/202317/6/2026
A vulnerability was found in Evolution Events Artaxerxes. It has been declared as problematic. This vulnerability affects unknown code of the file arta/common/middleware.py of the component POST Parameter Handler. The manipulation of the argument password leads to information disclosure. The attack can be initiated…
ModificadaAlta (7.5)1.2%—Rockwellautomation Factorytalk Alarms AND Events27/10/202217/6/2026
An unauthenticated attacker with network access to a victim's Rockwell Automation FactoryTalk Alarm and Events service could open a connection, causing the service to fault and become unavailable. The affected port could be used as a server ping port and uses messages structured with XML.
ModificadaAlta (8.8)1.3%—Mobileeventsmanager Mobile Events Manager16/9/202217/6/2026
The Mobile Events Manager WordPress plugin before 1.4.8 does not properly escape the Enquiry source field when exporting events, or the Paid for field when exporting transactions as CSV, leading to a CSV injection vulnerability.
ModificadaCrítica (9.8)37%—E-dynamics Events Made Easy20/6/202217/6/2026
The Events Made Easy WordPress plugin before 2.2.81 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection
ModificadaAlta (7.5)1.9%—Argo Events Project Argo Events17/6/202217/6/2026
The package github.com/argoproj/argo-events/sensors/artifacts before 1.7.1 are vulnerable to Directory Traversal in the (g *GitArtifactReader).Read() API in git.go. This could allow arbitrary file reads if the GitArtifactReader is provided a pathname containing a symbolic link or an implicit directory name such as ...
ModificadaMedia (5.4)0.55%—Webnus Modern Events Calendar Lite16/6/202217/6/2026
Cross-site scripting vulnerability in Modern Events Calendar Lite versions prior to 6.3.0 allows remote an authenticated attacker to inject an arbitrary script via unspecified vectors.
ModificadaAlta (7.5)1.6%—Argo Events Project Argo Events13/6/202217/6/2026
Argo Events is an event-driven workflow automation framework for Kubernetes. Prior to version 1.7.1, several `HandleRoute` endpoints make use of the deprecated `ioutil.ReadAll()`. `ioutil.ReadAll()` reads all the data into memory. As such, an attacker who sends a large request to the Argo Events server will be able to…
ModificadaCrítica (9.3)1.9%—EventsourceDebian Linux12/5/202217/6/2026
Improper Removal of Sensitive Information Before Storage or Transfer in GitHub repository eventsource/eventsource prior to v2.0.2.
ModificadaMedia (4.8)0.56%—Webnus Modern Events Calendar Lite14/4/202217/6/2026
Authenticated (admin+ user) Stored Cross-Site Scripting (XSS) in Modern Events Calendar Lite (WordPress plugin) <= 6.5.1
ModificadaMedia (5.4)70%—Webnus Modern Events Calendar Lite21/3/202217/6/2026
The Modern Events Calendar Lite WordPress plugin before 6.4.0 does not sanitize and escape some of the Hourly Schedule parameters which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks
ModificadaMedia (6.1)0.89%—Roundupwp Registrations FOR THE Events Calendar24/1/202217/6/2026
The Registrations for the Events Calendar WordPress plugin before 2.7.10 does not escape the qtype parameter before outputting it back in an attribute in the settings page, leading to a Reflected Cross-Site Scripting
ModificadaMedia (4.8)0.65%—Mobileeventsmanager Mobile Events Manager24/1/202217/6/2026
The Mobile Events Manager WordPress plugin before 1.4.4 does not sanitise and escape various of its settings, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
Orbitaley — Vulnerabilidades