Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
324 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.7% | — | Fsevents Project Fsevents | 6/10/2023 | 17/6/2026 | fsevents before 1.2.11 depends on the https://fsevents-binaries.s3-us-west-2.amazonaws.com URL, which might allow an adversary to execute arbitrary code if any JavaScript project (that depends on fsevents) distributes code that was obtained from that URL at a time when it was controlled by an adversary. NOTE: some… | |
| Modificada | Media (5.4) | 0.62% | — | Tiva Events Calendar Project Tiva Events Calendar | 20/7/2023 | 17/6/2026 | A vulnerability classified as problematic was found in Codecanyon Tiva Events Calender 1.4. This vulnerability affects unknown code. The manipulation of the argument name leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-235054 is the… | |
| Modificada | Alta (8.8) | 1.4% | — | Coolplugins Cool TimelineCoolplugins Cryptocurrency WidgetsCoolplugins Cryptocurrency Widgets FOR ElementorCoolplugins Event Single Page Builder FOR THE Event Calendar+6 | 7/6/2023 | 17/6/2026 | Several WordPress plugins developed by Cool Plugins are vulnerable to arbitrary plugin installation and activation that can lead to remote code execution by authenticated attackers with minimal permissions, such as a subscriber. | |
| Modificada | Media (4.8) | 0.37% | — | WP Simple Events Project WP Simple Events | 8/5/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Nico Graff WP Simple Events plugin <= 1.0 versions. | |
| Modificada | Media (4.8) | 0.44% | — | Amr-ical-events-list Project Amr-ical-events-list | 2/5/2023 | 17/6/2026 | The amr ical events lists WordPress plugin through 6.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Media (6.5) | 0.56% | — | WP Fevents Book Project WP Fevents Book | 24/4/2023 | 17/6/2026 | The WP FEvents Book WordPress plugin through 0.46 does not ensures that bookings to be updated belong to the user making the request, allowing any authenticated user to book, add notes, or cancel booking on behalf of other users. | |
| Modificada | Media (5.4) | 0.44% | — | WP Fevents Book Project WP Fevents Book | 24/4/2023 | 17/6/2026 | The WP FEvents Book WordPress plugin through 0.46 does not sanitise and escape some parameters, which could allow any authenticated users, such as subscriber to perform Cross-Site Scripting attacks | |
| Modificada | Media (4.8) | 0.50% | — | Webnus Modern Events Calendar Lite | 27/3/2023 | 17/6/2026 | The Modern Events Calendar Lite WordPress plugin before 6.5.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Modificada | Media (4.8) | 0.39% | — | Community Events Project Community Events | 23/3/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting vulnerability in Yannick Lefebvre Community Events plugin <= 1.4.8 versions. | |
| Modificada | Alta (8.8) | 0.87% | — | E-dynamics Events Made Easy | 22/3/2023 | 17/6/2026 | The Events Made Easy WordPress Plugin, version <= 2.3.14 is affected by an authenticated SQL injection vulnerability in the 'search_name' parameter in the eme_recurrences_list action. | |
| Modificada | Media (5.4) | 0.51% | — | E-dynamics Events Made Easy | 19/1/2023 | 17/6/2026 | The Events Made Easy plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several functions related to AJAX actions in versions up to, and including, 2.3.16. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to invoke those… | |
| Modificada | Media (6.1) | 0.89% | 💥 Exploit | Mhsoftware Wordpress Events Calendar Plugin | 16/1/2023 | 17/6/2026 | The WordPress Events Calendar WordPress plugin before 1.4.5 does not sanitize and escapes a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against both unauthenticated and authenticated users (such as high-privilege ones like admin). | |
| Modificada | Crítica (9.8) | 0.67% | — | Events Project Events | 16/1/2023 | 17/6/2026 | A vulnerability classified as critical was found in Events Extension on BigTree. Affected by this vulnerability is the function getRandomFeaturedEventByDate/getUpcomingFeaturedEventsInCategoriesWithSubcategories/recacheEvent/searchResults of the file classes/events.php. The manipulation leads to sql injection. The… | |
| Modificada | Alta (7.5) | 0.63% | — | Evolution-events Artaxerxes | 5/1/2023 | 17/6/2026 | A vulnerability was found in Evolution Events Artaxerxes. It has been declared as problematic. This vulnerability affects unknown code of the file arta/common/middleware.py of the component POST Parameter Handler. The manipulation of the argument password leads to information disclosure. The attack can be initiated… | |
| Modificada | Alta (7.5) | 1.2% | — | Rockwellautomation Factorytalk Alarms AND Events | 27/10/2022 | 17/6/2026 | An unauthenticated attacker with network access to a victim's Rockwell Automation FactoryTalk Alarm and Events service could open a connection, causing the service to fault and become unavailable. The affected port could be used as a server ping port and uses messages structured with XML. | |
| Modificada | Alta (8.8) | 1.3% | — | Mobileeventsmanager Mobile Events Manager | 16/9/2022 | 17/6/2026 | The Mobile Events Manager WordPress plugin before 1.4.8 does not properly escape the Enquiry source field when exporting events, or the Paid for field when exporting transactions as CSV, leading to a CSV injection vulnerability. | |
| Modificada | Crítica (9.8) | 37% | — | E-dynamics Events Made Easy | 20/6/2022 | 17/6/2026 | The Events Made Easy WordPress plugin before 2.2.81 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection | |
| Modificada | Alta (7.5) | 1.9% | — | Argo Events Project Argo Events | 17/6/2022 | 17/6/2026 | The package github.com/argoproj/argo-events/sensors/artifacts before 1.7.1 are vulnerable to Directory Traversal in the (g *GitArtifactReader).Read() API in git.go. This could allow arbitrary file reads if the GitArtifactReader is provided a pathname containing a symbolic link or an implicit directory name such as ... | |
| Modificada | Media (5.4) | 0.55% | — | Webnus Modern Events Calendar Lite | 16/6/2022 | 17/6/2026 | Cross-site scripting vulnerability in Modern Events Calendar Lite versions prior to 6.3.0 allows remote an authenticated attacker to inject an arbitrary script via unspecified vectors. | |
| Modificada | Alta (7.5) | 1.6% | — | Argo Events Project Argo Events | 13/6/2022 | 17/6/2026 | Argo Events is an event-driven workflow automation framework for Kubernetes. Prior to version 1.7.1, several `HandleRoute` endpoints make use of the deprecated `ioutil.ReadAll()`. `ioutil.ReadAll()` reads all the data into memory. As such, an attacker who sends a large request to the Argo Events server will be able to… | |
| Modificada | Crítica (9.3) | 1.9% | — | EventsourceDebian Linux | 12/5/2022 | 17/6/2026 | Improper Removal of Sensitive Information Before Storage or Transfer in GitHub repository eventsource/eventsource prior to v2.0.2. | |
| Modificada | Media (4.8) | 0.56% | — | Webnus Modern Events Calendar Lite | 14/4/2022 | 17/6/2026 | Authenticated (admin+ user) Stored Cross-Site Scripting (XSS) in Modern Events Calendar Lite (WordPress plugin) <= 6.5.1 | |
| Modificada | Media (5.4) | 70% | — | Webnus Modern Events Calendar Lite | 21/3/2022 | 17/6/2026 | The Modern Events Calendar Lite WordPress plugin before 6.4.0 does not sanitize and escape some of the Hourly Schedule parameters which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks | |
| Modificada | Media (6.1) | 0.89% | — | Roundupwp Registrations FOR THE Events Calendar | 24/1/2022 | 17/6/2026 | The Registrations for the Events Calendar WordPress plugin before 2.7.10 does not escape the qtype parameter before outputting it back in an attribute in the settings page, leading to a Reflected Cross-Site Scripting | |
| Modificada | Media (4.8) | 0.65% | — | Mobileeventsmanager Mobile Events Manager | 24/1/2022 | 17/6/2026 | The Mobile Events Manager WordPress plugin before 1.4.4 does not sanitise and escape various of its settings, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed |