Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
324 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.91% | — | Pixelite Events Manager | 22/8/2019 | 17/6/2026 | The events-manager plugin before 5.3.6.1 for WordPress has XSS via the booking form and admin areas. | |
| Modificada | Media (6.1) | 0.91% | — | Pixelite Events Manager | 22/8/2019 | 17/6/2026 | The events-manager plugin before 5.3.9 for WordPress has XSS in the search form field. | |
| Modificada | Media (6.1) | 0.91% | — | Pixelite Events Manager | 22/8/2019 | 17/6/2026 | The events-manager plugin before 5.5 for WordPress has XSS via EM_Ticket::get_post. | |
| Modificada | Media (6.1) | 0.91% | — | Pixelite Events Manager | 22/8/2019 | 17/6/2026 | The events-manager plugin before 5.5.2 for WordPress has XSS in the booking form. | |
| Modificada | Media (6.1) | 0.91% | — | Pixelite Events Manager | 22/8/2019 | 16/6/2026 | The events-manager plugin before 5.1.7 for WordPress has XSS via JSON call links. | |
| Modificada | Media (6.1) | 1.1% | — | Stellarwp THE Events Calendar | 21/8/2019 | 17/6/2026 | The the-events-calendar plugin before 4.8.2 for WordPress has XSS via the tribe_paged URL parameter. | |
| Modificada | Media (6.1) | 0.92% | — | Pixelite Events Manager | 13/8/2019 | 17/6/2026 | The events-manager plugin before 5.5.7 for WordPress has multiple XSS issues. | |
| Modificada | Media (6.1) | 0.92% | — | Pixelite Events Manager | 13/8/2019 | 17/6/2026 | The events-manager plugin before 5.5.7.1 for WordPress has DOM XSS. | |
| Modificada | Crítica (9.8) | 2.1% | — | Pixelite Events Manager | 13/8/2019 | 17/6/2026 | The events-manager plugin before 5.6 for WordPress has code injection. | |
| Modificada | Media (6.1) | 0.92% | — | Pixelite Events Manager | 13/8/2019 | 17/6/2026 | The events-manager plugin before 5.6 for WordPress has XSS. | |
| Modificada | Media (4.8) | 1.2% | — | Pixelite Events Manager | 12/4/2019 | 17/6/2026 | The Events Manager plugin 5.9.4 for WordPress has XSS via the dbem_event_reapproved_email_body parameter to the wp-admin/edit.php?post_type=event&page=events-manager-options URI. | |
| Modificada | Media (6.1) | 3.4% | 💥 Exploit | Upcoming Events Project Upcoming Events | 11/3/2019 | 17/6/2026 | An XSS issue was discovered in upcoming_events.php in the Upcoming Events plugin before 1.33 for MyBB via a crafted name for an event. | |
| Modificada | Media (6.1) | 1.6% | — | Oracle Hyperion Common Events | 17/10/2018 | 17/6/2026 | Vulnerability in the Hyperion Common Events component of Oracle Hyperion (subcomponent: User Interface). The supported version that is affected is 11.1.2.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Hyperion Common Events. Successful attacks require… | |
| Modificada | Media (6.1) | 1.6% | — | Oracle Hyperion Common Events | 17/10/2018 | 17/6/2026 | Vulnerability in the Hyperion Common Events component of Oracle Hyperion (subcomponent: User Interface). The supported version that is affected is 11.1.2.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Hyperion Common Events. Successful attacks require… | |
| Modificada | Media (6.1) | 1.6% | — | Oracle Hyperion Common Events | 17/10/2018 | 17/6/2026 | Vulnerability in the Hyperion Common Events component of Oracle Hyperion (subcomponent: User Interface). The supported version that is affected is 11.1.2.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Hyperion Common Events. Successful attacks require… | |
| Modificada | Media (6.1) | 1.6% | — | Oracle Hyperion Common Events | 17/10/2018 | 17/6/2026 | Vulnerability in the Hyperion Common Events component of Oracle Hyperion (subcomponent: User Interface). The supported version that is affected is 11.1.2.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Hyperion Common Events. Successful attacks require… | |
| Modificada | Media (5.4) | 1.5% | — | Pixelite Events Manager | 14/5/2018 | 17/6/2026 | Cross-site scripting vulnerability in Events Manager plugin prior to version 5.9 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (5.4) | 1.0% | — | Pixelite Events Manager | 26/3/2018 | 17/6/2026 | The Events Manager plugin before 5.8.1.2 for WordPress allows XSS via the events-manager.js mapTitle parameter in the Google Maps miniature. | |
| Modificada | Crítica (9.8) | 4.9% | 💥 Exploit | WP Events Calendar Project WP Events Calendar | 12/1/2018 | 17/6/2026 | The Wachipi WP Events Calendar plugin 1.0 for WordPress has SQL Injection via the event_id parameter to event.php. | |
| Modificada | Alta (7.5) | 4.2% | — | Rockwellautomation Factorytalk Alarms AND Events | 23/12/2017 | 17/6/2026 | An Improper Input Validation issue was discovered in Rockwell Automation FactoryTalk Alarms and Events, Version 2.90 and earlier. An unauthenticated attacker with remote access to a network with FactoryTalk Alarms and Events can send a specially crafted set of packets packet to Port 403/TCP (the history archiver… | |
| Modificada | Crítica (9.8) | 2.2% | 💥 Exploit | Responsive Events AND Movie Ticket Booking Script Project Responsive Events AND Movie Ticket Booking Script | 13/12/2017 | 17/6/2026 | Responsive Events And Movie Ticket Booking Script 3.2.1 has SQL Injection via the findcity.php q parameter. | |
| Modificada | Crítica (9.8) | 8.3% | 💥 Exploit | Community Events Project Community Events | 7/9/2017 | 17/6/2026 | SQL injection vulnerability in WordPress Community Events plugin before 1.4. | |
| Modificada | Media (6.1) | 0.63% | — | Netikus Eventsentry | 10/4/2017 | 17/6/2026 | Netikus EventSentry before 3.2.1.44 has XSS via SNMP. | |
| Modificada | Media (4.3) | 2.1% | — | Theeventscalendar Eventbrite Tickets | 18/8/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Event Import page (import-eventbrite-events.php) in the Modern Tribe Eventbrite Tickets plugin before 3.10.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the "error" parameter to wp-admin/edit.php. | |
| Modificada | Media (4.3) | 1.5% | — | Eventsentry | 23/1/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Web Reports in EventSentry 3.1.0 allows remote attackers to inject arbitrary web script or HTML via the pageId parameter to networktile/bullet. |