Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

324 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.91%—Pixelite Events Manager22/8/201917/6/2026
The events-manager plugin before 5.3.6.1 for WordPress has XSS via the booking form and admin areas.
ModificadaMedia (6.1)0.91%—Pixelite Events Manager22/8/201917/6/2026
The events-manager plugin before 5.3.9 for WordPress has XSS in the search form field.
ModificadaMedia (6.1)0.91%—Pixelite Events Manager22/8/201917/6/2026
The events-manager plugin before 5.5 for WordPress has XSS via EM_Ticket::get_post.
ModificadaMedia (6.1)0.91%—Pixelite Events Manager22/8/201917/6/2026
The events-manager plugin before 5.5.2 for WordPress has XSS in the booking form.
ModificadaMedia (6.1)0.91%—Pixelite Events Manager22/8/201916/6/2026
The events-manager plugin before 5.1.7 for WordPress has XSS via JSON call links.
ModificadaMedia (6.1)1.1%—Stellarwp THE Events Calendar21/8/201917/6/2026
The the-events-calendar plugin before 4.8.2 for WordPress has XSS via the tribe_paged URL parameter.
ModificadaMedia (6.1)0.92%—Pixelite Events Manager13/8/201917/6/2026
The events-manager plugin before 5.5.7 for WordPress has multiple XSS issues.
ModificadaMedia (6.1)0.92%—Pixelite Events Manager13/8/201917/6/2026
The events-manager plugin before 5.5.7.1 for WordPress has DOM XSS.
ModificadaCrítica (9.8)2.1%—Pixelite Events Manager13/8/201917/6/2026
The events-manager plugin before 5.6 for WordPress has code injection.
ModificadaMedia (6.1)0.92%—Pixelite Events Manager13/8/201917/6/2026
The events-manager plugin before 5.6 for WordPress has XSS.
ModificadaMedia (4.8)1.2%—Pixelite Events Manager12/4/201917/6/2026
The Events Manager plugin 5.9.4 for WordPress has XSS via the dbem_event_reapproved_email_body parameter to the wp-admin/edit.php?post_type=event&page=events-manager-options URI.
ModificadaMedia (6.1)3.4%💥 ExploitUpcoming Events Project Upcoming Events11/3/201917/6/2026
An XSS issue was discovered in upcoming_events.php in the Upcoming Events plugin before 1.33 for MyBB via a crafted name for an event.
ModificadaMedia (6.1)1.6%—Oracle Hyperion Common Events17/10/201817/6/2026
Vulnerability in the Hyperion Common Events component of Oracle Hyperion (subcomponent: User Interface). The supported version that is affected is 11.1.2.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Hyperion Common Events. Successful attacks require…
ModificadaMedia (6.1)1.6%—Oracle Hyperion Common Events17/10/201817/6/2026
Vulnerability in the Hyperion Common Events component of Oracle Hyperion (subcomponent: User Interface). The supported version that is affected is 11.1.2.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Hyperion Common Events. Successful attacks require…
ModificadaMedia (6.1)1.6%—Oracle Hyperion Common Events17/10/201817/6/2026
Vulnerability in the Hyperion Common Events component of Oracle Hyperion (subcomponent: User Interface). The supported version that is affected is 11.1.2.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Hyperion Common Events. Successful attacks require…
ModificadaMedia (6.1)1.6%—Oracle Hyperion Common Events17/10/201817/6/2026
Vulnerability in the Hyperion Common Events component of Oracle Hyperion (subcomponent: User Interface). The supported version that is affected is 11.1.2.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Hyperion Common Events. Successful attacks require…
ModificadaMedia (5.4)1.5%—Pixelite Events Manager14/5/201817/6/2026
Cross-site scripting vulnerability in Events Manager plugin prior to version 5.9 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (5.4)1.0%—Pixelite Events Manager26/3/201817/6/2026
The Events Manager plugin before 5.8.1.2 for WordPress allows XSS via the events-manager.js mapTitle parameter in the Google Maps miniature.
ModificadaCrítica (9.8)4.9%💥 ExploitWP Events Calendar Project WP Events Calendar12/1/201817/6/2026
The Wachipi WP Events Calendar plugin 1.0 for WordPress has SQL Injection via the event_id parameter to event.php.
ModificadaAlta (7.5)4.2%—Rockwellautomation Factorytalk Alarms AND Events23/12/201717/6/2026
An Improper Input Validation issue was discovered in Rockwell Automation FactoryTalk Alarms and Events, Version 2.90 and earlier. An unauthenticated attacker with remote access to a network with FactoryTalk Alarms and Events can send a specially crafted set of packets packet to Port 403/TCP (the history archiver…
ModificadaCrítica (9.8)2.2%💥 ExploitResponsive Events AND Movie Ticket Booking Script Project Responsive Events AND Movie Ticket Booking Script13/12/201717/6/2026
Responsive Events And Movie Ticket Booking Script 3.2.1 has SQL Injection via the findcity.php q parameter.
ModificadaCrítica (9.8)8.3%💥 ExploitCommunity Events Project Community Events7/9/201717/6/2026
SQL injection vulnerability in WordPress Community Events plugin before 1.4.
ModificadaMedia (6.1)0.63%—Netikus Eventsentry10/4/201717/6/2026
Netikus EventSentry before 3.2.1.44 has XSS via SNMP.
ModificadaMedia (4.3)2.1%—Theeventscalendar Eventbrite Tickets18/8/201517/6/2026
Cross-site scripting (XSS) vulnerability in the Event Import page (import-eventbrite-events.php) in the Modern Tribe Eventbrite Tickets plugin before 3.10.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the "error" parameter to wp-admin/edit.php.
ModificadaMedia (4.3)1.5%—Eventsentry23/1/201517/6/2026
Cross-site scripting (XSS) vulnerability in the Web Reports in EventSentry 3.1.0 allows remote attackers to inject arbitrary web script or HTML via the pageId parameter to networktile/bullet.