Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
1448 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.2) | 0.33% | — | Themewinter EventinAI | 9/1/2026 | 17/6/2026 | The Eventin – Event Manager, Events Calendar, Event Tickets and Registrations plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'post_settings' function in all versions up to, and including, 4.0.51. This makes it possible for unauthenticated attackers to… | |
| Aplazada | Media (4.3) | 0.18% | — | Tickera-event-ticketing-systemAI | 6/1/2026 | 17/6/2026 | Missing Authorization vulnerability in Tickera Tickera tickera-event-ticketing-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tickera: from n/a through <= 3.5.6.4. | |
| Aplazada | Media (5.4) | 0.20% | — | Stellarwp THE Events CalendarAI | 6/1/2026 | 7/10/2026 | Missing Authorization vulnerability in StellarWP The Events Calendar the-events-calendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects The Events Calendar: from n/a through <= 6.15.12.2. | |
| Aplazada | Media (4.3) | 0.18% | — | Coolhappy Countdown-for-the-events-calendarAI | 6/1/2026 | 7/10/2026 | Missing Authorization vulnerability in CoolHappy The Events Calendar Countdown Addon countdown-for-the-events-calendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects The Events Calendar Countdown Addon: from n/a through <= 1.4.15. | |
| Analizada | Alta (7.8) | 0.21% | — | Forcepoint ONE Data Loss Prevention | 6/1/2026 | 17/6/2026 | Forcepoint One DLP Client, version 23.04.5642 (and possibly newer versions), includes a restricted version of Python 2.5.4 that prevents use of the ctypes library. ctypes is a foreign function interface (FFI) for Python, enabling calls to DLLs/shared libraries, memory allocation, and direct code execution. It was… | |
| Aplazada | Media (4.3) | 0.24% | — | Stephen Harris Event OrganiserAI | 30/12/2025 | 7/10/2026 | Missing Authorization vulnerability in Stephen Harris Event Organiser event-organiser allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Event Organiser: from n/a through <= 3.12.8. | |
| Aplazada | Media (5.9) | 0.21% | — | Atte Moisio AM EventsAI | 30/12/2025 | 7/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Atte Moisio AM Events am-events allows Stored XSS.This issue affects AM Events: from n/a through <= 1.13.1. | |
| Aplazada | Media (5.3) | 0.29% | — | Google CalendarAIGoogle Calendar EventsAI | 30/12/2025 | 7/10/2026 | Authorization Bypass Through User-Controlled Key vulnerability in SimpleCalendar Google Calendar Events google-calendar-events allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Google Calendar Events: from n/a through <= 3.5.9. | |
| Analizada | Crítica (9.8) | 0.52% | 💥 PoC | Puneethreddyhc Event Management | 23/12/2025 | 17/6/2026 | Improper input handling in /Grocery/search_products_itname.php inPuneethReddyHC event-management 1.0 permits SQL injection via the sitem_name POST parameter. Crafted payloads can alter query logic and disclose database contents. Exploitation may result in sensitive data disclosure and backend compromise. | |
| Aplazada | Media (6.4) | 0.42% | — | Events ManagerAI | 18/12/2025 | 17/6/2026 | The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'events_list_grouped' shortcode in all versions up to, and including, 7.2.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes… | |
| Aplazada | Media (5.3) | 0.33% | — | Events ManagerAI | 12/12/2025 | 7/10/2026 | The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 7.2.2.2 via the 'get_location' action due to insufficient restrictions on which locations can be included. This makes it possible for unauthenticated attackers to… | |
| Aplazada | Media (4.3) | 0.13% | — | Wpeventsmanager Events ManagerAI | 12/12/2025 | 7/10/2026 | The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 7.2.2.2. This is due to missing or incorrect nonce validation on the 'location_delete' action. This makes it possible for unauthenticated attackers to… | |
| Analizada | Media (4.8) | 0.40% | — | HP Omen Gaming HUBHP System Event Utility | 9/12/2025 | 17/6/2026 | HP System Event Utility and Omen Gaming Hub might allow execution of certain files outside of their restricted paths. This potential vulnerability was remediated with HP System Event Utility version 3.2.12 and Omen Gaming Hub version 1101.2511.101.0. | |
| Aplazada | Media (6.5) | 0.23% | — | Myeventon EventonAI | 9/12/2025 | 7/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ashanjay EventON eventon allows Stored XSS.This issue affects EventON: from n/a through <= 4.9.12. | |
| Aplazada | Media (5.3) | 0.30% | — | Wpgoaltracker WP Google Analytics EventsAI | 9/12/2025 | 7/10/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in yuvalo WP Google Analytics Events wp-google-analytics-events allows Retrieve Embedded Sensitive Data.This issue affects WP Google Analytics Events: from n/a through <= 2.8.2. | |
| Aplazada | Media (4.3) | 0.26% | — | Metagauss EventprimeAI | 9/12/2025 | 7/10/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Metagauss EventPrime eventprime-event-calendar-management allows Retrieve Embedded Sensitive Data.This issue affects EventPrime: from n/a through <= 4.2.4.1. | |
| Aplazada | Media (4.3) | 0.21% | — | Metagauss EventprimeAI | 9/12/2025 | 7/10/2026 | Missing Authorization vulnerability in Metagauss EventPrime eventprime-event-calendar-management allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects EventPrime: from n/a through <= 4.2.4.1. | |
| Analizada | Baja (2.7) | 0.29% | — | IBM Qradar Security Information AND Event Manager | 9/12/2025 | 1/10/2026 | IBM QRadar SIEM 7.5 - 7.5.0 UP14 IF01 is affected by an information disclosure vulnerability involving exposure of directory information. IBM has addressed this vulnerability in the latest update. | |
| Aplazada | Baja (2.7) | 0.21% | — | Motopress Timetable AND Event ScheduleAI | 3/12/2025 | 17/6/2026 | The Timetable and Event Schedule by MotoPress WordPress plugin before 2.4.16 does not verify a user has access to a specific event when duplicating, leading to arbitrary event disclosure when to users with a role as low as Contributor. | |
| Aplazada | Media (5.3) | 0.25% | — | Magepeopleteam WP EventlyAI | 21/11/2025 | 17/6/2026 | Missing Authorization vulnerability in magepeopleteam WpEvently mage-eventpress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WpEvently: from n/a through <= 5.0.4. | |
| Aplazada | Media (5.3) | 0.26% | — | Magepeopleteam WP EventlyAIMagepeopleteam Mage EventpressAI | 21/11/2025 | 17/6/2026 | Missing Authorization vulnerability in magepeopleteam WpEvently mage-eventpress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WpEvently: from n/a through <= 5.0.4. | |
| Aplazada | Alta (7.5) | 0.32% | — | Community EventsAI | 19/11/2025 | 7/10/2026 | The Community Events plugin for WordPress is vulnerable to SQL Injection via the 'dayofyear' parameter in all versions up to, and including, 1.5.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated… | |
| Analizada | Media (6.5) | 0.24% | — | IBM Qradar Security Information AND Event Manager | 12/11/2025 | 17/6/2026 | IBM QRadar SIEM 7.5 through 7.5.0 UP14 stores user credentials in configuration files in source control which can be read by an authenticated user. | |
| Aplazada | Media (6.4) | 0.22% | — | Eventbee Ticketing WidgetAI | 11/11/2025 | 17/6/2026 | The Eventbee Ticketing Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'eventbeeticketwidget' shortcode in all versions up to, and including, 1.0. This is due to the plugin not properly sanitizing user input and output of several parameters. This makes it possible for authenticated… | |
| Aplazada | Media (4.3) | 0.22% | — | EventprimeAI | 8/11/2025 | 7/10/2026 | The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized booking note creation due to a missing capability check on the 'booking_add_notes' function in all versions up to, and including, 4.2.0.0. This makes it possible for authenticated attackers, with Subscriber-level… |