Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2736▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
1448 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.17% | — | George Sexton Wordpress Events Calendar Plugin ConnectdailyAI | 5/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in George Sexton WordPress Events Calendar Plugin – connectDaily connect-daily-web-calendar allows Stored XSS.This issue affects WordPress Events Calendar Plugin – connectDaily: from n/a through <= 1.5.5. | |
| Aplazada | Alta (7.1) | 0.12% | — | Quick-event-calendarAI | 5/9/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WP Corner Quick Event Calendar quick-event-calendar allows Stored XSS.This issue affects Quick Event Calendar: from n/a through <= 1.4.9. | |
| Aplazada | Media (6.5) | 0.21% | — | Bohemia Plugins Event Feed FOR EventbriteAI | 3/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bohemia Plugins Event Feed for Eventbrite event-feed-for-eventbrite allows DOM-Based XSS.This issue affects Event Feed for Eventbrite: from n/a through <= 1.3.2. | |
| Aplazada | Media (4.3) | 0.14% | — | Tickera Event Ticketing SystemAI | 3/9/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Tickera Tickera tickera-event-ticketing-system allows Cross Site Request Forgery.This issue affects Tickera: from n/a through <= 3.5.5.6. | |
| Analizada | Alta (7.5) | 0.42% | — | Bevy Events AND Groups | 2/9/2025 | 17/6/2026 | The Bevy Event service through 2025-07-22, as used for eBay Seller Events and other activities, allows account takeover, if SSO is used, when a victim changes the email address that they have configured. To exploit this, an attacker would create their own account and perform an SSO login. The root cause of the issue… | |
| Modificada | Media (6.3) | 0.39% | — | Eventlet | 29/8/2025 | 17/6/2026 | Eventlet is a concurrent networking library for Python. Prior to version 0.40.3, the Eventlet WSGI parser is vulnerable to HTTP Request Smuggling due to improper handling of HTTP trailer sections. This vulnerability could enable attackers to, bypass front-end security controls, launch targeted attacks against active… | |
| Aplazada | Media (6.4) | 0.24% | — | Nicheaddons Events Addon FOR ElementorAI | 29/8/2025 | 17/6/2026 | The Events Addon for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Typewriter and Countdown widgets in all versions up to, and including, 2.2.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Analizada | Media (5.5) | 0.42% | — | Carmelo Online Event Judging System | 29/8/2025 | 17/6/2026 | A vulnerability was determined in code-projects Online Event Judging System 1.0. This issue affects some unknown processing of the file /create_account.php. This manipulation of the argument fname causes sql injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may… | |
| Aplazada | Alta (8.1) | 0.54% | — | Ovatheme Ova-eventsAI | 28/8/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ovatheme Ovatheme Events ova-events allows PHP Local File Inclusion.This issue affects Ovatheme Events: from n/a through <= 1.2.8. | |
| Aplazada | Alta (8.8) | 0.37% | — | Magepeopleteam WP EventlyAI | 28/8/2025 | 25/9/2026 | Deserialization of Untrusted Data vulnerability in magepeopleteam WpEvently mage-eventpress allows Object Injection.This issue affects WpEvently: from n/a through <= 4.4.8. | |
| Aplazada | Alta (8.8) | 0.31% | — | Event ListAI | 26/8/2025 | 17/6/2026 | The Event List plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.0.4. This is due to the plugin not properly validating a user's capabilities prior to updating their profile in the el_update_profile() function. This makes it possible for authenticated attackers, with… | |
| Aplazada | Alta (7.2) | 0.29% | — | Themewinter EventinAI | 23/8/2025 | 17/6/2026 | The Events Calendar, Event Booking, Registrations and Event Tickets – Eventin plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.0.37 via the proxy_image function. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations… | |
| Analizada | Media (5.4) | 0.18% | — | IBM Qradar Incident ForensicsIBM Qradar Security Information AND Event Manager | 22/8/2025 | 17/6/2026 | IBM QRadar SIEM 7.5 through 7.5.0 Dashboard is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Analizada | Alta (7.8) | 0.15% | — | IBM Qradar Incident ForensicsIBM Qradar Security Information AND Event Manager | 22/8/2025 | 17/6/2026 | IBM QRadar SIEM 7.5 through 7.5.0 UP13 could allow an authenticated user to escalate their privileges via a misconfigured cronjob due to execution with unnecessary privileges. | |
| Analizada | Media (6.3) | 0.40% | — | Apache Eventmesh | 20/8/2025 | 17/6/2026 | CWE-918 Server-Side Request Forgery (SSRF) in eventmesh-runtime module in WebhookUtil.java on windows\linux\mac os e.g. allows the attacker can abuse functionality on the server to read or update internal resources. Users are recommended to upgrade to version 1.12.0 or use the master branch , which fixes this issue. | |
| Aplazada | Media (6.5) | 0.43% | — | Miniorange Prevent Files Folders AccessAI | 20/8/2025 | 17/6/2026 | Path Traversal: '.../...//' vulnerability in miniOrange Prevent files / folders access prevent-file-access allows Path Traversal.This issue affects Prevent files / folders access: from n/a through <= 2.6.0. | |
| Aplazada | Alta (8.1) | 0.66% | — | Joomla EventlistAI | 20/8/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ovatheme eventlist eventlist allows PHP Local File Inclusion.This issue affects eventlist: from n/a through <= 1.9.2. | |
| Aplazada | Media (4.3) | 0.41% | 💥 PoC | Eventontemplates Eventon LiteAI | 15/8/2025 | 17/6/2026 | The EventON Lite plugin for WordPress is vulnerable to Information Exposure in all versions less than, or equal to, 2.4.6 via the add_single_eventon and add_eventon shortcodes due to insufficient restrictions on which posts can be included. This makes it possible for unauthenticated attackers to extract data from… | |
| Aplazada | Media (4.3) | 0.25% | — | Magepeopleteam WpeventlyAI | 14/8/2025 | 17/6/2026 | Missing Authorization vulnerability in magepeopleteam WpEvently mage-eventpress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WpEvently: from n/a through <= 4.4.6. | |
| Aplazada | Alta (7.5) | 0.36% | — | Eventin-proAI | 14/8/2025 | 17/6/2026 | Missing Authorization vulnerability in themefunction WordPress Event Manager, Event Calendar and Booking Plugin eventin-pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WordPress Event Manager, Event Calendar and Booking Plugin: from n/a through <= 4.0.24. | |
| Aplazada | Media (6.5) | 0.21% | — | Themefunction Eventin PROAI | 14/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themefunction WordPress Event Manager, Event Calendar and Booking Plugin eventin-pro allows Stored XSS.This issue affects WordPress Event Manager, Event Calendar and Booking Plugin: from n/a through <= 4.0.24. | |
| Aplazada | Alta (8.8) | 0.38% | — | Arraytics EventinAI | 14/8/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Arraytics Eventin wp-event-solution allows Object Injection.This issue affects Eventin: from n/a through <= 4.0.31. | |
| Aplazada | Media (6.5) | 0.26% | — | Imithemes EventerAI | 14/8/2025 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in imithemes Eventer eventer allows Code Injection.This issue affects Eventer: from n/a through < 3.9.9.1. | |
| Analizada | Alta (8.8) | 0.59% | 💥 PoC | Themewinter Eventin | 8/8/2025 | 17/6/2026 | The Eventin plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 4.0.34. This is due to the plugin not properly validating a user's identity or capability prior to updating their details like email in the… | |
| Analizada | Media (5.4) | 0.21% | — | IBM Qradar Security Information AND Event Manager | 1/8/2025 | 17/6/2026 | IBM QRadar SIEM 7.5 through 7.5.0 Update Pack 12 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. |