Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

95 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.1)0.23%💥 PoCPuneethreddyhc Event Management System7/10/202517/6/2026
A Cross-Site Scripting (XSS) vulnerability was found in the register.php page of PuneethReddyHC Event Management System 1.0, where the event_id GET parameter is improperly handled. An attacker can craft a malicious URL to execute arbitrary JavaScript in the victim s browser by injecting code into this parameter.
AnalizadaBaja (2.4)0.21%—Hcltech Intelliops Event Management25/7/202517/6/2026
HCL IEM is affected by a cookie attribute not set vulnerability due to inconsistency of certain security-related configurations which could increase exposure to potential vulnerabilities.
AnalizadaMedia (4.8)0.14%—Hcltech Intelliops Event Management25/7/202517/6/2026
HCL IEM is affected by a password in cleartext vulnerability. Sensitive information is transmitted without adequate protection, potentially exposing it to unauthorized access during transit.
AnalizadaMedia (5.7)0.21%—Hcltech Intelliops Event Management25/7/202517/6/2026
HCL IEM is affected by a concurrent login vulnerability. The application allows multiple concurrent sessions using the same user credentials, which may introduce security risks.
AnalizadaMedia (4.9)0.18%—Hcltech Intelliops Event Management25/7/202517/6/2026
HCL IEM is affected by an authorization token sent in cookie vulnerability. A token used for authentication and authorization is being handled in a manner that may increase its exposure to security risks.
AnalizadaMedia (5.9)0.21%—Hcltech Intelliops Event Management25/7/202517/6/2026
HCL IEM is affected by an improper invalidation of access or JWT token vulnerability. A token was not invalidated which may allow attackers to access sensitive data without authorization.
ModificadaMedia (5.4)0.24%—Emarketdesign Event Rsvp AND Simple Event Management26/6/202517/6/2026
The Event RSVP and Simple Event Management Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'emd_mb_meta' shortcode in all versions up to, and including, 4.1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for…
AplazadaAlta (7.6)0.58%—Wpchill Rsvp AND Event ManagementAI24/1/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Chill RSVP and Event Management rsvp allows SQL Injection.This issue affects RSVP and Event Management: from n/a through <= 2.7.14.
AplazadaMedia (5.3)0.34%—Wpchill Rsvp AND Event ManagementAI7/1/202517/6/2026
The RSVP and Event Management plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several AJAX functions like bulk_delete_attendees() and bulk_delete_questions() in all versions up to, and including, 2.7.13. This makes it possible for unauthenticated attackers to delete…
AnalizadaMedia (5.3)0.75%—Codezips Event Management System29/12/202417/6/2026
A vulnerability, which was classified as critical, was found in Codezips Event Management System 1.0. Affected is an unknown function of the file /contact.php. The manipulation of the argument title leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and…
AnalizadaMedia (5.3)0.55%—Anisha University Event Management System4/11/202417/6/2026
A vulnerability was found in code-projects University Event Management System 1.0. It has been classified as critical. This affects an unknown part of the file doedit.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the…
AnalizadaMedia (5.3)0.45%—Anisha University Event Management System4/11/202417/6/2026
A vulnerability was found in code-projects University Event Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /dodelete.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the…
AnalizadaMedia (5.3)0.57%—Anisha University Event Management System2/11/202417/6/2026
A vulnerability was found in code-projects University Event Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file submit.php. The manipulation of the argument name/email/title/Year/gender/fromdate/todate/people leads to sql injection. The attack can be initiated…
AnalizadaMedia (6.1)0.36%—Angeljudesuarez Event Management System5/9/202417/6/2026
Sourcecodehero Event Management System 1.0 allows Stored Cross-Site Scripting via parameters Full Name, Address, Email, and contact# in /clientdetails/admin/regester.php.
AnalizadaCrítica (9.8)0.53%—Angeljudesuarez Event Management System5/9/202417/6/2026
Sourcecodehero Event Management System1.0 is vulnerable to SQL Injection via the parameter 'username' in /event/admin/login.php.
AnalizadaMedia (6.1)0.25%—Janobe School Event Management System6/8/202417/6/2026
Cross-Site Scripting (XSS) vulnerability in School Event Management System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain their session details via the 'view' parameter in '/event/index.php'.
AnalizadaMedia (6.1)0.25%—Janobe School Event Management System6/8/202417/6/2026
Cross-Site Scripting (XSS) vulnerability in School Event Management System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain their session details via the 'view' parameter in /candidate/index.php'.
AnalizadaMedia (6.1)0.25%—Janobe School Event Management System6/8/202417/6/2026
Cross-Site Scripting (XSS) vulnerability in School Event Management System affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the 'view' parameter in '/student/index.php'.
AnalizadaMedia (6.1)0.25%—Janobe School Event Management System6/8/202417/6/2026
Cross-Site Scripting (XSS) vulnerability in School Event Management System affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the 'view' parameter in '/eventwinner/index.php'.
AnalizadaMedia (6.1)0.25%—Janobe School Event Management System6/8/202417/6/2026
Cross-Site Scripting (XSS) vulnerability in School Event Management System affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted javascript payload to an authenticated user and partially take over their browser session via the 'id' and 'view' parameters in '/user/index.php'.
AnalizadaMedia (6.1)0.25%—Janobe School Event Management System6/8/202417/6/2026
Cross-Site Scripting (XSS) vulnerability in School Event Management System affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted javascript payload to an authenticated user and partially take over their browser session via the 'eventdate' and 'events' parameters in…
AnalizadaMedia (6.1)0.31%—Janobe School Attendence Monitoring SystemJanobe School Event Management System6/8/202417/6/2026
Cross-Site Scripting (XSS) vulnerability in School Attendance Monitoring System and School Event Management System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain details of their session cookie via the 'Attendance', 'attenddate' and 'YearLevel' parameters in…
AnalizadaMedia (6.1)0.31%—Janobe School Attendence Monitoring SystemJanobe School Event Management System6/8/202417/6/2026
Cross-Site Scripting (XSS) vulnerability in School Attendance Monitoring System and School Event Management System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain details of their session cookie via the 'Attendance', 'attenddate', 'YearLevel', 'eventdate',…
AnalizadaMedia (6.1)0.31%—Janobe School Attendence Monitoring SystemJanobe School Event Management System6/8/202417/6/2026
Cross-Site Scripting (XSS) vulnerability in School Attendance Monitoring System and School Event Management System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain details of their session cookie via the 'View' parameter in '/department/index.php'.
AnalizadaMedia (6.1)0.31%—Janobe School Attendence Monitoring SystemJanobe School Event Management System6/8/202417/6/2026
Cross-Site Scripting (XSS) vulnerability in School Attendance Monitoring System and School Event Management System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain details of their session cookie via the 'View' parameter in '/course/index.php'.
Orbitaley — Vulnerabilidades