Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
1448 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.3) | 0.29% | — | Metagauss Eventprime | 7/3/2025 | 17/6/2026 | The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability checks on the export_submittion_attendees function in all versions up to, and including, 4.0.7.3. This makes it possible for authenticated attackers, with… | |
| Modificada | Alta (8.8) | 0.69% | — | Wpgeodirectory Events Calendar* | 3/3/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Stiofan Events Calendar for GeoDirectory events-for-geodirectory allows Object Injection.This issue affects Events Calendar for GeoDirectory: from n/a through <= 2.3.14. | |
| Aplazada | Alta (7.1) | 0.39% | — | Abelony Events PlannerAI | 3/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in abelony Events Planner events-planner allows Reflected XSS.This issue affects Events Planner: from n/a through <= 1.3.10. | |
| Aplazada | Media (5.3) | 0.35% | — | Marcus Events ManagerAI | 26/2/2025 | 17/6/2026 | Missing Authorization vulnerability in Marcus (aka @msykes) Events Manager events-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Events Manager: from n/a through <= 6.6.4.1. | |
| Analizada | Media (6.1) | 0.60% | 💥 Exploit | Wp-base WP Base Booking OF Appointments, Services AND Events | 26/2/2025 | 17/6/2026 | The WP BASE Booking of Appointments, Services and Events WordPress plugin before 5.0.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin. | |
| Modificada | Alta (8.8) | 0.76% | — | Themewinter Eventin | 25/2/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Arraytics Eventin wp-event-solution allows PHP Local File Inclusion.This issue affects Eventin: from n/a through <= 4.0.20. | |
| Modificada | Media (6.1) | 0.23% | — | Imithemes Eventer | 23/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in imithemes Eventer eventer allows Reflected XSS.This issue affects Eventer: from n/a through < 3.9.9. | |
| Aplazada | Media (5.5) | 0.23% | — | Cloudevents Java SDKAI | 21/2/2025 | 17/6/2026 | An XML External Entity (XXE) vulnerability in the deserializeArgs() method of Java SDK for CloudEvents v4.0.1 allows attackers to access sensitive information via supplying a crafted XML-formatted event message. | |
| Analizada | Media (5.3) | 0.45% | — | Theeventscalendar Event Tickets | 21/2/2025 | 17/6/2026 | The Event Tickets and Registration plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'ajax_ticket_delete' function in all versions up to, and including, 5.19.1.1. This makes it possible for authenticated attackers, with Contributor-level access and above, to… | |
| Analizada | Alta (7.5) | 0.60% | — | Pixelite Events Manager | 21/2/2025 | 17/6/2026 | The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to time-based SQL Injection via the active_status parameter in all versions up to, and including, 6.6.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL… | |
| Modificada | Media (6.5) | 0.67% | — | Phpjabbers Event Ticketing System | 20/2/2025 | 17/6/2026 | A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Event Ticketing System v1.0 allows attackers to send an excessive amount of email for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail messages. | |
| Modificada | Media (5.4) | 0.35% | — | Phpjabbers Event Ticketing System | 20/2/2025 | 17/6/2026 | PHPJabbers Event Ticketing System v1.0 is vulnerable to Reflected Cross-Site Scripting (XSS) in "lid" parameter in index. | |
| Modificada | Media (5.4) | 0.42% | — | Phpjabbers Event Ticketing System | 20/2/2025 | 17/6/2026 | PHPJabbers Event Ticketing System v1.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) in the "name, title" parameters. | |
| Modificada | Media (5.4) | 0.29% | — | Bandsintown Events | 20/2/2025 | 17/6/2026 | The Bandsintown Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bandsintown_events' shortcode in all versions up to, and including, 1.3.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Modificada | Media (6.1) | 0.47% | — | Phpjabbers Event Ticketing System | 19/2/2025 | 17/6/2026 | PHPJabbers Event Ticketing System v1.0 is vulnerable to Multiple HTML Injection in the "lid, name, plugin_sms_api_key, plugin_sms_country_code, title, plugin_sms_api_key, title" parameters. | |
| Analizada | Media (4.7) | 0.41% | — | Phpjabbers Event Booking Calendar | 19/2/2025 | 17/6/2026 | PHPJabbers Event Booking Calendar v4.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on Languages section Labels any parameters field in System Options that is used to construct CSV file. | |
| Modificada | Media (6.1) | 0.46% | — | Phpjabbers Event Booking Calendar | 19/2/2025 | 17/6/2026 | PHPJabbers Event Booking Calendar v4.0 is vulnerable to Cross-Site Scripting (XSS) in the "name, plugin_sms_api_key, plugin_sms_country_code, title, plugin_sms_api_key" parameters which allows attackers to execute arbitrary code | |
| Modificada | Alta (7.5) | 0.75% | — | Phpjabbers Event Booking Calendar | 19/2/2025 | 17/6/2026 | A lack of rate limiting in the 'Forgot Password', 'Email Settings' feature of PHPJabbers Event Booking Calendar v4.0 allows attackers to send an excessive amount of email for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail messages. | |
| Aplazada | Crítica (9.8) | 0.52% | — | Seventhqueen K ElementsAI | 18/2/2025 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in SeventhQueen K Elements k-elements allows Privilege Escalation.This issue affects K Elements: from n/a through < 5.4.0. | |
| Aplazada | Media (5.3) | 0.47% | — | Seventh D-guardAI | 16/2/2025 | 17/6/2026 | A vulnerability classified as problematic has been found in Seventh D-Guard up to 20250206. This affects an unknown part of the component HTTP GET Request Handler. The manipulation leads to path traversal. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The… | |
| Analizada | Media (4.8) | 0.23% | — | IBM Qradar Security Information AND Event Manager | 14/2/2025 | 17/6/2026 | IBM QRadar SIEM 7.5 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Analizada | Crítica (9.8) | 0.79% | — | Apache Eventmesh | 14/2/2025 | 17/6/2026 | CWE-502 Deserialization of Untrusted Data at the eventmesh-meta-raft plugin module in Apache EventMesh master branch without release version on windows\linux\mac os e.g. platforms allows attackers to send controlled message and remote code execute via hessian deserialization rpc protocol. Users can use the code under… | |
| Modificada | Media (6.1) | 0.26% | — | Xylusthemes WP Event Aggregator | 14/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Xylus Themes WP Event Aggregator wp-event-aggregator allows Reflected XSS.This issue affects WP Event Aggregator: from n/a through <= 1.8.2. | |
| Aplazada | Crítica (9.8) | 1.2% | — | Gabrieleventuri PandasaiAI | 11/2/2025 | 17/6/2026 | PandasAI uses an interactive prompt function that is vulnerable to prompt injection and run arbitrary Python code that can lead to Remote Code Execution (RCE) instead of the intended explanation of the natural language processing by the LLM. | |
| Analizada | Media (6.5) | 0.32% | — | Imithemes Eventer | 3/2/2025 | 17/6/2026 | The Eventer plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'eventer_export_bookings_csv' function in all versions up to, and including, 3.9.9. This makes it possible for authenticated attackers with subscriber-level permissions or above, to download bookings,… |