Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2678▼ 660 respecto a la semana anterior
Críticas / altas1266▼ 293 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
1448 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.57% | — | Themewinter Eventin | 31/12/2024 | 17/6/2026 | Path Traversal: '.../...//' vulnerability in Arraytics Eventin wp-event-solution allows Path Traversal.This issue affects Eventin: from n/a through <= 4.0.7. | |
| Analizada | Media (5.3) | 0.75% | — | Codezips Event Management System | 29/12/2024 | 17/6/2026 | A vulnerability, which was classified as critical, was found in Codezips Event Management System 1.0. Affected is an unknown function of the file /contact.php. The manipulation of the argument title leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and… | |
| Aplazada | Media (6.5) | 1.3% | 💥 PoC | Wp-base Booking OF Appointments Services AND EventsAI | 21/12/2024 | 17/6/2026 | The WP BASE Booking of Appointments, Services and Events plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the export_db function in all versions up to, and including, 4.9.2. This makes it possible for authenticated attackers, with Subscriber-level access and above,… | |
| Analizada | Media (4.3) | 0.39% | — | Nicheaddons Events Addon FOR Elementor | 18/12/2024 | 17/6/2026 | The Events Addon for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.2.3 via the naevents_elementor_template shortcode due to insufficient restrictions on which posts can be included. This makes it possible for authenticated attackers, with Contributor-level… | |
| Modificada | Media (6.1) | 0.42% | — | Metagauss Eventprime | 17/12/2024 | 17/6/2026 | The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the em_ticket_category_data and em_ticket_individual_data parameters in all versions up to, and including, 4.0.7.3 due to insufficient input sanitization and output escaping. This makes it… | |
| Analizada | Media (5.3) | 1.1% | 💥 Exploit | Stellarwp THE Events Calendar | 16/12/2024 | 17/6/2026 | The Events Calendar WordPress plugin before 6.8.2.1 is missing access checks in the REST API, allowing for unauthenticated users to access information about password protected events. | |
| Aplazada | Media (6.1) | 0.37% | — | Import Eventbrite EventsAI | 14/12/2024 | 17/6/2026 | The Import Eventbrite Events plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, 1.7.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in… | |
| Aplazada | Media (6.5) | 0.33% | — | Christer F Hello Event Widgets FOR ElementorAI | 13/12/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in christer_f Hello Event Widgets For Elementor hello-event-widgets-for-elementor allows DOM-Based XSS.This issue affects Hello Event Widgets For Elementor: from n/a through <= 1.0.2. | |
| Modificada | Media (5.4) | 0.41% | — | Nicheaddons Events Addon FOR Elementor | 13/12/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in nicheaddons Events Addon for Elementor events-addon-for-elementor allows DOM-Based XSS.This issue affects Events Addon for Elementor: from n/a through <= 2.2.2. | |
| Aplazada | Media (5.3) | 0.63% | — | Theeventscalendar THE Events CalendarAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in The Events Calendar The Events Calendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects The Events Calendar: from n/a through 6.1.2.2. | |
| Aplazada | Media (6.4) | 0.36% | — | ADD Infos TO THE Events CalendarAI | 12/12/2024 | 17/6/2026 | The Add infos to the events calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'fuss' shortcode in all versions up to, and including, 1.4.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Aplazada | Crítica (9.8) | 0.78% | — | Seventhqueen Sweet DateAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in SeventhQueen Sweet Date sweetdate allows Privilege Escalation.This issue affects Sweet Date: from n/a through <= 3.7.3. | |
| Modificada | Alta (8.8) | 0.59% | — | Themewinter Eventin | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Arraytics Eventin wp-event-solution allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Eventin: from n/a through <= 3.3.52. | |
| Aplazada | Media (5.3) | 0.66% | — | Fullworksplugins Quick Event ManagerAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Fullworks Quick Event Manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Quick Event Manager: from n/a through 9.7.4. | |
| Aplazada | Baja (3.8) | 0.47% | — | Codepeople CP Multi View Event CalendarAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in CodePeople CP Multi View Event Calendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CP Multi View Event Calendar : from n/a through 1.4.13. | |
| Analizada | Media (5.4) | 0.23% | — | IBM Qradar Security Information AND Event Manager | 7/12/2024 | 17/6/2026 | IBM QRadar SIEM 7.5 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Aplazada | Media (5.4) | 0.31% | — | Vollstart Event Tickets With Ticket ScannerAI | 6/12/2024 | 17/6/2026 | The Event Tickets with Ticket Scanner plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data' parameters in all versions up to, and including, 2.4.4 due to insufficient input sanitization and output escaping and missing authorization on the functionality to manage tickets. This makes it… | |
| Aplazada | Media (6.5) | 0.31% | — | Stachethemes Advanced Event ManagerAI | 2/12/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Stachethemes Advanced Event Manager advanced-event-manager allows Stored XSS.This issue affects Advanced Event Manager: from n/a through <= 1.1.6. | |
| Aplazada | Alta (7.1) | 0.33% | — | Explara EventsAI | 2/12/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Explara Explara Events explara-events allows Reflected XSS.This issue affects Explara Events: from n/a through <= 0.1.3. | |
| Aplazada | Media (6.5) | 0.32% | — | Simpul Events BY EsotechAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in geilt Simpul Events by Esotech simpul-events-by-esotech allows Stored XSS.This issue affects Simpul Events by Esotech: from n/a through <= 1.8.5. | |
| Aplazada | Media (6.5) | 0.30% | — | Duogeek EventpressAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DuoGeek EventPress wp-eventpress allows Stored XSS.This issue affects EventPress: from n/a through <= 1.0.0. | |
| Aplazada | Alta (7.1) | 0.41% | — | Jerin K Alexander Events Manager PRO ExtendedAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jerin K Alexander Events Manager Pro – extended events-manager-pro-extended allows Reflected XSS.This issue affects Events Manager Pro – extended: from n/a through <= 0.1. | |
| Modificada | Alta (8.8) | 0.74% | — | Vollstart Event Tickets With Ticket Scanner | 18/11/2024 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Vollstart Event Tickets with Ticket Scanner event-tickets-with-ticket-scanner allows Server Side Include (SSI) Injection.This issue affects Event Tickets with Ticket Scanner: from n/a through <= 2.3.11. | |
| Analizada | Alta (7.5) | 1.4% | — | Cisco Cyber VisionCisco Secure Firewall Threat DefenseCisco Unified Threat Defense Snort Intrusion Prevention System Engine | 15/11/2024 | 11/8/2026 | A vulnerability in the Modbus preprocessor of the Snort detection engine could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to an integer overflow while processing Modbus traffic. An attacker could exploit this vulnerability by… | |
| Analizada | Crítica (9.6) | 0.69% | — | Roundupwp Registrations FOR THE Events Calendar | 8/11/2024 | 17/6/2026 | The Registrations for the Events Calendar WordPress plugin before 2.12.4 does not sanitise and escape some parameters when accepting event registrations, which could allow unauthenticated users to perform Cross-Site Scripting attacks. |