Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

323 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.1)1.2%—Adobe CommerceAdobe Commerce B2BAdobe MagentoAdobe I/O Events14/7/202628/8/2026
Adobe Commerce is affected by an Improper Encoding or Escaping of Output vulnerability that could result in arbitrary code execution in the context of the current user. An attacker with high privileges could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user…
AnalizadaCrítica (9.3)1.0%💥 PoCAdobe CommerceAdobe Commerce B2BAdobe MagentoAdobe I/O Events14/7/202628/8/2026
Adobe Commerce is affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution in the context of the current user, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue requires user interaction in…
AnalizadaBaja (3.7)0.51%—Adobe CommerceAdobe Commerce B2BAdobe MagentoAdobe I/O Events14/7/202628/8/2026
Adobe Commerce is affected by an Information Exposure vulnerability that could lead to a limited disclosure of sensitive information. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user interaction.
AnalizadaMedia (6.1)0.46%—Adobe CommerceAdobe Commerce B2BAdobe MagentoAdobe I/O Events14/7/202628/8/2026
Adobe Commerce is affected by an Improper Redirect (Open Redirect) vulnerability that could result in a Security feature bypass. An attacker could construct a malicious URL that redirects a victim to an attacker-controlled site. Exploitation of this issue requires user interaction in that a victim must click on a…
AnalizadaMedia (4.8)0.41%—Adobe CommerceAdobe Commerce B2BAdobe MagentoAdobe I/O Events14/7/202628/8/2026
Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is…
AnalizadaMedia (5.9)0.71%—Adobe CommerceAdobe Commerce B2BAdobe MagentoAdobe I/O Events14/7/202628/8/2026
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue…
AnalizadaMedia (5.9)0.71%—Adobe CommerceAdobe Commerce B2BAdobe MagentoAdobe I/O Events14/7/202628/8/2026
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue…
AnalizadaMedia (6.8)0.88%—Adobe CommerceAdobe Commerce B2BAdobe MagentoAdobe I/O Events14/7/202628/8/2026
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could lead to arbitrary file system read. A high-privileged attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue does not require user interaction.…
AnalizadaAlta (8.1)0.71%—Adobe CommerceAdobe Commerce B2BAdobe MagentoAdobe I/O Events14/7/202628/8/2026
Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field,…
AnalizadaAlta (8.7)0.70%—Adobe CommerceAdobe Commerce B2BAdobe MagentoAdobe I/O Events14/7/202628/8/2026
Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially…
AnalizadaAlta (7.2)0.99%—Adobe CommerceAdobe Commerce B2BAdobe MagentoAdobe I/O Events14/7/202628/8/2026
Adobe Commerce is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A high-privileged attacker could exploit this vulnerability to execute malicious SQL commands,…
AnalizadaAlta (8.6)0.76%—Adobe CommerceAdobe Commerce B2BAdobe MagentoAdobe I/O Events14/7/202628/8/2026
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read and limited write access, causing a limited disruption to availability. Exploitation of this issue…
AnalizadaAlta (8.2)0.73%—Adobe CommerceAdobe Commerce B2BAdobe MagentoAdobe I/O Events14/7/202628/8/2026
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read and limited write access. Exploitation of this issue does not require user interaction.
AplazadaMedia (5.1)0.30%—Hi.eventsAI14/7/202615/7/2026
Hi.Events before 1.11.0 contains a cross-site scripting vulnerability that allows authenticated attackers with event creation or edit permissions to inject arbitrary HTML and JavaScript by embedding a malicious event title containing the </script> sequence, which is not escaped by JSON.stringify() when embedded in…
AplazadaMedia (6.9)0.40%—Hi.eventsAI14/7/202615/7/2026
Hi.Events before 1.11.0 contains a missing server-side visibility enforcement vulnerability that allows unauthenticated attackers to purchase hidden tickets by referencing hidden product and price IDs in order creation requests without authorization checks. Attackers can enumerate sequential hidden ticket IDs from…
AplazadaAlta (8.8)0.46%—Marcus Events ManagerAI13/7/202613/7/2026
Deserialization of Untrusted Data vulnerability in Marcus (aka @msykes) Events Manager events-manager allows Object Injection.This issue affects Events Manager: from n/a through <= 7.3.6.
AplazadaAlta (8.3)0.43%—Hi.eventsAI29/6/202614/7/2026
Hi.Events through 1.9.0 public check-in list endpoints use short_id as sole access control, allowing unauthenticated access to retrieve full attendee lists including emails and personal information. Attackers with knowledge of the short_id can call GET /api/public/check-in-lists/{short_id}/attendees to read attendee…
AplazadaAlta (8.2)0.26%—HI EventsAI29/6/202614/7/2026
Hi.Events through 1.9.0 contains a promo code validation vulnerability where reservation validates usage count before asynchronous UpdateEventStatisticsJob increments it, allowing attackers to redeem limited promo codes unlimited times. Attackers can sequentially reserve multiple orders with the same restricted promo…
AplazadaAlta (8.5)0.34%—Theeventscalendar THE Events CalendarAI17/6/20266/10/2026
Subscriber SQL Injection in Events Schedule - WordPress Events Calendar Plugin <= 2.7.2 versions.
AplazadaCrítica (9.3)0.45%💥 PoCStellarwp THE Events CalendarAI16/6/202617/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Liquid Web / StellarWP The Events Calendar allows Blind SQL Injection. This issue affects The Events Calendar: from 6.15.12 through 6.16.2.
AplazadaAlta (8.8)0.52%—Geodir Events CalendarAIPHPAI15/6/202617/6/2026
Contributor PHP Object Injection in Events Calendar for GeoDirectory <= 2.3.25 versions.
AplazadaAlta (8.8)0.27%—THE Events Calendar FOR GeodirectoryAI9/6/202623/7/2026
The Events Calendar for GeoDirectory plugin for WordPress is vulnerable to Privilege Escalation in versions up to and including 2.3.28. This is due to the ajax_ayi_action() handler only applying strip_tags(esc_sql()) — with no allow-list — to the attacker-controlled $_POST['type'] and $_POST['postid'] values before…
AplazadaMedia (6.4)0.32%—Events IN CityAI27/5/202617/6/2026
The Events In City plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'org-events' shortcode in versions up to, and including, 3.0. This is due to insufficient input sanitization and output escaping on user supplied attributes (such as 'organizer_id', 'width', 'height', 'transparency', 'header',…
AnalizadaMedia (5.3)0.32%—Rexxars Eventsource-encoder26/5/202624/7/2026
eventsource-encoder encodes events as well-formed EventSource/Server Sent Event (SSE) messages. Prior to 1.0.2, eventsource-encoder does not sanitize the event or id fields of an EventSourceMessage before serializing them. An attacker who controls either field can inject arbitrary Server-Sent Events line terminators…
AplazadaAlta (7.1)0.27%—Redaxo MyeventsAI17/5/202617/6/2026
Redaxo CMS Addon MyEvents 2.2.1 contains an SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the myevents_id parameter. Attackers can send GET requests to the event_add.php page with malicious myevents_id values to extract or modify sensitive…
Orbitaley — Vulnerabilidades