Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
95 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 0.64% | — | Puneethreddyhc Event Management | 7/4/2024 | 17/6/2026 | A vulnerability was found in PuneethReddyHC Event Management 1.0. It has been rated as critical. This issue affects some unknown processing of the file /backend/register.php. The manipulation of the argument event_id/full_name/email/mobile/college/branch leads to sql injection. The attack may be initiated remotely.… | |
| Modificada | Alta (8.8) | 0.48% | — | Derhansen Event Management AND Registration | 13/2/2024 | 17/6/2026 | sf_event_mgt is an event management and registration extension for the TYPO3 CMS based on ExtBase and Fluid. In affected versions the existing access control check for events in the backend module got broken during the update of the extension to TYPO3 12.4, because the `RedirectResponse` from the `$this->redirect()`… | |
| Modificada | Alta (8.8) | 0.73% | — | Calendar Event Management System Project Calendar Event Management System | 4/2/2023 | 17/6/2026 | A vulnerability, which was classified as critical, was found in Calendar Event Management System 2.3.0. This affects an unknown part. The manipulation of the argument start/end leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The… | |
| Modificada | Crítica (9.8) | 0.88% | — | Calendar Event Management System Project Calendar Event Management System | 3/2/2023 | 17/6/2026 | A vulnerability was found in Calendar Event Management System 2.3.0. It has been rated as critical. This issue affects some unknown processing of the component Login Page. The manipulation of the argument name/pwd leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the… | |
| Modificada | Media (6.1) | 0.66% | — | Event Management System Project Event Management System | 7/1/2023 | 17/6/2026 | A vulnerability classified as problematic has been found in SourceCodester Royale Event Management System 1.0. Affected is an unknown function of the file /royal_event/companyprofile.php. The manipulation of the argument companyname/regno/companyaddress/companyemail leads to cross site scripting. It is possible to… | |
| Modificada | Crítica (9.8) | 1.00% | — | Event Management System Project Event Management System | 7/1/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Royale Event Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /royal_event/userregister.php. The manipulation leads to improper authentication. The attack may be initiated remotely. The identifier VDB-195785 was… | |
| Modificada | Alta (7.2) | 1.3% | — | Event Management System Project Event Management System | 15/9/2022 | 17/6/2026 | Event Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via the component /Royal_Event/update_image.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file. | |
| Modificada | Alta (8.8) | 57% | 💥 Exploit | Event Management System Project Event Management System | 5/5/2022 | 17/6/2026 | Royal Event Management System v1.0 was discovered to contain a SQL injection vulnerability via the todate parameter. | |
| Modificada | Media (5.3) | 4.2% | 💥 Exploit | Wpchill Rsvp AND Event Management | 18/4/2022 | 17/6/2026 | The RSVP and Event Management Plugin WordPress plugin before 2.7.8 does not have any authorisation checks when exporting its entries, and has the export function hooked to the init action. As a result, unauthenticated attackers could call it and retrieve PII such as first name, last name and email address of user… | |
| Modificada | Media (6.1) | 0.75% | — | Event Management Project Event Management | 2/3/2022 | 17/6/2026 | Event Management v1.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the full_name parameter under register.php. | |
| Modificada | Media (4.3) | 0.77% | — | Derhansen Event Management AND Registration | 2/9/2020 | 17/6/2026 | The sf_event_mgt (aka Event management and registration) extension before 4.3.1 and 5.x before 5.1.1 for TYPO3 allows Information Disclosure (participant data, and event data via email) because of Broken Access Control. | |
| Modificada | Crítica (9.8) | 3.2% | 💥 Exploit | School Event Management System Project School Event Management System | 16/11/2018 | 17/6/2026 | School Event Management System 1.0 has SQL Injection via the student/index.php or event/index.php id parameter. | |
| Modificada | Alta (8.8) | 2.4% | 💥 Exploit | School Event Management System Project School Event Management System | 16/11/2018 | 17/6/2026 | School Event Management System 1.0 allows CSRF via user/controller.php?action=edit. | |
| Modificada | Crítica (9.8) | 9.5% | 💥 Exploit | School Event Management System Project School Event Management System | 16/11/2018 | 17/6/2026 | School Event Management System 1.0 allows Arbitrary File Upload via event/controller.php?action=photos. | |
| Modificada | Media (4.4) | 0.32% | — | Mcafee Security Information AND Event Management | 5/1/2017 | 17/6/2026 | Authentication bypass vulnerability in Enterprise Security Manager (ESM) and License Manager (LM) in Intel Security McAfee Security Information and Event Management (SIEM) 9.6.0 MR3 allows an administrator to make changes to other SIEM users' information including user passwords without supplying the current… | |
| Modificada | Media (6.1) | 0.64% | — | Alienvault Open Source Security Information AND Event ManagementAlienvault Unified Security Management | 28/10/2016 | 17/6/2026 | Multiple GET parameters in the vulnerability scan scheduler of AlienVault OSSIM and USM before 5.3.2 are vulnerable to reflected XSS. | |
| Modificada | Crítica (9.8) | 57% | 💥 Exploit | Alienvault Open Source Security Information AND Event ManagementAlienvault Unified Security Management | 28/10/2016 | 17/6/2026 | A vulnerability exists in gauge.php of AlienVault OSSIM and USM before 5.3.2 that allows an attacker to execute an arbitrary SQL query and retrieve database information or read local system files via MySQL's LOAD_FILE. | |
| Modificada | Media (6.1) | 17% | 💥 Exploit | Alienvault Open Source Security Information AND Event ManagementAlienvault Unified Security Management | 28/10/2016 | 17/6/2026 | A persistent XSS vulnerability exists in the User-Agent header of the login process of AlienVault OSSIM and USM before 5.3.2 that allows an attacker to steal session IDs of logged in users when the current sessions are viewed by an administrator. | |
| Modificada | Crítica (9.8) | 6.9% | 💥 Exploit | Alienvault Open Source Security Information AND Event ManagementAlienvault Unified Security Management | 28/10/2016 | 17/6/2026 | PHP object injection vulnerabilities exist in multiple widget files in AlienVault OSSIM and USM before 5.3.2. These vulnerabilities allow arbitrary PHP code execution via magic methods in included classes. | |
| Modificada | Media (5.4) | 0.92% | — | Alienvault Open Source Security Information AND Event ManagementAlienvault Unified Security Management | 26/9/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in AlienVault OSSIM before 5.3 and USM before 5.3 allows remote attackers to inject arbitrary web script or HTML via the back parameter to ossim/conf/reload.php. |