Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
–

95 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.8)0.64%—Puneethreddyhc Event Management7/4/202417/6/2026
A vulnerability was found in PuneethReddyHC Event Management 1.0. It has been rated as critical. This issue affects some unknown processing of the file /backend/register.php. The manipulation of the argument event_id/full_name/email/mobile/college/branch leads to sql injection. The attack may be initiated remotely.…
ModificadaAlta (8.8)0.48%—Derhansen Event Management AND Registration13/2/202417/6/2026
sf_event_mgt is an event management and registration extension for the TYPO3 CMS based on ExtBase and Fluid. In affected versions the existing access control check for events in the backend module got broken during the update of the extension to TYPO3 12.4, because the `RedirectResponse` from the `$this->redirect()`…
ModificadaAlta (8.8)0.73%—Calendar Event Management System Project Calendar Event Management System4/2/202317/6/2026
A vulnerability, which was classified as critical, was found in Calendar Event Management System 2.3.0. This affects an unknown part. The manipulation of the argument start/end leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The…
ModificadaCrítica (9.8)0.88%—Calendar Event Management System Project Calendar Event Management System3/2/202317/6/2026
A vulnerability was found in Calendar Event Management System 2.3.0. It has been rated as critical. This issue affects some unknown processing of the component Login Page. The manipulation of the argument name/pwd leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the…
ModificadaMedia (6.1)0.66%—Event Management System Project Event Management System7/1/202317/6/2026
A vulnerability classified as problematic has been found in SourceCodester Royale Event Management System 1.0. Affected is an unknown function of the file /royal_event/companyprofile.php. The manipulation of the argument companyname/regno/companyaddress/companyemail leads to cross site scripting. It is possible to…
ModificadaCrítica (9.8)1.00%—Event Management System Project Event Management System7/1/202317/6/2026
A vulnerability was found in SourceCodester Royale Event Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /royal_event/userregister.php. The manipulation leads to improper authentication. The attack may be initiated remotely. The identifier VDB-195785 was…
ModificadaAlta (7.2)1.3%—Event Management System Project Event Management System15/9/202217/6/2026
Event Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via the component /Royal_Event/update_image.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
ModificadaAlta (8.8)57%💥 ExploitEvent Management System Project Event Management System5/5/202217/6/2026
Royal Event Management System v1.0 was discovered to contain a SQL injection vulnerability via the todate parameter.
ModificadaMedia (5.3)4.2%💥 ExploitWpchill Rsvp AND Event Management18/4/202217/6/2026
The RSVP and Event Management Plugin WordPress plugin before 2.7.8 does not have any authorisation checks when exporting its entries, and has the export function hooked to the init action. As a result, unauthenticated attackers could call it and retrieve PII such as first name, last name and email address of user…
ModificadaMedia (6.1)0.75%—Event Management Project Event Management2/3/202217/6/2026
Event Management v1.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the full_name parameter under register.php.
ModificadaMedia (4.3)0.77%—Derhansen Event Management AND Registration2/9/202017/6/2026
The sf_event_mgt (aka Event management and registration) extension before 4.3.1 and 5.x before 5.1.1 for TYPO3 allows Information Disclosure (participant data, and event data via email) because of Broken Access Control.
ModificadaCrítica (9.8)3.2%💥 ExploitSchool Event Management System Project School Event Management System16/11/201817/6/2026
School Event Management System 1.0 has SQL Injection via the student/index.php or event/index.php id parameter.
ModificadaAlta (8.8)2.4%💥 ExploitSchool Event Management System Project School Event Management System16/11/201817/6/2026
School Event Management System 1.0 allows CSRF via user/controller.php?action=edit.
ModificadaCrítica (9.8)9.5%💥 ExploitSchool Event Management System Project School Event Management System16/11/201817/6/2026
School Event Management System 1.0 allows Arbitrary File Upload via event/controller.php?action=photos.
ModificadaMedia (4.4)0.32%—Mcafee Security Information AND Event Management5/1/201717/6/2026
Authentication bypass vulnerability in Enterprise Security Manager (ESM) and License Manager (LM) in Intel Security McAfee Security Information and Event Management (SIEM) 9.6.0 MR3 allows an administrator to make changes to other SIEM users' information including user passwords without supplying the current…
ModificadaMedia (6.1)0.64%—Alienvault Open Source Security Information AND Event ManagementAlienvault Unified Security Management28/10/201617/6/2026
Multiple GET parameters in the vulnerability scan scheduler of AlienVault OSSIM and USM before 5.3.2 are vulnerable to reflected XSS.
ModificadaCrítica (9.8)57%💥 ExploitAlienvault Open Source Security Information AND Event ManagementAlienvault Unified Security Management28/10/201617/6/2026
A vulnerability exists in gauge.php of AlienVault OSSIM and USM before 5.3.2 that allows an attacker to execute an arbitrary SQL query and retrieve database information or read local system files via MySQL's LOAD_FILE.
ModificadaMedia (6.1)17%💥 ExploitAlienvault Open Source Security Information AND Event ManagementAlienvault Unified Security Management28/10/201617/6/2026
A persistent XSS vulnerability exists in the User-Agent header of the login process of AlienVault OSSIM and USM before 5.3.2 that allows an attacker to steal session IDs of logged in users when the current sessions are viewed by an administrator.
ModificadaCrítica (9.8)6.9%💥 ExploitAlienvault Open Source Security Information AND Event ManagementAlienvault Unified Security Management28/10/201617/6/2026
PHP object injection vulnerabilities exist in multiple widget files in AlienVault OSSIM and USM before 5.3.2. These vulnerabilities allow arbitrary PHP code execution via magic methods in included classes.
ModificadaMedia (5.4)0.92%—Alienvault Open Source Security Information AND Event ManagementAlienvault Unified Security Management26/9/201617/6/2026
Cross-site scripting (XSS) vulnerability in AlienVault OSSIM before 5.3 and USM before 5.3 allows remote attackers to inject arbitrary web script or HTML via the back parameter to ossim/conf/reload.php.