Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

1447 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.4)0.23%—Event Booking ManagerAI2/8/202626/8/2026
The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not properly verify authorization on the object being modified when quick-editing events, only checking a global capability, allowing users with the Contributor role and above to modify the title and publication status of arbitrary posts and…
AplazadaMedia (5.4)0.23%—Event Booking ManagerAI2/8/202626/8/2026
The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not sanitise or escape event timeline content submitted by users with post-editing access before storing it and rendering it on the public event page, allowing users with the Author role and above to inject arbitrary JavaScript that executes…
AplazadaMedia (6.6)0.59%—Event Booking ManagerAI2/8/202626/8/2026
The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not prevent the deserialization of user-controlled input in some of its event content fields, allowing users with Contributor-level access and above to inject PHP objects. No POP chain is present in the Event Booking Manager for WooCommerce…
AplazadaBaja (2.2)0.23%—Event Tickets AND RegistrationAI1/8/202626/8/2026
The Event Tickets and Registration WordPress plugin before 5.29.0.1 does not properly verify authorization on some of its seating actions, allowing users with contributor-level access and above to overwrite the seating layout, ticket inventory, and attendee seat assignments of events they do not own.
AplazadaMedia (5.3)0.30%—Eventbrite Event TicketsAI1/8/202626/8/2026
The Event Tickets and Registration WordPress plugin before 5.29.0.1 does not perform any authorization check on one of its order-management REST endpoints, allowing unauthenticated users to change the status of existing orders.
AplazadaBaja (2.7)0.28%—Booking FOR Appointments AND Events CalendarAI1/8/202626/8/2026
The Booking for Appointments and Events Calendar WordPress plugin before 2.4.4 does not restrict which fields can be written through its customer import, allowing a user with the Amelia Manager role to modify arbitrary columns of any stored user record by supplying them in the import request.
AplazadaMedia (5.3)0.30%—E-dynamics Events Made EasyAI31/7/202626/8/2026
The Events Made Easy WordPress plugin before 3.1.4 does not verify that the requester is authorized to modify the targeted record when handling an unauthenticated data-change request, relying only on a public nonce with no per-record token or ownership check, allowing unauthenticated attackers to overwrite the…
AplazadaAlta (7.5)0.36%—Themewinter EventinAI30/7/202630/7/2026
The Eventin WordPress plugin before 4.1.16 does not properly authorize order creation and accepts an attacker-supplied order status, allowing unauthenticated users to create orders marked as paid without completing any payment.
AplazadaMedia (4.3)0.40%—Eventbooking Event Booking Manager FOR WoocommerceAI29/7/202630/7/2026
The Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP & Event Calendar plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.3.7. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it…
AplazadaBaja (3.5)0.24%—Eventtickets Event TicketsAI28/7/202628/7/2026
The Event Tickets and Registration WordPress plugin before 5.28.4 does not properly escape event titles before outputting them in a ticket history log, allowing users with the Editor role and above to perform Stored Cross-Site Scripting attacks that execute against higher-privileged users on multisite installations.
Pendiente de análisisAlta (7.5)0.28%—Event Driven AnsibleAI27/7/20264/8/2026
A flaw was found in the Event-Driven Ansible (EDA) server. The ExternalEventStreamViewSet uses permissive access controls (permission_classes=[AllowAny], authentication_classes=[]) and relies solely on the Subject HTTP header value for mTLS authentication without verifying that the header originated from a trusted…
AplazadaMedia (5.3)0.29%—Event TicketsAI27/7/202627/7/2026
Unauthenticated Broken Access Control in Event Tickets <= 5.29.0.1 versions.
AplazadaMedia (6.5)0.33%—E-dynamics Events Made EasyAI27/7/202627/7/2026
Unauthenticated Broken Access Control in Events Made Easy <= 3.1.3 versions.
AplazadaMedia (5.3)0.30%—Theeventscalendar THE Events CalendarAI27/7/202627/7/2026
The Events Calendar WordPress plugin before 6.16.5.1 does not perform an authorization check on one of its Event Aggregator import REST API routes and skips an integrity check for a particular status value, allowing unauthenticated attackers to mark existing import records as failed and to store arbitrary content in a…
AplazadaAlta (7.3)0.34%—Eventeon Action UserAI24/7/202624/7/2026
The EventON Action User plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.5.14. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to grant EventON management capabilities…
AplazadaMedia (5.3)0.31%—EventAI23/7/202623/7/2026
Unauthenticated Broken Access Control in Event post <= 6.0.1 versions.
AplazadaAlta (8.8)0.70%—Mdjm Event ManagementAI23/7/202623/7/2026
The MDJM Event Management plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.7.8.4. This is due to missing capability checks and nonce verification in the `MDJM_Permissions::set_permissions()` and `MDJM_Employee_Manager::init()` functions, combined with the absence of…
AplazadaMedia (6.5)0.41%—Roundupwp Registrations FOR THE Events CalendarAI23/7/202623/7/2026
The Registrations For The Events Calendar plugin for WordPress is vulnerable to SQL Injection via JSON keys in the 'standard' parameter handled by the rtec_records_edit AJAX action in versions up to and including 3.2. The handler decodes attacker-controlled JSON from $_POST['standard'] and uses the JSON array keys…
AplazadaAlta (7.5)0.39%—Joomdonation Events BookingAI22/7/202623/7/2026
Joomla Extension - joomdonation.com - Invoice data exfiltration via incorrect ACL check in Events Booking 5.0.0-5.8.1 - The Joomla extension Events Booking prior version 5.0-5.8.1 did not properly verify that an actor is allowed to download invoice information.
AplazadaAlta (7.5)0.45%—Events ManagerAI22/7/202622/7/2026
The Events Manager WordPress plugin before 7.3.7 does not safely handle booking-registration data on sites using No-User-Account Booking Mode: a booker-supplied registration field is stored as booking meta and later deserialized without restricting allowed classes, enabling PHP object injection. The resulting gadget…
AnalizadaMedia (4.2)0.20%—Hcltech Intelliops Event Management21/7/202630/7/2026
HCL IEM was affected with X-Content-Type-Options Header Missing. It may enable attackers to perform SSL stripping or man-in-the-middle attacks and intercept sensitive data.
AnalizadaMedia (4.3)0.25%—Hcltech Intelliops Event Management21/7/202630/7/2026
HCL IEM was affected with the Anti Clickjacking XFrame Options Header Missing. It may allow attackers to embed the application in malicious pages and induce unauthorized user actions.
AnalizadaBaja (3.7)0.24%—Hcltech Intelliops Event Management21/7/202630/7/2026
HCL IEM was affected with Strict transport security not enforced. It may enable attackers to perform SSL stripping or man-in-the-middle attacks and compromise secure communications.
AnalizadaMedia (5.3)0.29%—Hcltech Intelliops Event Management21/7/202630/7/2026
HCL IEM was affected with the Information disclosure nginx server. It may enable attackers to identify outdated software versions and target known vulnerabilities or publicly available exploits.
AplazadaAlta (8.6)0.45%💥 PoCModern Event Calendar PROAIModern Event Calendar LiteAI20/7/202620/7/2026
The Modern Event Calendar Pro WordPress plugin before 7.34.0, Modern Events Calendar Lite WordPress plugin before 7.34.0 do not sanitise and escape a request parameter before using it in a SQL statement, through an AJAX action available to unauthenticated users, leading to an unauthenticated SQL injection…
Orbitaley — Vulnerabilidades