Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 554 respecto a la semana anterior
Críticas / altas1325▼ 178 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 242 respecto a la semana anterior
–

1447 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.7)0.52%—Open Event ServerAI17/7/202617/7/2026
Open Event Server through 1.19.1 contains a missing authentication vulnerability that allows unauthenticated attackers to export the complete member roster of any group, including email addresses, names, join dates, and roles, by submitting requests to the group followers CSV export endpoint which lacks any…
AplazadaAlta (8.8)0.20%—Joomdonation Events BookingAI17/7/202623/7/2026
Joomla Extension - joomdonation.com - User enumeration in Events Booking < 5.8.0 - The Joomla extension Events Booking prior version 5.8.0 had an frontend file upload endpoint that lacked CSRF protection.
AplazadaCrítica (9.8)0.55%—Joomdonation Events BookingAI17/7/202623/7/2026
Joomla Extension - joomdonation.com - Insecure default configuration Events Booking < 5.8.0 - The Joomla extension Events Booking prior version 5.8.0 did by default allow unauthenticated users to upload media assets.
AplazadaMedia (5.3)0.34%—Joomdonation Events BookingAI17/7/202623/7/2026
Joomla Extension - joomdonation.com - User enumeration in Events Booking < 5.8.0 - The Joomla extension Events Booking is vulnerable to an unauthenticated user enumeration that allows to retrieve account usernames and email addresses.
AnalizadaMedia (5.4)0.39%—Adobe CommerceAdobe Commerce B2BAdobe MagentoAdobe I/O Events14/7/202628/8/2026
Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is…
AnalizadaCrítica (9.1)1.2%—Adobe CommerceAdobe Commerce B2BAdobe MagentoAdobe I/O Events14/7/202628/8/2026
Adobe Commerce is affected by an Improper Encoding or Escaping of Output vulnerability that could result in arbitrary code execution in the context of the current user. An attacker with high privileges could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user…
AnalizadaCrítica (9.3)1.0%💥 PoCAdobe CommerceAdobe Commerce B2BAdobe MagentoAdobe I/O Events14/7/202628/8/2026
Adobe Commerce is affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution in the context of the current user, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue requires user interaction in…
AnalizadaBaja (3.7)0.51%—Adobe CommerceAdobe Commerce B2BAdobe MagentoAdobe I/O Events14/7/202628/8/2026
Adobe Commerce is affected by an Information Exposure vulnerability that could lead to a limited disclosure of sensitive information. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user interaction.
AnalizadaMedia (6.1)0.46%—Adobe CommerceAdobe Commerce B2BAdobe MagentoAdobe I/O Events14/7/202628/8/2026
Adobe Commerce is affected by an Improper Redirect (Open Redirect) vulnerability that could result in a Security feature bypass. An attacker could construct a malicious URL that redirects a victim to an attacker-controlled site. Exploitation of this issue requires user interaction in that a victim must click on a…
AnalizadaMedia (4.8)0.41%—Adobe CommerceAdobe Commerce B2BAdobe MagentoAdobe I/O Events14/7/202628/8/2026
Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is…
AnalizadaMedia (5.9)0.71%—Adobe CommerceAdobe Commerce B2BAdobe MagentoAdobe I/O Events14/7/202628/8/2026
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue…
AnalizadaMedia (5.9)0.71%—Adobe CommerceAdobe Commerce B2BAdobe MagentoAdobe I/O Events14/7/202628/8/2026
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue…
AnalizadaMedia (6.8)0.88%—Adobe CommerceAdobe Commerce B2BAdobe MagentoAdobe I/O Events14/7/202628/8/2026
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could lead to arbitrary file system read. A high-privileged attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue does not require user interaction.…
AnalizadaAlta (8.1)0.71%—Adobe CommerceAdobe Commerce B2BAdobe MagentoAdobe I/O Events14/7/202628/8/2026
Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field,…
AnalizadaAlta (8.7)0.70%—Adobe CommerceAdobe Commerce B2BAdobe MagentoAdobe I/O Events14/7/202628/8/2026
Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially…
AnalizadaAlta (7.2)0.99%—Adobe CommerceAdobe Commerce B2BAdobe MagentoAdobe I/O Events14/7/202628/8/2026
Adobe Commerce is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A high-privileged attacker could exploit this vulnerability to execute malicious SQL commands,…
AnalizadaAlta (8.6)0.76%—Adobe CommerceAdobe Commerce B2BAdobe MagentoAdobe I/O Events14/7/202628/8/2026
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read and limited write access, causing a limited disruption to availability. Exploitation of this issue…
AnalizadaAlta (8.2)0.73%—Adobe CommerceAdobe Commerce B2BAdobe MagentoAdobe I/O Events14/7/202628/8/2026
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read and limited write access. Exploitation of this issue does not require user interaction.
AplazadaMedia (5.1)0.30%—Hi.eventsAI14/7/202615/7/2026
Hi.Events before 1.11.0 contains a cross-site scripting vulnerability that allows authenticated attackers with event creation or edit permissions to inject arbitrary HTML and JavaScript by embedding a malicious event title containing the </script> sequence, which is not escaped by JSON.stringify() when embedded in…
AplazadaMedia (6.9)0.40%—Hi.eventsAI14/7/202615/7/2026
Hi.Events before 1.11.0 contains a missing server-side visibility enforcement vulnerability that allows unauthenticated attackers to purchase hidden tickets by referencing hidden product and price IDs in order creation requests without authorization checks. Attackers can enumerate sequential hidden ticket IDs from…
AplazadaAlta (8.8)0.46%—Marcus Events ManagerAI13/7/202613/7/2026
Deserialization of Untrusted Data vulnerability in Marcus (aka @msykes) Events Manager events-manager allows Object Injection.This issue affects Events Manager: from n/a through <= 7.3.6.
AplazadaAlta (7.5)0.35%—Nexcess Event TicketsAI13/7/202613/7/2026
Missing Authorization vulnerability in Nexcess Event Tickets event-tickets allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Event Tickets: from n/a through <= 5.28.5.
AplazadaMedia (6.5)0.33%—Wpswings Event Tickets Manager FOR WoocommerceAI13/7/202613/7/2026
Missing Authorization vulnerability in WP Swings Event Tickets Manager for WooCommerce event-tickets-manager-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Event Tickets Manager for WooCommerce: from n/a through <= 1.5.5.
AplazadaMedia (5.3)0.35%—Themewinter EventinAI10/7/202613/7/2026
The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to authorization bypass due to a regression in versions from 4.0.26 up to and including 4.1.15. This is due to the plugin not properly verifying that a user is authorized to perform an action in the…
AplazadaMedia (6.4)0.36%—Themewinter EventinAI10/7/202610/7/2026
The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'etn_faq_content' parameter in all versions up to, and including, 4.1.15 due to insufficient input sanitization and output escaping. This makes it possible for…
Orbitaley — Vulnerabilidades