Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2778▼ 418 respecto a la semana anterior
Críticas / altas1332▼ 108 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
1448 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.10% | — | Magepeople WpeventlyAI | 11/6/2026 | 23/7/2026 | Cross-Site request forgery (CSRF) vulnerability in Magepeople inc. WpEvently allows Cross Site Request Forgery. This issue affects WpEvently: from n/a through 4.1.2. | |
| Aplazada | Alta (8.8) | 0.27% | — | THE Events Calendar FOR GeodirectoryAI | 9/6/2026 | 23/7/2026 | The Events Calendar for GeoDirectory plugin for WordPress is vulnerable to Privilege Escalation in versions up to and including 2.3.28. This is due to the ajax_ayi_action() handler only applying strip_tags(esc_sql()) — with no allow-list — to the attacker-controlled $_POST['type'] and $_POST['postid'] values before… | |
| Aplazada | Alta (7.2) | 1.3% | 💥 PoC | Mdjm Event ManagementAI | 6/6/2026 | 23/7/2026 | The MDJM Event Management plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.7.8.3 via the mdjm_send_comm_email function. This is due to no file type, extension, or MIME type validation being performed on uploaded files. This makes it possible for authenticated… | |
| Aplazada | Media (5.3) | 0.22% | — | Awplife Event MonsterAI | 6/6/2026 | 23/7/2026 | The Event Monster – Event Management, Events Calendar, Tickets plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity in versions up to, and including, 2.1.0. This is due to the capture_payment() AJAX handler (registered via wp_ajax_nopriv_em_capture_payment) trusting client-supplied… | |
| Aplazada | Alta (7.5) | 0.35% | — | EventprimeAI | 2/6/2026 | 22/7/2026 | Missing Authorization vulnerability in EventPrime allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects EventPrime: from n/a through 4.3.2.0. | |
| Aplazada | Media (4.3) | 0.38% | — | Motopress Timetable AND Event ScheduleAI | 28/5/2026 | 17/6/2026 | The Timetable and Event Schedule by MotoPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.4.16 via the action_get_event_data due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with contributor-level… | |
| Analizada | Alta (8.8) | 0.46% | — | IBM Qradar Security Information AND Event Manager | 27/5/2026 | 17/6/2026 | IBM QRadar 7.5.0 through 7.5.0 UP15 Interim Fix 002 could allow a privileged user to upload a malicious backup archive that could be restored and used to gain access to the underlying operating system. | |
| Aplazada | Media (6.4) | 0.32% | — | Events IN CityAI | 27/5/2026 | 17/6/2026 | The Events In City plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'org-events' shortcode in versions up to, and including, 3.0. This is due to insufficient input sanitization and output escaping on user supplied attributes (such as 'organizer_id', 'width', 'height', 'transparency', 'header',… | |
| Aplazada | Alta (7.1) | 0.28% | — | EventpressAI | 27/5/2026 | 17/6/2026 | The EventPress WordPress theme before 22.2 does not sanitize or escape the 'id' parameter in the eventpress_customizer_notify_dismiss_action AJAX handler before outputting it back in the response, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting attacks against logged-in users. | |
| Analizada | Media (5.3) | 0.32% | — | Rexxars Eventsource-encoder | 26/5/2026 | 24/7/2026 | eventsource-encoder encodes events as well-formed EventSource/Server Sent Event (SSE) messages. Prior to 1.0.2, eventsource-encoder does not sanitize the event or id fields of an EventSourceMessage before serializing them. An attacker who controls either field can inject arbitrary Server-Sent Events line terminators… | |
| Aplazada | Media (5.3) | 0.29% | — | Wpchill Rsvp AND Event ManagementAI | 25/5/2026 | 20/7/2026 | Missing Authorization vulnerability in WP Chill RSVP and Event Management allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects RSVP and Event Management: from n/a through 2.7.16. | |
| Analizada | Alta (8.6) | 0.14% | — | Gallagher Active Directory SyncGallagher Cardholder Sync UtilityGallagher Command CentreGallagher Diagnostics Service+11 | 25/5/2026 | 17/8/2026 | Insertion of Sensitive Information into Log File (CWE-532) in some Command Centre Service installers could lead to Service Account credentials exposure. Mitigating Factor: Only sites that install Command Centre Services with a custom Service Account (not the default Network Service account) are potentially impacted.… | |
| Aplazada | Alta (7.1) | 0.27% | — | Redaxo MyeventsAI | 17/5/2026 | 17/6/2026 | Redaxo CMS Addon MyEvents 2.2.1 contains an SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the myevents_id parameter. Attackers can send GET requests to the event_add.php page with malicious myevents_id values to extract or modify sensitive… | |
| Aplazada | Alta (8.2) | 0.60% | — | Easy Paypal Events TicketsAI | 4/5/2026 | 17/6/2026 | The Easy PayPal Events & Tickets plugin for WordPress before version 1.4 contains an information disclosure vulnerability in the QR code scanning endpoint that allows unauthenticated attackers to enumerate and retrieve all customer order records. Attackers can iterate over sequential WordPress post IDs through the… | |
| Aplazada | Alta (8.7) | 0.79% | — | Easy Paypal Events AND TicketsAI | 4/5/2026 | 17/6/2026 | Easy PayPal Events & Tickets plugin for WordPress before version 1.4 contains a hardcoded authentication bypass vulnerability in the QR code scanning functionality that allows unauthenticated remote attackers to bypass hash verification by supplying 'test' as the hash parameter. Attackers can access the vulnerable… | |
| Aplazada | Media (4.3) | 0.28% | — | Themewinter EventinAI | 14/4/2026 | 17/6/2026 | The Eventin – Events Calendar, Event Booking, Ticket & Registration (AI Powered) plugin for WordPress is vulnerable to unauthorized access of data due to a improper capability check on the get_item_permissions_check() function in all versions up to, and including, 4.1.8. This makes it possible for authenticated… | |
| Aplazada | Media (5.3) | 0.33% | — | Wpchill Rsvp AND Event ManagementAI | 8/4/2026 | 24/7/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in WP Chill RSVP and Event Management rsvp allows Retrieve Embedded Sensitive Data.This issue affects RSVP and Event Management: from n/a through <= 2.7.16. | |
| Aplazada | Media (5.3) | 0.26% | — | Fullworks Display Eventbrite EventsAI | 8/4/2026 | 24/7/2026 | Missing Authorization vulnerability in fullworks Display Eventbrite Events widget-for-eventbrite-api allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Display Eventbrite Events: from n/a through <= 6.5.6. | |
| Pendiente de análisis | Media (6.9) | 0.45% | — | Wikimedia MediawikiAIWikimedia CampaigneventsAI | 7/4/2026 | 21/7/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - CampaignEvents Extension allows Cross-Site Scripting (XSS). This issue was remediated only on the `master` branch. | |
| Analizada | Alta (8.7) | 0.55% | — | Hi.events | 1/4/2026 | 17/6/2026 | Hi.Events is an open-source event management and ticket selling platform. From version 0.8.0-beta.1 to before version 1.7.1-beta, multiple repository classes pass the user-supplied sort_by query parameter directly to Eloquent's orderBy() without validation, enabling SQL injection. The application uses PostgreSQL which… | |
| Analizada | Alta (7.3) | 0.30% | — | Gabrieleventuri Pandasai | 1/4/2026 | 17/6/2026 | pandas-ai v3.0.0 was discovered to contain a SQL injection vulnerability via the pandasai.agent.base._execute_sql_query component. | |
| Pendiente de análisis | Alta (7.7) | 0.53% | — | Amazon C-event-streamAI | 31/3/2026 | 24/7/2026 | Out-of-bounds write in the streaming decoder component in aws-c-event-stream before 0.6.0 might allow a third party operating a server to cause memory corruption leading to arbitrary code execution on a client application that processes crafted event-stream messages. To remediate this issue, users should upgrade to… | |
| Pendiente de análisis | Alta (7.8) | 0.16% | — | Symantec Data Loss Prevention Windows EndpointAI | 30/3/2026 | 17/6/2026 | Symantec Data Loss Prevention Windows Endpoint, prior to 25.1 MP1, 16.1 MP2, 16.0 RU2 HF9, 16.0 RU1 MP1 HF12, and 16.0 MP2 HF15, may be susceptible to a Elevation of Privilege vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to… | |
| Aplazada | Media (5.5) | 0.67% | — | Gabrieleventuri PandasaiAI | 28/3/2026 | 17/6/2026 | A weakness has been identified in Sinaptik AI PandasAI up to 3.0.0. This vulnerability affects the function CodeExecutor.execute of the file pandasai/core/code_execution/code_executor.py of the component Chat Message Handler. Executing a manipulation can lead to code injection. The attack may be launched remotely. The… | |
| Aplazada | Media (5.5) | 0.77% | — | Gabrieleventuri PandasaiAI | 28/3/2026 | 17/6/2026 | A security flaw has been discovered in Sinaptik AI PandasAI up to 3.0.0. This affects the function is_sql_query_safe of the file pandasai/helpers/sql_sanitizer.py. Performing a manipulation results in path traversal. The attack may be initiated remotely. The exploit has been released to the public and may be used for… |