Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
324 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.32% | — | Pixelite Events Manager | 9/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Pixelite Events Manager.This issue affects Events Manager: from n/a through 6.4.6.4. | |
| Analizada | Crítica (9.1) | 2.1% | 💥 Exploit | Stellarwp THE Events Calendar | 4/6/2024 | 17/6/2026 | The Events Calendar WordPress plugin before 6.4.0.1 does not properly sanitize user-submitted content when rendering some views via AJAX. | |
| Aplazada | Media (6.5) | 0.48% | — | Theeventscalendar BookitAI | 17/5/2024 | 17/6/2026 | Improper Validation of Specified Quantity in Input vulnerability in The Events Calendar BookIt allows Manipulating Hidden Fields.This issue affects BookIt: from n/a through 2.4.0. | |
| Aplazada | Alta (7.1) | 0.28% | — | WP Hive Events Rich Snippets FOR GoogleAI | 17/5/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WP Hive Events Rich Snippets for Google allows Exploitation of Trusted Credentials.This issue affects Events Rich Snippets for Google: from n/a through 1.8. | |
| Aplazada | Alta (7.5) | 0.48% | — | Safe Software FME Modules EventsmanagerAI | 29/4/2024 | 17/6/2026 | An issue in FME Modules eventsmanager before 4.4.0 allows an attacker to obtain sensitive information from the ps_customer component. | |
| Aplazada | Media (4.3) | 0.20% | — | Stellarwp THE Events CalendarAI | 15/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in StellarWP The Events Calendar the-events-calendar.This issue affects The Events Calendar: from n/a through <= 6.3.0. | |
| Aplazada | Media (4.3) | 0.21% | — | Churchthemes Church Content Sermons Events AND MoreAI | 15/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in ChurchThemes Church Content – Sermons, Events and More.This issue affects Church Content – Sermons, Events and More: from n/a through 2.6. | |
| Modificada | Media (6.1) | 0.35% | — | Wpgoaltracker WP Google Analytics Events | 15/4/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PineWise WP Google Analytics Events allows Reflected XSS.This issue affects WP Google Analytics Events: from n/a through 2.8.0. | |
| Analizada | Media (5.4) | 0.42% | — | Wpeventsmanager User Profile Avatar | 15/4/2024 | 17/6/2026 | The WP User Profile Avatar WordPress plugin through 1.0.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks | |
| Aplazada | Media (4.3) | 0.21% | — | Pixelite Events ManagerAI | 28/3/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Pixelite Events Manager.This issue affects Events Manager: from n/a through 6.4.7.1. | |
| Modificada | Media (5.4) | 0.34% | — | Pixelite Events Manager | 28/3/2024 | 17/6/2026 | The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the physical location value in all versions up to, and including, 6.4.7.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with… | |
| Modificada | Media (4.3) | 0.21% | — | Pixelite Events Manager | 28/3/2024 | 17/6/2026 | The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.4.7.1. This is due to missing or incorrect nonce validation on several actions. This makes it possible for unauthenticated attackers to modify booking… | |
| Modificada | Media (4.8) | 0.68% | — | Pixelite Events Manager | 13/3/2024 | 17/6/2026 | The Events Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 6.4.6.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject… | |
| Analizada | Alta (7.5) | 0.66% | — | Cloudevents GO SDK | 6/3/2024 | 17/6/2026 | Go SDK for CloudEvents is the official CloudEvents SDK to integrate applications with CloudEvents. Prior to version 2.15.2, using cloudevents.WithRoundTripper to create a cloudevents.Client with an authenticated http.RoundTripper causes the go-sdk to leak credentials to arbitrary endpoints. When the transport is… | |
| Analizada | Media (4.9) | 0.61% | — | Kurrent Eventstoredb | 21/2/2024 | 17/6/2026 | EventStoreDB (ESDB) is an operational database built to store events. A vulnerability has been identified in the projections subsystem in versions 20 prior to 20.10.6, 21 prior to 21.10.11, 22 prior to 22.10.5, and 23 prior to 23.10.1. Only database instances that use custom projections are affected by this… | |
| Modificada | Media (5.3) | 0.56% | — | Stellarwp THE Events Calendar | 5/2/2024 | 17/6/2026 | The The Events Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.2.8.2 via the route function hooked into wp_ajax_nopriv_tribe_dropdown. This makes it possible for unauthenticated attackers to extract potentially sensitive data including post titles… | |
| Modificada | Media (6.1) | 0.42% | — | Myeventon Rsvp Events | 22/1/2024 | 17/6/2026 | The EventON-RSVP WordPress plugin before 2.9.5 does not sanitise and escape some parameters before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |
| Modificada | Alta (8.8) | 0.54% | — | Coolplugins Events Shortcodes FOR THE Events Calendar | 8/1/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cool Plugins Events Shortcodes For The Events Calendar.This issue affects Events Shortcodes For The Events Calendar: from n/a through 2.3.1. | |
| Modificada | Baja (3.3) | 0.17% | — | Amazon Awslabs Sandbox Accounts FOR Events | 22/12/2023 | 17/6/2026 | Sandbox Accounts for Events provides multiple, temporary AWS accounts to a number of authenticated users simultaneously via a browser-based GUI. Authenticated users could potentially read data from the events table by sending request payloads to the events API, collecting information on planned events, timeframes,… | |
| Modificada | Crítica (9) | 0.38% | — | Amazon Awslabs Sandbox Accounts FOR Events | 22/12/2023 | 17/6/2026 | "Sandbox Accounts for Events" provides multiple, temporary AWS accounts to a number of authenticated users simultaneously via a browser-based GUI. Authenticated users could potentially claim and access empty AWS accounts by sending request payloads to the account API containing non-existent event ids and self-defined… | |
| Modificada | Alta (7.5) | 0.78% | — | Stellarwp THE Events Calendar | 18/12/2023 | 17/6/2026 | The Events Calendar WordPress plugin before 6.2.8.1 discloses the content of password protected posts to unauthenticated users via a crafted request | |
| Modificada | Alta (7.5) | 0.48% | — | Nicheaddons Events Addon FOR Elementor | 30/11/2023 | 17/6/2026 | Incorrect Authorization vulnerability in NicheAddons Events Addon for Elementor allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Events Addon for Elementor: from n/a through 2.1.3. | |
| Modificada | Media (6.1) | 0.40% | — | Pixelite Events Manager | 30/11/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pixelite Events Manager allows Reflected XSS.This issue affects Events Manager: from n/a through 6.4.5. | |
| Modificada | Alta (8.8) | 0.31% | — | Chronosly-events-calendar Project Chronosly-events-calendar | 9/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Chronosly Chronosly Events Calendar plugin <= 2.6.2 versions. | |
| Modificada | Media (4.8) | 0.37% | — | Webnus Modern Events Calendar Lite | 20/10/2023 | 17/6/2026 | The Modern Events Calendar lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Google API key and Calendar ID in versions up to, but not including, 7.1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level… |