Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2616▼ 309 respecto a la semana anterior
Críticas / altas1342▲ 71 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 465 respecto a la semana anterior
95 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.40% | — | Mdjm Event ManagementAIMobileeventsmanager Mobile Events ManagerAI | 13/9/2026 | 14/9/2026 | The MDJM Event Management WordPress plugin before 1.7.8.5 and the Mobile Events Manager WordPress plugin through 1.4.8.3 do not check a capability, a nonce or the type of the record before permanently deleting the post identified in a request to their playlist entry removal, allowing unauthenticated attackers to… | |
| Aplazada | Baja (3.1) | 0.18% | — | HCL Intelliops Event ManagementAI | 27/8/2026 | 28/8/2026 | HCL IntelliOps Event Management (IEM) is affected by an Admin Session Concurrency Vulnerability. it may allows user sessions to remain active after logout or session deletion. | |
| Aplazada | Media (6.4) | 0.19% | — | HCL Intelliops Event ManagementAI | 27/8/2026 | 28/8/2026 | HCL IntelliOps Event Management (IEM) is affected by a Session Deletion Vulnerability. It may allow improper handling of user sessions, resulting in sessions not being fully terminated after logout or deletion. | |
| Aplazada | Media (4.8) | 0.24% | — | HCL Intelliops Event ManagementAI | 20/8/2026 | 28/8/2026 | HCL IntelliOps Event Management (IEM) is affected by missing or insecure Cross-Origin Security headers. This issue makes the application's environment and resources susceptible to unauthorized external interaction and potential exploitation. | |
| Aplazada | Media (5) | 0.28% | — | HCL Intelliops Event ManagementAI | 20/8/2026 | 29/9/2026 | HCL IntelliOps Event Management (IEM) is affected by information omission. The lack of information breaks auditability and observability of a workflow. if an attacker were to gain access to the application, the insufficient logging could hinder incident response. | |
| Aplazada | Media (5.9) | 0.23% | — | HCL Intelliops Event ManagementAI | 20/8/2026 | 29/9/2026 | HCL IntelliOps Event Management (IEM) is affected by a race condition. A "timing window" can occur where an attacker can modify the resource causing unpredictable behavior. | |
| Aplazada | Media (6.6) | 0.26% | — | HCL Intelliops Event ManagementAI | 20/8/2026 | 29/9/2026 | HCL IntelliOps Event Management (IEM) is affected by a least privileges violation which could allow an attacker to access the resource with the elevated privilege that could not be accessed with the attacker's original privileges. | |
| Aplazada | Media (5.4) | 0.25% | — | HCL Intelliops Event ManagementAI | 20/8/2026 | 29/9/2026 | HCL IntelliOps Event Management (IEM) is affected by insufficient logging. Insufficient logging weakens accountability, obscures attack detection, and enables privilege probing. | |
| Aplazada | Alta (8.8) | 0.70% | — | Mdjm Event ManagementAI | 23/7/2026 | 23/7/2026 | The MDJM Event Management plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.7.8.4. This is due to missing capability checks and nonce verification in the `MDJM_Permissions::set_permissions()` and `MDJM_Employee_Manager::init()` functions, combined with the absence of… | |
| Analizada | Media (4.2) | 0.20% | — | Hcltech Intelliops Event Management | 21/7/2026 | 30/7/2026 | HCL IEM was affected with X-Content-Type-Options Header Missing. It may enable attackers to perform SSL stripping or man-in-the-middle attacks and intercept sensitive data. | |
| Analizada | Media (4.3) | 0.25% | — | Hcltech Intelliops Event Management | 21/7/2026 | 30/7/2026 | HCL IEM was affected with the Anti Clickjacking XFrame Options Header Missing. It may allow attackers to embed the application in malicious pages and induce unauthorized user actions. | |
| Analizada | Baja (3.7) | 0.24% | — | Hcltech Intelliops Event Management | 21/7/2026 | 30/7/2026 | HCL IEM was affected with Strict transport security not enforced. It may enable attackers to perform SSL stripping or man-in-the-middle attacks and compromise secure communications. | |
| Analizada | Media (5.3) | 0.29% | — | Hcltech Intelliops Event Management | 21/7/2026 | 30/7/2026 | HCL IEM was affected with the Information disclosure nginx server. It may enable attackers to identify outdated software versions and target known vulnerabilities or publicly available exploits. | |
| Aplazada | Alta (7.2) | 1.3% | — | Mdjm Event ManagementAI | 6/6/2026 | 23/7/2026 | The MDJM Event Management plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.7.8.3 via the mdjm_send_comm_email function. This is due to no file type, extension, or MIME type validation being performed on uploaded files. This makes it possible for authenticated… | |
| Aplazada | Media (5.3) | 0.29% | — | Wpchill Rsvp AND Event ManagementAI | 25/5/2026 | 20/7/2026 | Missing Authorization vulnerability in WP Chill RSVP and Event Management allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects RSVP and Event Management: from n/a through 2.7.16. | |
| Aplazada | Media (5.3) | 0.33% | — | Wpchill Rsvp AND Event ManagementAI | 8/4/2026 | 24/7/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in WP Chill RSVP and Event Management rsvp allows Retrieve Embedded Sensitive Data.This issue affects RSVP and Event Management: from n/a through <= 2.7.16. | |
| Aplazada | Media (5.3) | 0.27% | — | Mdjm Event ManagementAI | 7/3/2026 | 17/6/2026 | The MDJM Event Management plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the 'custom_fields_controller' function in all versions up to, and including, 1.7.8.1. This makes it possible for unauthenticated attackers to delete arbitrary custom event fields via the… | |
| Aplazada | Media (5.4) | 0.19% | — | Puneethreddy Event Management SystemAI | 26/2/2026 | 17/6/2026 | A reflected Cross-Site Scripting (XSS) vulnerability exists in the register.php backend script of PuneethReddyHC Event Management System 1.0. The mobile POST parameter is improperly validated and echoed back in the HTTP response without sanitization, allowing an attacker to inject and execute arbitrary JavaScript code… | |
| Analizada | Baja (2.1) | 0.48% | — | Admerc Event Management System | 24/2/2026 | 17/6/2026 | A flaw has been found in itsourcecode Event Management System 1.0. The impacted element is an unknown function of the file /admin/navbar.php. Executing a manipulation of the argument page can lead to cross site scripting. The attack may be performed from remote. The exploit has been published and may be used. | |
| Analizada | Media (5.5) | 0.59% | — | Admerc Event Management System | 24/2/2026 | 17/6/2026 | A vulnerability was detected in itsourcecode Event Management System 1.0. The affected element is an unknown function of the file /admin/index.php. Performing a manipulation of the argument ID results in sql injection. The attack is possible to be carried out remotely. The exploit is now public and may be used. | |
| Analizada | Media (5.5) | 0.59% | — | Admerc Event Management System | 19/2/2026 | 17/6/2026 | A vulnerability has been found in itsourcecode Event Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/manage_register.php. Such manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the… | |
| Analizada | Media (5.5) | 0.59% | — | Admerc Event Management System | 19/2/2026 | 17/6/2026 | A flaw has been found in itsourcecode Event Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/ajax.php?action=login of the component Admin Login. This manipulation of the argument Username causes sql injection. It is possible to initiate the attack remotely. The… | |
| Analizada | Media (5.5) | 0.59% | — | Admerc Event Management System | 19/2/2026 | 17/6/2026 | A vulnerability was detected in itsourcecode Event Management System 1.0. Affected is an unknown function of the file /admin/manage_booking.php. The manipulation of the argument ID results in sql injection. The attack may be performed from remote. The exploit is now public and may be used. | |
| Analizada | Media (5.5) | 0.34% | — | Admerc Event Management System | 9/2/2026 | 17/6/2026 | A vulnerability was found in itsourcecode Event Management System 1.0. The impacted element is an unknown function of the file /admin/manage_user.php. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. The exploit has been made public and could be used. | |
| Analizada | Crítica (9.8) | 0.52% | — | Puneethreddyhc Event Management | 23/12/2025 | 17/6/2026 | Improper input handling in /Grocery/search_products_itname.php inPuneethReddyHC event-management 1.0 permits SQL injection via the sitem_name POST parameter. Crafted payloads can alter query logic and disclose database contents. Exploitation may result in sensitive data disclosure and backend compromise. |