Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
5 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.2) | 0.74% | — | Theeventscalendar Events Calendar PRO | 30/8/2024 | 17/6/2026 | The Events Calendar Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 7.0.2 via deserialization of untrusted input from the 'filters' parameter in widgets. This makes it possible for authenticated attackers, with administrator-level access and above, to inject a PHP… | |
| Modificada | Alta (8.8) | 0.31% | — | Chronosly-events-calendar Project Chronosly-events-calendar | 9/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Chronosly Chronosly Events Calendar plugin <= 2.6.2 versions. | |
| Modificada | Media (5.4) | 0.62% | — | Tiva Events Calendar Project Tiva Events Calendar | 20/7/2023 | 17/6/2026 | A vulnerability classified as problematic was found in Codecanyon Tiva Events Calender 1.4. This vulnerability affects unknown code. The manipulation of the argument name leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-235054 is the… | |
| Modificada | Alta (7.2) | 1.6% | — | Simple Events Calendar Project Simple Events Calendar | 23/8/2021 | 17/6/2026 | The Simple Events Calendar WordPress plugin through 1.4.0 does not sanitise, validate or escape the event_id POST parameter before using it in a SQL statement when deleting events, leading to an authenticated SQL injection issue | |
| Modificada | Crítica (9.8) | 4.9% | 💥 Exploit | WP Events Calendar Project WP Events Calendar | 12/1/2018 | 17/6/2026 | The Wachipi WP Events Calendar plugin 1.0 for WordPress has SQL Injection via the event_id parameter to event.php. |