Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2991▼ 71 respecto a la semana anterior
Críticas / altas1367▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)458▼ 52 respecto a la semana anterior
–

10 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.1)0.25%—E-dynamics Events Made EasyAI24/8/202624/8/2026
Unauthenticated Cross Site Scripting (XSS) in Events Made Easy <= 3.2.5 versions.
AplazadaAlta (7.5)0.87%—E-dynamics Events Made EasyAI20/8/202620/8/2026
The Events Made Easy plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.2.5 via the eme_single_event_page_template function. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary .php files on the…
AplazadaMedia (5.3)0.30%—E-dynamics Events Made EasyAI6/8/202626/8/2026
The Events Made Easy WordPress plugin before 3.1.2 does not bind the payment authorization token to the payment record being charged, allowing unauthenticated attackers to pay a low amount for a cheap booking and have a separate, higher-priced booking marked as fully paid.
AplazadaMedia (5.3)0.30%—E-dynamics Events Made EasyAI31/7/202626/8/2026
The Events Made Easy WordPress plugin before 3.1.4 does not verify that the requester is authorized to modify the targeted record when handling an unauthenticated data-change request, relying only on a public nonce with no per-record token or ownership check, allowing unauthenticated attackers to overwrite the…
AplazadaMedia (6.5)0.33%—E-dynamics Events Made EasyAI27/7/202627/7/2026
Unauthenticated Broken Access Control in Events Made Easy <= 3.1.3 versions.
ModificadaAlta (8.8)0.87%—E-dynamics Events Made Easy22/3/202317/6/2026
The Events Made Easy WordPress Plugin, version <= 2.3.14 is affected by an authenticated SQL injection vulnerability in the 'search_name' parameter in the eme_recurrences_list action.
ModificadaMedia (5.4)0.51%—E-dynamics Events Made Easy19/1/202317/6/2026
The Events Made Easy plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several functions related to AJAX actions in versions up to, and including, 2.3.16. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to invoke those…
ModificadaCrítica (9.8)37%—E-dynamics Events Made Easy20/6/202217/6/2026
The Events Made Easy WordPress plugin before 2.2.81 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection
ModificadaAlta (8.8)1.4%—E-dynamics Events Made Easy3/1/202217/6/2026
The Events Made Easy WordPress plugin before 2.2.36 does not sanitise and escape the search_text parameter before using it in a SQL statement via the eme_searchmail AJAX action, available to any authenticated users. As a result, users with a role as low as subscriber can call it and perform SQL injection attacks
ModificadaMedia (4.8)0.70%—E-dynamics Events Made Easy1/11/202117/6/2026
The Events Made Easy WordPress plugin before 2.2.24 does not sanitise and escape Custom Field Names, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed