Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2991▼ 71 respecto a la semana anterior
Críticas / altas1367▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)458▼ 52 respecto a la semana anterior
10 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.25% | — | E-dynamics Events Made EasyAI | 24/8/2026 | 24/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Events Made Easy <= 3.2.5 versions. | |
| Aplazada | Alta (7.5) | 0.87% | — | E-dynamics Events Made EasyAI | 20/8/2026 | 20/8/2026 | The Events Made Easy plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.2.5 via the eme_single_event_page_template function. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary .php files on the… | |
| Aplazada | Media (5.3) | 0.30% | — | E-dynamics Events Made EasyAI | 6/8/2026 | 26/8/2026 | The Events Made Easy WordPress plugin before 3.1.2 does not bind the payment authorization token to the payment record being charged, allowing unauthenticated attackers to pay a low amount for a cheap booking and have a separate, higher-priced booking marked as fully paid. | |
| Aplazada | Media (5.3) | 0.30% | — | E-dynamics Events Made EasyAI | 31/7/2026 | 26/8/2026 | The Events Made Easy WordPress plugin before 3.1.4 does not verify that the requester is authorized to modify the targeted record when handling an unauthenticated data-change request, relying only on a public nonce with no per-record token or ownership check, allowing unauthenticated attackers to overwrite the… | |
| Aplazada | Media (6.5) | 0.33% | — | E-dynamics Events Made EasyAI | 27/7/2026 | 27/7/2026 | Unauthenticated Broken Access Control in Events Made Easy <= 3.1.3 versions. | |
| Modificada | Alta (8.8) | 0.87% | — | E-dynamics Events Made Easy | 22/3/2023 | 17/6/2026 | The Events Made Easy WordPress Plugin, version <= 2.3.14 is affected by an authenticated SQL injection vulnerability in the 'search_name' parameter in the eme_recurrences_list action. | |
| Modificada | Media (5.4) | 0.51% | — | E-dynamics Events Made Easy | 19/1/2023 | 17/6/2026 | The Events Made Easy plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several functions related to AJAX actions in versions up to, and including, 2.3.16. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to invoke those… | |
| Modificada | Crítica (9.8) | 37% | — | E-dynamics Events Made Easy | 20/6/2022 | 17/6/2026 | The Events Made Easy WordPress plugin before 2.2.81 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection | |
| Modificada | Alta (8.8) | 1.4% | — | E-dynamics Events Made Easy | 3/1/2022 | 17/6/2026 | The Events Made Easy WordPress plugin before 2.2.36 does not sanitise and escape the search_text parameter before using it in a SQL statement via the eme_searchmail AJAX action, available to any authenticated users. As a result, users with a role as low as subscriber can call it and perform SQL injection attacks | |
| Modificada | Media (4.8) | 0.70% | — | E-dynamics Events Made Easy | 1/11/2021 | 17/6/2026 | The Events Made Easy WordPress plugin before 2.2.24 does not sanitise and escape Custom Field Names, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed |