Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2568▼ 304 respecto a la semana anterior
Críticas / altas1352▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
–

24 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.5)0.41%—Roundupwp Registrations FOR THE Events CalendarAI23/7/202623/7/2026
The Registrations For The Events Calendar plugin for WordPress is vulnerable to SQL Injection via JSON keys in the 'standard' parameter handled by the rtec_records_edit AJAX action in versions up to and including 3.2. The handler decodes attacker-controlled JSON from $_POST['standard'] and uses the JSON array keys…
AplazadaMedia (6.4)0.20%—RoundupAI13/7/202517/6/2026
In Roundup before 2.5.0, XSS can occur via interaction between URLs and issue tracker templates (devel and responsive).
AnalizadaMedia (6.1)0.27%—Roundupwp Registrations FOR THE Events Calendar25/3/202517/6/2026
The Registrations for the Events Calendar WordPress plugin before 2.13.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
AnalizadaCrítica (9.6)0.69%—Roundupwp Registrations FOR THE Events Calendar8/11/202417/6/2026
The Registrations for the Events Calendar WordPress plugin before 2.12.4 does not sanitise and escape some parameters when accepting event registrations, which could allow unauthenticated users to perform Cross-Site Scripting attacks.
AplazadaMedia (6.4)0.39%—Roundupwp Registrations FOR THE Events CalendarAI1/11/202417/6/2026
Missing Authorization vulnerability in Roundup WP Registrations for the Events Calendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Registrations for the Events Calendar: from n/a through 2.12.1.
AnalizadaAlta (8.8)0.44%—Roundupwp Registrations FOR THE Events Calendar29/8/202417/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Roundup WP Registrations for the Events Calendar allows SQL Injection.This issue affects Registrations for the Events Calendar: from n/a through 2.12.2.
ModificadaMedia (5.4)0.33%—Roundup-tracker Roundup17/7/202417/6/2026
Roundup before 2.4.0 allows XSS via JavaScript in PDF, XML, and SVG documents.
ModificadaMedia (5.4)0.29%—Roundup-tracker Roundup17/7/202417/6/2026
Roundup before 2.4.0 allows XSS via a SCRIPT element in an HTTP Referer header.
ModificadaMedia (5.4)0.29%—Roundup-tracker Roundup17/7/202417/6/2026
In Roundup before 2.4.0, classhelpers (_generic.help.html) allow XSS.
ModificadaMedia (6.1)0.89%—Roundupwp Registrations FOR THE Events Calendar24/1/202217/6/2026
The Registrations for the Events Calendar WordPress plugin before 2.7.10 does not escape the qtype parameter before outputting it back in an attribute in the settings page, leading to a Reflected Cross-Site Scripting
ModificadaCrítica (9.8)7.3%—Roundupwp Registrations FOR THE Events Calendar6/12/202117/6/2026
The Registrations for the Events Calendar WordPress plugin before 2.7.6 does not sanitise and escape the event_id in the rtec_send_unregister_link AJAX action (available to both unauthenticated and authenticated users) before using it in a SQL statement, leading to an unauthenticated SQL injection.
ModificadaMedia (6.1)1.2%—Roundupwp Registrations FOR THE Events Calendar29/11/202117/6/2026
The Registrations for the Events Calendar WordPress plugin before 2.7.5 does not escape the v parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting
ModificadaMedia (6.1)1.6%—Roundup-tracker Roundup30/1/202016/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Roundup before 1.4.20 allow remote attackers to inject arbitrary web script or HTML via the (1) @ok_message or (2) @error_message parameter to issue*.
ModificadaMedia (6.1)1.6%—Debian LinuxRoundup-tracker Roundup6/4/201917/6/2026
Roundup 1.6 allows XSS via the URI because frontends/roundup.cgi and roundup/cgi/wsgi_handler.py mishandle 404 errors.
ModificadaMedia (4.3)1.5%—Roundup-tracker RoundupDebian Linux13/4/201617/6/2026
schema.py in Roundup before 1.5.1 does not properly limit attributes included in default user permissions, which might allow remote authenticated users to obtain sensitive user information by viewing user details.
ModificadaMedia (5.4)0.27%—Ticketroundup Ticket Round UP23/9/201417/6/2026
The Ticket Round Up (aka com.xcr.android.ticketroundupapp) application 3.0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (4.3)2.0%—Roundup-tracker Roundup11/4/201416/6/2026
Cross-site scripting (XSS) vulnerability in cgi/client.py in Roundup before 1.4.20 allows remote attackers to inject arbitrary web script or HTML via the @action parameter to support/issue1.
ModificadaMedia (4.3)2.0%—Roundup-tracker Roundup11/4/201416/6/2026
Cross-site scripting (XSS) vulnerability in the history display in Roundup before 1.4.20 allows remote attackers to inject arbitrary web script or HTML via a username, related to generating a link.
ModificadaMedia (4.3)1.8%—Roundup-tracker Roundup10/4/201416/6/2026
Cross-site scripting (XSS) vulnerability in Roundup before 1.4.20 allows remote attackers to inject arbitrary web script or HTML via the otk parameter.
ModificadaMedia (4.3)2.6%—Roundup-tracker Roundup24/9/201016/6/2026
Cross-site scripting (XSS) vulnerability in cgi/client.py in Roundup before 1.4.14 allows remote attackers to inject arbitrary web script or HTML via the template argument to the /issue program.
ModificadaMedia (5.5)2.3%—Toni Mueller Roundup11/8/200916/6/2026
The EditCSVAction function in cgi/actions.py in Roundup 1.2 before 1.2.1, 1.4 through 1.4.6, and possibly other versions does not properly check permissions, which allows remote authenticated users with edit or create privileges for a class to modify arbitrary items within that class, as demonstrated by editing all…
ModificadaMedia (4.3)1.5%—Roundup-tracker Roundup24/3/200816/6/2026
Multiple unspecified vulnerabilities in Roundup before 1.4.4 have unknown impact and attack vectors, some of which may be related to cross-site scripting (XSS).
ModificadaMedia (6.4)1.8%—Roundup-tracker Roundup24/3/200816/6/2026
The xml-rpc server in Roundup 1.4.4 does not check property permissions, which allows attackers to bypass restrictions and edit or read restricted properties via the (1) list, (2) display, and (3) set methods.
ModificadaMedia (5)8.9%—Roundup-tracker Roundup31/12/200416/6/2026
Directory traversal vulnerability in Roundup 0.6.4 and earlier allows remote attackers to view arbitrary files via .. (dot dot) sequences in an @@ command in an HTTP GET request.