Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2568▼ 304 respecto a la semana anterior
Críticas / altas1352▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
24 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.41% | — | Roundupwp Registrations FOR THE Events CalendarAI | 23/7/2026 | 23/7/2026 | The Registrations For The Events Calendar plugin for WordPress is vulnerable to SQL Injection via JSON keys in the 'standard' parameter handled by the rtec_records_edit AJAX action in versions up to and including 3.2. The handler decodes attacker-controlled JSON from $_POST['standard'] and uses the JSON array keys… | |
| Aplazada | Media (6.4) | 0.20% | — | RoundupAI | 13/7/2025 | 17/6/2026 | In Roundup before 2.5.0, XSS can occur via interaction between URLs and issue tracker templates (devel and responsive). | |
| Analizada | Media (6.1) | 0.27% | — | Roundupwp Registrations FOR THE Events Calendar | 25/3/2025 | 17/6/2026 | The Registrations for the Events Calendar WordPress plugin before 2.13.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Analizada | Crítica (9.6) | 0.69% | — | Roundupwp Registrations FOR THE Events Calendar | 8/11/2024 | 17/6/2026 | The Registrations for the Events Calendar WordPress plugin before 2.12.4 does not sanitise and escape some parameters when accepting event registrations, which could allow unauthenticated users to perform Cross-Site Scripting attacks. | |
| Aplazada | Media (6.4) | 0.39% | — | Roundupwp Registrations FOR THE Events CalendarAI | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in Roundup WP Registrations for the Events Calendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Registrations for the Events Calendar: from n/a through 2.12.1. | |
| Analizada | Alta (8.8) | 0.44% | — | Roundupwp Registrations FOR THE Events Calendar | 29/8/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Roundup WP Registrations for the Events Calendar allows SQL Injection.This issue affects Registrations for the Events Calendar: from n/a through 2.12.2. | |
| Modificada | Media (5.4) | 0.33% | — | Roundup-tracker Roundup | 17/7/2024 | 17/6/2026 | Roundup before 2.4.0 allows XSS via JavaScript in PDF, XML, and SVG documents. | |
| Modificada | Media (5.4) | 0.29% | — | Roundup-tracker Roundup | 17/7/2024 | 17/6/2026 | Roundup before 2.4.0 allows XSS via a SCRIPT element in an HTTP Referer header. | |
| Modificada | Media (5.4) | 0.29% | — | Roundup-tracker Roundup | 17/7/2024 | 17/6/2026 | In Roundup before 2.4.0, classhelpers (_generic.help.html) allow XSS. | |
| Modificada | Media (6.1) | 0.89% | — | Roundupwp Registrations FOR THE Events Calendar | 24/1/2022 | 17/6/2026 | The Registrations for the Events Calendar WordPress plugin before 2.7.10 does not escape the qtype parameter before outputting it back in an attribute in the settings page, leading to a Reflected Cross-Site Scripting | |
| Modificada | Crítica (9.8) | 7.3% | — | Roundupwp Registrations FOR THE Events Calendar | 6/12/2021 | 17/6/2026 | The Registrations for the Events Calendar WordPress plugin before 2.7.6 does not sanitise and escape the event_id in the rtec_send_unregister_link AJAX action (available to both unauthenticated and authenticated users) before using it in a SQL statement, leading to an unauthenticated SQL injection. | |
| Modificada | Media (6.1) | 1.2% | — | Roundupwp Registrations FOR THE Events Calendar | 29/11/2021 | 17/6/2026 | The Registrations for the Events Calendar WordPress plugin before 2.7.5 does not escape the v parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting | |
| Modificada | Media (6.1) | 1.6% | — | Roundup-tracker Roundup | 30/1/2020 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Roundup before 1.4.20 allow remote attackers to inject arbitrary web script or HTML via the (1) @ok_message or (2) @error_message parameter to issue*. | |
| Modificada | Media (6.1) | 1.6% | — | Debian LinuxRoundup-tracker Roundup | 6/4/2019 | 17/6/2026 | Roundup 1.6 allows XSS via the URI because frontends/roundup.cgi and roundup/cgi/wsgi_handler.py mishandle 404 errors. | |
| Modificada | Media (4.3) | 1.5% | — | Roundup-tracker RoundupDebian Linux | 13/4/2016 | 17/6/2026 | schema.py in Roundup before 1.5.1 does not properly limit attributes included in default user permissions, which might allow remote authenticated users to obtain sensitive user information by viewing user details. | |
| Modificada | Media (5.4) | 0.27% | — | Ticketroundup Ticket Round UP | 23/9/2014 | 17/6/2026 | The Ticket Round Up (aka com.xcr.android.ticketroundupapp) application 3.0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (4.3) | 2.0% | — | Roundup-tracker Roundup | 11/4/2014 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in cgi/client.py in Roundup before 1.4.20 allows remote attackers to inject arbitrary web script or HTML via the @action parameter to support/issue1. | |
| Modificada | Media (4.3) | 2.0% | — | Roundup-tracker Roundup | 11/4/2014 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the history display in Roundup before 1.4.20 allows remote attackers to inject arbitrary web script or HTML via a username, related to generating a link. | |
| Modificada | Media (4.3) | 1.8% | — | Roundup-tracker Roundup | 10/4/2014 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Roundup before 1.4.20 allows remote attackers to inject arbitrary web script or HTML via the otk parameter. | |
| Modificada | Media (4.3) | 2.6% | — | Roundup-tracker Roundup | 24/9/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in cgi/client.py in Roundup before 1.4.14 allows remote attackers to inject arbitrary web script or HTML via the template argument to the /issue program. | |
| Modificada | Media (5.5) | 2.3% | — | Toni Mueller Roundup | 11/8/2009 | 16/6/2026 | The EditCSVAction function in cgi/actions.py in Roundup 1.2 before 1.2.1, 1.4 through 1.4.6, and possibly other versions does not properly check permissions, which allows remote authenticated users with edit or create privileges for a class to modify arbitrary items within that class, as demonstrated by editing all… | |
| Modificada | Media (4.3) | 1.5% | — | Roundup-tracker Roundup | 24/3/2008 | 16/6/2026 | Multiple unspecified vulnerabilities in Roundup before 1.4.4 have unknown impact and attack vectors, some of which may be related to cross-site scripting (XSS). | |
| Modificada | Media (6.4) | 1.8% | — | Roundup-tracker Roundup | 24/3/2008 | 16/6/2026 | The xml-rpc server in Roundup 1.4.4 does not check property permissions, which allows attackers to bypass restrictions and edit or read restricted properties via the (1) list, (2) display, and (3) set methods. | |
| Modificada | Media (5) | 8.9% | — | Roundup-tracker Roundup | 31/12/2004 | 16/6/2026 | Directory traversal vulnerability in Roundup 0.6.4 and earlier allows remote attackers to view arbitrary files via .. (dot dot) sequences in an @@ command in an HTTP GET request. |