Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2532▼ 361 respecto a la semana anterior
Críticas / altas1338▲ 69 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 6 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
11 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.47% | — | Eventbrite Event TicketsAI | 8/9/2026 | 9/9/2026 | The Event Tickets and Registration plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the Stripe OAuth return endpoint in all versions up to, and including, 5.27.4. This makes it possible for unauthenticated attackers to overwrite the site's Stripe merchant… | |
| Aplazada | Media (5.3) | 0.30% | — | Eventbrite Event TicketsAI | 1/8/2026 | 26/8/2026 | The Event Tickets and Registration WordPress plugin before 5.29.0.1 does not perform any authorization check on one of its order-management REST endpoints, allowing unauthenticated users to change the status of existing orders. | |
| Aplazada | Media (5.3) | 0.26% | — | Fullworks Display Eventbrite EventsAI | 8/4/2026 | 24/7/2026 | Missing Authorization vulnerability in fullworks Display Eventbrite Events widget-for-eventbrite-api allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Display Eventbrite Events: from n/a through <= 6.5.6. | |
| Aplazada | Media (6.5) | 0.21% | — | Bohemia Plugins Event Feed FOR EventbriteAI | 3/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bohemia Plugins Event Feed for Eventbrite event-feed-for-eventbrite allows DOM-Based XSS.This issue affects Event Feed for Eventbrite: from n/a through <= 1.3.2. | |
| Aplazada | Alta (7.5) | 0.77% | — | Fullworks Display Eventbrite EventsAI | 7/5/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in fullworks Display Eventbrite Events widget-for-eventbrite-api allows PHP Local File Inclusion.This issue affects Display Eventbrite Events: from n/a through < 6.3. | |
| Aplazada | Media (6.1) | 0.37% | — | Import Eventbrite EventsAI | 14/12/2024 | 17/6/2026 | The Import Eventbrite Events plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, 1.7.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in… | |
| Aplazada | Media (4.3) | 0.50% | — | Extendthemes PathwayAIExtendthemes Hugo WPAIExtendthemes Althea WPAIExtendthemes Elevate WPAI+3 | 29/4/2024 | 17/6/2026 | Missing Authorization vulnerability in Extend Themes Pathway, Extend Themes Hugo WP, Extend Themes Althea WP, Extend Themes Elevate WP, Extend Themes Brite, Extend Themes Colibri WP, Extend Themes Vertice.This issue affects Pathway: from n/a through 1.0.15; Hugo WP: from n/a through 1.0.8; Althea WP: from n/a through… | |
| Modificada | Alta (7.5) | 2.5% | — | Cellebrite Ufed Firmware | 30/6/2020 | 17/6/2026 | The Cellebrite UFED physical device 5.0 through 7.5.0.845 relies on key material hardcoded within both the executable code supporting the decryption process, and within the encrypted files themselves by using a key enveloping technique. The recovered key material is the same for every device running the same version… | |
| Modificada | Media (5.5) | 0.45% | — | Cellebrite Ufed Firmware | 14/4/2020 | 17/6/2026 | Cellebrite UFED 5.0 through 7.29 uses four hardcoded RSA private keys to authenticate to the ADB daemon on target devices. Extracted keys can be used to place evidence onto target devices when performing a forensic extraction. | |
| Modificada | Media (4.3) | 2.1% | — | Theeventscalendar Eventbrite Tickets | 18/8/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Event Import page (import-eventbrite-events.php) in the Modern Tribe Eventbrite Tickets plugin before 3.10.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the "error" parameter to wp-admin/edit.php. | |
| Modificada | Alta (7.5) | 1.2% | — | Xbrite Members | 11/4/2006 | 16/6/2026 | SQL injection vulnerability in members.php in XBrite Members 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. |