Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2734▲ 30 respecto a la semana anterior
Críticas / altas1469▲ 361 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 458 respecto a la semana anterior
14 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.7% | — | Eventum Project Eventum | 5/9/2019 | 17/6/2026 | Controller/ListController.php in Eventum 3.5.0 is vulnerable to Deserialization of Untrusted Data. Fixed in version 3.5.2. | |
| Modificada | Alta (8.8) | 0.66% | — | Eventum Project Eventum | 10/7/2019 | 17/6/2026 | An issue was discovered in Eventum 3.5.0. CSRF in htdocs/manage/users.php allows creating another user with admin privileges. | |
| Modificada | Media (6.1) | 0.91% | — | Eventum Project Eventum | 10/7/2019 | 17/6/2026 | An issue was discovered in Eventum 3.5.0. /htdocs/list.php has XSS via the show_notification_list_issues or show_authorized_issues parameter. | |
| Modificada | Media (6.1) | 0.91% | — | Eventum Project Eventum | 10/7/2019 | 17/6/2026 | An issue was discovered in Eventum 3.5.0. /htdocs/popup.php has XSS via the cat parameter. | |
| Modificada | Media (6.1) | 0.91% | — | Eventum Project Eventum | 10/7/2019 | 17/6/2026 | An issue was discovered in Eventum 3.5.0. /htdocs/validate.php has XSS via the values parameter. | |
| Modificada | Media (6.1) | 0.91% | — | Eventum Project Eventum | 10/7/2019 | 17/6/2026 | An issue was discovered in Eventum 3.5.0. htdocs/switch.php has XSS via the current_page parameter. | |
| Modificada | Media (6.1) | 0.91% | — | Eventum Project Eventum | 10/7/2019 | 17/6/2026 | An issue was discovered in Eventum 3.5.0. htdocs/ajax/update.php has XSS via the field_name parameter. | |
| Modificada | Media (6.1) | 0.91% | — | Eventum Project Eventum | 5/7/2019 | 17/6/2026 | An issue was discovered in Eventum 3.5.0. /htdocs/switch.php has an Open Redirect via the current_page parameter. | |
| Modificada | Media (6.1) | 0.91% | — | Eventum Project Eventum | 24/5/2019 | 17/6/2026 | An issue was discovered in Eventum 3.5.0. /htdocs/post_note.php has XSS via the garlic_prefix parameter. | |
| Modificada | Media (6.1) | 2.2% | — | Eventum Project Eventum | 9/9/2018 | 17/6/2026 | Eventum before 3.4.0 has an open redirect vulnerability. | |
| Modificada | Alta (8.1) | 10% | — | Eventum Project Eventum | 31/1/2018 | 17/6/2026 | htdocs/setup/index.php in Eventum before 2.3.5 allows remote attackers to inject and execute arbitrary PHP code via the hostname parameter. | |
| Modificada | Alta (7.5) | 9.3% | — | Eventum Project Eventum | 31/1/2018 | 17/6/2026 | Eventum before 2.3.5 allows remote attackers to reinstall the application via direct request to /setup/index.php. | |
| Modificada | Media (6.4) | 2.0% | — | Mysql Eventum | 31/12/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in MySQL Eventum 1.5.5 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) isCorrectPassword or (2) userExist function in class.auth.php, getCustomFieldReport function in (4) custom_fields.php, (5) custom_fields_graph.php, or (6) class.report.php, or… | |
| Modificada | Media (5.8) | 2.9% | — | Mysql Eventum | 31/12/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in MySQL Eventum 1.5.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to view.php, (2) release parameter to list.php, or (3) F parameter to get_jsrs_data.php. |