Vulnerabilities
381,276
with PoCs
37,250
CISA KEV
1,665
Ransomware
606
with Nuclei
4,342

Showing 3 vulnerabilities on this page

Signals CISA KEV Ransomware Nuclei
Vulnerability search results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Registrations for The Events Calendar < 2.12.4 - Unauthenticated Stored XSS

The Registrations for the Events Calendar WordPress plugin before 2.12.4 does not sanitise and escape some parameters when accepting event registrations, which could allow unauthenticated users to perform Cross-Site Scripting attacks.

CWE-79Nov 8, 2024
CVSS9.6v3.1EPSS0.665%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Registrations for the Events Calendar < 2.7.6 - Unauthenticated SQL Injection

The Registrations for the Events Calendar WordPress plugin before 2.7.6 does not sanitise and escape the event_id in the rtec_send_unregister_link AJAX action (available to both unauthenticated and authenticated users) before using it in a SQL statement, leading to an unauthenticated SQL injection.

CWE-89Dec 6, 20211 related artifact
CVSS9.8v3.1EPSS7.47%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

Registrations for The Events Calendar < 2.7.5 - Reflected Cross-Site Scripting

The Registrations for the Events Calendar WordPress plugin before 2.7.5 does not escape the v parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting

CWE-79Nov 29, 20211 related artifact
CVSS6.1v3.1EPSS1.17%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX