Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
797 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 0.46% | — | TRI THE Events Calendar | 14/6/2024 | 17/6/2026 | The events-calendar-pro WordPress plugin before 6.4.0.1, The Events Calendar WordPress plugin before 6.4.0.1 does not prevent users with at least the contributor role from leaking details about events they shouldn't have access to. (e.g. password-protected events, drafts, etc.) | |
| Modificada | Crítica (9.8) | 0.41% | — | Typps Calendarista | 9/6/2024 | 17/6/2026 | Missing Authorization vulnerability in typps Calendarista Basic Edition calendarista-basic-edition.This issue affects Calendarista Basic Edition: from n/a through <= 3.0.5. | |
| Modificada | Media (6.3) | 0.28% | — | Spiffyplugins Spiffy Calendar | 4/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Spiffy Plugins Spiffy Calendar.This issue affects Spiffy Calendar: from n/a through 4.9.10. | |
| Analizada | Crítica (9.1) | 2.1% | 💥 Exploit | Stellarwp THE Events Calendar | 4/6/2024 | 17/6/2026 | The Events Calendar WordPress plugin before 6.4.0.1 does not properly sanitize user-submitted content when rendering some views via AJAX. | |
| Aplazada | Media (4.3) | 0.31% | — | Codepeople CP Multi View Event CalendarAI | 3/6/2024 | 17/6/2026 | Missing Authorization vulnerability in CodePeople CP Multi View Event Calendar allows Functionality Misuse.This issue affects CP Multi View Event Calendar: from n/a through 1.4.10. | |
| Analizada | Crítica (9.8) | 0.35% | — | Wpdevart Booking Calendar | 3/6/2024 | 17/6/2026 | External Control of Assumed-Immutable Web Parameter vulnerability in WpDevArt Booking calendar, Appointment Booking System allows Manipulating Hidden Fields.This issue affects Booking calendar, Appointment Booking System: from n/a through 3.2.3. | |
| Aplazada | Media (6.5) | 0.48% | — | Theeventscalendar BookitAI | 17/5/2024 | 17/6/2026 | Improper Validation of Specified Quantity in Input vulnerability in The Events Calendar BookIt allows Manipulating Hidden Fields.This issue affects BookIt: from n/a through 2.4.0. | |
| Aplazada | Alta (8.2) | 0.50% | — | Room 34 Creative Services ICS CalendarAI | 17/5/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Server-Side Request Forgery (SSRF) vulnerability in Room 34 Creative Services, LLC ICS Calendar ics-calendar allows Absolute Path Traversal, : Server Side Request Forgery.This issue affects ICS Calendar: from n/a through 10.12.0.3. | |
| Aplazada | Media (5.9) | 0.44% | — | Archives Calendar WidgetAI | 14/5/2024 | 17/6/2026 | Administrator Cross Site Scripting (XSS) in Archives Calendar Widget <= 1.0.15 versions. | |
| Analizada | Alta (7.5) | 0.32% | — | MF GIG Calendar Project MF GIG Calendar | 6/5/2024 | 17/6/2026 | The MF Gig Calendar WordPress plugin through 1.2.1 does not have CSRF checks in some places, which could allow attackers to make logged in Contributors and above delete arbitrary events via a CSRF attack | |
| Analizada | Media (5.4) | 0.43% | — | MF GIG Calendar Project MF GIG Calendar | 6/5/2024 | 17/6/2026 | The MF Gig Calendar WordPress plugin through 1.2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as editor to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Aplazada | Alta (8.8) | 0.61% | — | CalendarAI | 2/5/2024 | 17/6/2026 | The Calendar plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcodes in all versions up to, and including, 1.3.14 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (6.5) | 0.32% | — | Lbell Pretty Google CalendarAI | 29/4/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LBell Pretty Google Calendar allows Stored XSS.This issue affects Pretty Google Calendar: from n/a through 1.7.2. | |
| Modificada | Alta (8.8) | 0.23% | — | MF GIG Calendar Project MF GIG Calendar | 26/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Matthew Fries MF Gig Calendar.This issue affects MF Gig Calendar : from n/a through 1.2.1. | |
| Aplazada | Media (4.3) | 0.20% | — | Stellarwp THE Events CalendarAI | 15/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in StellarWP The Events Calendar the-events-calendar.This issue affects The Events Calendar: from n/a through <= 6.3.0. | |
| Aplazada | Media (4.3) | 0.23% | — | Typps Calendarista Basic EditionAI | 15/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in typps Calendarista Basic Edition calendarista-basic-edition.This issue affects Calendarista Basic Edition: from n/a through <= 3.0.2. | |
| Aplazada | Media (6.1) | 0.58% | — | Bizcalendar WEBAI | 10/4/2024 | 17/6/2026 | The BizCalendar Web plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter in all versions up to, and including, 1.1.0.25 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that… | |
| Analizada | Media (5.4) | 0.43% | — | Joedolson MY Calendar | 2/4/2024 | 17/6/2026 | The My Calendar WordPress plugin before 3.4.24 does not sanitise and escape some parameters, which could allow users with a role as low as Subscriber to perform Cross-Site Scripting attacks (depending on the permissions set by the admin) | |
| Aplazada | Alta (7.1) | 0.40% | — | Apointzilla Appointment CalendarAI | 31/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Scientech It Solution Appointment Calendar allows Reflected XSS.This issue affects Appointment Calendar: from n/a through 2.9.6. | |
| Aplazada | Media (6.5) | 0.34% | — | Moises Heberle Woocommerce Bookings CalendarAI | 31/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Moises Heberle WooCommerce Bookings Calendar.This issue affects WooCommerce Bookings Calendar: from n/a through 1.0.36. | |
| Modificada | Media (6.1) | 0.41% | — | Spiffyplugins Spiffy Calendar | 29/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Spiffy Plugins Spiffy Calendar allows Reflected XSS.This issue affects Spiffy Calendar: from n/a through 4.9.7. | |
| Aplazada | Alta (8.5) | 0.55% | — | Typps CalendaristaAI | 28/3/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Typps Calendarista.This issue affects Calendarista: from n/a through 15.5.7. | |
| Aplazada | Alta (7.6) | 0.52% | — | Wpdevelop Booking CalendarAI | 26/3/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPdevelop / Oplugins Booking Calendar allows SQL Injection.This issue affects Booking Calendar: from n/a through 9.4.3. | |
| Aplazada | Alta (7.1) | 0.37% | — | Typps Calendarista-basic-editionAI | 21/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in typps Calendarista Basic Edition calendarista-basic-edition.This issue affects Calendarista Basic Edition: from n/a through <= 3.0.2. | |
| Analizada | Alta (8.8) | 0.38% | — | Codepeople Appointment Booking Calendar | 20/3/2024 | 17/6/2026 | The Appointment Booking Calendar WordPress plugin before 1.3.83 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks such as adding a booking to the calendar without paying. |