Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

797 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)0.46%—TRI THE Events Calendar14/6/202417/6/2026
The events-calendar-pro WordPress plugin before 6.4.0.1, The Events Calendar WordPress plugin before 6.4.0.1 does not prevent users with at least the contributor role from leaking details about events they shouldn't have access to. (e.g. password-protected events, drafts, etc.)
ModificadaCrítica (9.8)0.41%—Typps Calendarista9/6/202417/6/2026
Missing Authorization vulnerability in typps Calendarista Basic Edition calendarista-basic-edition.This issue affects Calendarista Basic Edition: from n/a through <= 3.0.5.
ModificadaMedia (6.3)0.28%—Spiffyplugins Spiffy Calendar4/6/202417/6/2026
Missing Authorization vulnerability in Spiffy Plugins Spiffy Calendar.This issue affects Spiffy Calendar: from n/a through 4.9.10.
AnalizadaCrítica (9.1)2.1%💥 ExploitStellarwp THE Events Calendar4/6/202417/6/2026
The Events Calendar WordPress plugin before 6.4.0.1 does not properly sanitize user-submitted content when rendering some views via AJAX.
AplazadaMedia (4.3)0.31%—Codepeople CP Multi View Event CalendarAI3/6/202417/6/2026
Missing Authorization vulnerability in CodePeople CP Multi View Event Calendar allows Functionality Misuse.This issue affects CP Multi View Event Calendar: from n/a through 1.4.10.
AnalizadaCrítica (9.8)0.35%—Wpdevart Booking Calendar3/6/202417/6/2026
External Control of Assumed-Immutable Web Parameter vulnerability in WpDevArt Booking calendar, Appointment Booking System allows Manipulating Hidden Fields.This issue affects Booking calendar, Appointment Booking System: from n/a through 3.2.3.
AplazadaMedia (6.5)0.48%—Theeventscalendar BookitAI17/5/202417/6/2026
Improper Validation of Specified Quantity in Input vulnerability in The Events Calendar BookIt allows Manipulating Hidden Fields.This issue affects BookIt: from n/a through 2.4.0.
AplazadaAlta (8.2)0.50%—Room 34 Creative Services ICS CalendarAI17/5/202417/6/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Server-Side Request Forgery (SSRF) vulnerability in Room 34 Creative Services, LLC ICS Calendar ics-calendar allows Absolute Path Traversal, : Server Side Request Forgery.This issue affects ICS Calendar: from n/a through 10.12.0.3.
AplazadaMedia (5.9)0.44%—Archives Calendar WidgetAI14/5/202417/6/2026
Administrator Cross Site Scripting (XSS) in Archives Calendar Widget <= 1.0.15 versions.
AnalizadaAlta (7.5)0.32%—MF GIG Calendar Project MF GIG Calendar6/5/202417/6/2026
The MF Gig Calendar WordPress plugin through 1.2.1 does not have CSRF checks in some places, which could allow attackers to make logged in Contributors and above delete arbitrary events via a CSRF attack
AnalizadaMedia (5.4)0.43%—MF GIG Calendar Project MF GIG Calendar6/5/202417/6/2026
The MF Gig Calendar WordPress plugin through 1.2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as editor to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
AplazadaAlta (8.8)0.61%—CalendarAI2/5/202417/6/2026
The Calendar plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcodes in all versions up to, and including, 1.3.14 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with…
AplazadaMedia (6.5)0.32%—Lbell Pretty Google CalendarAI29/4/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LBell Pretty Google Calendar allows Stored XSS.This issue affects Pretty Google Calendar: from n/a through 1.7.2.
ModificadaAlta (8.8)0.23%—MF GIG Calendar Project MF GIG Calendar26/4/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Matthew Fries MF Gig Calendar.This issue affects MF Gig Calendar : from n/a through 1.2.1.
AplazadaMedia (4.3)0.20%—Stellarwp THE Events CalendarAI15/4/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in StellarWP The Events Calendar the-events-calendar.This issue affects The Events Calendar: from n/a through <= 6.3.0.
AplazadaMedia (4.3)0.23%—Typps Calendarista Basic EditionAI15/4/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in typps Calendarista Basic Edition calendarista-basic-edition.This issue affects Calendarista Basic Edition: from n/a through <= 3.0.2.
AplazadaMedia (6.1)0.58%—Bizcalendar WEBAI10/4/202417/6/2026
The BizCalendar Web plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter in all versions up to, and including, 1.1.0.25 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that…
AnalizadaMedia (5.4)0.43%—Joedolson MY Calendar2/4/202417/6/2026
The My Calendar WordPress plugin before 3.4.24 does not sanitise and escape some parameters, which could allow users with a role as low as Subscriber to perform Cross-Site Scripting attacks (depending on the permissions set by the admin)
AplazadaAlta (7.1)0.40%—Apointzilla Appointment CalendarAI31/3/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Scientech It Solution Appointment Calendar allows Reflected XSS.This issue affects Appointment Calendar: from n/a through 2.9.6.
AplazadaMedia (6.5)0.34%—Moises Heberle Woocommerce Bookings CalendarAI31/3/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Moises Heberle WooCommerce Bookings Calendar.This issue affects WooCommerce Bookings Calendar: from n/a through 1.0.36.
ModificadaMedia (6.1)0.41%—Spiffyplugins Spiffy Calendar29/3/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Spiffy Plugins Spiffy Calendar allows Reflected XSS.This issue affects Spiffy Calendar: from n/a through 4.9.7.
AplazadaAlta (8.5)0.55%—Typps CalendaristaAI28/3/202417/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Typps Calendarista.This issue affects Calendarista: from n/a through 15.5.7.
AplazadaAlta (7.6)0.52%—Wpdevelop Booking CalendarAI26/3/202417/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPdevelop / Oplugins Booking Calendar allows SQL Injection.This issue affects Booking Calendar: from n/a through 9.4.3.
AplazadaAlta (7.1)0.37%—Typps Calendarista-basic-editionAI21/3/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in typps Calendarista Basic Edition calendarista-basic-edition.This issue affects Calendarista Basic Edition: from n/a through <= 3.0.2.
AnalizadaAlta (8.8)0.38%—Codepeople Appointment Booking Calendar20/3/202417/6/2026
The Appointment Booking Calendar WordPress plugin before 1.3.83 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks such as adding a booking to the calendar without paying.
Orbitaley — Vulnerabilidades