Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

797 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)0.20%—Wpsimplebookingcalendar WP Simple Booking Calendar15/3/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Veribo, Roland Murg WP Simple Booking Calendar.This issue affects WP Simple Booking Calendar: from n/a through 2.0.8.4.
AplazadaMedia (6.5)0.33%—Joseph C Dolson MY CalendarAI15/3/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Joseph C Dolson My Calendar allows Stored XSS.This issue affects My Calendar: from n/a through 3.4.23.
AnalizadaMedia (5.3)0.48%—Spiffyplugins Spiffy Calendar27/2/202417/6/2026
The Spiffy Calendar WordPress plugin before 4.9.9 doesn't check the event_author parameter, and allows any user to alter it when creating an event, leading to deceiving users/admins that a page was created by a Contributor+.
AnalizadaMedia (5.3)0.42%—Discourse Calendar22/2/202417/6/2026
Discourse Calendar adds the ability to create a dynamic calendar in the first post of a topic on the open-source discussion platform Discourse. Prior to version 0.4, event invitees created in topics in private categories or PMs (private messages) can be retrieved by anyone, even if they're not logged in. This problem…
AnalizadaMedia (4.3)0.39%—Discourse Calendar21/2/202417/6/2026
Discourse Calendar adds the ability to create a dynamic calendar in the first post of a topic on Discourse. Uninvited users are able to gain access to private events by crafting a request to update their attendance. This problem is resolved in commit dfc4fa15f340189f177a1d1ab2cc94ffed3c1190. As a workaround, one may…
AnalizadaMedia (6.1)0.31%—Digital-peak Dpcalendar15/2/202417/6/2026
XSS vulnerability in DP Calendar component for Joomla.
ModificadaCrítica (9.8)3.2%💥 PoCWpbookingcalendar Booking Calendar8/2/202417/6/2026
The WP Booking Calendar plugin for WordPress is vulnerable to SQL Injection via the 'calendar_request_params[dates_ddmmyy_csv]' parameter in all versions up to, and including, 9.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it…
ModificadaCrítica (9.8)0.80%—Bookingcalendar Project Bookingcalendar7/2/202417/6/2026
SQL Injection vulnerability in RM bookingcalendar module for PrestaShop versions 2.7.9 and before, allows remote attackers to execute arbitrary code, escalate privileges, and obtain sensitive information via ics_export.php.
ModificadaMedia (5.3)0.56%—Stellarwp THE Events Calendar5/2/202417/6/2026
The The Events Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.2.8.2 via the route function hooked into wp_ajax_nopriv_tribe_dropdown. This makes it possible for unauthenticated attackers to extract potentially sensitive data including post titles…
ModificadaMedia (5.4)0.74%💥 PoCDandulaney Dan's Embedder FOR Google Calendar5/2/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dan Dulaney Dan's Embedder for Google Calendar allows Stored XSS.This issue affects Dan's Embedder for Google Calendar: from n/a through 1.2.
ModificadaMedia (5.4)0.33%—Wpbookingcalendar Booking Calendar1/2/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPdevelop / Oplugins WP Booking Calendar allows Stored XSS.This issue affects WP Booking Calendar: from n/a before 9.7.4.
ModificadaMedia (6.1)0.46%—Webcalendar Project Webcalendar25/1/202417/6/2026
WebCalendar v1.3.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /WebCalendarvqsmnseug2/edit_entry.php.
ModificadaMedia (5.4)0.31%—Michielvaneerd Private Google Calendars8/1/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michiel van Eerd Private Google Calendars allows Stored XSS.This issue affects Private Google Calendars: from n/a through 20231125.
ModificadaAlta (8.8)0.54%—Coolplugins Events Shortcodes FOR THE Events Calendar8/1/202417/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cool Plugins Events Shortcodes For The Events Calendar.This issue affects Events Shortcodes For The Events Calendar: from n/a through 2.3.1.
ModificadaAlta (8.8)0.48%—MF GIG Calendar Project MF GIG Calendar28/12/202317/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Matthew Fries MF Gig Calendar.This issue affects MF Gig Calendar: from n/a through 1.2.1.
ModificadaAlta (7.5)0.58%—Zhwnl Chinese Perpetual Calendar28/12/202317/6/2026
An issue in the openFile method of Chinese Perpetual Calendar v9.0.0 allows attackers to read any file via unspecified vectors.
ModificadaMedia (6.5)0.55%—Nextcloud Calendar22/12/202317/6/2026
Nextcloud/Cloud is a calendar app for Nextcloud. An attacker can gain access to stacktrace and internal paths of the server when generating an exception while editing a calendar appointment. It is recommended that the Nextcloud Calendar app is upgraded to 4.5.3
ModificadaAlta (8.1)0.43%—Zackgrossbart Editorial Calendar20/12/202317/6/2026
Authorization Bypass Through User-Controlled Key vulnerability in MarketingFire Editorial Calendar.This issue affects Editorial Calendar: from n/a through 3.7.12.
ModificadaAlta (7.5)0.78%—Stellarwp THE Events Calendar18/12/202317/6/2026
The Events Calendar WordPress plugin before 6.2.8.1 discloses the content of password protected posts to unauthenticated users via a crafted request
ModificadaMedia (5.4)0.40%—Sureswiftcapital Simple Calendar14/12/202317/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Simple Calendar Simple Calendar – Google Calendar Plugin allows Stored XSS.This issue affects Simple Calendar – Google Calendar Plugin: from n/a through 3.2.6.
ModificadaMedia (5.4)0.41%—Spiffyplugins Spiffy Calendar14/12/202317/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Spiffy Plugins Spiffy Calendar allows Stored XSS.This issue affects Spiffy Calendar: from n/a through 4.9.5.
ModificadaAlta (7.5)1.1%—Phpjabbers Time Slots Booking Calendar7/12/202317/6/2026
A lack of rate limiting in pjActionAJaxSend in Time Slots Booking Calendar 4.0 allows attackers to cause resource exhaustion.
ModificadaAlta (7.5)1.2%—Phpjabbers Availability Booking Calendar7/12/202317/6/2026
A lack of rate limiting in pjActionAJaxSend in Availability Booking Calendar 5.0 allows attackers to cause resource exhaustion.
ModificadaMedia (5.4)0.46%—Phpjabbers Time Slots Booking Calendar7/12/202317/6/2026
Time Slots Booking Calendar 4.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) issues via the name, plugin_sms_api_key, plugin_sms_country_code, calendar_id, title, country name, or customer_name parameter.
ModificadaMedia (5.4)0.46%—Phpjabbers Time Slots Booking Calendar7/12/202317/6/2026
Time Slots Booking Calendar 4.0 is vulnerable to Multiple HTML Injection issues via the name, plugin_sms_api_key, plugin_sms_country_code, calendar_id, title, country name, or customer_name parameter.
Orbitaley — Vulnerabilidades