Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
797 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 0.20% | — | Wpsimplebookingcalendar WP Simple Booking Calendar | 15/3/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Veribo, Roland Murg WP Simple Booking Calendar.This issue affects WP Simple Booking Calendar: from n/a through 2.0.8.4. | |
| Aplazada | Media (6.5) | 0.33% | — | Joseph C Dolson MY CalendarAI | 15/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Joseph C Dolson My Calendar allows Stored XSS.This issue affects My Calendar: from n/a through 3.4.23. | |
| Analizada | Media (5.3) | 0.48% | — | Spiffyplugins Spiffy Calendar | 27/2/2024 | 17/6/2026 | The Spiffy Calendar WordPress plugin before 4.9.9 doesn't check the event_author parameter, and allows any user to alter it when creating an event, leading to deceiving users/admins that a page was created by a Contributor+. | |
| Analizada | Media (5.3) | 0.42% | — | Discourse Calendar | 22/2/2024 | 17/6/2026 | Discourse Calendar adds the ability to create a dynamic calendar in the first post of a topic on the open-source discussion platform Discourse. Prior to version 0.4, event invitees created in topics in private categories or PMs (private messages) can be retrieved by anyone, even if they're not logged in. This problem… | |
| Analizada | Media (4.3) | 0.39% | — | Discourse Calendar | 21/2/2024 | 17/6/2026 | Discourse Calendar adds the ability to create a dynamic calendar in the first post of a topic on Discourse. Uninvited users are able to gain access to private events by crafting a request to update their attendance. This problem is resolved in commit dfc4fa15f340189f177a1d1ab2cc94ffed3c1190. As a workaround, one may… | |
| Analizada | Media (6.1) | 0.31% | — | Digital-peak Dpcalendar | 15/2/2024 | 17/6/2026 | XSS vulnerability in DP Calendar component for Joomla. | |
| Modificada | Crítica (9.8) | 3.2% | 💥 PoC | Wpbookingcalendar Booking Calendar | 8/2/2024 | 17/6/2026 | The WP Booking Calendar plugin for WordPress is vulnerable to SQL Injection via the 'calendar_request_params[dates_ddmmyy_csv]' parameter in all versions up to, and including, 9.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it… | |
| Modificada | Crítica (9.8) | 0.80% | — | Bookingcalendar Project Bookingcalendar | 7/2/2024 | 17/6/2026 | SQL Injection vulnerability in RM bookingcalendar module for PrestaShop versions 2.7.9 and before, allows remote attackers to execute arbitrary code, escalate privileges, and obtain sensitive information via ics_export.php. | |
| Modificada | Media (5.3) | 0.56% | — | Stellarwp THE Events Calendar | 5/2/2024 | 17/6/2026 | The The Events Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.2.8.2 via the route function hooked into wp_ajax_nopriv_tribe_dropdown. This makes it possible for unauthenticated attackers to extract potentially sensitive data including post titles… | |
| Modificada | Media (5.4) | 0.74% | 💥 PoC | Dandulaney Dan's Embedder FOR Google Calendar | 5/2/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dan Dulaney Dan's Embedder for Google Calendar allows Stored XSS.This issue affects Dan's Embedder for Google Calendar: from n/a through 1.2. | |
| Modificada | Media (5.4) | 0.33% | — | Wpbookingcalendar Booking Calendar | 1/2/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPdevelop / Oplugins WP Booking Calendar allows Stored XSS.This issue affects WP Booking Calendar: from n/a before 9.7.4. | |
| Modificada | Media (6.1) | 0.46% | — | Webcalendar Project Webcalendar | 25/1/2024 | 17/6/2026 | WebCalendar v1.3.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /WebCalendarvqsmnseug2/edit_entry.php. | |
| Modificada | Media (5.4) | 0.31% | — | Michielvaneerd Private Google Calendars | 8/1/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michiel van Eerd Private Google Calendars allows Stored XSS.This issue affects Private Google Calendars: from n/a through 20231125. | |
| Modificada | Alta (8.8) | 0.54% | — | Coolplugins Events Shortcodes FOR THE Events Calendar | 8/1/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cool Plugins Events Shortcodes For The Events Calendar.This issue affects Events Shortcodes For The Events Calendar: from n/a through 2.3.1. | |
| Modificada | Alta (8.8) | 0.48% | — | MF GIG Calendar Project MF GIG Calendar | 28/12/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Matthew Fries MF Gig Calendar.This issue affects MF Gig Calendar: from n/a through 1.2.1. | |
| Modificada | Alta (7.5) | 0.58% | — | Zhwnl Chinese Perpetual Calendar | 28/12/2023 | 17/6/2026 | An issue in the openFile method of Chinese Perpetual Calendar v9.0.0 allows attackers to read any file via unspecified vectors. | |
| Modificada | Media (6.5) | 0.55% | — | Nextcloud Calendar | 22/12/2023 | 17/6/2026 | Nextcloud/Cloud is a calendar app for Nextcloud. An attacker can gain access to stacktrace and internal paths of the server when generating an exception while editing a calendar appointment. It is recommended that the Nextcloud Calendar app is upgraded to 4.5.3 | |
| Modificada | Alta (8.1) | 0.43% | — | Zackgrossbart Editorial Calendar | 20/12/2023 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in MarketingFire Editorial Calendar.This issue affects Editorial Calendar: from n/a through 3.7.12. | |
| Modificada | Alta (7.5) | 0.78% | — | Stellarwp THE Events Calendar | 18/12/2023 | 17/6/2026 | The Events Calendar WordPress plugin before 6.2.8.1 discloses the content of password protected posts to unauthenticated users via a crafted request | |
| Modificada | Media (5.4) | 0.40% | — | Sureswiftcapital Simple Calendar | 14/12/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Simple Calendar Simple Calendar – Google Calendar Plugin allows Stored XSS.This issue affects Simple Calendar – Google Calendar Plugin: from n/a through 3.2.6. | |
| Modificada | Media (5.4) | 0.41% | — | Spiffyplugins Spiffy Calendar | 14/12/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Spiffy Plugins Spiffy Calendar allows Stored XSS.This issue affects Spiffy Calendar: from n/a through 4.9.5. | |
| Modificada | Alta (7.5) | 1.1% | — | Phpjabbers Time Slots Booking Calendar | 7/12/2023 | 17/6/2026 | A lack of rate limiting in pjActionAJaxSend in Time Slots Booking Calendar 4.0 allows attackers to cause resource exhaustion. | |
| Modificada | Alta (7.5) | 1.2% | — | Phpjabbers Availability Booking Calendar | 7/12/2023 | 17/6/2026 | A lack of rate limiting in pjActionAJaxSend in Availability Booking Calendar 5.0 allows attackers to cause resource exhaustion. | |
| Modificada | Media (5.4) | 0.46% | — | Phpjabbers Time Slots Booking Calendar | 7/12/2023 | 17/6/2026 | Time Slots Booking Calendar 4.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) issues via the name, plugin_sms_api_key, plugin_sms_country_code, calendar_id, title, country name, or customer_name parameter. | |
| Modificada | Media (5.4) | 0.46% | — | Phpjabbers Time Slots Booking Calendar | 7/12/2023 | 17/6/2026 | Time Slots Booking Calendar 4.0 is vulnerable to Multiple HTML Injection issues via the name, plugin_sms_api_key, plugin_sms_country_code, calendar_id, title, country name, or customer_name parameter. |