Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
324 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 2.4% | — | Google Calendar Events Project Google Calendar Events | 16/10/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Google Calendar Events plugin before 2.0.4 for WordPress allows remote attackers to inject arbitrary web script or HTML via the gce_feed_ids parameter in a gce_ajax action to wp-admin/admin-ajax.php. | |
| Modificada | Media (4.3) | 2.1% | — | Netweblogic Events ManagerNetweblogic Events Manager PRO | 13/5/2014 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the Events Manager plugin before 5.3.5 and Events Manager Pro plugin before 2.2.9 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) scope parameter to index.php; (2) user_name, (3) dbem_phone, (4) user_email, or (5)… | |
| Modificada | Media (5) | 1.4% | — | Tibco Activematrix Service BUSTibco Activematrix Service GridTibco Activematrix Businessworks Service EngineTibco Silver Fabric Activematrix Service Grid Distribution+3 | 13/3/2012 | 16/6/2026 | TIBCO ActiveMatrix Runtime Platform in Service Grid and Service Bus 2.x before 2.3.2 and BusinessWorks Service Engine before 5.8.2; TIBCO ActiveMatrix Platform in TIBCO Silver Fabric ActiveMatrix Service Grid Distribution 3.1.3, Service Grid and Service Bus 3.x before 3.1.5, BusinessWorks Service Engine 5.9.x before… | |
| Modificada | Alta (7.5) | 1.1% | — | Jevents Search Plugin | 12/2/2010 | 16/6/2026 | SQL injection vulnerability in the plgSearchEventsearch::onSearch method in eventsearch.php in the JEvents Search plugin 1.5 through 1.5.3 for Joomla! allows remote attackers to execute arbitrary SQL commands via unspecified vectors. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (10) | 3.3% | — | IBM Websphere Business Events | 18/9/2009 | 16/6/2026 | Unspecified vulnerability in the wberuntimeear application in the test servlet in IBM WebSphere Business Events 6.1 and 6.2 allows remote attackers to execute arbitrary code via unknown vectors. | |
| Modificada | Alta (7.2) | 2.6% | — | Mevin Basic PHP Events Lister | 11/9/2009 | 16/6/2026 | Mevin Productions Basic PHP Events Lister 2.0 does not properly restrict access to (1) admin/reset.php and (2) admin/user_add.php, which allows remote authenticated users to reset administrative passwords or add administrators via a direct request. | |
| Modificada | Alta (7.5) | 2.4% | 💥 Exploit | Developiteasy Events Calendar | 6/4/2009 | 16/6/2026 | Multiple SQL injection vulnerabilities in DevelopItEasy Events Calendar 1.2 allow remote attackers to execute arbitrary SQL commands via (1) the user_name parameter (aka user field) to admin/index.php, (2) the user_pass parameter (aka pass field) to admin/index.php, or (3) the id parameter to calendar_details.php.… | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Mevin Basic-php-events-lister | 13/3/2009 | 16/6/2026 | SQL injection vulnerability in event.php in Mevin Productions Basic PHP Events Lister 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Media (5) | 2.6% | 💥 Exploit | Donnafontenot Mycal Personal Events Calendar | 2/3/2009 | 16/6/2026 | MyCal Personal Events Calendar stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing the username and password via a direct request to mycal.mdb. | |
| Modificada | Media (5) | 2.6% | 💥 Exploit | Donnafontenot Evcal Events Calendar | 2/3/2009 | 16/6/2026 | evCal Events Calendar stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing the username and password via a direct request to (1) evcal.mdb and (2) evcal97.mdb. | |
| Modificada | Media (5) | 1.2% | — | Asp-dev XM Events Diary | 21/1/2009 | 16/6/2026 | ASP-DEv XM Events Diary stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for diary.mdb. | |
| Modificada | Alta (7.5) | 1.0% | — | Asp-dev XM Events Diary | 21/1/2009 | 16/6/2026 | SQL injection vulnerability in diary_viewC.asp in ASP-DEv XM Events Diary allows remote attackers to execute arbitrary SQL commands via the cat parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Asp-dev XM Events Diary | 21/1/2009 | 16/6/2026 | SQL injection vulnerability in default.asp in ASP-DEv XM Events Diary allows remote attackers to execute arbitrary SQL commands the cat parameter. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Sirium AM Events Module | 30/12/2008 | 16/6/2026 | SQL injection vulnerability in print.php in the AM Events (aka Amevents) module 0.22 for XOOPS allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Alta (10) | 4.5% | 💥 Exploit | Webbiscuits Events Calendar | 22/10/2008 | 16/6/2026 | PHP remote file inclusion vulnerability in panel/common/theme/default/header_setup.php in WebBiscuits Software Events Calendar 1.1 allows remote attackers to execute arbitrary PHP code via a URL in the (1) path[docroot] and (2) component parameters. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Dale Mooney Calendar Events | 31/8/2007 | 16/6/2026 | SQL injection vulnerability in viewevent.php in Moonware (aka Dale Mooney Gallery) allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Webevents | 3/8/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in webevent.cgi in WebEvent 2.61 through 4.03 allows remote attackers to inject arbitrary web script or HTML via the cmd parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Alta (7.5) | 2.0% | 💥 Exploit | Dragon Internet Events Listing | 22/11/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in Dragon Calendar / Events Listing 2.x allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameter to (a) admin_login.asp, the (3) ID parameter to (b) event_searchdetail.asp, or the (4) VenueID parameter to (c) venue_detail.asp. | |
| Modificada | Media (5) | 1.0% | — | Webevents Online Event Registration | 21/11/2006 | 16/6/2026 | save_profile.asp in WebEvents (Online Event Registration Template) 2.0 and earlier allows remote attackers to change the profiles, passwords, and other information for arbitrary users via a modified UserID parameter. | |
| Modificada | Alta (7.5) | 1.4% | — | Joomla COM EventsJoomla Events Module | 27/9/2006 | 16/6/2026 | Unspecified vulnerability in Events 1.3 beta module (com_events) for Joomla! has unspecified impact and attack vectors. | |
| Modificada | Alta (7.5) | 4.0% | 💥 Exploit | Web-scripts Visual Events Calendar | 10/8/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in calendar.php in Visual Events Calendar 1.1 allows remote attackers to execute arbitrary PHP code via a URL in the cfg_dir parameter. | |
| Modificada | Alta (7.5) | 1.4% | — | Maian Events | 21/3/2006 | 16/6/2026 | SQL injection vulnerability in events.php in Maian Events 1.0 allows remote attackers to execute arbitrary SQL commands via the (1) month and (2) year parameters. | |
| Modificada | Alta (7.5) | 1.3% | — | Wwweb Concepts Events System | 5/6/2005 | 16/6/2026 | SQL injection vulnerability in login.asp for WWWeb Concepts Events System 1.0 allows remote attackers to execute arbitrary SQL commands via the password. | |
| Modificada | Baja (3.3) | 0.32% | — | Heysoft EventsaveHeysoft Eventsave+ | 31/12/2002 | 16/6/2026 | Heysoft EventSave 5.1 and 5.2 and Heysoft EventSave+ 5.1 and 5.2 does not check whether the log file can be written to, which allows attackers to prevent events from being recorded by opening the log file using an application such as Microsoft's Event Viewer. |