Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

797 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)1.2%—Phpjabbers Time Slots Booking Calendar7/12/202317/6/2026
Time Slots Booking Calendar 4.0 is vulnerable to CSV Injection via the unique ID field of the Reservations List.
ModificadaMedia (5.4)0.45%—Phpjabbers Availability Booking Calendar7/12/202317/6/2026
Availability Booking Calendar 5.0 is vulnerable to Multiple HTML Injection issues via SMS API Key or Default Country Code.
ModificadaMedia (6.1)0.50%—Phpjabbers Availability Booking Calendar7/12/202317/6/2026
A Cross Site Scripting vulnerability in Availability Booking Calendar 5.0 allows an attacker to inject JavaScript via the name, plugin_sms_api_key, plugin_sms_country_code, uuid, title, or country name parameter to index.php.
ModificadaAlta (8.8)1.2%—Phpjabbers Availability Booking Calendar7/12/202317/6/2026
Availability Booking Calendar 5.0 allows CSV injection via the unique ID field in the Reservations list component.
ModificadaMedia (6.1)0.56%—Cainor Calendarinho1/12/202317/6/2026
Calendarinho is an open source calendaring application to manage large teams of consultants. An Open Redirect issue occurs when a web application redirects users to external URLs without proper validation. This can lead to phishing attacks, where users are tricked into visiting malicious sites, potentially leading to…
ModificadaCrítica (9.8)63%💥 ExploitJoedolson MY Calendar30/11/202317/6/2026
The 'My Calendar' WordPress Plugin, version < 3.4.22 is affected by an unauthenticated SQL injection vulnerability in the 'from' and 'to' parameters in the '/my-calendar/v1/events' rest route.
ModificadaAlta (8.8)0.25%—Offshorewebmaster Availability Calendar30/11/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Offshore Web Master Availability Calendar allows Cross Site Request Forgery.This issue affects Availability Calendar: from n/a through 1.2.6.
ModificadaMedia (6.1)0.68%—Luxsoft Luxcal WEB Calendar20/11/202317/6/2026
Cross-site scripting vulnerability in LuxCal Web Calendar prior to 5.2.4M (MySQL version) and LuxCal Web Calendar prior to 5.2.4L (SQLite version) allows a remote unauthenticated attacker to execute an arbitrary script on the web browser of the user who is accessing the product.
ModificadaCrítica (9.8)1.0%—Luxsoft Luxcal WEB Calendar20/11/202317/6/2026
SQL injection vulnerability in LuxCal Web Calendar prior to 5.2.4M (MySQL version) and LuxCal Web Calendar prior to 5.2.4L (SQLite version) allows a remote unauthenticated attacker to execute an arbitrary SQL command by sending a crafted request, and obtain or alter information stored in the database.
ModificadaAlta (8.8)1.1%—Oss-calendar OSS Calendar14/11/202317/6/2026
SQL injection vulnerability in OSS Calendar versions prior to v.2.0.3 allows a remote authenticated attacker to execute arbitrary code or obtain and/or alter the information stored in the database by sending a specially crafted request.
ModificadaAlta (8.8)0.31%—Chronosly-events-calendar Project Chronosly-events-calendar9/11/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Chronosly Chronosly Events Calendar plugin <= 2.6.2 versions.
ModificadaMedia (5.4)0.41%—Add-to-calendar-button ADD TO Calendar Button8/11/202317/6/2026
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Jens Kuerschner Add to Calendar Button plugin <= 1.5.1 versions.
ModificadaCrítica (9.8)0.68%—Wpdevart Booking Calendar6/11/202317/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WpDevArt Booking calendar, Appointment Booking System allows SQL Injection.This issue affects Booking calendar, Appointment Booking System: from n/a through 3.2.7.
ModificadaCrítica (9.8)0.55%—Spiffyplugins Spiffy Calendar3/11/202317/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Spiffy Plugins Spiffy Calendar spiffy-calendar allows SQL Injection.This issue affects Spiffy Calendar: from n/a through 4.9.1.
ModificadaAlta (8.8)0.27%—Apointzilla Appointment Calendar25/10/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Scientech It Solution Appointment Calendar plugin <= 2.9.6 versions.
ModificadaAlta (8.8)0.28%—Xtendify Simple Calendar25/10/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Simple Calendar – Google Calendar Plugin <= 3.2.5 versions.
ModificadaMedia (5.4)0.41%—Osmansorkar Ajax Archive Calendar25/10/202317/6/2026
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Osmansorkar Ajax Archive Calendar plugin <= 2.6.7 versions.
ModificadaMedia (4.8)0.37%—Webnus Modern Events Calendar Lite20/10/202317/6/2026
The Modern Events Calendar lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Google API key and Calendar ID in versions up to, but not including, 7.1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level…
ModificadaMedia (6.1)0.50%—Discourse Calendar16/10/202317/6/2026
dicourse-calendar is a plugin for the Discourse messaging platform which adds the ability to create a dynamic calendar in the first post of a topic. Improper escaping of event titles could lead to Cross-site Scripting (XSS) within the 'email preview' UI when a site has CSP disabled. Having CSP disabled is a…
ModificadaMedia (4.3)0.39%—Nextcloud Calendar16/10/202317/6/2026
Nextcloud calendar is a calendar app for the Nextcloud server platform. Due to missing precondition checks the server was trying to validate strings of any length as email addresses even when megabytes of data were provided, eventually making the server busy and unresponsive. It is recommended that the Nextcloud…
ModificadaMedia (6.1)0.56%—Wpbookingcalendar Booking Calendar16/10/202317/6/2026
The Booking Calendar WordPress plugin before 9.7.3.1 does not sanitize and escape some of its booking from data, allowing unauthenticated users to perform Stored Cross-Site Scripting attacks against administrators
ModificadaAlta (8.8)0.21%—Mattmckenny Stout Google Calendar16/10/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Matt McKenny Stout Google Calendar plugin <= 1.2.3 versions.
ModificadaAlta (8.8)0.26%—Toolstack Schedule Posts Calendar6/10/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Greg Ross Schedule Posts Calendar plugin <= 5.2 versions.
ModificadaMedia (4.8)0.37%—Toolstack Schedule Posts Calendar6/9/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Greg Ross Schedule Posts Calendar plugin <= 5.2 versions.
ModificadaMedia (6.1)0.37%—Vcita Online Booking & Scheduling Calendar4/9/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in vCita.Com Online Booking & Scheduling Calendar for WordPress by vcita plugin <= 4.3.2 versions.
Orbitaley — Vulnerabilidades