Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2715▼ 529 respecto a la semana anterior
Críticas / altas1290▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
797 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.44% | — | Editorial Calendar Project Editorial Calendar | 27/6/2023 | 17/6/2026 | The Editorial Calendar WordPress plugin before 3.8.3 does not sanitise and escape its settings, allowing users with roles as low as contributor to inject arbitrary web scripts in the plugin admin panel, enabling a Stored Cross-Site Scripting vulnerability targeting higher privileged users. | |
| Modificada | Media (4.3) | 0.48% | — | Vcita Online Booking & Scheduling Calendar | 9/6/2023 | 17/6/2026 | The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the vcita_save_settings_callback function in versions up to, and including, 4.4.6. This makes it possible for authenticated attackers with minimal… | |
| Modificada | Alta (8.8) | 1.4% | — | Coolplugins Cool TimelineCoolplugins Cryptocurrency WidgetsCoolplugins Cryptocurrency Widgets FOR ElementorCoolplugins Event Single Page Builder FOR THE Event Calendar+6 | 7/6/2023 | 17/6/2026 | Several WordPress plugins developed by Cool Plugins are vulnerable to arbitrary plugin installation and activation that can lead to remote code execution by authenticated attackers with minimal permissions, such as a subscriber. | |
| Modificada | Media (6.5) | 0.39% | — | Vcita Online Booking & Scheduling Calendar | 3/6/2023 | 17/6/2026 | The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Cross-Site Request Forgery due to a missing nonce check on the vcita_logout_callback function in versions up to, and including, 4.5. This makes it possible for unauthenticated to logout a vctia connected account which… | |
| Modificada | Media (5.4) | 0.70% | — | Vcita Online Booking & Scheduling Calendar | 3/6/2023 | 17/6/2026 | The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the vcita_logout_callback function in versions up to, and including, 4.2.10. This makes it possible for authenticated attackers with minimal… | |
| Modificada | Media (6.5) | 0.42% | — | Event Registration Calendar BY VcitaVcita Online Payments - GET Paid With Paypal, Square & Stripe | 3/6/2023 | 17/6/2026 | The Event Registration Calendar By vcita plugin, versions up to and including 3.10.0, and Online Payments – Get Paid with PayPal, Square & Stripe plugin, for WordPress are vulnerable to Cross-Site Request Forgery. This is due to missing nonce validation in the ls_parse_vcita_callback() function. This makes it possible… | |
| Modificada | Media (5.4) | 0.76% | — | Event Registration Calendar BY VcitaVcita Online Payments - GET Paid With Paypal, Square & Stripe | 3/6/2023 | 17/6/2026 | The Event Registration Calendar By vcita plugin, versions up to and including 3.9.1, and Online Payments – Get Paid with PayPal, Square & Stripe plugin, for WordPress are vulnerable to Stored Cross-Site Scripting via the 'email' parameter in versions up to, and including, 1.3.1 due to insufficient input sanitization… | |
| Modificada | Media (5.3) | 0.64% | — | Vcita Online Booking & Scheduling Calendar | 3/6/2023 | 17/6/2026 | The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to unauthorized medication of data via the /wp-json/vcita-wordpress/v1/actions/auth REST-API endpoint in versions up to, and including, 4.4.2 due to a missing capability check on the processAction function. This makes it… | |
| Modificada | Media (6.1) | 0.60% | — | Vcita Online Booking & Scheduling Calendar | 3/6/2023 | 17/6/2026 | The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'business_id' parameter in versions up to, and including, 4.3.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to… | |
| Modificada | Media (4.3) | 0.44% | — | Nextcloud Calendar | 30/5/2023 | 17/6/2026 | Calendar app for Nextcloud easily sync events from various devices with your Nextcloud. Some internal paths of the website are disclosed when the SMTP server is unavailable. It is recommended that the Calendar app is updated to 3.5.5 or 4.2.3 | |
| Modificada | Alta (8.8) | 0.26% | — | Bookingultrapro Booking Ultra PRO Appointments Booking Calendar | 24/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Booking Ultra Pro Appointments Booking Calendar Plugin plugin <= 1.1.4 versions. | |
| Modificada | Alta (8.8) | 0.27% | — | MY Calendar Project MY Calendar | 22/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Joseph C Dolson My Calendar plugin <= 3.4.3 versions. | |
| Modificada | Media (4.8) | 0.37% | — | Easy Event Calendar Project Easy Event Calendar | 8/5/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in CoreFortress Easy Event calendar plugin <= 1.0 versions. | |
| Modificada | Crítica (9.8) | 1.0% | — | Codepeople CP Appointment Calendar | 10/4/2023 | 17/6/2026 | A vulnerability classified as critical has been found in CP Appointment Calendar Plugin up to 1.1.5 on WordPress. This affects the function dex_process_ready_to_go_appointment of the file dex_appointments.php. The manipulation of the argument itemnumber leads to sql injection. It is possible to initiate the attack… | |
| Modificada | Crítica (9.8) | 0.72% | — | Editorial Calendar Project Editorial Calendar | 8/4/2023 | 16/6/2026 | A vulnerability was found in Editorial Calendar Plugin up to 2.6 on WordPress. It has been declared as critical. Affected by this vulnerability is the function edcal_filter_where of the file edcal.php. The manipulation of the argument edcal_startDate/edcal_endDate leads to sql injection. The attack can be launched… | |
| Modificada | Media (5.4) | 0.38% | — | Wpdevart Booking Calendar | 29/3/2023 | 17/6/2026 | Auth. (editor+) Stored Cross-Site Scripting (XSS) vulnerability in WpDevArt Booking calendar, Appointment Booking System plugin <= 3.2.3 versions. | |
| Modificada | Media (4.8) | 0.50% | — | Webnus Modern Events Calendar Lite | 27/3/2023 | 17/6/2026 | The Modern Events Calendar Lite WordPress plugin before 6.5.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Modificada | Media (5.4) | 0.39% | — | WP Calendar Project WP Calendar | 17/3/2023 | 17/6/2026 | Stored Cross-Site Scripting (XSS) vulnerability in Fabian von Allmen WP Calendar plugin <= 1.5.3 versions. | |
| Modificada | Baja (3.3) | 0.14% | — | Samsung Calendar | 16/3/2023 | 17/6/2026 | Improper access control in Samsung Calendar prior to versions 12.4.02.9000 in Android 13 and 12.3.08.2000 in Android 12 allows local attacker to configure improper status. | |
| Modificada | Alta (8.8) | 0.27% | — | MY Calendar Project MY Calendar | 15/3/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Joseph C Dolson My Calendar plugin <= 3.3.24.1 versions. | |
| Modificada | Media (5.4) | 0.23% | — | Wpdevart Booking Calendar | 17/2/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WpDevArt Booking calendar, Appointment Booking System plugin <= 3.2.3 versions affects plugin forms actions (create, duplicate, edit, delete). | |
| Modificada | Media (5.3) | 0.69% | — | Pixelite WP Fullcalendar | 13/2/2023 | 17/6/2026 | The WP FullCalendar WordPress plugin before 1.5 does not ensure that the post retrieved via an AJAX action is public and can be accessed by the user making the request, allowing unauthenticated attackers to get the content of arbitrary posts, including draft/private as well as password-protected ones. | |
| Modificada | Alta (8.8) | 0.73% | — | Calendar Event Management System Project Calendar Event Management System | 4/2/2023 | 17/6/2026 | A vulnerability, which was classified as critical, was found in Calendar Event Management System 2.3.0. This affects an unknown part. The manipulation of the argument start/end leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The… | |
| Modificada | Crítica (9.8) | 0.88% | — | Calendar Event Management System Project Calendar Event Management System | 3/2/2023 | 17/6/2026 | A vulnerability was found in Calendar Event Management System 2.3.0. It has been rated as critical. This issue affects some unknown processing of the component Login Page. The manipulation of the argument name/pwd leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the… | |
| Modificada | Media (6.1) | 0.89% | 💥 Exploit | Mhsoftware Wordpress Events Calendar Plugin | 16/1/2023 | 17/6/2026 | The WordPress Events Calendar WordPress plugin before 1.4.5 does not sanitize and escapes a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against both unauthenticated and authenticated users (such as high-privilege ones like admin). |