Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

797 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)0.53%—Webcalendar Project Webcalendar13/1/202317/6/2026
Cross-site Scripting (XSS) - Stored in GitHub repository craigk5n/webcalendar prior to master.
ModificadaMedia (6.1)0.56%—Calendarxp15/12/202217/6/2026
A vulnerability classified as problematic was found in CalendarXP up to 10.0.1. This vulnerability affects unknown code. The manipulation leads to cross site scripting. The attack can be initiated remotely. Upgrading to version 10.0.2 is able to address this issue. The name of the patch is…
ModificadaMedia (5.1)0.60%—Php-calendar13/12/202217/6/2026
A vulnerability was identified in sproctor php-calendar up to 2.0.13. This impacts an unknown function of the file index.php. Such manipulation of the argument $_SERVER['PHP_SELF'] leads to cross site scripting. The attack may be launched remotely. The name of the patch is a2941109b42201c19733127ced763e270a357809. It…
ModificadaCrítica (9.8)4.5%💥 ExploitWpdevart Booking Calendar12/12/202217/6/2026
The Booking calendar, Appointment Booking System WordPress plugin before 3.2.2 does not validate uploaded files, which could allow unauthenticated users to upload arbitrary files, such as PHP and achieve RCE
ModificadaMedia (5.5)0.30%—Samsung Calendar8/12/202217/6/2026
Improper access control vulnerability in Calendar prior to versions 11.6.08.0 in Android Q(10), 12.2.11.3000 in Android R(11), 12.3.07.2000 in Android S(12), and 12.4.02.0 in Android T(13) allows attackers to access sensitive information via implicit intent.
ModificadaMedia (6.5)0.25%—Elbtide Advanced Booking Calendar5/12/202217/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Advanced Booking Calendar plugin <= 1.7.1 on WordPress.
ModificadaCrítica (9.8)0.81%—Elbtide Advanced Booking Calendar5/12/202217/6/2026
Unauth. SQL Injection (SQLi) vulnerability in Advanced Booking Calendar plugin <= 1.7.1 on WordPress.
ModificadaAlta (8.8)0.54%—Codepeople Appointment Booking Calendar18/11/202217/6/2026
Missing Authorization vulnerability in Appointment Booking Calendar plugin <= 1.3.69 on WordPress.
ModificadaMedia (5.4)0.41%—Discourse Calendar14/11/202217/6/2026
Discourse-calendar is a plugin for the Discourse messaging platform which adds the ability to create a dynamic calendar in the first post of a topic. Members of private groups or public groups with private members can be listed by users, who can create and edit post events. This vulnerability only affects sites which…
ModificadaMedia (6.5)0.50%—VR Calendar Project VR Calendar3/11/202217/6/2026
The VR Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.3.3. This is due to missing or incorrect nonce validation on several functions. This makes it possible for unauthenticated attackers to delete, and modify calendars as well as the plugin settings, via…
ModificadaMedia (6.1)0.27%—Bookingultrapro Booking Ultra PRO Appointments Booking Calendar30/9/202217/6/2026
Cross-Site Scripting (XSS) via Cross-Site Request Forgery (CSRF) vulnerability in Booking Ultra Pro plugin <= 1.1.4 at WordPress.
ModificadaAlta (8.8)0.34%—Bookingultrapro Booking Ultra PRO Appointments Booking Calendar30/9/202217/6/2026
Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in Booking Ultra Pro plugin <= 1.1.4 at WordPress.
ModificadaMedia (5.4)0.55%—Total-soft Event Calendar21/9/202217/6/2026
Authenticated (subscriber+) Reflected Cross-Site Scripting (XSS) vulnerability in Totalsoft Event Calendar – Calendar plugin <= 1.4.6 at WordPress.
ModificadaMedia (5.3)0.66%—Total-soft Event Calendar9/9/202217/6/2026
Unauthenticated Event Deletion vulnerability in Totalsoft Event Calendar – Calendar plugin <= 1.4.6 at WordPress.
ModificadaMedia (4.3)0.32%—Wpbookingcalendar Booking Calendar6/9/202217/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in WPdevelop/Oplugins Booking Calendar plugin <= 9.2.1 at WordPress leading to Translations Update.
ModificadaMedia (4.3)2.6%💥 ExploitDwbooster Calendar Event Multi View16/8/202217/6/2026
The Calendar Event Multi View WordPress plugin before 1.4.07 does not have any authorisation and CSRF checks in place when creating an event, and is also lacking sanitisation as well as escaping in some of the event fields. This could allow unauthenticated attackers to create arbitrary events and put Cross-Site…
ModificadaCrítica (9.8)17%💥 ExploitVR Calendar Project VR Calendar15/8/202217/6/2026
The VR Calendar WordPress plugin through 2.3.2 lets any user execute arbitrary PHP functions on the site.
ModificadaMedia (4.3)0.91%—Synology Calendar3/8/202217/6/2026
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Synology Calendar before 2.3.4-0631 allows remote authenticated users to download arbitrary files via unspecified vectors.
ModificadaAlta (8)0.33%—Synology Calendar26/7/202217/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in webapi component in Synology Calendar before 2.3.4-0631 allows remote authenticated users to hijack the authentication of administrators via unspecified vectors.
ModificadaBaja (3.3)0.20%—Samsung Calendar12/7/202217/6/2026
Information exposure in Calendar prior to version 12.3.05.10000 allows attacker to access calendar schedule without READ_CALENDAR permission.
ModificadaMedia (5.4)0.56%—Synology Calendar12/7/202217/6/2026
Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Event Management in Synology Calendar before 2.4.5-10930 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (5.4)0.55%—Webnus Modern Events Calendar Lite16/6/202217/6/2026
Cross-site scripting vulnerability in Modern Events Calendar Lite versions prior to 6.3.0 allows remote an authenticated attacker to inject an arbitrary script via unspecified vectors.
ModificadaMedia (5.4)0.74%—Discourse Calendar14/6/202217/6/2026
Discourse Calendar is a calendar plugin for Discourse, an open-source messaging app. Prior to version 1.0.1, parsing and rendering of Event names can be susceptible to cross-site scripting (XSS) attacks. This vulnerability only affects sites which have modified or disabled Discourse’s default Content Security Policy.…
ModificadaMedia (5.3)0.79%—Otrs Calendar Resource PlanningOtrs13/6/202217/6/2026
When Secure::DisableBanner system configuration has been disabled and agent shares his calendar via public URL, received ICS file contains OTRS release number.
ModificadaMedia (5.4)0.70%—Spiffyplugins Spiffy Calendar20/5/202217/6/2026
Insecure Direct Object References (IDOR) vulnerability in Spiffy Plugins Spiffy Calendar <= 4.9.0 at WordPress allows an attacker to edit or delete events.