Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2756▼ 505 respecto a la semana anterior
Críticas / altas1305▼ 214 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
797 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 1.6% | — | Wpsimplebookingcalendar WP Simple Booking Calendar | 13/9/2021 | 17/6/2026 | The WP Simple Booking Calendar WordPress plugin before 2.0.6 did not escape, validate or sanitise the orderby parameter in its Search Calendars action, before using it in a SQL statement, leading to an authenticated SQL injection issue | |
| Modificada | Media (6.1) | 2.7% | 💥 Exploit | MF GIG Calendar Project MF GIG Calendar | 13/9/2021 | 17/6/2026 | The MF Gig Calendar WordPress plugin before 1.2 does not sanitise and escape the id GET parameter before outputting back in the admin dashboard when editing an Event, leading to a reflected Cross-Site Scripting issue | |
| Modificada | Alta (8.8) | 0.82% | — | Roosty Diary-availability-calendar | 23/8/2021 | 17/6/2026 | The daac_delete_booking_callback function, hooked to the daac_delete_booking AJAX action, takes the id POST parameter which is passed into the SQL statement without proper sanitisation, validation or escaping, leading to a SQL Injection issue. Furthermore, the ajax action is lacking any CSRF and capability check,… | |
| Modificada | Alta (7.2) | 1.6% | — | Timeline Calendar Project Timeline Calendar | 23/8/2021 | 17/6/2026 | The Timeline Calendar WordPress plugin through 1.2 does not sanitise, validate or escape the edit GET parameter before using it in a SQL statement when editing events, leading to an authenticated SQL injection issue. Other SQL Injections are also present in the plugin | |
| Modificada | Alta (7.2) | 1.6% | — | Simple Events Calendar Project Simple Events Calendar | 23/8/2021 | 17/6/2026 | The Simple Events Calendar WordPress plugin through 1.4.0 does not sanitise, validate or escape the event_id POST parameter before using it in a SQL statement when deleting events, leading to an authenticated SQL injection issue | |
| Modificada | Media (6.1) | 0.90% | — | Calendar Plugin Project Calendar Plugin | 16/8/2021 | 17/6/2026 | The Calendar_plugin WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to the use of `$_SERVER['PHP_SELF']` in the ~/calendar.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.0. | |
| Modificada | Media (6.1) | 3.5% | 💥 Exploit | Dwbooster Calendar Event Multi View | 2/8/2021 | 17/6/2026 | The Calendar Event Multi View WordPress plugin before 1.4.01 does not sanitise or escape the 'start' and 'end' GET parameters before outputting them in the page (via php/edit.php), leading to a reflected Cross-Site Scripting issue. | |
| Modificada | Alta (7.5) | 2.4% | — | Oracle Advanced Networking OptionOracle Agile Engineering Data ManagementOracle Agile Product Lifecycle ManagementOracle Agile Product Lifecycle Management FOR Process+107 | 21/7/2021 | 25/8/2026 | Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Advanced Networking Option. Successful attacks… | |
| Modificada | Alta (7.5) | 1.1% | — | Synology Calendar | 18/6/2021 | 17/6/2026 | Use of hard-coded credentials vulnerability in php component in Synology Calendar before 2.4.0-0761 allows remote attackers to obtain sensitive information via unspecified vectors. | |
| Modificada | Alta (8.8) | 1.6% | — | Xllentech English Islamic Calendar | 14/6/2021 | 17/6/2026 | When deleting a date in the Xllentech English Islamic Calendar WordPress plugin before 2.6.8, the year_number and month_number POST parameters are not sanitised, escaped or validated before being used in a SQL statement, leading to SQL injection. | |
| Modificada | Media (6.1) | 0.78% | — | Calendar01 Project Calendar01 | 24/5/2021 | 17/6/2026 | Reflected cross-site scripting vulnerability in the admin page of [Calendar01] free edition ver1.0.1 and earlier allows a remote attacker to inject an arbitrary script via unspecified vectors. | |
| Modificada | Media (5.4) | 0.62% | — | Elbtide Advanced Booking Calendar | 22/4/2021 | 17/6/2026 | The Advanced Booking Calendar WordPress plugin before 1.6.8 does not sanitise the license error message when output in the settings page, leading to an authenticated reflected Cross-Site Scripting issue | |
| Modificada | Media (5.4) | 0.69% | — | Elbtide Advanced Booking Calendar | 12/4/2021 | 17/6/2026 | The Advanced Booking Calendar WordPress plugin before 1.6.7 did not sanitise the calId GET parameter in the "Seasons & Calendars" page before outputing it in an A tag, leading to a reflected XSS issue | |
| Modificada | Media (5.4) | 0.80% | — | Larsens Calendar Project Larsens Calendar | 9/4/2021 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in the Larsens Calender plugin Version <= 1.2 for WordPress allows remote attackers to execute arbitrary web script via the "titel" column on the "Eintrage hinzufugen" tab. | |
| Modificada | Alta (8.8) | 1.5% | — | Webnus Modern Events Calendar Lite | 18/3/2021 | 17/6/2026 | Unvalidated input in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.6, did not sanitise the mec[post_id] POST parameter in the mec_fes_form AJAX action when logged in as an author+, leading to an authenticated SQL Injection issue. | |
| Modificada | Media (5.4) | 0.75% | — | Webnus Modern Events Calendar Lite | 18/3/2021 | 17/6/2026 | Unvalidated input and lack of output encoding in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.5, did not sanitise the mic_comment field (Notes on time) when adding/editing an event, allowing users with privilege as low as author to add events with a Cross-Site Scripting payload in them, which… | |
| Modificada | Alta (7.5) | 31% | 💥 Exploit | Webnus Modern Events Calendar Lite | 18/3/2021 | 17/6/2026 | Lack of authorisation checks in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.5, did not properly restrict access to the export files, allowing unauthenticated users to exports all events data in CSV or XML format for example. | |
| Modificada | Alta (7.2) | 87% | 💥 Exploit | Webnus Modern Events Calendar Lite | 18/3/2021 | 17/6/2026 | Arbitrary file upload in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.5, did not properly check the imported file, allowing PHP ones to be uploaded by administrator by using the 'text/csv' content-type in the request. | |
| Modificada | Media (6.1) | 6.2% | 💥 Exploit | Triconsole Datepicker Calendar | 25/2/2021 | 17/6/2026 | Triconsole Datepicker Calendar <3.77 is affected by cross-site scripting (XSS) in calendar_form.php. Attackers can read authentication cookies that are still active, which can be used to perform further attacks such as reading browser history, directory listings, and file contents. | |
| Modificada | Alta (7.6) | 0.93% | — | Oracle Common Applications Calendar | 20/1/2021 | 17/6/2026 | Vulnerability in the Oracle Common Applications Calendar product of Oracle E-Business Suite (component: Tasks). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.10. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Common… | |
| Modificada | Alta (8.2) | 59% | — | Oracle Common Applications Calendar | 20/1/2021 | 17/6/2026 | Vulnerability in the Oracle Common Applications Calendar product of Oracle E-Business Suite (component: Applications Calendar). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle… | |
| Modificada | Alta (8.2) | 1.2% | — | Oracle Common Applications Calendar | 20/1/2021 | 17/6/2026 | Vulnerability in the Oracle Common Applications Calendar product of Oracle E-Business Suite (component: Tasks). Supported versions that are affected are 12.1.1-12.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Common Applications Calendar.… | |
| Modificada | Alta (8.1) | 7.3% | 💥 PoC | Fasterxml Jackson-databindOracle Agile Product Lifecycle ManagementOracle Application Testing SuiteOracle Autovue FOR Agile Product Lifecycle Management+22 | 17/9/2020 | 25/8/2026 | FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to com.pastdev.httpcomponents.configuration.JndiConfiguration. | |
| Modificada | Alta (8.1) | 7.6% | 💥 PoC | Fasterxml Jackson-databindNetapp Active IQ Unified ManagerOracle Agile Product Lifecycle ManagementOracle Application Testing Suite+21 | 25/8/2020 | 25/8/2026 | FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPDataSource (aka Anteros-DBCP). | |
| Modificada | Crítica (9.8) | 3.1% | — | Calendar01 Project Calendar01Calendar02 Project Calendar02Calendarform01 Project Calendarform01Gallery01 Project Gallery01+4 | 4/8/2020 | 17/6/2026 | [Calendar01], [Calendar02], [PKOBO-News01], [PKOBO-vote01], [Telop01], [Gallery01], [CalendarForm01], and [Link01] [Calendar01] free edition ver1.0.0, [Calendar02] free edition ver1.0.0, [PKOBO-News01] free edition ver1.0.3 and earlier, [PKOBO-vote01] free edition ver1.0.1 and earlier, [Telop01] free edition ver1.0.0,… |