Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
52 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 2.7% | 💥 Exploit | MF GIG Calendar Project MF GIG Calendar | 13/9/2021 | 17/6/2026 | The MF Gig Calendar WordPress plugin before 1.2 does not sanitise and escape the id GET parameter before outputting back in the admin dashboard when editing an Event, leading to a reflected Cross-Site Scripting issue | |
| Modificada | Alta (7.2) | 1.6% | — | Timeline Calendar Project Timeline Calendar | 23/8/2021 | 17/6/2026 | The Timeline Calendar WordPress plugin through 1.2 does not sanitise, validate or escape the edit GET parameter before using it in a SQL statement when editing events, leading to an authenticated SQL injection issue. Other SQL Injections are also present in the plugin | |
| Modificada | Alta (7.2) | 1.6% | — | Simple Events Calendar Project Simple Events Calendar | 23/8/2021 | 17/6/2026 | The Simple Events Calendar WordPress plugin through 1.4.0 does not sanitise, validate or escape the event_id POST parameter before using it in a SQL statement when deleting events, leading to an authenticated SQL injection issue | |
| Modificada | Media (5.4) | 0.80% | — | Larsens Calendar Project Larsens Calendar | 9/4/2021 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in the Larsens Calender plugin Version <= 1.2 for WordPress allows remote attackers to execute arbitrary web script via the "titel" column on the "Eintrage hinzufugen" tab. | |
| Modificada | Media (5.3) | 1.6% | — | Webcalendar Project Webcalendar | 4/2/2020 | 16/6/2026 | webcalendar before 1.2.7 shows the reason for a failed login (e.g., "no such user"). | |
| Modificada | Alta (8.8) | 2.5% | 💥 Exploit | Webcalendar Project Webcalendar | 27/1/2020 | 16/6/2026 | Local file inclusion in WebCalendar before 1.2.5. | |
| Modificada | Crítica (9.8) | 80% | 💥 Exploit | Webcalendar Project Webcalendar | 27/1/2020 | 16/6/2026 | install/index.php in WebCalendar before 1.2.5 allows remote attackers to execute arbitrary code via the form_single_user_login parameter. | |
| Modificada | Media (6.1) | 2.2% | 💥 Exploit | MY Calendar Project MY Calendar | 28/8/2019 | 17/6/2026 | The my-calendar plugin before 3.1.10 for WordPress has XSS. | |
| Modificada | Alta (8.8) | 19% | 💥 Exploit | Booking Calendar Project Booking Calendar | 21/3/2019 | 17/6/2026 | SQL injection vulnerability in Booking Calendar plugin 8.4.3 for WordPress allows remote attackers to execute arbitrary SQL commands via the booking_id parameter. | |
| Modificada | Alta (8.8) | 0.77% | — | Booking Calendar Project Booking Calendar | 13/1/2018 | 17/6/2026 | An issue was discovered in the booking-calendar plugin 2.1.7 for WordPress. CSRF exists via wp-admin/admin.php. | |
| Modificada | Media (4.8) | 0.62% | — | Booking Calendar Project Booking Calendar | 13/1/2018 | 17/6/2026 | An issue was discovered in the booking-calendar plugin 2.1.7 for WordPress. XSS exists via the wp-admin/admin.php form_field5[label] parameter. | |
| Modificada | Media (4.8) | 0.62% | — | Booking Calendar Project Booking Calendar | 13/1/2018 | 17/6/2026 | An issue was discovered in the booking-calendar plugin 2.1.7 for WordPress. XSS exists via the wp-admin/admin.php extra_field1[items][field_item1][price_percent] parameter. | |
| Modificada | Media (4.8) | 0.62% | — | Booking Calendar Project Booking Calendar | 13/1/2018 | 17/6/2026 | An issue was discovered in the booking-calendar plugin 2.1.7 for WordPress. XSS exists via the wp-admin/admin.php sale_conditions[count][] parameter. | |
| Modificada | Crítica (9.8) | 4.9% | 💥 Exploit | WP Events Calendar Project WP Events Calendar | 12/1/2018 | 17/6/2026 | The Wachipi WP Events Calendar plugin 1.0 for WordPress has SQL Injection via the event_id parameter to event.php. | |
| Modificada | Media (4.9) | 2.4% | — | Webcalendar Project Webcalendar | 29/8/2017 | 17/6/2026 | Directory traversal vulnerability in WebCalendar 1.2.7 and earlier allows authenticated attackers to read arbitrary files via unspecified vectors. | |
| Modificada | Media (6.1) | 0.93% | — | Webcalendar Project Webcalendar | 29/8/2017 | 17/6/2026 | Cross-site scripting vulnerability in WebCalendar 1.2.7 and earlier allows an attacker to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (6.1) | 0.85% | — | Booking Calendar Project Booking Calendar | 28/4/2017 | 17/6/2026 | Cross-site scripting vulnerability in Booking Calendar version 7.1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (5.3) | 2.4% | — | Booking Calendar Project Booking Calendar | 28/4/2017 | 17/6/2026 | Directory traversal vulnerability in Booking Calendar version 7.0 and earlier allows remote attackers to read arbitrary files via specially crafted captcha_chalange parameter. | |
| Modificada | Alta (7.5) | 40% | 💥 Exploit | CP Multi View Event Calendar Project CP Multi View Event Calendar | 4/11/2014 | 17/6/2026 | SQL injection vulnerability in the CP Multi View Event Calendar plugin 1.01 for WordPress allows remote attackers to execute arbitrary SQL commands via the calid parameter. | |
| Modificada | Media (4.3) | 1.6% | — | Vn-calendar Project Vn-calendar | 2/7/2014 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in vncal.js.php in the VN-Calendar plugin 1.0 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) fs or (2) w parameter. | |
| Modificada | Media (4.3) | 1.2% | — | Webcalendar Project Webcalendar | 22/4/2014 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Craig Knudsen WebCalendar before 1.2.5, 1.2.6, and other versions before 1.2.7 allows remote attackers to inject arbitrary web script or HTML via the Category Name field to category.php. | |
| Modificada | Alta (7.5) | 2.2% | — | Webcalendar Project Webcalendar | 11/10/2012 | 16/6/2026 | install/index.php in Craig Knudsen WebCalendar before 1.2.5 allows remote attackers to modify settings.php and possibly execute arbitrary code via vectors related to the user theme preference. | |
| Modificada | Media (4.3) | 0.93% | — | Webcalendar Project Webcalendar | 11/10/2012 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Craig Knudsen WebCalendar allow remote attackers to inject arbitrary web script or HTML via the (1) $name or (2) $description variables in edit_entry_handler.php, or (3) $url, (4) $tempfullname, or (5) $ext_users[] variables in view_entry.php, different vectors… | |
| Modificada | Media (4.3) | 9.3% | 💥 Exploit | MF GIG Calendar Project MF GIG Calendar | 1/10/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the MF Gig Calendar plugin 0.9.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the query string to the calendar page. | |
| Modificada | Crítica (9.8) | 5.2% | 💥 Exploit | Extcalendar Project Extcalendar | 3/2/2007 | 16/6/2026 | profile.php in ExtCalendar 2 and earlier allows remote attackers to change the passwords of arbitrary users without providing the original password, and possibly perform other unauthorized actions, via modified values to register.php. |