Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 646 respecto a la semana anterior
Críticas / altas1266▼ 292 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
799 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.66% | — | Brizoit Work Time Calendar | 12/12/2019 | 17/6/2026 | The Work Time Calendar app before 4.7.1 for Jira allows XSS. | |
| Modificada | Media (5.5) | 0.50% | — | Claws-mail Vcalendar | 25/11/2019 | 16/6/2026 | Claws Mail vCalendar plugin: credentials exposed on interface | |
| Modificada | Media (6.1) | 2.2% | 💥 PoC | Redhat Hibernate ValidatorRedhat FuseRedhat Jboss Data GridRedhat Jboss Enterprise Application Platform+183 | 8/11/2019 | 25/8/2026 | A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack. | |
| Modificada | Crítica (9.8) | 5.4% | — | Fasterxml Jackson-databindDebian LinuxRedhat Jboss Enterprise Application PlatformOracle Banking Platform+18 | 12/10/2019 | 17/6/2026 | A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the apache-log4j-extra (version 1.2.x) jar in the classpath, and an attacker can provide… | |
| Modificada | Crítica (9.8) | 5.7% | — | Fasterxml Jackson-databindDebian LinuxFedoraproject FedoraRedhat Jboss Enterprise Application Platform+24 | 1/10/2019 | 17/6/2026 | A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the commons-dbcp (1.4) jar in the classpath, and an attacker can find an RMI service… | |
| Modificada | Crítica (9.8) | 4.9% | — | Fasterxml Jackson-databindDebian LinuxFedoraproject FedoraRedhat Jboss Enterprise Application Platform+22 | 1/10/2019 | 7/10/2026 | A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the p6spy (3.8.6) jar in the classpath, and an attacker can find an RMI service endpoint… | |
| Modificada | Media (6.5) | 1.0% | — | Jenkins Google Calendar | 25/9/2019 | 17/6/2026 | Jenkins Google Calendar Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system. | |
| Modificada | Media (6.1) | 2.2% | 💥 Exploit | MY Calendar Project MY Calendar | 28/8/2019 | 17/6/2026 | The my-calendar plugin before 3.1.10 for WordPress has XSS. | |
| Modificada | Crítica (9.8) | 1.8% | — | Codepeople Appointment Booking Calendar | 22/8/2019 | 17/6/2026 | The appointment-booking-calendar plugin before 1.1.24 for WordPress has SQL injection, a different vulnerability than CVE-2015-7319. | |
| Modificada | Media (6.1) | 0.91% | — | Mediaburst Booking Calendar | 21/8/2019 | 17/6/2026 | The booking-sms plugin before 1.1.0 for WordPress has XSS. | |
| Modificada | Crítica (9.8) | 1.8% | — | Codepeople Booking Calendar Contact Form | 21/8/2019 | 17/6/2026 | The booking-calendar-contact-form plugin before 1.0.24 for WordPress has SQL injection. | |
| Modificada | Media (6.1) | 0.91% | — | Codepeople Booking Calendar Contact Form | 21/8/2019 | 17/6/2026 | The booking-calendar-contact-form plugin before 1.0.24 for WordPress has XSS. | |
| Modificada | Media (6.1) | 1.1% | — | Stellarwp THE Events Calendar | 21/8/2019 | 17/6/2026 | The the-events-calendar plugin before 4.8.2 for WordPress has XSS via the tribe_paged URL parameter. | |
| Modificada | Media (6.1) | 1.4% | — | Codepeople Appointment Booking Calendar | 9/8/2019 | 17/6/2026 | The Appointment Booking Calendar plugin 1.3.18 for WordPress allows XSS via the wp-admin/admin-post.php editionarea parameter. | |
| Modificada | Media (6.5) | 5.3% | — | Microsoft Exchange ServerMicrosoft LyncMicrosoft Lync BasicMicrosoft Mail AND Calendar+5 | 15/7/2019 | 17/6/2026 | An information disclosure vulnerability exists when Exchange allows creation of entities with Display Names having non-printable characters. An authenticated attacker could exploit this vulnerability by creating entities with invalid display names, which, when added to conversations, remain invisible. This security… | |
| Modificada | Crítica (9.8) | 2.2% | — | Synology Calendar | 30/6/2019 | 17/6/2026 | OS command injection vulnerability in drivers_syno_import_user.php in Synology Calendar before 2.3.1-0617 allows remote attackers to execute arbitrary commands via the crafted 'X-Real-IP' header. | |
| Modificada | Media (5.4) | 0.80% | — | Synology Calendar | 30/6/2019 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Event Editor in Synology Calendar before 2.3.0-0615 allows remote attackers to inject arbitrary web script or HTML via the title parameter. | |
| Modificada | Media (5.4) | 0.72% | — | Kieranoshea Calendar | 13/5/2019 | 17/6/2026 | The Kieran O'Shea Calendar plugin before 1.3.11 for WordPress has Stored XSS via the event_title parameter in a wp-admin/admin.php?page=calendar add action, or the category name during category creation at the wp-admin/admin.php?page=calendar-categories URI. | |
| Modificada | Media (5.5) | 0.28% | — | Synology Calendar | 9/5/2019 | 17/6/2026 | Information exposure through process environment vulnerability in Synology Calendar before 2.3.3-0620 allows local users to obtain credentials via cmdline. | |
| Modificada | Media (6.5) | 1.4% | — | Synology Calendar | 1/4/2019 | 17/6/2026 | Relative path traversal vulnerability in Attachment Uploader in Synology Calendar before 2.2.2-0532 allows remote authenticated users to upload arbitrary files via the filename parameter. | |
| Modificada | Alta (8.8) | 19% | 💥 Exploit | Booking Calendar Project Booking Calendar | 21/3/2019 | 17/6/2026 | SQL injection vulnerability in Booking Calendar plugin 8.4.3 for WordPress allows remote attackers to execute arbitrary SQL commands via the booking_id parameter. | |
| Modificada | Media (5.4) | 1.2% | — | Web-dorado Event Calendar WD | 9/1/2019 | 17/6/2026 | Cross-site scripting vulnerability in Event Calendar WD version 1.1.21 and earlier allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Crítica (9) | 1.1% | — | Apereo Bw-calendar-engine | 20/12/2018 | 17/6/2026 | bw-calendar-engine version <= bw-calendar-engine-3.12.0 contains a XML External Entity (XXE) vulnerability in IscheduleClient XML Parser that can result in Disclosure of confidential data, denial of service, SSRF, port scanning. This attack appear to be exploitable via Man in the Middle or malicious server. | |
| Modificada | Media (6.1) | 0.99% | — | Theholidaycalendar Holiday Calendar | 1/10/2018 | 17/6/2026 | XSS exists in the the-holiday-calendar plugin before 1.11.3 for WordPress via the thc-month parameter. | |
| Modificada | Media (6.5) | 8.4% | — | Microsoft Windows CalendarMicrosoft Windows MailMicrosoft Windows People | 11/7/2018 | 17/6/2026 | An information disclosure vulnerability exists in Windows Mail Client when a message is opened, aka "Windows Mail Client Information Disclosure Vulnerability." This affects Mail, Calendar, and People in Windows 8.1 App Store. |