Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
799 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.8) | 0.61% | — | Nextcloud Calendar | 5/7/2018 | 17/6/2026 | In Nextcloud Calendar before 1.5.8 and 1.6.1, a missing sanitization of search results for an autocomplete field could lead to a stored XSS requiring user-interaction. The missing sanitization only affected group names, hence malicious search results could only be crafted by privileged users like admins or group… | |
| Modificada | Media (6.5) | 0.91% | — | Synology Calendar | 14/6/2018 | 17/6/2026 | Improper authorization vulnerability in SYNO.Cal.Event in Calendar before 2.1.2-0511 allows remote authenticated users to create arbitrary events via the (1) cal_id or (2) original_cal_id parameter. | |
| Modificada | Alta (7.5) | 1.4% | — | Wpdevart Booking Calendar | 13/6/2018 | 17/6/2026 | An issue was discovered in the WpDevArt "Booking calendar, Appointment Booking System" plugin 2.2.2 for WordPress. Multiple parameters allow remote attackers to manipulate the values to change data such as prices. | |
| Modificada | Media (6.1) | 3.5% | 💥 Exploit | Emssoftware EMS Master Calendar | 1/6/2018 | 17/6/2026 | Data input into EMS Master Calendar before 8.0.0.201805210 via URL parameters is not properly sanitized, allowing malicious attackers to send a crafted URL for XSS. | |
| Modificada | Media (5.4) | 0.80% | — | Synology Calendar | 10/5/2018 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Notification Center in Synology Calendar before 2.1.1-0502 allows remote authenticated users to inject arbitrary web script or HTML via title parameter. | |
| Modificada | Alta (7.5) | 0.89% | — | Cisco Spark Hybrid Calendar Service | 27/3/2018 | 17/6/2026 | A vulnerability in the auto discovery phase of Cisco Spark Hybrid Calendar Service could allow an unauthenticated, remote attacker to view sensitive information in the unencrypted headers of an HTTP method request. The attacker could use this information to conduct additional reconnaissance attacks leading to the… | |
| Modificada | Media (5.4) | 0.71% | — | Mail.ru Calendar | 16/3/2018 | 17/6/2026 | The Mail.ru Calendar plugin before 2.5.0.61 for Atlassian Jira has XSS via the Name field in a Create Calender action, related to a MailRuCalendar.jspa#period/month URI. | |
| Modificada | Crítica (9.8) | 2.7% | 💥 Exploit | Albonico Simplecalendar | 17/2/2018 | 17/6/2026 | SQL Injection exists in the SimpleCalendar 3.1.9 component for Joomla! via the catid array parameter. | |
| Modificada | Crítica (9.8) | 2.7% | 💥 Exploit | Joomlacalendars Event Calendar | 30/1/2018 | 17/6/2026 | SQL Injection exists in the CP Event Calendar 3.0.1 component for Joomla! via the id parameter in a task=load action. | |
| Modificada | Alta (7.5) | 12% | 💥 Exploit | Joomlacalendars Picture Calendar | 30/1/2018 | 17/6/2026 | Directory Traversal exists in the Picture Calendar 3.1.4 component for Joomla! via the list.php folder parameter. | |
| Modificada | Crítica (9.8) | 2.7% | 💥 Exploit | Joomlacalendars Visual Calendar | 30/1/2018 | 17/6/2026 | SQL Injection exists in the Visual Calendar 3.1.3 component for Joomla! via the id parameter in a view=load action. | |
| Modificada | Alta (8.8) | 0.77% | — | Booking Calendar Project Booking Calendar | 13/1/2018 | 17/6/2026 | An issue was discovered in the booking-calendar plugin 2.1.7 for WordPress. CSRF exists via wp-admin/admin.php. | |
| Modificada | Media (4.8) | 0.62% | — | Booking Calendar Project Booking Calendar | 13/1/2018 | 17/6/2026 | An issue was discovered in the booking-calendar plugin 2.1.7 for WordPress. XSS exists via the wp-admin/admin.php form_field5[label] parameter. | |
| Modificada | Media (4.8) | 0.62% | — | Booking Calendar Project Booking Calendar | 13/1/2018 | 17/6/2026 | An issue was discovered in the booking-calendar plugin 2.1.7 for WordPress. XSS exists via the wp-admin/admin.php extra_field1[items][field_item1][price_percent] parameter. | |
| Modificada | Media (4.8) | 0.62% | — | Booking Calendar Project Booking Calendar | 13/1/2018 | 17/6/2026 | An issue was discovered in the booking-calendar plugin 2.1.7 for WordPress. XSS exists via the wp-admin/admin.php sale_conditions[count][] parameter. | |
| Modificada | Crítica (9.8) | 4.9% | 💥 Exploit | WP Events Calendar Project WP Events Calendar | 12/1/2018 | 17/6/2026 | The Wachipi WP Events Calendar plugin 1.0 for WordPress has SQL Injection via the event_id parameter to event.php. | |
| Modificada | Media (6.1) | 0.95% | — | Mediaburst Booking Calendar SMSMediaburst Clockwork SMS NotficationsMediaburst Contact Form 7 SMSMediaburst Fast Secure Contact Form SMS+4 | 20/12/2017 | 17/6/2026 | The Clockwork SMS clockwork-test-message.php component has XSS via a crafted "to" parameter in a clockwork-test-message request to wp-admin/admin.php. This component code is found in the following WordPress plugins: Clockwork Free and Paid SMS Notifications 2.0.3, Two-Factor Authentication - Clockwork SMS 1.0.2,… | |
| Modificada | Crítica (9.8) | 3.0% | 💥 Exploit | Event Calendar Category Script Project Event Calendar Category Script | 13/12/2017 | 17/6/2026 | Event Search Script 1.0 has SQL Injection via the /event-list city parameter. | |
| Modificada | Media (6.5) | 1.0% | — | Synology Calendar | 8/12/2017 | 17/6/2026 | Improper access control vulnerability in SYNO.Cal.EventBase in Synology Calendar before 2.0.1-0242 allows remote authenticated users to modify calendar event via unspecified vectors. | |
| Modificada | Alta (8.2) | 1.9% | — | Oracle Common Applications Calendar | 19/10/2017 | 17/6/2026 | Vulnerability in the Oracle Common Applications Calendar component of Oracle E-Business Suite (subcomponent: Applications Calendar). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6 and 12.2.7. Easily exploitable vulnerability allows unauthenticated attacker with network… | |
| Modificada | Alta (8.2) | 1.9% | — | Oracle Common Applications Calendar | 19/10/2017 | 17/6/2026 | Vulnerability in the Oracle Common Applications Calendar component of Oracle E-Business Suite (subcomponent: Applications Calendar). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6 and 12.2.7. Easily exploitable vulnerability allows unauthenticated attacker with network… | |
| Modificada | Media (5.3) | 1.9% | — | Oracle Common Applications Calendar | 19/10/2017 | 17/6/2026 | Vulnerability in the Oracle Common Applications Calendar component of Oracle E-Business Suite (subcomponent: Applications Calendar). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6 and 12.2.7. Easily exploitable vulnerability allows unauthenticated attacker with network… | |
| Modificada | Crítica (9.8) | 4.1% | 💥 Exploit | Calendarscripts Watupro | 7/9/2017 | 17/6/2026 | SQL injection vulnerability in the WatuPRO plugin before 5.5.3.7 for WordPress allows remote attackers to execute arbitrary SQL commands via the watupro_questions parameter in a watupro_submit action to wp-admin/admin-ajax.php. | |
| Modificada | Media (4.9) | 2.4% | — | Webcalendar Project Webcalendar | 29/8/2017 | 17/6/2026 | Directory traversal vulnerability in WebCalendar 1.2.7 and earlier allows authenticated attackers to read arbitrary files via unspecified vectors. | |
| Modificada | Media (6.1) | 0.93% | — | Webcalendar Project Webcalendar | 29/8/2017 | 17/6/2026 | Cross-site scripting vulnerability in WebCalendar 1.2.7 and earlier allows an attacker to inject arbitrary web script or HTML via unspecified vectors. |