Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2713▼ 329 respecto a la semana anterior
Críticas / altas1265▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 108 respecto a la semana anterior
799 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 4.0% | 💥 Exploit | Softcomplex PHP Event Calendar | 15/9/2006 | 16/6/2026 | Vulnerabilidad de secuencias de comandos en sitios cruzados(XSS) en cl_files/index.php en SoftComplex PHP Event Calendar 1.5.1 y posiblemente anteriores, permite a atacantes remotos inyectar secuencias de comandos web o HTML a través de los parámetros (1) ti, (2) bi o (3) cbgi. | |
| Modificada | Alta (7.5) | 1.9% | — | Vincent HOR Calendarix | 14/8/2006 | 16/6/2026 | ** IMPUGNADA ** Vulnerabilidad de inclusión remota de archivo en PHP en cal_config.inc.php de Calendarix 0.7.2006401 y anteriores permite a atacantes remotos ejecutar código PHP de su elección mediante una URL en el parámetro calpath. NOTA: este problema ha sido impugnado por una tercera parte, la cual dice que la… | |
| Modificada | Alta (7.5) | 4.0% | 💥 Exploit | Web-scripts Visual Events Calendar | 10/8/2006 | 16/6/2026 | Vulnerabilidad de inclusión remota de archivo en PHP en calendar.php de Visual Events Calendar 1.1 permite a atacantes remotos ejecutar código PHP de su elección mediante una URL en el parámetro cfg_dir. | |
| Modificada | Alta (7.5) | 2.6% | 💥 Exploit | Mambo Calendar | 25/7/2006 | 16/6/2026 | Vulnerabilidad PHP de inclusión remota de archivo en com_calendar.php en Calendar Mambo Module 1.5.7 y anteriores permite a atacantes remotos ejecutar código PHP de su elección a través de una URL en el parámetro absolute_path. | |
| Modificada | Alta (7.5) | 2.1% | — | Softcomplex PHP Event Calendar | 21/7/2006 | 16/6/2026 | Vulnerabilidad de inclusión remota de archivo en PHP en calendar.php de SoftComplex PHP Event Calendar 1.4 permite a atacantes remotos ejecutar código PHP de su elección mediante un URL en el parámetro path_to_calendar, el cual sobrescribe la variable $path_to_calendar de una llamada a la función extract. | |
| Modificada | Media (6.8) | 6.9% | 💥 Exploit | Extcalendar | 13/7/2006 | 16/6/2026 | Vulnerabilidad de inclusión de archivo PHP remoto en extcalendar.php de Mohamed Moujami ExtCalendar 2.0. Permite a atacantes remotos ejecutar código PHP de su elección mediante un URL en el parámetro mosConfig_absolute_path. | |
| Modificada | Media (4.3) | 1.4% | — | PHP Icalendar | 30/6/2006 | 16/6/2026 | Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en rss/index.php de PHP iCalendar v2.22 y versiones anteriores, permite a usuarios remotos inyectar codigo web script o código HTML de su elección a través del parámetro call. | |
| Modificada | Media (5.1) | 1.9% | — | Vincent HOR Calendarix Basic | 19/6/2006 | 16/6/2026 | Múltiples vulnerabilidades de inyección SQL en Calendarix Basic v0.7.20060401 y versiones anteriores, con discapacidad magic_quotes_gpc, permite a atacantes remotos ejecutar comandos SQL a través del parámetro id en (1) cal_event.php y cal_popup.php (2). | |
| Modificada | Alta (7.5) | 1.5% | — | Codewalkers Ltwcalendar | 15/6/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in Ltwcalendar/calendar.php in Codewalkers Ltwcalendar 4.1.3 allows remote attackers to execute arbitrary PHP code via a URL in the ltw_config[include_dir] parameter. NOTE: CVE disputes this claim, since the $ltw_config[include_dir] variable is defined as a static value in an… | |
| Modificada | Media (6.8) | 1.7% | — | Lucid Designs Lucid Calendar | 15/6/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Cal.PHP3 in Chris Lea Lucid Calendar 0.22 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters. NOTE: the provenance of this information is unknown; the details are obtained from third party information. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | PHP Lite Calendar Express | 12/6/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in month.php in PHP Lite Calendar Express 2.2 allow remote attackers to execute arbitrary SQL commands via the (1) catid and (2) cid parameter. NOTE: this might be a duplicate of CVE-2005-4009.c. | |
| Modificada | Media (6.8) | 2.2% | 💥 Exploit | Phpcommunitycalendar | 3/6/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in phpCommunityCalendar 4.0.3 allow remote attackers to inject arbitrary web script or HTML via the (1) LoName parameter in (a) week.php and (b) month.php and (2) AddressLink parameter in (c) event.php. | |
| Modificada | Alta (7.5) | 2.1% | 💥 Exploit | Phpcommunitycalendar | 3/6/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in phpCommunityCalendar 4.0.3 allow remote attackers to execute arbitrary SQL commands via the (1) CalendarDetailsID parameter in (a) month.php, (b) day.php, and (c) delCalendar.php; (2) ID parameter in (d) event.php; (3) AdminUserID parameter in (e) delAdmin.php; (4)… | |
| Modificada | Media (6.4) | 2.2% | — | Webcalendar | 2/6/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in includes/config.php in WebCalendar 1.0.3 allows remote attackers to execute arbitrary PHP code via a URL in the includedir parameter, which is remotely accessed in an fopen call whose results are used to define a user_inc setting that is used in an include_once call. | |
| Modificada | Media (5) | 1.2% | — | Calendarscripts.com Chatpat | 30/5/2006 | 16/6/2026 | SQL injection vulnerability in ChatPat 1.0 allows remote attackers to execute arbitrary SQL commands via the nickname field. | |
| Modificada | Media (5.8) | 1.2% | — | Calendarscripts.com Chatpat | 30/5/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in ChatPat 1.0 allow remote attackers to inject arbitrary web script or HTML via a chat message in (1) fastchat.php and (2) fastshow.php. | |
| Modificada | Alta (7.5) | 2.5% | 💥 Exploit | Calogic Calendars | 24/5/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in CaLogic Calendars 1.2.2 allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS["CLPath"] parameter to (1) reconfig.php and (2) srxclr.php. NOTE: this might be due to a globals overwrite issue. | |
| Modificada | Media (5.8) | 1.2% | — | Inhouse Associates Ia-calendar | 10/5/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in calendar_new.asp in IA-Calendar allows remote attackers to inject arbitrary web script or HTML via the TypeName1 parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information. | |
| Modificada | Media (6.4) | 1.3% | — | Inhouse Associates Ia-calendar | 10/5/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in IA-Calendar allow remote attackers to execute arbitrary SQL commands via the (1) type parameter in (a) calendar_new.asp and (b) default.asp, and (2) ID parameter in (c) calendar_detail.asp. NOTE: the provenance of this information is unknown; the details are obtained from… | |
| Modificada | Media (6.4) | 1.2% | 💥 Exploit | Expinion.net Multicalendars | 10/5/2006 | 16/6/2026 | SQL injection vulnerability in all_calendars.asp in MultiCalendars 3.0 allows remote attackers to execute arbitrary SQL commands via the calsids parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information. | |
| Modificada | Media (5) | 1.7% | — | Webcalendar | 9/5/2006 | 16/6/2026 | WebCalendar 1.0.1 to 1.0.3 generates different error messages depending on whether or not a username is valid, which allows remote attackers to enumerate valid usernames. | |
| Modificada | Media (6.5) | 1.1% | 💥 Exploit | Ocean12 Technologies Calendar Manager PRO | 9/5/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in Ocean12 Calendar Manager Pro 1.00 allow remote attackers to execute arbitrary SQL commands via the (1) date parameter to admin/main.asp, (2) SearchFor parameter to admin/view.asp, or (3) ID parameter to admin/edit.asp. NOTE: the provenance of this information is unknown; the… | |
| Modificada | Baja (2.6) | 2.0% | 💥 Exploit | Ocean12 Technologies Calendar Manager PRO | 9/5/2006 | 16/6/2026 | Cross-site scripting vulnerability in admin/main.asp in Ocean12 Calendar Manager Pro 1.00 allows remote attackers to inject arbitrary web script or HTML via the date parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Baja (2.6) | 1.4% | — | Kcscripts CalendarKcscripts Portal Pack | 21/4/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in calendar/Visitor.cgi in KCScripts Calendar, distributed individually and as part of Portal Pack 6.0 and earlier, allows remote attackers to inject arbitrary web script or HTML via the sort_order parameter. | |
| Modificada | Media (6.4) | 3.1% | 💥 Exploit | Sweetphp Totalcalendar | 20/4/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in (1) about.php or (2) auth.php in TotalCalendar allows remote attackers to execute arbitrary PHP code via a URL in the inc_dir parameter. |