Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2712▼ 359 respecto a la semana anterior
Críticas / altas1261▼ 231 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)213▼ 109 respecto a la semana anterior
799 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Baja (2.6) | 2.1% | 💥 Exploit | Vincent HOR CalendarixVincent HOR Calendarix Advanced | 19/4/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in yearcal.php in Calendarix allows remote attackers to inject arbitrary web script or HTML via the ycyear parameter. | |
| Modificada | Media (5) | 2.3% | — | Webcalendar | 30/3/2006 | 16/6/2026 | Craig Knudsen WebCalendar 1.1.0-CVS allows remote attackers to obtain sensitive information via a direct request to (1) includes/index.php, (2) tests/add_duration_test.php, (3) tests/all_tests.php, (4) groups.php, (5) nonusers.php, (6) includes/settings.php, (7) includes/init.php, (8) includes/settings.php.orig, (9)… | |
| Modificada | Media (5) | 1.1% | 💥 Exploit | Jjwwebdesign Phpbookingcalendar | 28/3/2006 | 16/6/2026 | SQL injection vulnerability in details_view.php in PHP Booking Calendar 1.0c and earlier allows remote attackers to execute arbitrary SQL commands via the event_id parameter. | |
| Modificada | Media (4.3) | 1.2% | — | PHP Lite Calendar Express | 28/3/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in search.php in Calendar Express 2.2 allow remote attackers to inject arbitrary web script or HTML via the (1) allwords or (2) oneword parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information. | |
| Modificada | Media (5) | 1.8% | 💥 Exploit | Benson IT Solutions 1webcalendar | 24/3/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in 1WebCalendar 4.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) EventID parameter in viewEvent.cfm, (2) NewsID parameter in newsView.cfm, or (3) ThisDate parameter in mainCal.cfm. | |
| Modificada | Media (5) | 6.7% | 💥 Exploit | Extcalendar | 21/3/2006 | 16/6/2026 | Cross-site scripting vulnerability in calendar.php in ExtCalendar 1.0 and possibly other versions before 2.0 allows remote attackers to inject arbitrary web script or HTML via the (1) year, (2) month, (3) next, and (4) prev parameters. | |
| Modificada | Alta (7.5) | 7.1% | 💥 Exploit | PHP Icalendar | 19/3/2006 | 16/6/2026 | publish.ical.php in Jim Hu and Chad Little PHP iCalendar 2.21 and earlier does not require authentication for write access to the calendars directory, which allows remote attackers to upload and execute arbitrary PHP scripts via a WebDAV PUT request with a filename containing a .php extension and a trailing null… | |
| Modificada | Media (5) | 2.8% | 💥 Exploit | PHP Icalendar | 19/3/2006 | 16/6/2026 | Directory traversal vulnerability in Jim Hu and Chad Little PHP iCalendar 2.21 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences and a NUL (%00) character in the phpicalendar[cookie_language] and phpicalendar[cookie_style] cookies, as demonstrated by… | |
| Modificada | Alta (7.5) | 2.6% | 💥 Exploit | Light Weight Calendar | 19/3/2006 | 16/6/2026 | Vulnerabilidad de inyección Eval en cal.php en Light Weight Calendar (LWC) 1.0 permite a atacantes remotos ejecutar código PHP arbitrario a través del parámetro date en index.php. | |
| Modificada | Media (4.3) | 1.2% | — | JAY Eckles CGI Calendar | 3/3/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Jay Eckles CGI Calendar 2.7 allow remote attackers to inject arbitrary web script or HTML via the year parameter in (1) index.cgi and (2) viewday.cgi. | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Mitridat WEB Calendar PRO | 22/2/2006 | 16/6/2026 | SQL injection vulnerability in dropbase.php in MitriDAT Web Calendar Pro allows remote attackers to modify internal SQL queries and cause a denial of service (inaccessible database) via the tabls parameter. | |
| Modificada | Alta (7.5) | 2.1% | 💥 Exploit | Reamday Enterprises Magic Calendar Lite | 13/2/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in cms/index.php in Magic Calendar Lite 1.02, with magic_quotes_gpc disabled, allow remote attackers to execute arbitrary SQL commands via the (1) $total_login and (2) $total_password parameter. | |
| Modificada | Baja (3.5) | 1.1% | — | Softcomplex PHP Event Calendar | 13/2/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Softcomplex PHP Event Calendar 1.5 allows remote authenticated users to inject arbitrary web script or HTML, and corrupt data, via the (1) username and (2) password parameters, which are not sanitized before being written to users.php. NOTE: while this issue was originally… | |
| Modificada | Media (5) | 2.1% | — | PHP Icalendar | 13/2/2006 | 16/6/2026 | Multiple directory traversal vulnerabilities in PHP iCalendar 2.0.1, 2.1, and 2.2 allow remote attackers to include arbitrary files via the (1) getdate and possibly other parameters used in the replace_files function in search.php and (2) $file variable as used in the parse function in functions/template.php. | |
| Modificada | Alta (7.5) | 1.9% | — | 2200net Calendar | 9/2/2006 | 16/6/2026 | Múltiples vulnerabilidades de inyección SQL en 2200net Calendar system 1.2, con gpc_magic_quotes incapacitado, permiten a atacantes remotos ejecutar comandos SQL arbitrarios y eludir la autenticación a través de (1) el parámetro fm_data[id] para calendar.php y (2) la variable $ad['acc'] en adminlogin.php. | |
| Modificada | Alta (7.5) | 1.9% | — | Vincent HOR Calendarix | 1/2/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in Calendarix allow remote attackers to execute arbitrary SQL commands via (1) the catview parameter in cal_functions.inc.php and (2) the login parameter in cal_login.php. NOTE: the catview vector might overlap CVE-2005-1865. | |
| Modificada | Alta (7.5) | 1.6% | — | Benders Calendar | 18/1/2006 | 16/6/2026 | SQL injection vulnerability in Benders Calendar 1.0 allows remote attackers to execute arbitrary SQL commands via multiple parameters, as demonstrated by the (1) year, (2) month, and (3) day parameters. | |
| Modificada | Alta (7.5) | 4.3% | 💥 Exploit | Light Weight Calendar | 13/1/2006 | 16/6/2026 | Vulnerabilidad de inyección Eval en Light Weight Calendar (LWC) 1.0 (20040909) y versiones anteriores permite a atacantes remotos ejecutar código PHP arbitrario a través del parámetro date en cal.php, que está incluido en index.php. | |
| Modificada | Media (6.5) | 1.3% | — | Acal Calendar Project | 12/1/2006 | 16/6/2026 | Direct static code injection vulnerability in edit.php in ACal Calendar Project 2.2.5 allows authenticated users to execute arbitrary PHP code via (1) the edit=header value, which modifies header.php, or (2) the edit=footer value, which modifies footer.php. NOTE: this issue might be resultant from the poor… | |
| Modificada | Media (4.3) | 1.4% | — | Calogic Calendars | 12/1/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in CaLogic Calendars 1.2.2 allows remote attackers to inject arbitrary web script or HTML via the Title field on the "Adding New Event" page, and possibly other vectors, involving iframe tags. | |
| Modificada | Alta (7.5) | 1.9% | — | Acal Calendar Project | 12/1/2006 | 16/6/2026 | login.php in ACal Calendar Project 2.2.5 allows remote attackers to bypass authentication by setting the ACalAuthenticate cookie variable to "inside". | |
| Modificada | Alta (7.5) | 3.0% | 💥 Exploit | Ocean12 Technologies Calendar Manager PRO | 31/12/2005 | 16/6/2026 | Ocean12 Calendar Manager Pro 1.01 allows remote attackers to bypass authentication and obtain sensitive information via a direct request to /admin/view.asp. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Alta (7.5) | 1.3% | — | JAX Calendar | 5/12/2005 | 16/6/2026 | SQL injection vulnerability in jax_calendar.php in Jax Calendar 1.34 allows remote attackers to execute arbitrary SQL commands via the (1) cal_id parameter, and possibly the (2) Y and (3) m parameters. | |
| Modificada | Alta (7.5) | 2.4% | 💥 Exploit | Codewalkers Ltwcalendar | 5/12/2005 | 16/6/2026 | SQL injection vulnerability in calendar.php in Codewalkers ltwCalendar (aka PHP Event Calendar) 4.2, 4.1.3, and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Alta (7.5) | 1.3% | — | PHP Lite Calendar Express | 5/12/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in PHP Lite Calendar Express 2.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) cid and (2) catid parameters to (a) day.php, (b) week.php, (c) month.php, and (d) year.php. |