Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2736▼ 336 respecto a la semana anterior
Críticas / altas1272▼ 222 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)213▼ 108 respecto a la semana anterior
799 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.3% | — | Webcalendar | 4/12/2005 | 16/6/2026 | SQL injection vulnerability in WebCalendar 1.0.1 allows remote attackers to execute arbitrary SQL commands via the time_range parameter to edit_report_handler.php. NOTE: the startid/activity_log.php vector is already covered by CVE-2005-3949. | |
| Modificada | Media (5) | 7.1% | 💥 Exploit | Webcalendar | 4/12/2005 | 16/6/2026 | CRLF injection vulnerability in layers_toggle.php in WebCalendar 1.0.1 might allow remote attackers to modify HTTP headers and conduct HTTP response splitting attacks via the ret parameter, which is used to redirect URL requests. | |
| Modificada | Alta (7.5) | 2.1% | — | Webcalendar | 1/12/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in WebCalendar 1.0.1 allow remote attackers to execute arbitrary SQL commands via the (1) startid parameter to activity_log.php, (2) startid parameter to admin_handler.php, (3) template parameter to edit_template.php, and (4) multiple parameters to export_handler.php. | |
| Modificada | Media (5) | 2.2% | — | Webcalendar | 1/12/2005 | 16/6/2026 | export_handler.php in WebCalendar 1.0.1 allows remote attackers to overwrite WebCalendar data files via a modified id parameter. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | 88script Event Calendar | 1/12/2005 | 16/6/2026 | SQL injection vulnerability in index.php in 88Script's Event Calendar 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the m parameter. | |
| Modificada | Media (5) | 3.5% | 💥 Exploit | Codegrrl PhpcalendarCodegrrl PhpcliqueCodegrrl PhpcurrentlyCodegrrl Phpfanbase+1 | 16/11/2005 | 16/6/2026 | PHP file inclusion vulnerability in protection.php in CodeGrrl (a) PHPCalendar 1.0, (b) PHPClique 1.0, (c) PHPCurrently 2.0, (d) PHPFanBase 2.1, and (e) PHPQuotes 1.0 allows remote attackers to include arbitrary local files via the siteurl parameter when register_globals is enabled. NOTE: It was later reported that… | |
| Modificada | Media (6.8) | 2.4% | — | PHP Icalendar | 30/10/2005 | 16/6/2026 | PHP file inclusion vulnerability in index.php in PHP iCalendar 2.0a2 through 2.0.1 allows remote attackers to execute arbitrary PHP code and include arbitrary local files via the phpicalendar cookie. NOTE: this is not a cross-site scripting (XSS) issue as claimed by the original researcher. | |
| Modificada | Media (4.3) | 1.3% | — | Phpcommunitycalendar | 14/9/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in phpCommunityCalendar 4.0.3, and possibly earlier versions, allow remote attackers to inject arbitrary web script or HTML via the LocationID parameter to (1) thankyou.php or (2) day.php, font parameter to (3) calDaily.php, (4) calMonthly.php, (5) calMonthlyP.php,… | |
| Modificada | Alta (7.5) | 1.3% | — | Phpcommunitycalendar | 14/9/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in phpCommunityCalendar 4.0.3, and possibly earlier versions, allow remote attackers to execute arbitrary SQL commands via the (1) login field in login.php or (2) LocationID parameter to week.php. | |
| Modificada | Alta (7.5) | 1.8% | — | Phpcommunitycalendar | 14/9/2005 | 16/6/2026 | phpCommunityCalendar 4.0.3 allows remote attackers to bypass authentication and gain unauthorized access via a direct request to the admin directory. | |
| Modificada | Alta (7.5) | 2.0% | — | Webcalendar | 29/8/2005 | 16/6/2026 | PHP remote file inclusion vulnerability in WebCalendar before 1.0.1 allows remote attackers to execute arbitrary PHP code when opening settings.php, possibly via send_reminders.php or other scripts. | |
| Modificada | Alta (7.5) | 1.4% | — | Webcalendar | 19/7/2005 | 16/6/2026 | WebCalendar anteriror a la 1.0.0 no restringe adecuadamente el acceso a "assitant_edit.php", lo que permite que atacantes remotos ganen privilegios. | |
| Modificada | Alta (7.5) | 3.4% | 💥 Exploit | Easyphpcalendar | 6/7/2005 | 16/6/2026 | PHP remote file inclusion vulnerability in EasyPHPCalendar 6.1.5 and earlier allows remote attackers to execute arbitrary code via the serverPath parameter. | |
| Modificada | Media (5) | 1.1% | — | Vincent HOR Calendarix Advanced | 9/6/2005 | 16/6/2026 | PHP remote file inclusion vulnerability in cal_admintop.php in Calendarix Advanced 1.5 allows remote attackers to execute arbitrary PHP code via the calpath parameter. | |
| Modificada | Alta (7.5) | 1.9% | — | Vincent HOR Calendarix Advanced | 9/6/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in Calendarix Advanced 1.5 allow remote attackers to execute arbitrary SQL commands via the catview parameter to (1) cal_week.php, (2) cal_cat.php, or (3) cal_day.php, or (4) id parameter to cal_pophols.php. | |
| Modificada | Media (4.3) | 1.2% | — | Vincent HOR Calendarix Advanced | 31/5/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in calendar.php in Calendarix Advanced 1.5 allows remote attackers to inject arbitrary web script or HTML via the year parameter. | |
| Modificada | Alta (7.5) | 1.4% | — | Aaronoutpost ASP Inline Corporate Calendar | 11/5/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in Aaron Outpost ASP Inline Corporate Calendar allow remote attackers to execute arbitrary SQL commands via the Event_ID parameter to (1) defer.asp or (2) details.asp. | |
| Modificada | Alta (7.5) | 1.8% | — | Php-calendar | 3/5/2005 | 16/6/2026 | SQL injection vulnerability in search.php for PHP-Calendar before 0.10.3 allows remote attackers to execute arbitrary SQL commands via unknown vectors. | |
| Modificada | Media (5) | 1.6% | — | Calendarscript | 2/5/2005 | 16/6/2026 | calendar.pl in CalendarScript 3.21 allows remote attackers to obtain sensitive information via invalid (1) year or (2) month parameters, which leaks the full pathname and debug information. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Ocean12 Technologies Calendar Manager PRO | 2/5/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in Ocean12 Calendar manager 1.01 allow remote attackers to execute arbitrary SQL commands via the Admin_id field. | |
| Modificada | Media (5) | 1.4% | — | Easyphpcalendar | 12/4/2005 | 16/6/2026 | popup.php in EasyPHPCalendar before 6.2.8 allows remote attackers to obtain sensitive information via an invalid ev parameter, which reveals the full pathname of the web server in a PHP error message. | |
| Modificada | Media (4.3) | 1.2% | — | Calendarscript | 12/4/2005 | 16/6/2026 | NOTE: this issue has been disputed by the vendor. Cross-site scripting (XSS) vulnerability in calendar.pl in CalendarScript 3.20 allows remote attackers to inject arbitrary web script or HTML via the template parameter, a different vulnerability than CVE-2005-1146 | |
| Modificada | Media (4.3) | 1.2% | — | Calendarscript | 12/4/2005 | 16/6/2026 | NOTE: this issue has been disputed by the vendor. Cross-site scripting (XSS) vulnerability in the login command in calendar.pl in CalendarScript 3.21 allows remote attackers to inject arbitrary web script or HTML via the username parameter, a different vulnerability than CVE-2005-1145 | |
| Modificada | Media (5) | 1.4% | — | CalendarscriptAI | 12/4/2005 | 16/6/2026 | calendar.pl in CalendarScript 3.20 allows remote attackers to obtain sensitive information via invalid (1) calendar or (2) template parameters, which leaks the full pathname and debug information. | |
| Modificada | Media (4.3) | 1.2% | — | Easyphpcalendar | 12/4/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in EasyPHPCalendar before 6.2.8 allows remote attackers to inject arbitrary web script or HTML via the yr parameter. |