Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2769▼ 305 respecto a la semana anterior
Críticas / altas1294▼ 203 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)207▼ 114 respecto a la semana anterior
799 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.4) | 1.4% | — | Webcalendar | 30/3/2005 | 16/6/2026 | Vulnerabilidad de inyección de SQL en la función user_valid_crypt del fichero user.php en WebCalendar 0.9.45 permite a atacantes remotos la ejecución arbitraria de comandos SQL mediante una cookie webcalendar_session cifrada. | |
| Modificada | Alta (7.5) | 1.3% | — | Postnuke Software Foundation Postcalendar | 31/12/2004 | 16/6/2026 | SQL injection vulnerability in PostCalendar 4.0.0 allows remote attackers to execute arbitrary SQL commands via search queries. | |
| Modificada | Alta (7.5) | 1.6% | — | Webcalendar | 31/12/2004 | 16/6/2026 | init.php in WebCalendar allows remote attackers to execute arbitrary local PHP scripts via the user_inc parameter. | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | Francisco Burzi Php-nukeShiba-design Nukecalendar | 31/12/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in modules.php in NukeCalendar 1.1.a, as used in PHP-Nuke, allows remote attackers to inject arbitrary web script or HTML via the eid parameter. | |
| Modificada | Media (4.3) | 1.4% | — | ROB Sutton Php-nuke Event Calendar | 31/12/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Event Calendar module 2.13 for PHP-Nuke allows remote attackers to execute arbitrary web script via the (1) type, (2) day, (3) month, or (4) year parameters in a Preview operation, or (5) event comments. | |
| Modificada | Media (5) | 1.5% | — | Webcalendar | 31/12/2004 | 16/6/2026 | CRLF injection vulnerability in login.php in WebCalendar allows remote attackers to inject CRLF sequences via the return_path parameter and perform HTTP Response Splitting attacks to modify expected HTML content from the server. | |
| Modificada | Alta (7.5) | 1.3% | — | Phpnuke Event CalendarAI | 31/12/2004 | 16/6/2026 | SQL injection vulnerability in the Event Calendar module 2.13 for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the (1) eid or (2) cid parameters. | |
| Modificada | Media (5) | 1.6% | — | WebcalendarAI | 31/12/2004 | 16/6/2026 | validate.php in WebCalendar allows remote attackers to gain sensitive information via an invalid encoded_login parameter, which reveals the full path in an error message. | |
| Modificada | Alta (7.5) | 7.2% | 💥 Exploit | Active Server Corner ASP Calendar | 31/12/2004 | 16/6/2026 | The control panel in ASP Calendar does not require authentication to access, which allows remote attackers to gain unauthorized access via a direct request to main.asp. | |
| Modificada | Alta (7.5) | 1.7% | 💥 Exploit | Francisco Burzi Php-nukeShiba-design Nukecalendar | 31/12/2004 | 16/6/2026 | SQL injection vulnerability in modules.php in NukeCalendar 1.1.a, as used in PHP-Nuke, allows remote attackers to execute arbitrary SQL commands via the eid parameter. | |
| Modificada | Alta (7.5) | 2.7% | — | WebcalendarAI | 31/12/2004 | 16/6/2026 | WebCalendar allows remote attackers to gain privileges by modifying critical parameters to (1) view_entry.php or (2) upcoming.php. | |
| Modificada | Media (5) | 1.5% | — | ROB Sutton Php-nuke Event Calendar | 31/12/2004 | 16/6/2026 | The Event Calendar module 2.13 for PHP-Nuke allows remote attackers to gain sensitive information via an HTTP request to (1) config.php, (2) index.php, or (3) submit.php, which reveal the full path in an error message. | |
| Modificada | Media (4.3) | 1.3% | — | Webcalendar | 31/12/2004 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in WebCalendar allow remote attackers to inject arbitrary web script via (1) view_entry.php, (2) view_d.php, (3) usersel.php, (4) datesel.php, (5) trailer.php, or (6) styles.php, as demonstrated using img srg tags. | |
| Modificada | Media (5) | 3.5% | 💥 Exploit | Francisco Burzi Php-nukeShiba-design Nukecalendar | 31/12/2004 | 16/6/2026 | The (1) modules.php, (2) block-Calendar.php, (3) block-Calendar1.php, (4) block-Calendar_center.php scripts in NukeCalendar 1.1.a, as used in PHP-Nuke, allow remote attackers to obtain sensitive information via a URL with an invalid argument, which reveals the full path in an error message. | |
| Modificada | Alta (7.5) | 15% | 💥 Exploit | Php-calendar | 31/12/2004 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in Sean Proctor PHP-Calendar before 0.10.1, as used in Commonwealth of Massachusetts Virtual Law Office (VLO) and other products, allow remote attackers to execute arbitrary PHP code via a URL in the phpc_root_path parameter to (1) includes/calendar.php or (2)… | |
| Modificada | Alta (7.5) | 4.1% | 💥 Exploit | Full Revolution Aspwebcalendar | 31/12/2004 | 16/6/2026 | SQL injection vulnerability in aspWebCalendar allows remote attackers to execute arbitrary SQL statements via (1) the username field on the login page or (2) the eventid parameter to calendar.asp. | |
| Modificada | Alta (10) | 4.5% | — | SUN Java System Calendar Server | 27/7/2004 | 16/6/2026 | Sun Java Portal Sever 6.2 (anteriormente Sun One) permite a usuarios remotos autenticados obtener prilegios de Calendar Server y modificar datos del calendario cambiando las opciones de visualización a una vista no predeterminada. | |
| Modificada | Media (5) | 2.0% | — | Mike Spice MY Calendar | 31/12/2002 | 16/6/2026 | Directory traversal vulnerability in Mike Spice My Calendar before 1.5 allows remote attackers to write arbitrary files via .. (dot dot) sequences in a URL. | |
| Modificada | Media (5) | 1.6% | — | Webcalendar | 31/12/2002 | 16/6/2026 | WebCalendar 0.9.34 and earlier with 'browsing in includes directory' enabled allows remote attackers to read arbitrary include files with .inc extensions from the web root. | |
| Modificada | Alta (7.5) | 2.6% | — | Wesmo Phpeventcalendar | 31/12/2002 | 16/6/2026 | Unknown vulnerability in WesMo phpEventCalendar 1.1 allows remote attackers to execute arbitrary commands via unknown attack vectors. | |
| Modificada | Alta (7.5) | 1.8% | — | Postnuke Software Foundation Postcalendar | 12/8/2002 | 16/6/2026 | Scripting de sitio cruzado en PostCalendar 3.02 permite que atacantes remotos inserten HTML arbitrario y script, y roben cookies, modificando una entrada de calendario en su página "preview". | |
| Modificada | Baja (2.1) | 0.37% | — | Iplanet Calendar Server | 2/8/2001 | 16/6/2026 | iPlanet Calendar Server 5.0p2 and earlier allows a local attacker to gain access to the Netscape Admin Server (NAS) LDAP database and read arbitrary files by obtaining the cleartext administrator username and password from the configuration file, which has insecure permissions. | |
| Modificada | Alta (7.5) | 4.0% | — | Webcalendar | 27/6/2001 | 16/6/2026 | Vulnerability in WebCalendar 0.9.26 allows remote command execution. | |
| Modificada | Alta (7.5) | 7.7% | 💥 Exploit | Matt Kruse Calendar Script | 16/5/2000 | 16/6/2026 | The calender.pl and the calendar_admin.pl calendar scripts by Matt Kruse allow remote attackers to execute arbitrary commands via shell metacharacters. |