Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
796 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.42% | — | Booking CalendarAI | 15/12/2025 | 17/6/2026 | The Booking Calendar plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'dates_to_check' parameter in all versions up to, and including, 10.14.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for… | |
| Aplazada | Media (4.3) | 0.18% | — | Joedolson MY CalendarAI | 9/12/2025 | 17/6/2026 | Missing Authorization vulnerability in Joe Dolson My Calendar my-calendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects My Calendar: from n/a through <= 3.6.16. | |
| Aplazada | Media (5.3) | 0.25% | — | Wpdevart Booking CalendarAI | 9/12/2025 | 17/6/2026 | Missing Authorization vulnerability in wpdevart Booking calendar, Appointment Booking System booking-calendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Booking calendar, Appointment Booking System: from n/a through <= 3.2.30. | |
| Modificada | Media (5.4) | 0.25% | — | Vcita Online Booking & Scheduling Calendar | 9/12/2025 | 17/6/2026 | Missing Authorization vulnerability in vcita Online Booking & Scheduling Calendar for WordPress by vcita meeting-scheduler-by-vcita allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Online Booking & Scheduling Calendar for WordPress by vcita: from n/a through <= 4.5.5. | |
| Modificada | Alta (8.8) | 0.15% | — | Vcita Online Booking & Scheduling Calendar | 9/12/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in vcita Online Booking & Scheduling Calendar for WordPress by vcita meeting-scheduler-by-vcita allows Cross Site Request Forgery.This issue affects Online Booking & Scheduling Calendar for WordPress by vcita: from n/a through <= 4.5.5. | |
| Analizada | Media (5.7) | 0.34% | — | Nextcloud Calendar | 5/12/2025 | 17/6/2026 | Nextcloud Calendar is a calendar app for Nextcloud. Prior to 4.7.17 and 5.2.4, when a malicious user creates a calendar event with a crafted attachment that links to a download link of a file on the same Nextcloud server, the file would be downloaded without the user confirming the action. This vulnerability is fixed… | |
| Analizada | Baja (3.3) | 0.14% | — | Nextcloud Calendar | 5/12/2025 | 17/6/2026 | Nextcloud Calendar is a calendar app for Nextcloud. Prior to 4.7.19, 5.5.6, and 6.0.1, the calendar app allowed blindly booking appointments with a squential ID without known the appointment token. This vulnerability is fixed in 4.7.19, 5.5.6, and 6.0.1. | |
| Analizada | Media (6.5) | 0.29% | — | Nextcloud Calendar | 5/12/2025 | 17/6/2026 | Nextcloud Calendar is a calendar app for Nextcloud. Prior to 6.0.3, the Calendar app generates participant tokens for meeting proposals using a hash function, allowing an attacker to compute valid participant tokens, which allowed them to request details and submit dates in meeting proposals. The tokens are not purely… | |
| Aplazada | Media (6.4) | 0.18% | — | Booking CalendarAI | 5/12/2025 | 17/6/2026 | The Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin 'bookingcalendar' shortcode in all versions up to, and including, 10.14.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,… | |
| Aplazada | Media (5.3) | 0.30% | — | Codepeople Booking Calendar Contact FormAI | 22/11/2025 | 17/6/2026 | The Booking Calendar Contact Form plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.2.60. This is due to missing authorization checks and payment verification in the `dex_bccf_check_IPN_verification` function. This makes it possible for unauthenticated attackers to… | |
| Aplazada | Media (5.3) | 0.28% | — | Appointment Booking CalendarAI | 22/11/2025 | 17/6/2026 | The Appointment Booking Calendar plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.3.96. This is due to the plugin exposing an unauthenticated booking processing endpoint (cpabc_appointments_check_IPN_verification) that trusts attacker-supplied payment notifications… | |
| Aplazada | Media (6.5) | 0.15% | — | Wpdevelop Booking CalendarAI | 13/11/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdevelop Booking Calendar booking allows Stored XSS.This issue affects Booking Calendar: from n/a through <= 10.14.7. | |
| Aplazada | Media (5.4) | 0.20% | — | Codepeople Appointment Booking CalendarAI | 13/11/2025 | 17/6/2026 | Missing Authorization vulnerability in codepeople Appointment Booking Calendar appointment-booking-calendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Appointment Booking Calendar: from n/a through <= 1.3.95. | |
| Aplazada | Crítica (9.8) | 0.85% | — | Holiday Class Post CalendarAI | 11/11/2025 | 17/6/2026 | The Holiday class post calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 7.1 via the 'contents' parameter. This is due to a lack of sanitization of user-supplied data when creating a cache file. This makes it possible for unauthenticated attackers to execute… | |
| Aplazada | Media (4.3) | 0.22% | — | Michielvaneerd Private Google CalendarsAI | 11/11/2025 | 17/6/2026 | The Private Google Calendars plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'pgc_remove' action in all versions up to, and including, 20250811. This makes it possible for authenticated attackers, with Subscriber-level access and above, to reset the… | |
| Aplazada | Media (5.3) | 0.27% | — | Theeventscalendar THE Events CalendarAI | 5/11/2025 | 17/6/2026 | The Events Calendar plugin for WordPress is vulnerable to information disclosure in versions up to, and including, 6.15.9. The sysinfo REST endpoint compares the provided key to the stored opt-in key using a loose comparison, allowing unauthenticated attackers to send a boolean value and obtain the full system report… | |
| Aplazada | Alta (7.5) | 18% | — | Theeventscalendar THE Events CalendarAI | 5/11/2025 | 17/6/2026 | The The Events Calendar plugin for WordPress is vulnerable to blind SQL Injection via the 's' parameter in versions 6.15.1.1 to 6.15.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append… | |
| Aplazada | Media (4.3) | 0.24% | — | Theeventscalendar THE Events CalendarAI | 31/10/2025 | 17/6/2026 | The The Events Calendar plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'tec_qr_code_modal' AJAX endpoint in all versions up to, and including, 6.15.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to view draft event… | |
| Aplazada | Media (6.5) | 0.22% | — | Jonathanjernigan PIE CalendarAI | 22/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jonathan Jernigan Pie Calendar pie-calendar.This issue affects Pie Calendar: from n/a through <= 1.2.9. | |
| Aplazada | Alta (7.1) | 0.25% | — | Webjunk Calendar PlusAI | 22/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webjunk Calendar Plus calendar-plus allows Reflected XSS.This issue affects Calendar Plus: from n/a through <= 1.2.4. | |
| Aplazada | Media (6.4) | 0.24% | — | Event Tickets Rsvps CalendarAI | 3/10/2025 | 17/6/2026 | The Event Tickets, RSVPs, Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ticket_spot' shortcode in all versions up to, and including, 1.0.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Aplazada | Baja (3.8) | 0.31% | — | Codepeople CP Multi View Event CalendarAI | 22/9/2025 | 17/6/2026 | Missing Authorization vulnerability in codepeople CP Multi View Event Calendar cp-multi-view-calendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CP Multi View Event Calendar : from n/a through <= 1.4.35. | |
| Aplazada | Media (5.3) | 0.83% | 💥 Exploit | Theeventscalendar THE Events CalendarAI | 16/9/2025 | 17/6/2026 | The The Events Calendar plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 6.15.2 via the REST endpoint. This makes it possible for unauthenticated attackers to extract information about password-protected vendors or venues. | |
| Aplazada | Alta (7.5) | 0.35% | — | Theeventscalendar THE Events CalendarAI | 12/9/2025 | 25/9/2026 | The The Events Calendar plugin for WordPress is vulnerable to time-based SQL Injection via the ‘s’ parameter in all versions up to, and including, 6.15.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated… | |
| Aplazada | Media (6.4) | 0.30% | — | Digital Events CalendarAI | 11/9/2025 | 17/6/2026 | The Digital Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘column’ parameter in all versions up to, and including, 1.0.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above,… |