Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2841▼ 157 respecto a la semana anterior
Críticas / altas1370▲ 51 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 258 respecto a la semana anterior
9 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 0.35% | — | Theeventscalendar Eventcalendar | 17/1/2022 | 17/6/2026 | The EventCalendar WordPress plugin before 1.1.51 does not have proper authorisation and CSRF checks in the add_calendar_event AJAX actions, allowing users with a role as low as subscriber to create events | |
| Modificada | Media (6.1) | 0.81% | — | Theeventscalendar Eventcalendar | 17/1/2022 | 17/6/2026 | The EventCalendar WordPress plugin before 1.1.51 does not escape some user input before outputting it back in attributes, leading to Reflected Cross-SIte Scripting issues | |
| Modificada | Alta (7.5) | 0.98% | — | Harmistechnology COM Jeajaxeventcalendar | 1/12/2010 | 16/6/2026 | SQL injection vulnerability in JE Ajax Event Calendar (com_jeajaxeventcalendar) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the event_id parameter in an alleventlist_more action to index.php. | |
| Modificada | Alta (7.5) | 1.1% | — | Harmistechnology COM Jeajaxeventcalendar | 28/6/2010 | 16/6/2026 | SQL injection vulnerability in the JE Ajax Event Calendar (com_jeajaxeventcalendar) component 1.0.5 for Joomla! allows remote attackers to execute arbitrary SQL commands via the view parameter to index.php. | |
| Modificada | Media (6.8) | 5.0% | — | Harmistechnology COM Jeajaxeventcalendar | 1/6/2010 | 16/6/2026 | Directory traversal vulnerability in the JE Ajax Event Calendar (com_jeajaxeventcalendar) component 1.0.1 and 1.0.3 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the view parameter to index.php. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (7.5) | 1.2% | — | Harmistechnology COM Jeeventcalendar | 2/3/2010 | 16/6/2026 | SQL injection vulnerability in the JE Quiz (com_jequizmanagement) component 1.b01 for Joomla! allows remote attackers to execute arbitrary SQL commands via the eid parameter in a question action to index.php. | |
| Modificada | Alta (7.5) | 1.0% | — | Harmistechnology COM Jeeventcalendar | 2/3/2010 | 16/6/2026 | SQL injection vulnerability in the JE Event Calendars (com_jeeventcalendar) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the event_id parameter in an event action to index.php. | |
| Modificada | Alta (7.5) | 1.2% | — | Wesmo Phpeventcalendar | 3/7/2007 | 16/6/2026 | SQL injection vulnerability in eventdisplay.php in phpEventCalendar 0.2.3 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Alta (7.5) | 2.6% | — | Wesmo Phpeventcalendar | 31/12/2002 | 16/6/2026 | Unknown vulnerability in WesMo phpEventCalendar 1.1 allows remote attackers to execute arbitrary commands via unknown attack vectors. |