Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2629▼ 216 respecto a la semana anterior
Críticas / altas1378▲ 154 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
17 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (6.5) | 0.31% | — | IcalendarAI | 22/9/2026 | 23/9/2026 | icalendar is an RFC 5545 compatible parser and generator of iCalendar files for Python. From 6.1.0 until 7.2.2, vInt.from_ical accepts an attacker-controlled VALARM REPEAT value and applications that request alarm times can eagerly expand it without an application-level limit. Alarms.times and Alarms.active reach the… | |
| Aplazada | Alta (7.5) | 0.63% | — | IcalendarAI | 25/8/2026 | 9/9/2026 | icalendar is an RFC 5545 compatible parser and generator of iCalendar files for Python. From 7.1.0 until 7.1.3, the Component equality method in src/icalendar/cal/component.py compares nested subcomponents with two membership loops, and each membership test invokes the same method on child components, causing O(2^n)… | |
| Analizada | Media (4.3) | 0.37% | — | Icalendar Project Icalendar | 26/3/2026 | 17/6/2026 | iCalendar is a Ruby library for dealing with iCalendar files in the iCalendar format defined by RFC-5545. Starting in version 2.0.0 and prior to version 2.12.2, .ics serialization does not properly sanitize URI property values, enabling ICS injection through attacker-controlled input, adding arbitrary calendar lines… | |
| Aplazada | Media (6.5) | 0.21% | — | Bramwaas Simple Google Icalendar WidgetAI | 27/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bramwaas Simple Google Calendar Outlook Events Block Widget simple-google-icalendar-widget allows Stored XSS.This issue affects Simple Google Calendar Outlook Events Block Widget: from n/a through <= 2.5.0. | |
| Modificada | Media (4.3) | 1.9% | — | Codepeople COM Multicalendar | 19/3/2014 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in tmpl/layout_editevent.php in the Multi Calendar (com_multicalendar) component 4.0.2, and possibly 4.8.5 and earlier, for Joomla! allow remote attackers to inject arbitrary web script or HTML via the (1) calid or (2) paletteDefault parameter in an editevent action… | |
| Modificada | Media (5) | 1.2% | — | Phpicalendar PHP Icalendar | 24/9/2011 | 16/6/2026 | PHP iCalendar 2.4 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by rss/rss_common.php and certain other files. | |
| Modificada | Alta (7.5) | 2.9% | — | Phpicalendar | 26/1/2009 | 16/6/2026 | Directory traversal vulnerability in print.php in PHP iCalendar 2.24 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the cookie_language parameter in a phpicalendar_* cookie, a different vector than CVE-2006-1292. | |
| Modificada | Alta (7.5) | 3.3% | — | Phpicalendar | 26/1/2009 | 16/6/2026 | admin/index.php in PHP iCalendar 2.3.4, 2.24, and earlier does not require administrative authentication for an addupdate action, which allows remote attackers to upload a calendar (aka .ics) file with arbitrary content to the calendars/ directory outside the web root. | |
| Modificada | Alta (7.5) | 3.0% | — | PhpicalendarPhpicalendar2.0 | 5/1/2009 | 16/6/2026 | PHP iCalendar 2.24 and earlier allows remote attackers to bypass authentication by setting the phpicalendar and phpicalendar_login cookies to 1. | |
| Modificada | Media (4.3) | 2.6% | — | PHP Icalendar | 29/12/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Jim Hu and Chad Little PHP iCalendar 2.23 rc1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) getdate parameter in (a) day.php, (b) month.php, (c) year.php, (d) week.php, (e) search.php, (f) rss/index.php, (g) print.php, and… | |
| Modificada | Alta (7.5) | 1.1% | — | Expinion.net Multicalendars | 20/11/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in MultiCalendars allow remote attackers to execute arbitrary SQL commands via the (1) M or (2) Y parameter to rss_out.asp, or the (3) cate parameter to all_calendars.asp. NOTE: the all_calendars.asp/calsids vector is already covered by CVE-2006-2293. | |
| Modificada | Media (4.3) | 1.4% | — | PHP Icalendar | 30/6/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in rss/index.php in PHP iCalendar 2.22 and earlier allows remote attackers to inject arbitrary web script or HTML via the cal parameter. | |
| Modificada | Media (6.4) | 1.2% | — | Expinion.net Multicalendars | 10/5/2006 | 16/6/2026 | SQL injection vulnerability in all_calendars.asp in MultiCalendars 3.0 allows remote attackers to execute arbitrary SQL commands via the calsids parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information. | |
| Modificada | Alta (7.5) | 7.1% | — | PHP Icalendar | 19/3/2006 | 16/6/2026 | publish.ical.php in Jim Hu and Chad Little PHP iCalendar 2.21 and earlier does not require authentication for write access to the calendars directory, which allows remote attackers to upload and execute arbitrary PHP scripts via a WebDAV PUT request with a filename containing a .php extension and a trailing null… | |
| Modificada | Media (5) | 2.8% | — | PHP Icalendar | 19/3/2006 | 16/6/2026 | Directory traversal vulnerability in Jim Hu and Chad Little PHP iCalendar 2.21 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences and a NUL (%00) character in the phpicalendar[cookie_language] and phpicalendar[cookie_style] cookies, as demonstrated by… | |
| Modificada | Media (5) | 2.1% | — | PHP Icalendar | 13/2/2006 | 16/6/2026 | Multiple directory traversal vulnerabilities in PHP iCalendar 2.0.1, 2.1, and 2.2 allow remote attackers to include arbitrary files via the (1) getdate and possibly other parameters used in the replace_files function in search.php and (2) $file variable as used in the parse function in functions/template.php. | |
| Modificada | Media (6.8) | 2.4% | — | PHP Icalendar | 30/10/2005 | 16/6/2026 | PHP file inclusion vulnerability in index.php in PHP iCalendar 2.0a2 through 2.0.1 allows remote attackers to execute arbitrary PHP code and include arbitrary local files via the phpicalendar cookie. NOTE: this is not a cross-site scripting (XSS) issue as claimed by the original researcher. |