Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2722▼ 6 respecto a la semana anterior
Críticas / altas1451▲ 315 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
48 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.4) | 0.33% | — | K5N Webcalendar | 15/11/2024 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability exists in craigk5n/webcalendar version 1.3.0. The vulnerability occurs in the 'Report Name' input field while creating a new report. An attacker can inject malicious scripts, which are then executed in the context of other users who view the report, potentially leading… | |
| Modificada | Media (6.1) | 0.46% | — | Webcalendar Project Webcalendar | 25/1/2024 | 17/6/2026 | WebCalendar v1.3.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /WebCalendarvqsmnseug2/edit_entry.php. | |
| Modificada | Media (5.4) | 0.53% | — | Webcalendar Project Webcalendar | 13/1/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in GitHub repository craigk5n/webcalendar prior to master. | |
| Modificada | Media (5.3) | 1.6% | — | Webcalendar Project Webcalendar | 4/2/2020 | 16/6/2026 | webcalendar before 1.2.7 shows the reason for a failed login (e.g., "no such user"). | |
| Modificada | Alta (8.8) | 2.5% | — | Webcalendar Project Webcalendar | 27/1/2020 | 16/6/2026 | Local file inclusion in WebCalendar before 1.2.5. | |
| Modificada | Crítica (9.8) | 80% | — | Webcalendar Project Webcalendar | 27/1/2020 | 16/6/2026 | install/index.php in WebCalendar before 1.2.5 allows remote attackers to execute arbitrary code via the form_single_user_login parameter. | |
| Modificada | Media (4.9) | 2.4% | — | Webcalendar Project Webcalendar | 29/8/2017 | 17/6/2026 | Directory traversal vulnerability in WebCalendar 1.2.7 and earlier allows authenticated attackers to read arbitrary files via unspecified vectors. | |
| Modificada | Media (6.1) | 0.93% | — | Webcalendar Project Webcalendar | 29/8/2017 | 17/6/2026 | Cross-site scripting vulnerability in WebCalendar 1.2.7 and earlier allows an attacker to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (4.3) | 1.2% | — | Webcalendar Project Webcalendar | 22/4/2014 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Craig Knudsen WebCalendar before 1.2.5, 1.2.6, and other versions before 1.2.7 allows remote attackers to inject arbitrary web script or HTML via the Category Name field to category.php. | |
| Modificada | Alta (7.5) | 2.2% | — | Webcalendar Project Webcalendar | 11/10/2012 | 16/6/2026 | install/index.php in Craig Knudsen WebCalendar before 1.2.5 allows remote attackers to modify settings.php and possibly execute arbitrary code via vectors related to the user theme preference. | |
| Modificada | Media (4.3) | 0.93% | — | Webcalendar Project Webcalendar | 11/10/2012 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Craig Knudsen WebCalendar allow remote attackers to inject arbitrary web script or HTML via the (1) $name or (2) $description variables in edit_entry_handler.php, or (3) $url, (4) $tempfullname, or (5) $ext_users[] variables in view_entry.php, different vectors… | |
| Modificada | Media (4.3) | 1.7% | — | K5N Webcalendar | 8/10/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Craig Knudsen WebCalendar 1.2.4 allows remote attackers to inject arbitrary web script or HTML via the Location variable. | |
| Modificada | Media (5) | 1.2% | — | K5N Webcalendar | 24/9/2011 | 16/6/2026 | WebCalendar 1.2.3, and other versions before 1.2.5, allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by ws/user_mod.php and certain other files. | |
| Modificada | Media (5) | 1.3% | — | 111webcalendar | 23/9/2011 | 16/6/2026 | 111WebCalendar 1.2.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by footer.php and certain other files. | |
| Modificada | Media (6.8) | 0.57% | — | K5N Webcalendar | 15/2/2010 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in WebCalendar 1.2.0 allows remote attackers to hijack the authentication of administrators for requests that change the administrative password via unknown vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party… | |
| Modificada | Media (6.8) | 0.59% | — | K5N Webcalendar | 12/2/2010 | 16/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in WebCalendar 1.2.0, and other versions before 1.2.5, allow remote attackers to hijack the authentication of administrators for requests that (1) delete an event or (2) ban an IP address from posting via unknown vectors. NOTE: some of these details are… | |
| Modificada | Media (4.3) | 1.1% | — | K5N Webcalendar | 12/2/2010 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in WebCalendar 1.2.0, and other versions before 1.2.5, allow remote attackers to inject arbitrary web script or HTML via the (1) tab parameter to users.php and the PATH_INFO to (2) day.php, (3) month.php, and (4) week.php. NOTE: some of these details are obtained… | |
| Modificada | Media (4.3) | 1.1% | — | C-3.co.jp Webcalenderc3 | 15/1/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in C3 Corp. WebCalenderC3 0.32 and earlier allows remote attackers to inject arbitrary web script or HTML via unknown vectors. NOTE: this issue could not be reproduced by the vendor, but a patch was provided anyway. The original researcher is reliable. | |
| Modificada | Media (5) | 1.6% | — | C-3.co.jp Webcalenderc3 | 15/1/2010 | 16/6/2026 | Directory traversal vulnerability in C3 Corp. WebCalenderC3 0.32 and earlier allows remote attackers to read arbitrary files via unknown vectors. | |
| Modificada | Alta (7.5) | 1.0% | — | TZO Webcal | 5/6/2009 | 16/6/2026 | SQL injection vulnerability in webCal3_detail.asp in WebCal 3.04 allows remote attackers to execute arbitrary SQL commands via the event_id parameter. | |
| Modificada | Media (5) | 1.1% | — | Fullrevolution Aspwebcalendar | 2/4/2009 | 16/6/2026 | aspWebCalendar Free Edition stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing user credentials via a direct request for calendar/calendar.mdb. | |
| Modificada | Alta (10) | 12% | — | Fullrevolution Aspwebcalendar2008 | 24/6/2008 | 16/6/2026 | Unrestricted file upload vulnerability in calendar_admin.asp in Full Revolution aspWebCalendar 2008 allows remote attackers to upload and execute arbitrary code via the FILE1 parameter in an uploadfileprocess action, probably followed by a direct request to the file in calendar/eventimages/. | |
| Modificada | Alta (7.5) | 3.1% | — | K5N Webcalendar | 24/6/2008 | 16/6/2026 | PHP remote file inclusion vulnerability in send_reminders.php in WebCalendar 1.0.4 allows remote attackers to execute arbitrary PHP code via a URL in the includedir parameter and a 0 value for the noSet parameter, a different vector than CVE-2007-1483. | |
| Modificada | Alta (7.5) | 1.2% | — | Webcalendar WEB Calendar PRO | 25/4/2008 | 16/6/2026 | SQL injection vulnerability in one_day.php in Web Calendar Pro 4.1 and earlier allows remote attackers to execute arbitrary SQL commands via the user_id parameter. | |
| Modificada | Baja (2.1) | 1.7% | — | Webcalendar | 1/2/2008 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in WebCalendar 1.1.6 allow remote attackers to inject arbitrary web script or HTML via (1) an event description, (2) the query string to pref.php, and (3) the adv parameter to search.php. NOTE: vector 1 requires user authentication. |