Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2722▼ 6 respecto a la semana anterior
Críticas / altas1451▲ 315 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
–

48 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.4)0.33%—K5N Webcalendar15/11/202417/6/2026
A stored cross-site scripting (XSS) vulnerability exists in craigk5n/webcalendar version 1.3.0. The vulnerability occurs in the 'Report Name' input field while creating a new report. An attacker can inject malicious scripts, which are then executed in the context of other users who view the report, potentially leading…
ModificadaMedia (6.1)0.46%—Webcalendar Project Webcalendar25/1/202417/6/2026
WebCalendar v1.3.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /WebCalendarvqsmnseug2/edit_entry.php.
ModificadaMedia (5.4)0.53%—Webcalendar Project Webcalendar13/1/202317/6/2026
Cross-site Scripting (XSS) - Stored in GitHub repository craigk5n/webcalendar prior to master.
ModificadaMedia (5.3)1.6%—Webcalendar Project Webcalendar4/2/202016/6/2026
webcalendar before 1.2.7 shows the reason for a failed login (e.g., "no such user").
ModificadaAlta (8.8)2.5%—Webcalendar Project Webcalendar27/1/202016/6/2026
Local file inclusion in WebCalendar before 1.2.5.
ModificadaCrítica (9.8)80%—Webcalendar Project Webcalendar27/1/202016/6/2026
install/index.php in WebCalendar before 1.2.5 allows remote attackers to execute arbitrary code via the form_single_user_login parameter.
ModificadaMedia (4.9)2.4%—Webcalendar Project Webcalendar29/8/201717/6/2026
Directory traversal vulnerability in WebCalendar 1.2.7 and earlier allows authenticated attackers to read arbitrary files via unspecified vectors.
ModificadaMedia (6.1)0.93%—Webcalendar Project Webcalendar29/8/201717/6/2026
Cross-site scripting vulnerability in WebCalendar 1.2.7 and earlier allows an attacker to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (4.3)1.2%—Webcalendar Project Webcalendar22/4/201416/6/2026
Cross-site scripting (XSS) vulnerability in Craig Knudsen WebCalendar before 1.2.5, 1.2.6, and other versions before 1.2.7 allows remote attackers to inject arbitrary web script or HTML via the Category Name field to category.php.
ModificadaAlta (7.5)2.2%—Webcalendar Project Webcalendar11/10/201216/6/2026
install/index.php in Craig Knudsen WebCalendar before 1.2.5 allows remote attackers to modify settings.php and possibly execute arbitrary code via vectors related to the user theme preference.
ModificadaMedia (4.3)0.93%—Webcalendar Project Webcalendar11/10/201216/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Craig Knudsen WebCalendar allow remote attackers to inject arbitrary web script or HTML via the (1) $name or (2) $description variables in edit_entry_handler.php, or (3) $url, (4) $tempfullname, or (5) $ext_users[] variables in view_entry.php, different vectors…
ModificadaMedia (4.3)1.7%—K5N Webcalendar8/10/201216/6/2026
Cross-site scripting (XSS) vulnerability in Craig Knudsen WebCalendar 1.2.4 allows remote attackers to inject arbitrary web script or HTML via the Location variable.
ModificadaMedia (5)1.2%—K5N Webcalendar24/9/201116/6/2026
WebCalendar 1.2.3, and other versions before 1.2.5, allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by ws/user_mod.php and certain other files.
ModificadaMedia (5)1.3%—111webcalendar23/9/201116/6/2026
111WebCalendar 1.2.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by footer.php and certain other files.
ModificadaMedia (6.8)0.57%—K5N Webcalendar15/2/201016/6/2026
Cross-site request forgery (CSRF) vulnerability in WebCalendar 1.2.0 allows remote attackers to hijack the authentication of administrators for requests that change the administrative password via unknown vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party…
ModificadaMedia (6.8)0.59%—K5N Webcalendar12/2/201016/6/2026
Multiple cross-site request forgery (CSRF) vulnerabilities in WebCalendar 1.2.0, and other versions before 1.2.5, allow remote attackers to hijack the authentication of administrators for requests that (1) delete an event or (2) ban an IP address from posting via unknown vectors. NOTE: some of these details are…
ModificadaMedia (4.3)1.1%—K5N Webcalendar12/2/201016/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in WebCalendar 1.2.0, and other versions before 1.2.5, allow remote attackers to inject arbitrary web script or HTML via the (1) tab parameter to users.php and the PATH_INFO to (2) day.php, (3) month.php, and (4) week.php. NOTE: some of these details are obtained…
ModificadaMedia (4.3)1.1%—C-3.co.jp Webcalenderc315/1/201016/6/2026
Cross-site scripting (XSS) vulnerability in C3 Corp. WebCalenderC3 0.32 and earlier allows remote attackers to inject arbitrary web script or HTML via unknown vectors. NOTE: this issue could not be reproduced by the vendor, but a patch was provided anyway. The original researcher is reliable.
ModificadaMedia (5)1.6%—C-3.co.jp Webcalenderc315/1/201016/6/2026
Directory traversal vulnerability in C3 Corp. WebCalenderC3 0.32 and earlier allows remote attackers to read arbitrary files via unknown vectors.
ModificadaAlta (7.5)1.0%—TZO Webcal5/6/200916/6/2026
SQL injection vulnerability in webCal3_detail.asp in WebCal 3.04 allows remote attackers to execute arbitrary SQL commands via the event_id parameter.
ModificadaMedia (5)1.1%—Fullrevolution Aspwebcalendar2/4/200916/6/2026
aspWebCalendar Free Edition stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing user credentials via a direct request for calendar/calendar.mdb.
ModificadaAlta (10)12%—Fullrevolution Aspwebcalendar200824/6/200816/6/2026
Unrestricted file upload vulnerability in calendar_admin.asp in Full Revolution aspWebCalendar 2008 allows remote attackers to upload and execute arbitrary code via the FILE1 parameter in an uploadfileprocess action, probably followed by a direct request to the file in calendar/eventimages/.
ModificadaAlta (7.5)3.1%—K5N Webcalendar24/6/200816/6/2026
PHP remote file inclusion vulnerability in send_reminders.php in WebCalendar 1.0.4 allows remote attackers to execute arbitrary PHP code via a URL in the includedir parameter and a 0 value for the noSet parameter, a different vector than CVE-2007-1483.
ModificadaAlta (7.5)1.2%—Webcalendar WEB Calendar PRO25/4/200816/6/2026
SQL injection vulnerability in one_day.php in Web Calendar Pro 4.1 and earlier allows remote attackers to execute arbitrary SQL commands via the user_id parameter.
ModificadaBaja (2.1)1.7%—Webcalendar1/2/200816/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in WebCalendar 1.1.6 allow remote attackers to inject arbitrary web script or HTML via (1) an event description, (2) the query string to pref.php, and (3) the adv parameter to search.php. NOTE: vector 1 requires user authentication.