Vulnerabilities

Summary — last 7 days

New vulnerabilities2,851▼ 221 vs. last week
Critical / high1,331▼ 168 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)223▼ 98 vs. last week
–

5 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
ModifiedHigh (7.5)2.4%💥 ExploitMyphpcalendar12/29/20066/16/2026
Multiple PHP remote file inclusion vulnerabilities in myPHPCalendar 10.1 allow remote attackers to execute arbitrary PHP code via a URL in the cal_dir parameter to (1) admin.php, (2) contacts.php, or (3) convert-date.php.
ModifiedMedium (5)3.5%💥 ExploitCodegrrl PhpcalendarCodegrrl PhpcliqueCodegrrl PhpcurrentlyCodegrrl Phpfanbase+111/16/20056/16/2026
PHP file inclusion vulnerability in protection.php in CodeGrrl (a) PHPCalendar 1.0, (b) PHPClique 1.0, (c) PHPCurrently 2.0, (d) PHPFanBase 2.1, and (e) PHPQuotes 1.0 allows remote attackers to include arbitrary local files via the siteurl parameter when register_globals is enabled. NOTE: It was later reported that…
ModifiedHigh (7.5)3.4%💥 ExploitEasyphpcalendar7/6/20056/16/2026
PHP remote file inclusion vulnerability in EasyPHPCalendar 6.1.5 and earlier allows remote attackers to execute arbitrary code via the serverPath parameter.
ModifiedMedium (5)1.4%—Easyphpcalendar4/12/20056/16/2026
popup.php in EasyPHPCalendar before 6.2.8 allows remote attackers to obtain sensitive information via an invalid ev parameter, which reveals the full pathname of the web server in a PHP error message.
ModifiedMedium (4.3)1.2%—Easyphpcalendar4/12/20056/16/2026
Cross-site scripting (XSS) vulnerability in index.php in EasyPHPCalendar before 6.2.8 allows remote attackers to inject arbitrary web script or HTML via the yr parameter.
Orbitaley — Vulnerabilities