Vulnerabilities
Summary — last 7 days
New vulnerabilities2,851▼ 221 vs. last week
Critical / high1,331▼ 168 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)223▼ 98 vs. last week
5 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Modified | High (7.5) | 2.4% | 💥 Exploit | Myphpcalendar | 12/29/2006 | 6/16/2026 | Multiple PHP remote file inclusion vulnerabilities in myPHPCalendar 10.1 allow remote attackers to execute arbitrary PHP code via a URL in the cal_dir parameter to (1) admin.php, (2) contacts.php, or (3) convert-date.php. | |
| Modified | Medium (5) | 3.5% | 💥 Exploit | Codegrrl PhpcalendarCodegrrl PhpcliqueCodegrrl PhpcurrentlyCodegrrl Phpfanbase+1 | 11/16/2005 | 6/16/2026 | PHP file inclusion vulnerability in protection.php in CodeGrrl (a) PHPCalendar 1.0, (b) PHPClique 1.0, (c) PHPCurrently 2.0, (d) PHPFanBase 2.1, and (e) PHPQuotes 1.0 allows remote attackers to include arbitrary local files via the siteurl parameter when register_globals is enabled. NOTE: It was later reported that… | |
| Modified | High (7.5) | 3.4% | 💥 Exploit | Easyphpcalendar | 7/6/2005 | 6/16/2026 | PHP remote file inclusion vulnerability in EasyPHPCalendar 6.1.5 and earlier allows remote attackers to execute arbitrary code via the serverPath parameter. | |
| Modified | Medium (5) | 1.4% | — | Easyphpcalendar | 4/12/2005 | 6/16/2026 | popup.php in EasyPHPCalendar before 6.2.8 allows remote attackers to obtain sensitive information via an invalid ev parameter, which reveals the full pathname of the web server in a PHP error message. | |
| Modified | Medium (4.3) | 1.2% | — | Easyphpcalendar | 4/12/2005 | 6/16/2026 | Cross-site scripting (XSS) vulnerability in index.php in EasyPHPCalendar before 6.2.8 allows remote attackers to inject arbitrary web script or HTML via the yr parameter. |