Lucene search

K

Calendar Security Vulnerabilities

cve
cve

CVE-2018-6397

Directory Traversal exists in the Picture Calendar 3.1.4 component for Joomla! via the list.php folder...

7.5CVSS

7.4AI Score

0.036EPSS

2018-01-30 03:29 PM
33
cve
cve

CVE-2018-5672

An issue was discovered in the booking-calendar plugin 2.1.7 for WordPress. XSS exists via the wp-admin/admin.php form_field5[label]...

4.8CVSS

4.9AI Score

0.001EPSS

2018-01-13 12:29 AM
19
cve
cve

CVE-2018-5671

An issue was discovered in the booking-calendar plugin 2.1.7 for WordPress. XSS exists via the wp-admin/admin.php extra_field1[items][field_item1][price_percent]...

4.8CVSS

4.9AI Score

0.001EPSS

2018-01-13 12:29 AM
25
cve
cve

CVE-2018-5673

An issue was discovered in the booking-calendar plugin 2.1.7 for WordPress. CSRF exists via...

8.8CVSS

8.6AI Score

0.002EPSS

2018-01-13 12:29 AM
23
cve
cve

CVE-2018-5670

An issue was discovered in the booking-calendar plugin 2.1.7 for WordPress. XSS exists via the wp-admin/admin.php sale_conditions[count][]...

4.8CVSS

4.9AI Score

0.001EPSS

2018-01-13 12:29 AM
20
cve
cve

CVE-2018-5315

The Wachipi WP Events Calendar plugin 1.0 for WordPress has SQL Injection via the event_id parameter to...

9.8CVSS

9.9AI Score

0.003EPSS

2018-01-12 05:29 PM
31
cve
cve

CVE-2017-17780

The Clockwork SMS clockwork-test-message.php component has XSS via a crafted "to" parameter in a clockwork-test-message request to wp-admin/admin.php. This component code is found in the following WordPress plugins: Clockwork Free and Paid SMS Notifications 2.0.3, Two-Factor Authentication -...

6.1CVSS

5.9AI Score

0.001EPSS

2017-12-20 03:29 AM
26
2
cve
cve

CVE-2017-17616

Event Search Script 1.0 has SQL Injection via the /event-list city...

9.8CVSS

9.9AI Score

0.002EPSS

2017-12-13 09:29 AM
23
cve
cve

CVE-2017-15891

Improper access control vulnerability in SYNO.Cal.EventBase in Synology Calendar before 2.0.1-0242 allows remote authenticated users to modify calendar event via unspecified...

6.5CVSS

6AI Score

0.001EPSS

2017-12-08 04:29 PM
25
cve
cve

CVE-2017-10322

Vulnerability in the Oracle Common Applications Calendar component of Oracle E-Business Suite (subcomponent: Applications Calendar). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6 and 12.2.7. Easily exploitable vulnerability allows unauthenticated...

5.3CVSS

4.7AI Score

0.002EPSS

2017-10-19 05:29 PM
24
cve
cve

CVE-2017-10326

Vulnerability in the Oracle Common Applications Calendar component of Oracle E-Business Suite (subcomponent: Applications Calendar). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6 and 12.2.7. Easily exploitable vulnerability allows unauthenticated...

8.2CVSS

8.1AI Score

0.001EPSS

2017-10-19 05:29 PM
31
cve
cve

CVE-2017-10325

Vulnerability in the Oracle Common Applications Calendar component of Oracle E-Business Suite (subcomponent: Applications Calendar). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6 and 12.2.7. Easily exploitable vulnerability allows unauthenticated...

8.2CVSS

8.1AI Score

0.001EPSS

2017-10-19 05:29 PM
25
cve
cve

CVE-2017-2224

Cross-site scripting vulnerability in Event Calendar WD prior to version 1.0.94 allows remote attackers to inject arbitrary web script or HTML via unspecified...

6.1CVSS

6AI Score

0.002EPSS

2017-07-07 01:29 PM
30
2
cve
cve

CVE-2017-9420

Cross site scripting (XSS) vulnerability in the Spiffy Calendar plugin before 3.3.0 for WordPress allows remote attackers to inject arbitrary JavaScript via the yr...

6.1CVSS

6.1AI Score

0.001EPSS

2017-06-05 07:29 PM
25
cve
cve

CVE-2017-2150

Directory traversal vulnerability in Booking Calendar version 7.0 and earlier allows remote attackers to read arbitrary files via specially crafted captcha_chalange...

5.3CVSS

5.3AI Score

0.002EPSS

2017-04-28 04:59 PM
24
cve
cve

CVE-2017-2151

Cross-site scripting vulnerability in Booking Calendar version 7.1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified...

6.1CVSS

6AI Score

0.001EPSS

2017-04-28 04:59 PM
22
cve
cve

CVE-2017-7719

SQL injection in the Spider Event Calendar (aka spider-event-calendar) plugin before 1.5.52 for WordPress is exploitable with the order_by parameter to calendar_functions.php or widget_Theme_functions.php, related to...

9.8CVSS

9.8AI Score

0.003EPSS

2017-04-12 03:59 PM
27
cve
cve

CVE-2017-6485

A Cross-Site Scripting (XSS) issue was discovered in php-calendar before 2017-03-03. The vulnerability exists due to insufficient filtration of user-supplied data (errorMsg) passed to the "php-calendar-master/error.php" URL. An attacker could execute arbitrary HTML and script code in a browser in.....

6.1CVSS

5.8AI Score

0.001EPSS

2017-03-05 08:59 PM
25
cve
cve

CVE-2016-3543

Unspecified vulnerability in the Oracle Common Applications Calendar component in Oracle E-Business Suite 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, and 12.2.5 allows remote attackers to affect confidentiality and integrity via vectors related to...

9.1CVSS

7.8AI Score

0.002EPSS

2016-07-21 10:13 AM
17
4
cve
cve

CVE-2016-3541

Unspecified vulnerability in the Oracle Common Applications Calendar component in Oracle E-Business Suite 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, and 12.2.5 allows remote attackers to affect confidentiality and integrity via vectors related to...

9.1CVSS

7.8AI Score

0.002EPSS

2016-07-21 10:13 AM
15
4
cve
cve

CVE-2016-3436

Unspecified vulnerability in the Oracle Common Applications Calendar component in Oracle E-Business Suite 12.1.1, 12.1.2, and 12.1.3 allows remote attackers to affect confidentiality and integrity via vectors related to...

8.2CVSS

7.5AI Score

0.002EPSS

2016-04-21 11:00 AM
17
cve
cve

CVE-2015-7320

Multiple cross-site scripting (XSS) vulnerabilities in cpabc_appointments_admin_int_bookings_list.inc.php in the Appointment Booking Calendar plugin before 1.1.8 for WordPress allow remote attackers to inject arbitrary web script or HTML via unspecified...

5.8AI Score

0.003EPSS

2015-09-29 07:59 PM
26
cve
cve

CVE-2015-7319

SQL injection vulnerability in cpabc_appointments_admin_int_calendar_list.inc.php in the Appointment Booking Calendar plugin before 1.1.8 for WordPress allows remote attackers to execute arbitrary SQL commands via unspecified vectors related to updating the...

9.8AI Score

0.001EPSS

2015-09-29 07:59 PM
27
cve
cve

CVE-2014-10014

Multiple cross-site request forgery (CSRF) vulnerabilities in PHPJabbers Event Booking Calendar 2.0 allow remote attackers to hijack the authentication of administrators for requests that (1) change the username and password of the administrator via an update action to the AdminOptions controller.....

6.9AI Score

0.004EPSS

2015-01-13 11:59 AM
21
cve
cve

CVE-2014-8586

SQL injection vulnerability in the CP Multi View Event Calendar plugin 1.01 for WordPress allows remote attackers to execute arbitrary SQL commands via the calid...

8.8AI Score

0.109EPSS

2014-11-04 03:55 PM
27
cve
cve

CVE-2014-4904

The Crossmo Calendar (aka com.crossmo.calendar) application 1.7.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted...

6AI Score

0.0005EPSS

2014-10-21 10:55 AM
19
cve
cve

CVE-2014-7138

Cross-site scripting (XSS) vulnerability in the Google Calendar Events plugin before 2.0.4 for WordPress allows remote attackers to inject arbitrary web script or HTML via the gce_feed_ids parameter in a gce_ajax action to...

5.8AI Score

0.005EPSS

2014-10-16 07:55 PM
26
cve
cve

CVE-2014-5841

The Girls Calendar Period&Weight (aka jp.co.cybird.apps.lifestyle.cal) application 3.2.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted...

6AI Score

0.0005EPSS

2014-09-09 10:55 AM
16
cve
cve

CVE-2014-4571

Multiple cross-site scripting (XSS) vulnerabilities in vncal.js.php in the VN-Calendar plugin 1.0 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) fs or (2) w...

6AI Score

0.002EPSS

2014-07-02 08:55 PM
19
cve
cve

CVE-2013-2698

Cross-site request forgery (CSRF) vulnerability in the Calendar plugin before 1.3.3 for WordPress allows remote attackers to hijack the authentication of users for requests that add a calendar entry via unspecified...

7.3AI Score

0.002EPSS

2014-05-27 03:00 PM
16
cve
cve

CVE-2012-6527

Cross-site scripting (XSS) vulnerability in the My Calendar plugin before 1.10.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the...

6AI Score

0.008EPSS

2013-01-31 05:44 AM
32
cve
cve

CVE-2012-4242

Cross-site scripting (XSS) vulnerability in the MF Gig Calendar plugin 0.9.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the query string to the calendar...

5.9AI Score

0.002EPSS

2012-10-01 11:55 PM
36
cve
cve

CVE-2011-5109

Multiple SQL injection vulnerabilities in Freelancer calendar 1.01 and earlier allow remote attackers to inject arbitrary web script or HTML via the SearchField parameter in a search action to (1) category_list.php, (2) Copy_of_calendar_list.php, (3) customer_statistics_list.php, (4)...

7.7AI Score

0.002EPSS

2012-08-23 08:55 PM
19
cve
cve

CVE-2011-5045

Cross-site scripting (XSS) vulnerability in details_view.php in PHP Booking Calendar 10e allows remote attackers to inject arbitrary web script or HTML via the page_info_message...

5.9AI Score

0.002EPSS

2011-12-30 07:55 PM
19
cve
cve

CVE-2010-5023

SQL injection vulnerability in index.asp in Digital Interchange Calendar 5.8.5 allows remote attackers to execute arbitrary SQL commands via the intDivisionID...

8.7AI Score

0.002EPSS

2011-11-02 09:55 PM
21
cve
cve

CVE-2010-4953

Unspecified vulnerability in the JW Calendar (jw_calendar) extension 1.3.20 and earlier for TYPO3 allows remote attackers to execute arbitrary code via unknown...

7.9AI Score

0.018EPSS

2011-10-09 10:55 AM
17
cve
cve

CVE-2010-4880

Multiple cross-site scripting (XSS) vulnerabilities in calendar.class.php in ApPHP Calendar (ApPHP CAL) allow remote attackers to inject arbitrary web script or HTML via the (1) category_name, (2) category_description, (3) event_name, or (4) event_description...

5.9AI Score

0.002EPSS

2011-10-07 10:55 AM
20
cve
cve

CVE-2010-4881

Multiple cross-site request forgery (CSRF) vulnerabilities in calendar.class.php in ApPHP Calendar (ApPHP CAL) allow remote attackers to hijack the authentication of unspecified victims for requests that use the (1) category_name, (2) category_description, (3) event_name, or (4) event_description.....

7.5AI Score

0.003EPSS

2011-10-07 10:55 AM
17
cve
cve

CVE-2010-2041

Multiple cross-site scripting (XSS) vulnerabilities in index.php in PHP-Calendar before 2.0 Beta7 allow remote attackers to inject arbitrary web script or HTML via the (1) description and (2) lastaction...

5.9AI Score

0.003EPSS

2010-05-25 02:30 PM
21
cve
cve

CVE-2009-3702

Multiple absolute path traversal vulnerabilities in PHP-Calendar 1.1 allow remote attackers to include and execute arbitrary local files via a full pathname in the configfile parameter to (1) update08.php or (2) update10.php. NOTE: in some environments, this can be leveraged for remote file...

7.2AI Score

0.007EPSS

2009-12-22 07:30 PM
22
cve
cve

CVE-2009-4336

Cross-site scripting (XSS) vulnerability in the Diocese of Portsmouth Calendar (pd_calendar) extension 0.4.1 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified...

5.8AI Score

0.002EPSS

2009-12-17 05:30 PM
22
cve
cve

CVE-2009-4337

SQL injection vulnerability in the Diocese of Portsmouth Calendar (pd_calendar) extension 0.4.1 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unknown vectors, a different issue than...

8.4AI Score

0.002EPSS

2009-12-17 05:30 PM
27
cve
cve

CVE-2008-7018

Cross-site scripting (XSS) vulnerability in NashTech Easy PHP Calendar 6.3.25 allows remote attackers to inject arbitrary web script or HTML via the Details field (descr parameter) in an Add New Event action in an unspecified request as generated by an add action in...

6AI Score

0.002EPSS

2009-08-21 02:30 PM
21
cve
cve

CVE-2009-2243

SQL injection vulnerability in active_appointments.asp in ASP Inline Corporate Calendar allows remote attackers to execute arbitrary SQL commands via the sortby parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party...

8.3AI Score

0.002EPSS

2009-06-27 06:48 PM
24
cve
cve

CVE-2009-2241

Cross-site scripting (XSS) vulnerability in search.asp in ASP Inline Corporate Calendar allows remote attackers to inject arbitrary web script or HTML via the keyword...

5.9AI Score

0.002EPSS

2009-06-27 06:48 PM
22
cve
cve

CVE-2009-2242

SQL injection vulnerability in active_appointments.asp in ASP Inline Corporate Calendar allows remote attackers to execute arbitrary SQL commands via the order...

8.7AI Score

0.001EPSS

2009-06-27 06:48 PM
21
cve
cve

CVE-2008-6736

Flat Calendar 1.1 does not properly restrict access to administrative functions, which allows remote attackers to (1) add new events via calAdd.php, as reachable from admin/add.php, or (2) delete events via admin/deleteEvent.php. NOTE: this is only a vulnerability when the administrator does not...

6.9AI Score

0.022EPSS

2009-04-21 06:30 PM
20
cve
cve

CVE-2008-6691

SQL injection vulnerability in Diocese of Portsmouth Calendar Today (pd_calendar_today) extension 0.0.3 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unknown...

8.7AI Score

0.002EPSS

2009-04-10 10:00 PM
19
cve
cve

CVE-2008-6608

Multiple SQL injection vulnerabilities in DevelopItEasy Events Calendar 1.2 allow remote attackers to execute arbitrary SQL commands via (1) the user_name parameter (aka user field) to admin/index.php, (2) the user_pass parameter (aka pass field) to admin/index.php, or (3) the id parameter to...

8.8AI Score

0.002EPSS

2009-04-06 02:30 PM
19
cve
cve

CVE-2009-1219

Sun Calendar Express Web Server in Sun ONE Calendar Server 6.0 and Sun Java System Calendar Server 6 2004Q2 through 6.3-7.01 allows remote attackers to cause a denial of service (daemon crash) via multiple requests to the default URI with alphabetic characters in the tzid...

6.7AI Score

0.146EPSS

2009-04-01 06:30 PM
28
Total number of security vulnerabilities417