Vincent Hor's vulnerability profile centers on the Calendarix product line, a modestly represented set of calendar-management applications that occupy a niche within the broader software landscape. The recurring disclosures carry a notable tendency toward public exploit availability, though the structural context of these vulnerabilities—categorized as miscellaneous application-level flaws—suggests web or integration-focused exposure rather than a singular dominant weakness pattern. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Vincent Hor over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-3183MEDIUM Multiple SQL injection vulnerabilities in Calendarix 0.7.20070307, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) month and | Jun 26, 2007 | 6.8 | 30 | NO | YES |
CVE-2007-3182MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Calendarix 0.7.20070307, when register_globals is enabled, allow remote attackers to inject arbitrary web script or HTML via | Jun 26, 2007 | 4.3 | 24 | NO | YES |
CVE-2006-4135HIGH PHP remote file inclusion vulnerability in cal_config.inc.php in Calendarix 0.7.20060401 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the calpath | Aug 14, 2006 | 7.5 | 20 | NO | NO |
CVE-2006-0492HIGH Multiple SQL injection vulnerabilities in Calendarix allow remote attackers to execute arbitrary SQL commands via (1) the catview parameter in cal_functions.inc.php and (2) the log | Feb 1, 2006 | 7.5 | 20 | NO | NO |
CVE-2005-1865HIGH Multiple SQL injection vulnerabilities in Calendarix Advanced 1.5 allow remote attackers to execute arbitrary SQL commands via the catview parameter to (1) cal_week.php, (2) cal_ca | Jun 9, 2005 | 7.5 | 20 | NO | NO |
Cross-site scripting (XSS) vulnerability in yearcal.php in Calendarix allows remote attackers to inject arbitrary web script or HTML via the ycyear parameter. | Apr 19, 2006 | 2.6 | 18 | NO | YES |
CVE-2007-3259MEDIUM Calendarix 0.7.20070307 allows remote attackers to obtain sensitive information via (1) an invalid month[] parameter to calendar.php, (2) an invalid catview[] parameter to cal_week | Jun 26, 2007 | 5.0 | 16 | NO | NO |
CVE-2005-1866MEDIUM Cross-site scripting (XSS) vulnerability in calendar.php in Calendarix Advanced 1.5 allows remote attackers to inject arbitrary web script or HTML via the year parameter. | May 31, 2005 | 4.3 | 16 | NO | NO |
CVE-2007-3258MEDIUM calendar.php in Calendarix 0.7.20070307 allows remote attackers to obtain sensitive information via large values to the (1) year and (2) month parameters, which causes negative val | Jun 27, 2007 | 5.0 | 15 | NO | NO |
CVE-2006-3094MEDIUM Multiple SQL injection vulnerabilities in Calendarix Basic 0.7.20060401 and earlier, with magic_quotes_gpc disabled, allow remote attackers to execute arbitrary SQL commands via th | Jun 19, 2006 | 5.1 | 15 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Vincent Hor.
Media articles that mention a CVE ID that affects a product developed by Vincent Hor — matched by CVE ID, not by vendor name.