LuxSoft records
10 published records for vendor luxsoft.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')4
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-306 Missing Authentication for Critical Function1
The weakness classes this vendor ships most often: where to look.
CWEAll records
10 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2021-45914No exploit | In LuxSoft LuxCal Web Calendar before 5.2.0, an unauthenticated attacker can manipulate a POST request.luxsoft · luxcal | Critical9.8 | — | 1.6% | May 24, 2022 |
39Monitor | CVE-2021-45915No exploit | In LuxSoft LuxCal Web Calendar before 5.2.0, an unauthenticated attacker can manipulate a cookie value.luxsoft · luxcal | Critical9.8 | — | 1.6% | May 24, 2022 |
39Monitor | CVE-2023-46700No exploit | SQL injection vulnerability in LuxCal Web Calendar prior to 5.2.4M (MySQL version) and LuxCal Web Calendar prior to 5.2.4L (SQLite version) luxsoft · luxcal web calendar · CWE-89 | Critical9.8 | — | 1.0% | Nov 20, 2023 |
39Monitor | CVE-2025-25221No exploit | The LuxCal Web Calendar prior to 5.3.3M (MySQL version) and prior to 5.3.3L (SQLite version) contains an SQL injection vulnerability in pdf.luxsoft · luxcal web calendar · CWE-89 | Critical9.8 | — | 0.5% | Feb 17, 2025 |
39Monitor | CVE-2025-25222No exploit | The LuxCal Web Calendar prior to 5.3.3M (MySQL version) and prior to 5.3.3L (SQLite version) contains an SQL injection vulnerability in retrluxsoft · luxcal web calendar · CWE-89 | Critical9.8 | — | 0.5% | Feb 17, 2025 |
36Monitor | CVE-2023-39939No exploit | SQL injection vulnerability in LuxCal Web Calendar prior to 5.2.3M (MySQL version) and LuxCal Web Calendar prior to 5.2.3L (SQLite version) luxsoft · luxcal web calendar · CWE-89 | Critical9.1 | — | 1.0% | Aug 21, 2023 |
30Monitor | CVE-2025-25224No exploit | The LuxCal Web Calendar prior to 5.3.3M (MySQL version) and prior to 5.3.3L (SQLite version) contains a missing authentication vulnerabilityluxsoft · luxcal web calendar · CWE-306 | High7.5 | — | 0.6% | Feb 17, 2025 |
24Monitor | CVE-2023-47175No exploit | Cross-site scripting vulnerability in LuxCal Web Calendar prior to 5.2.4M (MySQL version) and LuxCal Web Calendar prior to 5.2.4L (SQLite veluxsoft · luxcal web calendar · CWE-79 | Medium6.1 | — | 0.7% | Nov 20, 2023 |
24Monitor | CVE-2023-39543No exploit | Cross-site scripting vulnerability in LuxCal Web Calendar prior to 5.2.3M (MySQL version) and LuxCal Web Calendar prior to 5.2.3L (SQLite veluxsoft · luxcal web calendar · CWE-79 | Medium6.1 | — | 0.7% | Aug 21, 2023 |
21Monitor | CVE-2025-25223No exploit | The LuxCal Web Calendar prior to 5.3.3M (MySQL version) and prior to 5.3.3L (SQLite version) contains a path traversal vulnerability in dloaluxsoft · luxcal web calendar · CWE-22 | Medium5.3 | — | 0.6% | Feb 17, 2025 |
- CVE-2021-4591439Monitor
In LuxSoft LuxCal Web Calendar before 5.2.0, an unauthenticated attacker can manipulate a POST request.
CriticalCVSS 9.8No exploitEPSS 2%luxsoft · luxcalMay 24, 2022
- CVE-2021-4591539Monitor
In LuxSoft LuxCal Web Calendar before 5.2.0, an unauthenticated attacker can manipulate a cookie value.
CriticalCVSS 9.8No exploitEPSS 2%luxsoft · luxcalMay 24, 2022
- CVE-2023-4670039Monitor
SQL injection vulnerability in LuxCal Web Calendar prior to 5.2.4M (MySQL version) and LuxCal Web Calendar prior to 5.2.4L (SQLite version)
CriticalCVSS 9.8No exploitEPSS 1%luxsoft · luxcal web calendarNov 20, 2023
- CVE-2025-2522139Monitor
The LuxCal Web Calendar prior to 5.3.3M (MySQL version) and prior to 5.3.3L (SQLite version) contains an SQL injection vulnerability in pdf.
CriticalCVSS 9.8No exploitEPSS 0%luxsoft · luxcal web calendarFeb 17, 2025
- CVE-2025-2522239Monitor
The LuxCal Web Calendar prior to 5.3.3M (MySQL version) and prior to 5.3.3L (SQLite version) contains an SQL injection vulnerability in retr
CriticalCVSS 9.8No exploitEPSS 0%luxsoft · luxcal web calendarFeb 17, 2025
- CVE-2023-3993936Monitor
SQL injection vulnerability in LuxCal Web Calendar prior to 5.2.3M (MySQL version) and LuxCal Web Calendar prior to 5.2.3L (SQLite version)
CriticalCVSS 9.1No exploitEPSS 1%luxsoft · luxcal web calendarAug 21, 2023
- CVE-2025-2522430Monitor
The LuxCal Web Calendar prior to 5.3.3M (MySQL version) and prior to 5.3.3L (SQLite version) contains a missing authentication vulnerability
HighCVSS 7.5No exploitEPSS 1%luxsoft · luxcal web calendarFeb 17, 2025
- CVE-2023-4717524Monitor
Cross-site scripting vulnerability in LuxCal Web Calendar prior to 5.2.4M (MySQL version) and LuxCal Web Calendar prior to 5.2.4L (SQLite ve
MediumCVSS 6.1No exploitEPSS 1%luxsoft · luxcal web calendarNov 20, 2023
- CVE-2023-3954324Monitor
Cross-site scripting vulnerability in LuxCal Web Calendar prior to 5.2.3M (MySQL version) and LuxCal Web Calendar prior to 5.2.3L (SQLite ve
MediumCVSS 6.1No exploitEPSS 1%luxsoft · luxcal web calendarAug 21, 2023
- CVE-2025-2522321Monitor
The LuxCal Web Calendar prior to 5.3.3M (MySQL version) and prior to 5.3.3L (SQLite version) contains a path traversal vulnerability in dloa
MediumCVSS 5.3No exploitEPSS 1%luxsoft · luxcal web calendarFeb 17, 2025