Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2853▼ 343 respecto a la semana anterior
Críticas / altas1376▼ 50 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
–

21.034 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisMedia (4.1)——Quasar APP ViteAI6/10/20266/10/2026
Quasar Framework is a framework for building high-performance Vue.js user interfaces. From 1.0.0 until 3.3.0, @quasar/app-vite recursively removed the resolved build.distDir before building without rejecting the project root, user home directory, filesystem roots, or symlink-resolved external directories. An unsafe…
Pendiente de análisisAlta (7.1)——Quasar Render SSR ErrorAIQuasar APP ViteAI6/10/20266/10/2026
Quasar Framework is a framework for building high-performance Vue.js user interfaces. Prior to @quasar/render-ssr-error 2.2.4 and @quasar/app-vite 3.3.0, renderSSRError() in utils/render-ssr-error/src/index.js used diagnostic data from utils/render-ssr-error/src/env.js to serialize process.env, request headers, and…
Pendiente de análisisAlta (8.4)——Quasar SSL CertificateAIQuasar CLIAIQuasar APP ViteAI6/10/20266/10/2026
Quasar Framework is a framework for building high-performance Vue.js user interfaces. Prior to @quasar/ssl-certificate 2.1.0, @quasar/cli 5.0.4, and @quasar/app-vite 3.3.0, the @quasar/ssl-certificate utility cached a combined private key and certificate PEM without explicitly applying owner-only filesystem…
AplazadaMedia (5.3)——Webkul QloappsAI6/10/20266/10/2026
QloApps through 1.7.0 contains an authorization bypass vulnerability in AdminProductsController::ajaxProcessBulkUpdateRooms that allows hotel-restricted back-office employees to modify rooms of other hotels. Attackers can submit foreign room IDs in the id_rooms parameter to change status, floor, comments, or inactive…
AplazadaAlta (7.8)0.30%—EloanappAI6/10/20266/10/2026
SQL injection (SQLi) vulnerability in the eLoanApp application, specifically in the POST parameter 'logina' of the user process endpoint '/ajax/users.php?op=verify'. The parameter is vulnerable to boolean-based and time-based SQL injection. Successfully exploiting this vulnerability would allow an attacker to discover…
AplazadaMedia (6.5)0.26%—WappointmentAI6/10/20266/10/2026
Unauthenticated Insecure Direct Object References (IDOR) in Wappointment <= 2.7.7 versions.
AplazadaMedia (6.5)0.28%—APP FOR CloudflareAI6/10/20266/10/2026
Subscriber Broken Access Control in App for Cloudflare® <= 1.10.1 versions.
AplazadaCrítica (9.3)0.38%—Woocommerce AppointmentsAI6/10/20266/10/2026
Unauthenticated SQL Injection in WooCommerce Appointments <= 5.3.2 versions.
AplazadaBaja (2.1)0.20%—Anisha Online Appointment Booking SystemAI5/10/20266/10/2026
A weakness has been identified in girishsaraf Online-Appointment-Booking-System up to f427b4757128ca253d33d0cc4e87bbb9c999a4d5. The affected element is an unknown function of the file book.php of the component Booking Handler. This manipulation of the argument Doctor/appointment causes sql injection. The attack is…
AplazadaMedia (5.5)0.26%—Anisha Online Appointment Booking SystemAI5/10/20266/10/2026
A security flaw has been discovered in girishsaraf Online-Appointment-Booking-System up to f427b4757128ca253d33d0cc4e87bbb9c999a4d5. Impacted is an unknown function of the file signup.php of the component Registration Handler. The manipulation of the argument fname results in sql injection. The attack can be executed…
AplazadaMedia (5.5)0.26%—Anisha Online Appointment Booking SystemAI5/10/20266/10/2026
A vulnerability was identified in girishsaraf Online-Appointment-Booking-System up to f427b4757128ca253d33d0cc4e87bbb9c999a4d5. This issue affects the function mysqli_query of the file locateus.php of the component Doctor Search Endpoint. The manipulation of the argument doctorname leads to sql injection. Remote…
AplazadaMedia (5.5)0.33%—Anisha Online Appointment Booking SystemAI5/10/20266/10/2026
A vulnerability was determined in girishsaraf Online-Appointment-Booking-System up to f427b4757128ca253d33d0cc4e87bbb9c999a4d5. This vulnerability affects unknown code of the file get_town.php of the component AJAX Endpoint. Executing a manipulation of the argument countryid/townid/cid/didval/cidval can lead to sql…
AplazadaMedia (5.5)0.26%—Anisha Online Appointment Booking SystemAI5/10/20266/10/2026
A vulnerability was found in girishsaraf Online-Appointment-Booking-System up to f427b4757128ca253d33d0cc4e87bbb9c999a4d5. This affects the function mysqli_query of the file Admin/mlogin.php of the component Login Handler. Performing a manipulation of the argument uname/pass results in sql injection. The attack may be…
AplazadaAlta (7.6)0.25%—Appsmav Scratch WIN Giveaways FOR Website FacebookAI5/10/20266/10/2026
Missing Authorization vulnerability in Apps Mav Scratch & Win – Giveaways and Contests scratch-win-giveaways-for-website-facebook allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Scratch & Win – Giveaways and Contests: from n/a through 3.0.2.
AplazadaMedia (5.5)0.33%—Anisha Online Appointment Booking SystemAI5/10/20266/10/2026
A security flaw has been discovered in girishsaraf Online-Appointment-Booking-System up to f427b4757128ca253d33d0cc4e87bbb9c999a4d5. This affects the function mysqli_query of the file cover.php of the component Patient Login Handler. The manipulation of the argument uname/psw results in sql injection. It is possible…
AnalizadaAlta (8.7)0.59%⚠ Explotación activaCitrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway4/10/20265/10/2026
Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS, and before 13.1-37.282; Gateway: before 14.1-73.41 and before 13.1-64.28.
AplazadaCrítica (9.1)0.88%—Vikappointments Services Booking CalendarAI3/10/20266/10/2026
The VikAppointments Services Booking Calendar plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the extract function in all versions up to, and including, 1.2.21. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which…
AplazadaMedia (5.4)0.22%—Wpmobile APPAI3/10/20266/10/2026
The WPMobile.App – Android and iOS App Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'REQUEST_URI (path segment after /android_json/search/)' parameter in all versions up to, and including, 11.84 due to insufficient input sanitization and output escaping. This makes it possible for…
AplazadaAlta (7.2)0.19%—JetappointmentAI2/10/20262/10/2026
The JetAppointment plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'friendlyTime' parameter in all versions up to, and including, 2.5.2.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages…
AplazadaCrítica (9.8)0.49%💥 PoCAmauri Wpmobile.appAI2/10/20262/10/2026
The WPMobile.App – Android and iOS App Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 11.82 This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to exfiltrate…
AplazadaMedia (5.3)0.27%—Appointment Booking Plugin LatepointAI2/10/20263/10/2026
The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 5.7.1 via the OsPaypalConnectController::create_order_for_transaction() action registered as a public (unauthenticated) route through…
AplazadaMedia (6.9)0.26%—Wormhole.appAI1/10/20261/10/2026
Wormhole.app as deployed before 2026-08-22 misconfigures the coturn TURN server and does not properly restrict TCP relay peers, allowing an unauthenticated attacker to access instance metadata or to source TCP connections from the Wormhole relay's IP.
AplazadaAlta (7.2)0.26%—Dwbooster Appointment Hour BookingAI1/10/20261/10/2026
The Appointment Hour Booking – Booking Calendar plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via Booking Form Single-Line Field via Schedule Calendar List Renderer in all versions up to, and including, 1.5.97 due to insufficient input sanitization and output escaping. This makes it…
AplazadaAlta (7.5)0.43%—Simply Schedule AppointmentsAI1/10/20263/10/2026
The Simply Schedule Appointments plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.6.12.32 via the 'recursive' parameter. This makes it possible for unauthenticated attackers to extract customer PII — including names, email addresses, phone numbers, and custom…
AplazadaMedia (6.5)0.32%—Simply Schedule AppointmentsAI1/10/20263/10/2026
The Simply Schedule Appointments plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.6.12.31 via the 'complete_group' parameter due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with subscriber-level access…