Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
2543 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.25% | — | Themetechmount TruebookerAI | 6/10/2026 | 6/10/2026 | Unauthenticated Settings Change in TrueBooker <= 1.2.9 versions. | |
| Aplazada | Alta (7.1) | 0.19% | — | Nicdark Hotel BookingAI | 6/10/2026 | 6/10/2026 | Unauthenticated Cross Site Scripting (XSS) in Hotel Booking <= 3.8 versions. | |
| Aplazada | Crítica (9.3) | 0.30% | — | Radiustheme Radius BookingAI | 6/10/2026 | 6/10/2026 | Unauthenticated SQL Injection in Radius Booking — Booking Calendar for Appointments & Services <= 1.0.19 versions. | |
| Aplazada | Crítica (9.3) | 0.38% | — | Fs-code BookneticAI | 6/10/2026 | 6/10/2026 | Unauthenticated SQL Injection in Booknetic <= 4.8.5 versions. | |
| Aplazada | Alta (7.1) | 0.27% | — | Mooberry Book ManagerAI | 6/10/2026 | 6/10/2026 | Subscriber SQL Injection in Mooberry Book Manager 4.16.2 versions. | |
| Aplazada | Alta (8.8) | 0.29% | — | Salonbookingsystem Salon Booking SystemAI | 6/10/2026 | 6/10/2026 | Unauthenticated Privilege Escalation in Salon booking system <= 10.31.7 versions. | |
| Aplazada | Alta (7.1) | 0.15% | — | Real 3D FlipbookAI | 6/10/2026 | 6/10/2026 | Unauthenticated Cross Site Scripting (XSS) in Real 3D FlipBook <= 5.5 versions. | |
| Aplazada | Alta (7.5) | 0.20% | — | Fluentbooking PROAI | 6/10/2026 | 6/10/2026 | Unauthenticated Broken Access Control in FluentBooking Pro < 2.5.0 versions. | |
| Aplazada | Baja (2.1) | 0.20% | — | Anisha Online Appointment Booking SystemAI | 5/10/2026 | 6/10/2026 | A weakness has been identified in girishsaraf Online-Appointment-Booking-System up to f427b4757128ca253d33d0cc4e87bbb9c999a4d5. The affected element is an unknown function of the file book.php of the component Booking Handler. This manipulation of the argument Doctor/appointment causes sql injection. The attack is… | |
| Aplazada | Media (5.5) | 0.26% | — | Anisha Online Appointment Booking SystemAI | 5/10/2026 | 6/10/2026 | A security flaw has been discovered in girishsaraf Online-Appointment-Booking-System up to f427b4757128ca253d33d0cc4e87bbb9c999a4d5. Impacted is an unknown function of the file signup.php of the component Registration Handler. The manipulation of the argument fname results in sql injection. The attack can be executed… | |
| Aplazada | Media (5.5) | 0.26% | — | Anisha Online Appointment Booking SystemAI | 5/10/2026 | 6/10/2026 | A vulnerability was identified in girishsaraf Online-Appointment-Booking-System up to f427b4757128ca253d33d0cc4e87bbb9c999a4d5. This issue affects the function mysqli_query of the file locateus.php of the component Doctor Search Endpoint. The manipulation of the argument doctorname leads to sql injection. Remote… | |
| Aplazada | Media (5.5) | 0.33% | — | Anisha Online Appointment Booking SystemAI | 5/10/2026 | 6/10/2026 | A vulnerability was determined in girishsaraf Online-Appointment-Booking-System up to f427b4757128ca253d33d0cc4e87bbb9c999a4d5. This vulnerability affects unknown code of the file get_town.php of the component AJAX Endpoint. Executing a manipulation of the argument countryid/townid/cid/didval/cidval can lead to sql… | |
| Aplazada | Media (5.5) | 0.26% | — | Anisha Online Appointment Booking SystemAI | 5/10/2026 | 6/10/2026 | A vulnerability was found in girishsaraf Online-Appointment-Booking-System up to f427b4757128ca253d33d0cc4e87bbb9c999a4d5. This affects the function mysqli_query of the file Admin/mlogin.php of the component Login Handler. Performing a manipulation of the argument uname/pass results in sql injection. The attack may be… | |
| Aplazada | Alta (8.5) | 0.26% | — | Wp-base WP Base BookingAI | 5/10/2026 | 6/10/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP BASE WP BASE Booking wp-base-booking-of-appointments-services-and-events allows Blind SQL Injection.This issue affects WP BASE Booking: from n/a through 6.4.0. | |
| Aplazada | Alta (7.6) | 0.25% | — | Appsmav Scratch WIN Giveaways FOR Website FacebookAI | 5/10/2026 | 6/10/2026 | Missing Authorization vulnerability in Apps Mav Scratch & Win – Giveaways and Contests scratch-win-giveaways-for-website-facebook allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Scratch & Win – Giveaways and Contests: from n/a through 3.0.2. | |
| Aplazada | Media (5.5) | 0.33% | — | Anisha Online Appointment Booking SystemAI | 5/10/2026 | 6/10/2026 | A security flaw has been discovered in girishsaraf Online-Appointment-Booking-System up to f427b4757128ca253d33d0cc4e87bbb9c999a4d5. This affects the function mysqli_query of the file cover.php of the component Patient Login Handler. The manipulation of the argument uname/psw results in sql injection. It is possible… | |
| Aplazada | Crítica (9.3) | 0.25% | — | Wp-base WP Base BookingAI | 5/10/2026 | 6/10/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP BASE WP BASE Booking wp-base-booking-of-appointments-services-and-events allows Blind SQL Injection.This issue affects WP BASE Booking: from n/a through 6.4.0. | |
| Aplazada | Media (5.3) | 0.23% | — | Magepeople Taxi Booking ManagerAI | 5/10/2026 | 6/10/2026 | Improper Validation of Specified Quantity in Input vulnerability in Magepeople inc. Taxi Booking Manager for WooCommerce ecab-taxi-booking-manager allows Input Data Manipulation.This issue affects Taxi Booking Manager for WooCommerce: from n/a through 2.1.1. | |
| Aplazada | Media (5.3) | 0.20% | — | Mayswind EzbookkeepingAI | 4/10/2026 | 6/10/2026 | ezBookkeeping 1.2.0 before 2.0.1 contains a privilege escalation vulnerability that allows attackers holding an API token to obtain a full session token via /api/v1/tokens/refresh.json. Because TokenRefreshHandler never checks token type, attackers can exchange short-lived or IP-restricted API tokens for 30-day normal… | |
| Aplazada | Crítica (9.1) | 0.88% | — | Vikappointments Services Booking CalendarAI | 3/10/2026 | 6/10/2026 | The VikAppointments Services Booking Calendar plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the extract function in all versions up to, and including, 1.2.21. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which… | |
| Aplazada | Baja (3.7) | 0.16% | — | Wpdevelop Booking CalendarAI | 2/10/2026 | 5/10/2026 | Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in WPdevelop Booking Calendar booking allows Leveraging Race Conditions.This issue affects Booking Calendar: from n/a through 11.8.4. | |
| Aplazada | Media (5.3) | 0.27% | — | Appointment Booking Plugin LatepointAI | 2/10/2026 | 3/10/2026 | The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 5.7.1 via the OsPaypalConnectController::create_order_for_transaction() action registered as a public (unauthenticated) route through… | |
| Aplazada | Alta (7.2) | 0.31% | — | Ba-booking BA Book EverythingAI | 2/10/2026 | 3/10/2026 | The BA Book Everything plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'booking_service_qty' parameter in all versions up to, and including, 1.8.28 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts… | |
| Aplazada | Media (6.5) | 0.24% | — | Mage-people BUS Ticket Booking With Seat ReservationAI | 1/10/2026 | 1/10/2026 | Unauthenticated Insecure Direct Object References (IDOR) in Bus Ticket Booking with Seat Reservation <= 5.9.3 versions. | |
| Aplazada | Alta (7.2) | 0.26% | — | Dwbooster Appointment Hour BookingAI | 1/10/2026 | 1/10/2026 | The Appointment Hour Booking – Booking Calendar plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via Booking Form Single-Line Field via Schedule Calendar List Renderer in all versions up to, and including, 1.5.97 due to insufficient input sanitization and output escaping. This makes it… |