Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
–

1060 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.1)0.19%—Nicdark Hotel BookingAI6/10/20266/10/2026
Unauthenticated Cross Site Scripting (XSS) in Hotel Booking <= 3.8 versions.
AplazadaCrítica (9.3)0.30%—Radiustheme Radius BookingAI6/10/20266/10/2026
Unauthenticated SQL Injection in Radius Booking — Booking Calendar for Appointments &amp; Services <= 1.0.19 versions.
AplazadaAlta (8.8)0.29%—Salonbookingsystem Salon Booking SystemAI6/10/20266/10/2026
Unauthenticated Privilege Escalation in Salon booking system <= 10.31.7 versions.
AplazadaAlta (7.5)0.20%—Fluentbooking PROAI6/10/20266/10/2026
Unauthenticated Broken Access Control in FluentBooking Pro < 2.5.0 versions.
AplazadaBaja (2.1)0.20%—Anisha Online Appointment Booking SystemAI5/10/20266/10/2026
A weakness has been identified in girishsaraf Online-Appointment-Booking-System up to f427b4757128ca253d33d0cc4e87bbb9c999a4d5. The affected element is an unknown function of the file book.php of the component Booking Handler. This manipulation of the argument Doctor/appointment causes sql injection. The attack is…
AplazadaMedia (5.5)0.26%—Anisha Online Appointment Booking SystemAI5/10/20266/10/2026
A security flaw has been discovered in girishsaraf Online-Appointment-Booking-System up to f427b4757128ca253d33d0cc4e87bbb9c999a4d5. Impacted is an unknown function of the file signup.php of the component Registration Handler. The manipulation of the argument fname results in sql injection. The attack can be executed…
AplazadaMedia (5.5)0.26%—Anisha Online Appointment Booking SystemAI5/10/20266/10/2026
A vulnerability was identified in girishsaraf Online-Appointment-Booking-System up to f427b4757128ca253d33d0cc4e87bbb9c999a4d5. This issue affects the function mysqli_query of the file locateus.php of the component Doctor Search Endpoint. The manipulation of the argument doctorname leads to sql injection. Remote…
AplazadaMedia (5.5)0.33%—Anisha Online Appointment Booking SystemAI5/10/20266/10/2026
A vulnerability was determined in girishsaraf Online-Appointment-Booking-System up to f427b4757128ca253d33d0cc4e87bbb9c999a4d5. This vulnerability affects unknown code of the file get_town.php of the component AJAX Endpoint. Executing a manipulation of the argument countryid/townid/cid/didval/cidval can lead to sql…
AplazadaMedia (5.5)0.26%—Anisha Online Appointment Booking SystemAI5/10/20266/10/2026
A vulnerability was found in girishsaraf Online-Appointment-Booking-System up to f427b4757128ca253d33d0cc4e87bbb9c999a4d5. This affects the function mysqli_query of the file Admin/mlogin.php of the component Login Handler. Performing a manipulation of the argument uname/pass results in sql injection. The attack may be…
AplazadaAlta (8.5)0.26%—Wp-base WP Base BookingAI5/10/20266/10/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP BASE WP BASE Booking wp-base-booking-of-appointments-services-and-events allows Blind SQL Injection.This issue affects WP BASE Booking: from n/a through 6.4.0.
AplazadaMedia (5.5)0.33%—Anisha Online Appointment Booking SystemAI5/10/20266/10/2026
A security flaw has been discovered in girishsaraf Online-Appointment-Booking-System up to f427b4757128ca253d33d0cc4e87bbb9c999a4d5. This affects the function mysqli_query of the file cover.php of the component Patient Login Handler. The manipulation of the argument uname/psw results in sql injection. It is possible…
AplazadaCrítica (9.3)0.25%—Wp-base WP Base BookingAI5/10/20266/10/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP BASE WP BASE Booking wp-base-booking-of-appointments-services-and-events allows Blind SQL Injection.This issue affects WP BASE Booking: from n/a through 6.4.0.
AplazadaMedia (5.3)0.23%—Magepeople Taxi Booking ManagerAI5/10/20266/10/2026
Improper Validation of Specified Quantity in Input vulnerability in Magepeople inc. Taxi Booking Manager for WooCommerce ecab-taxi-booking-manager allows Input Data Manipulation.This issue affects Taxi Booking Manager for WooCommerce: from n/a through 2.1.1.
AplazadaCrítica (9.1)0.88%—Vikappointments Services Booking CalendarAI3/10/20266/10/2026
The VikAppointments Services Booking Calendar plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the extract function in all versions up to, and including, 1.2.21. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which…
AplazadaBaja (3.7)0.16%—Wpdevelop Booking CalendarAI2/10/20265/10/2026
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in WPdevelop Booking Calendar booking allows Leveraging Race Conditions.This issue affects Booking Calendar: from n/a through 11.8.4.
AplazadaMedia (5.3)0.27%—Appointment Booking Plugin LatepointAI2/10/20263/10/2026
The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 5.7.1 via the OsPaypalConnectController::create_order_for_transaction() action registered as a public (unauthenticated) route through…
AplazadaAlta (7.2)0.31%—Ba-booking BA Book EverythingAI2/10/20263/10/2026
The BA Book Everything plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'booking_service_qty' parameter in all versions up to, and including, 1.8.28 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts…
AplazadaMedia (6.5)0.24%—Mage-people BUS Ticket Booking With Seat ReservationAI1/10/20261/10/2026
Unauthenticated Insecure Direct Object References (IDOR) in Bus Ticket Booking with Seat Reservation <= 5.9.3 versions.
AplazadaAlta (7.2)0.26%—Dwbooster Appointment Hour BookingAI1/10/20261/10/2026
The Appointment Hour Booking – Booking Calendar plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via Booking Form Single-Line Field via Schedule Calendar List Renderer in all versions up to, and including, 1.5.97 due to insufficient input sanitization and output escaping. This makes it…
AplazadaCrítica (9.8)0.39%—Booking ActivitiesAI30/9/202630/9/2026
Unauthenticated PHP Object Injection in Booking Activities <= 1.18.7.1 versions.
AplazadaMedia (4.3)0.28%—Webba-booking Webba BookingAI30/9/202630/9/2026
Subscriber Insecure Direct Object References (IDOR) in Webba Booking <= 6.5.0 versions.
AplazadaAlta (7.5)0.27%—Booking-wp-plugin BooklyAI30/9/202630/9/2026
Unauthenticated Broken Access Control in Bookly <= 28.2 versions.
AplazadaMedia (6.5)0.28%—Booking-wp-plugin BooklyAI30/9/202630/9/2026
Subscriber Insecure Direct Object References (IDOR) in Bookly <= 28.2 versions.
AplazadaMedia (5.3)0.21%—Course Booking SystemAI30/9/202630/9/2026
The Course Booking System WordPress plugin before 7.0.9 does not restrict access to its booking export, allowing unauthenticated users to download the name, email address and billing address of every customer who has booked a course.
AplazadaMedia (5.3)0.22%—Booking-wp-plugin BooklyAI28/9/202628/9/2026
The Bookly WordPress plugin before 28.3 does not validate client-supplied booking quantity values on the server before computing the appointment total, allowing unauthenticated users to reduce the total to zero and book paid services for free while bypassing the payment step.
Orbitaley — Vulnerabilidades