Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

2544 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.5)0.39%—Shopfiles Ebook StoreAI27/7/202627/7/2026
Unauthenticated Sensitive Data Exposure in Ebook Store <= 6.19 versions.
AplazadaAlta (8.2)0.43%💥 PoCBookingpress Appointment Booking PROAI27/7/202627/7/2026
The bookingpress-appointment-booking-pro WordPress plugin before 5.7.3 does not correctly invoke its REST permission callback, leaving every route in one of its API namespaces reachable without authentication and allowing unauthenticated attackers to read customer booking data and modify other users' bookings.
AplazadaAlta (7.2)0.60%—VikbookingAI24/7/202624/7/2026
The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'vbfX' parameter in all versions up to, and including, 1.8.13 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…
AplazadaMedia (6.1)0.46%—VikbookingAI24/7/202624/7/2026
The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'category_id' parameter in all versions up to, and including, 1.8.13 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject…
AplazadaMedia (6.4)0.33%—Thimpress WP Hotel BookingAI24/7/202624/7/2026
The WP Hotel Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'widget_search' Shortcode Attribute in all versions up to, and including, 2.3.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and…
AplazadaMedia (5.1)0.44%—Phoca GuestbookAI23/7/202624/7/2026
Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Guestbook 5.0.0-6.1.0 - Improper validation of user inputs lead to a reflective XSS vulnerability.
AplazadaAlta (7.5)0.57%—Facebook ProxygenAI23/7/202623/7/2026
Proxygen lacked a generalized slow-consumer detection mechanism in its core HTTP session layer. A remote, unauthenticated attacker could exploit HTTP/2 flow-control by setting SETTINGS_INITIAL_WINDOW_SIZE to 0 or withholding WINDOW_UPDATE frames, causing the server to buffer complete response bodies in memory…
AplazadaMedia (6.5)0.22%—Dwbooster Appointment Hour BookingAI23/7/202623/7/2026
Contributor Cross Site Scripting (XSS) in Appointment Hour Booking <= 1.5.86 versions.
AplazadaMedia (5.3)0.29%—JetbookingAI23/7/202623/7/2026
Unauthenticated Broken Access Control in JetBooking <= 4.1.2 versions.
AplazadaMedia (4.9)0.19%—JetbookingAI23/7/202623/7/2026
Custom role Server Side Request Forgery (SSRF) in JetBooking <= 4.1.2 versions.
AplazadaMedia (5.3)0.29%—Shopfiles Ebook StoreAI23/7/202623/7/2026
Unauthenticated Broken Access Control in Ebook Store <= 6.19 versions.
AplazadaMedia (5.3)0.31%—Shopfiles Ebook StoreAI23/7/202623/7/2026
Unauthenticated Broken Access Control in Ebook Store <= 6.19 versions.
AplazadaCrítica (9.8)0.48%—Themetechmount TruebookerAI23/7/202623/7/2026
Unauthenticated Privilege Escalation in TrueBooker <= 1.2.3 versions.
AplazadaCrítica (9.3)0.40%—Themetechmount TruebookerAI23/7/202623/7/2026
Unauthenticated SQL Injection in TrueBooker <= 1.2.3 versions.
AplazadaCrítica (9.3)0.40%—Booking-wp-plugin BooklyAI23/7/202623/7/2026
Unauthenticated SQL Injection in Bookly <= 27.7 versions.
AplazadaAlta (7.1)0.25%—Booking-wp-plugin BooklyAI23/7/202623/7/2026
Unauthenticated Cross Site Scripting (XSS) in Bookly <= 27.7 versions.
AplazadaAlta (8.8)0.42%—Wp-base BookingAI23/7/202623/7/2026
Subscriber Privilege Escalation in WP BASE Booking <= 6.3.1 versions.
AplazadaAlta (7.1)0.34%—Wpbookingsystem WP Booking SystemAI23/7/202623/7/2026
Subscriber Broken Access Control in WP Booking System < 5.12.8.1 versions.
AplazadaAlta (7.5)0.39%—Joomdonation Events BookingAI22/7/202623/7/2026
Joomla Extension - joomdonation.com - Invoice data exfiltration via incorrect ACL check in Events Booking 5.0.0-5.8.1 - The Joomla extension Events Booking prior version 5.0-5.8.1 did not properly verify that an actor is allowed to download invoice information.
Pendiente de análisisAlta (7.5)0.60%—Facebook React-server-dom-webpackAIFacebook React-server-dom-parcelAIFacebook React-server-dom-turbopackAI21/7/202621/7/2026
A denial of service vulnerability could be triggered by sending specially crafted HTTP requests to server function endpoints, this could lead to excessive CPU usage; affecting the following packages: react-server-dom-webpack, react-server-dom-parcel, react-server-dom-turbopack (versions 19.0.0 through 19.0.7, 19.1.0…
AplazadaAlta (8.8)0.20%—Joomdonation Events BookingAI17/7/202623/7/2026
Joomla Extension - joomdonation.com - User enumeration in Events Booking < 5.8.0 - The Joomla extension Events Booking prior version 5.8.0 had an frontend file upload endpoint that lacked CSRF protection.
AplazadaCrítica (9.8)0.55%—Joomdonation Events BookingAI17/7/202623/7/2026
Joomla Extension - joomdonation.com - Insecure default configuration Events Booking < 5.8.0 - The Joomla extension Events Booking prior version 5.8.0 did by default allow unauthenticated users to upload media assets.
AplazadaMedia (5.3)0.34%—Joomdonation Events BookingAI17/7/202623/7/2026
Joomla Extension - joomdonation.com - User enumeration in Events Booking < 5.8.0 - The Joomla extension Events Booking is vulnerable to an unauthenticated user enumeration that allows to retrieve account usernames and email addresses.
AplazadaMedia (5.4)0.29%—WPS Bookings FOR WoocommerceAI17/7/202617/7/2026
The WPS Bookings for WooCommerce WordPress plugin before 3.11.7 does not verify that a booking order belongs to the requesting user before cancelling it, allowing any authenticated user, such as a Subscriber or Customer, to cancel and void other customers' booking orders.
AplazadaMedia (6.1)0.69%💥 ExploitThimpress WP Hotel BookingAI17/7/202617/7/2026
The WP Hotel Booking plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'check_in_date' parameter in all versions up to, and including, 2.3.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in…