Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
1090 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.39% | — | Codepeople Appointment Booking Calendar | 22/4/2025 | 17/6/2026 | Missing Authorization vulnerability in codepeople Appointment Booking Calendar appointment-booking-calendar allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Appointment Booking Calendar: from n/a through <= 1.3.92. | |
| Modificada | Alta (8.8) | 0.19% | — | Codepeople Appointment Booking Calendar | 22/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in codepeople Appointment Booking Calendar appointment-booking-calendar allows SQL Injection.This issue affects Appointment Booking Calendar: from n/a through <= 1.3.92. | |
| Aplazada | Media (5.9) | 0.22% | — | Codepeople Payment Form FOR Paypal PROAI | 17/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in codepeople Payment Form for PayPal Pro payment-form-for-paypal-pro allows Stored XSS.This issue affects Payment Form for PayPal Pro: from n/a through <= 1.1.72. | |
| Aplazada | Media (5.3) | 0.33% | — | Magepeopleteam Booking AND Rental ManagerAI | 17/4/2025 | 17/6/2026 | Missing Authorization vulnerability in magepeopleteam Booking and Rental Manager booking-and-rental-manager-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Booking and Rental Manager: from n/a through <= 2.2.8. | |
| Aplazada | Alta (7.5) | 0.64% | — | Magepeopleteam Booking AND Rental Manager FOR WoocommerceAI | 15/4/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in magepeopleteam Booking and Rental Manager booking-and-rental-manager-for-woocommerce allows PHP Local File Inclusion.This issue affects Booking and Rental Manager: from n/a through <= 2.2.8. | |
| Analizada | Alta (8.1) | 0.36% | — | Oracle Peoplesoft Enterprise CC Common Application Objects | 15/4/2025 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise CC Common Application Objects product of Oracle PeopleSoft (component: Page and Field Configuration). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft… | |
| Analizada | Media (5.4) | 0.36% | — | Oracle Peoplesoft Enterprise HCM Talent Acquisition Manager | 15/4/2025 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise HCM Talent Acquisition Manager product of Oracle PeopleSoft (component: Job Opening). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise HCM Talent… | |
| Analizada | Media (5.4) | 0.36% | — | Oracle Peoplesoft Enterprise Peopletools | 15/4/2025 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Panel Processor). Supported versions that are affected are 8.60, 8.61 and 8.62. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.… | |
| Aplazada | Crítica (9.8) | 0.88% | — | Magepeopleteam WpbookinglyAI | 11/4/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in magepeopleteam WpBookingly service-booking-manager allows Object Injection.This issue affects WpBookingly: from n/a through <= 1.3.0. | |
| Aplazada | Alta (8.8) | 0.48% | — | Magepeopleteam WpeventlyAI | 10/4/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in magepeopleteam WpEvently mage-eventpress allows Object Injection.This issue affects WpEvently: from n/a through <= 4.3.6. | |
| Aplazada | Alta (8.8) | 0.66% | — | Magepeopleteam WP TravellyAIMagepeopleteam Tour Booking ManagerAI | 1/4/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in magepeopleteam WpTravelly tour-booking-manager allows Object Injection.This issue affects WpTravelly: from n/a through <= 1.8.7. | |
| Aplazada | Alta (7.5) | 0.81% | — | Magepeopleteam WpeventlyAI | 27/3/2025 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in magepeopleteam WpEvently mage-eventpress allows PHP Local File Inclusion.This issue affects WpEvently: from n/a through <= 4.2.9. | |
| Aplazada | Alta (8.8) | 0.67% | — | Magepeopleteam WptravellyAI | 27/3/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in magepeopleteam WpTravelly tour-booking-manager allows PHP Local File Inclusion.This issue affects WpTravelly: from n/a through <= 1.8.7. | |
| Aplazada | Media (5.3) | 0.37% | — | Magepeopleteam WP EventlyAI | 27/3/2025 | 17/6/2026 | Missing Authorization vulnerability in magepeopleteam WpEvently mage-eventpress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WpEvently: from n/a through <= 4.2.9. | |
| Aplazada | Media (5.3) | 0.49% | — | Magepeopleteam Taxi Booking Manager FOR WoocommerceAI | 27/3/2025 | 17/6/2026 | Missing Authorization vulnerability in magepeopleteam Taxi Booking Manager for WooCommerce ecab-taxi-booking-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Taxi Booking Manager for WooCommerce: from n/a through <= 1.2.1. | |
| Aplazada | Alta (8.8) | 0.46% | — | Magepeopleteam Booking AND Rental ManagerAI | 15/3/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in magepeopleteam Booking and Rental Manager booking-and-rental-manager-for-woocommerce allows Object Injection.This issue affects Booking and Rental Manager: from n/a through <= 2.2.6. | |
| Analizada | Media (6.5) | 0.23% | — | Thepluginpeople Enterprise Mail Handler | 13/3/2025 | 17/6/2026 | An authenticated stored cross-site scripting (XSS) vulnerability in The Plugin People Enterprise Mail Handler for Jira Data Center (JEMH) before v4.1.69-dc allows attackers with Administrator privileges to execute arbitrary Javascript in context of a user's browser via injecting a crafted payload into the HTML field… | |
| Aplazada | Media (6.9) | 0.53% | — | Peoplesoft HrmsAI | 2/3/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in pbrong hrms up to 1.0.1. This affects the function HrmsDB of the file \resource\resource.go. The manipulation of the argument user_cookie leads to improper authorization. It is possible to initiate the attack remotely. The exploit has been disclosed to… | |
| Aplazada | Alta (8.8) | 0.63% | — | Magepeopleteam Taxi Booking Manager FOR WoocommerceAI | 3/2/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in magepeopleteam Taxi Booking Manager for WooCommerce ecab-taxi-booking-manager allows Object Injection.This issue affects Taxi Booking Manager for WooCommerce: from n/a through <= 1.1.8. | |
| Aplazada | Media (5.8) | 0.33% | — | Magepeopleteam Booking AND Rental Manager FOR WoocommerceAI | 31/1/2025 | 17/6/2026 | Missing Authorization vulnerability in magepeopleteam Booking and Rental Manager booking-and-rental-manager-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Booking and Rental Manager: from n/a through <= 2.2.1. | |
| Aplazada | Alta (7.1) | 0.26% | — | Codepeople Music StoreAI | 27/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in codepeople Music Store music-store allows Reflected XSS.This issue affects Music Store: from n/a through <= 1.1.19. | |
| Modificada | Media (4.8) | 0.31% | — | Codepeople Contact Form Email | 24/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in codepeople Contact Form Email contact-form-to-email allows Stored XSS.This issue affects Contact Form Email: from n/a through <= 1.3.52. | |
| Aplazada | Media (5.9) | 0.31% | — | Codepeople Booking Calendar Contact FormAI | 24/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in codepeople Booking Calendar Contact Form booking-calendar-contact-form allows Stored XSS.This issue affects Booking Calendar Contact Form: from n/a through <= 1.2.55. | |
| Aplazada | Media (4.3) | 0.40% | — | Ctltwp People ListsAI | 24/1/2025 | 17/6/2026 | Missing Authorization vulnerability in ctltwp People Lists people-lists allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects People Lists: from n/a through <= 1.3.10. | |
| Aplazada | Alta (8.5) | 0.46% | — | Codepeople Form Builder CPAI | 24/1/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in codepeople Form Builder CP cp-easy-form-builder allows SQL Injection.This issue affects Form Builder CP: from n/a through <= 1.2.41. |