Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
–

372 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)0.46%—Phpjabbers Appointment Scheduler7/12/202317/6/2026
Appointment Scheduler 3.0 is vulnerable to Multiple HTML Injection issues via the SMS API Key or Default Country Code.
ModificadaMedia (4.8)0.42%—Gappointments27/11/202317/6/2026
The gAppointments WordPress plugin through 1.9.5.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
ModificadaAlta (8.8)0.27%—Apointzilla Appointment Calendar25/10/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Scientech It Solution Appointment Calendar plugin <= 2.9.6 versions.
ModificadaAlta (7.5)0.59%—Phpjabbers Appointment Scheduler10/10/202317/6/2026
User enumeration is found in in PHPJabbers Appointment Scheduler 3.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.
ModificadaMedia (6.1)0.38%—Phpjabbers Appointment Scheduler10/10/202317/6/2026
There is a Cross Site Scripting (XSS) vulnerability in the "theme" parameter of preview.php in PHPJabbers Appointment Scheduler v3.0
ModificadaCrítica (9.8)0.93%—Doctor Appointment System Project Doctor Appointment System11/9/202317/6/2026
Sourcecodester Doctor Appointment System 1.0 is vulnerable to SQL Injection in the variable $userid at doctors\myDetails.php.
ModificadaMedia (6.1)0.46%—Gappointments11/9/202317/6/2026
The gAppointments WordPress plugin before 1.10.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against admin
ModificadaMedia (6.1)0.38%—Bookingultrapro Booking Ultra PRO Appointments Booking Calendar24/8/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Booking Ultra Pro Booking Ultra Pro Appointments Booking Calendar Plugin plugin <= 1.1.8 versions.
ModificadaMedia (6.1)0.38%—Bookingultrapro Appointments Booking Calendar23/8/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Booking Ultra Pro Booking Ultra Pro Appointments Booking Calendar Plugin <= 1.1.8 versions.
ModificadaCrítica (9.8)1.0%—Doctor Appointment System Project Doctor Appointment System15/8/202317/6/2026
Doctormms v1.0 was discovered to contain a SQL injection vulnerability via the $userid parameter at myAppoinment.php. NOTE: this is disputed by a third party who claims that the userid is a session variable controlled by the server, and thus cannot be used for exploitation. The original reporter counterclaims that…
ModificadaAlta (7.5)0.77%—Doctors Appointment System Project Doctors Appointment System8/8/202317/6/2026
A vulnerability was found in SourceCodester Doctors Appointment System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file login.php. The manipulation of the argument useremail leads to sql injection. The attack can be launched remotely. The exploit has been…
ModificadaAlta (8.8)0.26%—Easy-appointments Easy Appointments17/7/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Nikola Loncar Easy Appointments plugin <= 3.11.9 versions.
ModificadaMedia (4.3)0.44%—Easyappointments17/7/202317/6/2026
Authorization Bypass Through User-Controlled Key in GitHub repository alextselegidis/easyappointments prior to 1.5.0.
ModificadaMedia (6.1)0.38%—Gzscripts PHP GZ Appointment Scheduling Script10/7/202317/6/2026
A vulnerability classified as problematic was found in GZ Scripts PHP GZ Appointment Scheduling Script 1.8. Affected by this vulnerability is an unknown functionality of the file /load.php. The manipulation of the argument first_name/second_name/phone/address_1/country leads to cross site scripting. The attack can be…
ModificadaAlta (8.8)0.26%—Bookingultrapro Booking Ultra PRO Appointments Booking Calendar24/5/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Booking Ultra Pro Appointments Booking Calendar Plugin plugin <= 1.1.4 versions.
ModificadaMedia (6.1)0.57%—Dental Clinic Appointment Reservation System Project Dental Clinic Appointment Reservation System20/5/202317/6/2026
A vulnerability was found in SourceCodester Dental Clinic Appointment Reservation System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /admin/service.php of the component POST Parameter Handler. The manipulation of the argument service leads to cross site…
ModificadaAlta (8.8)0.67%—Easyappointments15/4/202317/6/2026
Session Fixation in GitHub repository alextselegidis/easyappointments prior to 1.5.0.
ModificadaMedia (5.4)0.45%—Easyappointments15/4/202317/6/2026
Improper Access Control in GitHub repository alextselegidis/easyappointments prior to 1.5.0.
ModificadaMedia (5.4)0.47%—Easyappointments15/4/202317/6/2026
Cross-site Scripting (XSS) - Stored in GitHub repository alextselegidis/easyappointments prior to 1.5.0.
ModificadaMedia (4.8)0.50%—Easyappointments15/4/202317/6/2026
Cross-site Scripting (XSS) - Stored in GitHub repository alextselegidis/easyappointments prior to 1.5.0.
ModificadaCrítica (9.8)1.0%—Codepeople CP Appointment Calendar10/4/202317/6/2026
A vulnerability classified as critical has been found in CP Appointment Calendar Plugin up to 1.1.5 on WordPress. This affects the function dex_process_ready_to_go_appointment of the file dex_appointments.php. The manipulation of the argument itemnumber leads to sql injection. It is possible to initiate the attack…
ModificadaBaja (3.8)0.43%—Easyappointments13/3/202317/6/2026
Code Injection in GitHub repository alextselegidis/easyappointments prior to 1.5.0.
ModificadaCrítica (9.8)0.74%—Easyappointments8/3/202317/6/2026
Use of Hard-coded Credentials in GitHub repository alextselegidis/easyappointments prior to 1.5.0.
ModificadaAlta (8.8)0.73%—Doctors Appointment System Project Doctors Appointment System27/2/202317/6/2026
A vulnerability has been found in SourceCodester Doctors Appointment System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/patient.php of the component Parameter Handler. The manipulation of the argument search leads to sql injection. The attack can be…
ModificadaAlta (8.8)0.70%—Doctors Appointment System Project Doctors Appointment System27/2/202317/6/2026
A vulnerability, which was classified as critical, was found in SourceCodester Doctors Appointment System 1.0. Affected is an unknown function of the file /admin/add-new.php of the component Parameter Handler. The manipulation of the argument email leads to sql injection. It is possible to launch the attack remotely.…
Orbitaley — Vulnerabilidades