Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

2544 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.1)0.29%—BookedAI2/7/20262/7/2026
Subscriber Broken Access Control in Booked <= 3.0.0 versions.
AplazadaCrítica (9.8)0.56%—BookticsAI2/7/20262/7/2026
Unauthenticated PHP Object Injection in Booktics <= 1.0.21 versions.
AplazadaMedia (6.5)0.37%—Motopress Hotel Booking LiteAI2/7/20262/7/2026
Subscriber Sensitive Data Exposure in Hotel Booking Lite <= 6.0.3 versions.
AplazadaAlta (7.4)0.17%—E4jvikwp Vikbooking Hotel Booking Engine AND PMSAI1/7/20261/7/2026
Cross-Site Request Forgery (CSRF) vulnerability in e4jvikwp VikBooking Hotel Booking Engine & PMS allows Path Traversal. This issue affects VikBooking Hotel Booking Engine & PMS: from n/a through 1.8.12.
AplazadaMedia (5.3)0.32%—Webba-booking Webba BookingAI1/7/20261/7/2026
Missing Authorization vulnerability in Webba Plugins Webba Booking allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Webba Booking: from n/a through 6.4.13.
AplazadaAlta (8.1)0.33%—Biovia WorkbookAI1/7/20262/7/2026
A Race Condition vulnerability affecting BIOVIA Workbook from Release 2021 through Release 2026 could allow a user to access unauthorized data from another user.
AplazadaMedia (6.5)0.45%—Motopress Appointment BookingAI1/7/20261/7/2026
The MotoPress Appointment Booking plugin for WordPress is vulnerable to generic SQL Injection via the 's' parameter in all versions up to, and including, 2.4.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for…
AplazadaMedia (6.1)0.37%—VikbookingAI1/7/20261/7/2026
The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'layoutstyle' parameter in all versions up to, and including, 1.8.12 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject…
AplazadaMedia (4.3)0.28%—Salonbookingsystem Salon Booking SystemAI1/7/20261/7/2026
The Salon Booking System WordPress plugin before 10.30.20 does not have proper authorisation checks on one of its AJAX actions, allowing any authenticated user, such as a subscriber, to modify a Salon Booking System WordPress plugin before 10.30.20 setting and bypass the manual approval of new bookings.
AplazadaAlta (7.5)0.46%—Bookingpress Appointment Booking PROAI1/7/20261/7/2026
The BookingPress Appointment Booking Pro plugin for WordPress is vulnerable to SQL Injection via the 'store_service_date' parameter of the bpa_assign_staffmember_to_slots() function in versions up to and including 5.7.1. This is due to the explicit use of stripslashes_deep() on user-supplied POST data before it is…
AplazadaMedia (4.3)0.39%—Appointment Booking CalendarAI1/7/20261/7/2026
The Appointment Booking Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.02 via the cpabc_appointments_filter_list. This makes it possible for authenticated attackers, with contributor-level access and above, to extract customer names, email…
AplazadaMedia (4.9)0.40%—Fluentbooking Fluent BookingAI30/6/202630/6/2026
The Fluent Booking WordPress plugin before 2.1.2 does not verify ownership of the requested group_id before exporting attendee data via the export endpoint, allowing users with at least the Calendar Manager role to retrieve attendees' PII (name, email, phone, address, payment information) from calendar groups they do…
AplazadaMedia (5.3)0.29%—Booking AND Rental ManagerAI26/6/202629/6/2026
Unauthenticated Broken Access Control in Booking and Rental Manager <= 2.7.1 versions.
AplazadaMedia (6.5)0.22%—Fluentbooking Fluent BookingAI26/6/202626/6/2026
Contributor Cross Site Scripting (XSS) in Fluent Booking <= 2.1.0 versions.
AplazadaCrítica (9.9)0.48%—Travel BookingAI26/6/202626/6/2026
Subscriber Arbitrary File Upload in Travel Booking <= 2.2.5 versions.
AplazadaCrítica (9.3)0.40%—JetbookingAI26/6/202626/6/2026
Unauthenticated SQL Injection in JetBooking <= 4.0.4.1 versions.
AplazadaAlta (8.8)0.20%—Eagle BookingAI26/6/20265/10/2026
Unauthenticated Cross Site Request Forgery (CSRF) in Eagle Booking <= 1.3.4.3 versions.
AplazadaMedia (5.3)0.31%—BookproAI26/6/20265/10/2026
Unauthenticated Insecure Direct Object References (IDOR) in BookPro <= 1.1.0 versions.
AplazadaMedia (6.8)0.17%💥 PoCToshiba Generic IO Memory Access DriverAIDynabook Generic IO Memory Access DriverAI25/6/202625/6/2026
Generic IO & Memory Access driver for PCs provided by TOSHIBA CORPORATION and Dynabook Inc. exposes its IOCTL with insufficient access control. A logged-in user with no administrative privilege may access physical memory.
AplazadaMedia (6.5)0.40%—Gravityforms BookingAI25/6/202625/6/2026
The Gravity Forms Booking plugin for WordPress is vulnerable to time-based SQL Injection via the ‘staff_id’ parameter in all versions up to, and including, 2.7.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for…
AplazadaMedia (4.3)0.13%—Book A Room Event CalendarAI24/6/202625/6/2026
The Book a Room Event Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.9. This is due to missing or incorrect nonce validation on the settings_form()/update_settings() functionality. The plugin's options page handler dispatches on the 'action' POST…
AnalizadaAlta (8.7)0.66%—Artio Book IT!19/6/202621/8/2026
Joomla com_booking component 2.4.9 contains an information disclosure vulnerability that allows unauthenticated attackers to enumerate user accounts by exploiting the getUserData function in the customer controller. Attackers can send GET requests to index.php with option=com_booking, controller=customer,…
AnalizadaAlta (8.8)0.49%—Joombooking JB Visa19/6/202619/8/2026
Joomla! Component JB Visa 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the visatype parameter. Attackers can send GET requests to index.php with the option=com_bookpro and view=popup parameters, injecting SQL…
AplazadaMedia (6.5)0.34%—Thimpress WP Hotel BookingAI19/6/202622/6/2026
The WP Hotel Booking WordPress plugin before 2.3.1 does not enforce capability checks in several of its AJAX handlers, allowing authenticated users with Subscriber-level access to read other users' booking line items, enumerate active coupons, and read pricing data.
AplazadaMedia (6.4)0.33%—Appointment Booking CalendarAI19/6/202622/6/2026
The Appointment Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom booking field labels in all versions up to, and including, 1.4.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and…