Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
2544 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.28% | — | Appointment Booking CalendarAI | 18/6/2026 | 18/6/2026 | The Appointment Booking Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 1.4.01. This is due to insufficient authorization and missing per-calendar ownership checks in the cpabc_appointments_calendar_load2() function, which is reachable via the… | |
| Aplazada | Alta (8.5) | 0.36% | — | Wpwax Directorist BookingAI | 17/6/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in wpWax Directorist Booking allows Blind SQL Injection. This issue affects Directorist Booking: from n/a through 3.0.3. | |
| Aplazada | Alta (7.3) | 0.30% | — | Salonbookingsystem Salon Booking SystemAI | 17/6/2026 | 17/6/2026 | Unauthenticated Insecure Direct Object References (IDOR) in Salon booking system <= 10.30.24 versions. | |
| Aplazada | Alta (8.1) | 0.44% | — | Alloggio Hotel BookingAI | 17/6/2026 | 17/6/2026 | Unauthenticated PHP Object Injection in Alloggio - Hotel Booking <= 2.1.2 versions. | |
| Aplazada | Alta (8.6) | 0.53% | — | BookproAI | 17/6/2026 | 17/6/2026 | Unauthenticated Arbitrary File Deletion in BookPro <= 1.1.0 versions. | |
| Aplazada | Alta (8.1) | 0.46% | — | Fs-code BookneticAI | 17/6/2026 | 17/6/2026 | Unauthenticated Broken Authentication in Booknetic <= 4.8.5 versions. | |
| Aplazada | Alta (7.5) | 0.47% | — | Woocommerce Book PriceAI | 17/6/2026 | 17/6/2026 | Subscriber Arbitrary File Download in Woocommerce Book Price <= 1.3 versions. | |
| Aplazada | Alta (8.8) | 0.48% | — | Pixel Makers Creative Entrepreneur Booking FOR Small BusinessesAI | 17/6/2026 | 6/10/2026 | Deserialization of Untrusted Data vulnerability in Pixel Makers Creative INC. Entrepreneur - Booking for Small Businesses WordPress Theme allows Object Injection. This issue affects Entrepreneur - Booking for Small Businesses WordPress Theme: from n/a before 3.1.5. | |
| Aplazada | Media (5.3) | 0.25% | — | Avirtum Ipages FlipbookAI | 17/6/2026 | 1/10/2026 | Missing Authorization vulnerability in Avirtum iPages Flipbook allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects iPages Flipbook: from n/a through 1.5.1. | |
| Aplazada | Alta (8.8) | 0.42% | — | Ameliabooking AmeliaAI | 15/6/2026 | 17/6/2026 | Subscriber Privilege Escalation in Amelia <= 2.3 versions. | |
| Aplazada | Alta (8.5) | 0.36% | — | Codepeople WP Time Slots Booking FormAI | 15/6/2026 | 17/6/2026 | Subscriber SQL Injection in WP Time Slots Booking Form <= 1.2.50 versions. | |
| Aplazada | Crítica (9.1) | 0.40% | — | Themetechmount TruebookerAI | 15/6/2026 | 17/6/2026 | Unauthenticated Broken Access Control in TrueBooker <= 1.1.9 versions. | |
| Aplazada | Alta (7.5) | 0.42% | — | Booking-wp-plugin BooklyAI | 15/6/2026 | 17/6/2026 | Unauthenticated Sensitive Data Exposure in Bookly <= 27.4 versions. | |
| Aplazada | Alta (7.5) | 0.39% | — | Salonbookingsystem Salon Booking SystemAI | 15/6/2026 | 17/6/2026 | Unauthenticated Broken Access Control in Salon booking system <= 10.30.25 versions. | |
| Aplazada | Alta (7.1) | 0.25% | 💥 PoC | Codepeople WP Time Slots Booking FormAI | 15/6/2026 | 17/6/2026 | Unauthenticated Cross Site Scripting (XSS) in WP Time Slots Booking Form <= 1.2.46 versions. | |
| Aplazada | Alta (7.5) | 0.42% | — | Ameliabooking AmeliaAI | 15/6/2026 | 17/6/2026 | Unauthenticated Sensitive Data Exposure in Amelia <= 2.2 versions. | |
| Aplazada | Alta (7.5) | 0.35% | — | Booking PackageAI | 15/6/2026 | 17/6/2026 | Unauthenticated Broken Access Control in Booking Package <= 1.7.06 versions. | |
| Aplazada | Alta (8.1) | 0.37% | — | Wp-base BookingAI | 15/6/2026 | 17/6/2026 | Unauthenticated Privilege Escalation in WP BASE Booking <= 5.9.0 versions. | |
| Aplazada | Media (6.5) | 0.33% | — | Booking ActivitiesAI | 15/6/2026 | 17/6/2026 | Unauthenticated Broken Access Control in Booking Activities <= 1.16.48.1 versions. | |
| Aplazada | Media (6.5) | 0.33% | — | BookifyAI | 15/6/2026 | 7/10/2026 | Subscriber Broken Access Control in Bookify <= 1.1.1 versions. | |
| Aplazada | Media (5.1) | 0.24% | — | Appointment Booking CalendarAI | 15/6/2026 | 17/6/2026 | WordPress appointment-booking-calendar 1.1.24 contains multiple privilege escalation vulnerabilities that allow unauthenticated attackers to modify calendar settings and inject persistent cross-site scripting payloads through the admin.php page parameters. Attackers can inject malicious JavaScript into the 'ict' and… | |
| Aplazada | Media (6.9) | 0.78% | — | Dharma BookingAI | 15/6/2026 | 17/6/2026 | WordPress Dharma Booking 2.28.3 and earlier contains a local file inclusion vulnerability that allows unauthenticated attackers to include arbitrary files by manipulating the gateway parameter. Attackers can supply file paths with directory traversal sequences or null byte injection to the gateway parameter in… | |
| Aplazada | Media (5.1) | 0.22% | — | Wordpress Booking Calendar Contact FormAI | 15/6/2026 | 17/6/2026 | WordPress Booking Calendar Contact Form 1.0.23 contains privilege escalation and stored cross-site scripting vulnerabilities that allow authenticated users to modify plugin options and inject malicious scripts by failing to verify user privileges and sanitize input parameters. Attackers with subscriber-level accounts… | |
| Aplazada | Alta (8.8) | 0.24% | — | Wordpress Booking Calendar Contact FormAI | 15/6/2026 | 17/6/2026 | WordPress Booking Calendar Contact Form 1.0.23 contains an unauthenticated blind SQL injection vulnerability in the shortcode function that fails to sanitize the calendar parameter before using it in database queries. Attackers can inject SQL commands through the calendar shortcode parameter to execute arbitrary SQL… | |
| Aplazada | Alta (8.8) | 0.30% | — | Wordpress Booking Calendar Contact FormAI | 15/6/2026 | 17/6/2026 | WordPress Booking Calendar Contact Form version 1.0.23 contains an unauthenticated blind SQL injection vulnerability that allows remote attackers to execute arbitrary SQL queries by injecting malicious code through the 'id' parameter. Attackers can send requests to the admin-ajax.php endpoint with the action parameter… |