Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

3073 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.5)0.57%—Cisco Secure EndpointClamav1/7/20269/7/2026
A vulnerability in the InstallShield file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper handling of temporary resources during file scanning. An attacker could exploit this vulnerability by submitting a…
AnalizadaAlta (7.5)0.57%—Cisco Secure EndpointClamav1/7/20269/7/2026
A vulnerability in the 7z file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded impacts, resulting from memory corruption on an affected device. This vulnerability is due to improper boundary checks for content in 7z files during scanning,…
AnalizadaAlta (7.5)0.57%—Cisco Secure EndpointClamav1/7/20269/7/2026
A vulnerability in the FSG file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded impacts, resulting from memory corruption on an affected device. This vulnerability is due to improper boundary checks for content in FSG files during scanning,…
AnalizadaAlta (7.5)0.57%—Cisco Secure EndpointClamav1/7/20269/7/2026
A vulnerability in the PE file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded impacts, resulting from memory corruption on an affected device. This vulnerability is due to improper boundary checks for content in PE files during scanning,…
AplazadaAlta (8.8)0.58%—LatepointAI1/7/20261/7/2026
The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Privilege Escalation to Administrator in versions up to, and including, 5.6.3 This is due to an Insecure Direct Object Reference (IDOR) in the create_or_update() function of OsOrdersController, which allows an…
AplazadaMedia (6.5)0.45%—Motopress Appointment BookingAI1/7/20261/7/2026
The MotoPress Appointment Booking plugin for WordPress is vulnerable to generic SQL Injection via the 's' parameter in all versions up to, and including, 2.4.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for…
AplazadaAlta (7.5)0.46%—Bookingpress Appointment Booking PROAI1/7/20261/7/2026
The BookingPress Appointment Booking Pro plugin for WordPress is vulnerable to SQL Injection via the 'store_service_date' parameter of the bpa_assign_staffmember_to_slots() function in versions up to and including 5.7.1. This is due to the explicit use of stripslashes_deep() on user-supplied POST data before it is…
AplazadaMedia (4.3)0.39%—Appointment Booking CalendarAI1/7/20261/7/2026
The Appointment Booking Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.02 via the cpabc_appointments_filter_list. This makes it possible for authenticated attackers, with contributor-level access and above, to extract customer names, email…
AplazadaAlta (7.6)0.20%—PinpointAI29/6/202614/7/2026
Pinpoint through version 3.1.0 contains an insecure session management vulnerability that allows attackers to access the pinpointJwt session cookie due to missing HttpOnly and Secure attributes, enabling JavaScript access via document.cookie and cleartext transmission over HTTP. Attackers can exploit stored or…
AplazadaMedia (6.3)0.33%—PinpointAI29/6/202614/7/2026
Pinpoint through 3.1.0 contains a server-side request forgery vulnerability in the webhook registration endpoint that allows authenticated users to register internal URLs due to missing SSRF protection. Attackers can trigger alarm threshold breaches to force the server to issue POST requests to internal hosts and…
AplazadaAlta (8.2)0.20%—OpenprojectAIMicrosoft OnedriveAIMicrosoft SharepointAIMicrosoft Azure ADAI26/6/202629/6/2026
OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, OpenProject's Storages module writes the OneDrive/SharePoint userless OAuth access_token plaintext to Rails.cache under the deterministic key storage.<id>.httpx_access_token, repopulated continuously by an hourly cron and…
Pendiente de análisisAlta (7.5)0.41%💥 PoCSafetica Endpoint ClientAI26/6/202626/6/2026
Kernel driver ProcessMonitorDriver.sys in Safetica's endpoint client x64 , versions 10.5.75.0 and 11.11.4.0, allows unprivileged user to abuse IOCTL path and terminate protected system processes.
AplazadaAlta (7.1)0.23%—Simply Schedule AppointmentsAI26/6/202626/6/2026
Unauthenticated Cross Site Scripting (XSS) in Simply Schedule Appointments <= 1.6.12.2 versions.
AnalizadaAlta (8.8)0.49%—Focalpointx Focalpoint19/6/202619/8/2026
Joomla! Component FocalPoint Pro/Free 1.2.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id parameter. Attackers can send GET requests to index.php with option=com_focalpoint, view=location, and a crafted id…
AplazadaMedia (6.4)0.33%—Appointment Booking CalendarAI19/6/202622/6/2026
The Appointment Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom booking field labels in all versions up to, and including, 1.4.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and…
AplazadaMedia (4.3)0.28%—Appointment Booking CalendarAI18/6/202618/6/2026
The Appointment Booking Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 1.4.01. This is due to insufficient authorization and missing per-calendar ownership checks in the cpabc_appointments_calendar_load2() function, which is reachable via the…
AplazadaMedia (6.5)0.40%—Steeltoe Management EndpointAISteeltoe Management EndpointcoreAIVmware Spring BootAI17/6/202622/6/2026
Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. In Steeltoe.Management.Endpoint prior to version 4.2.0 and Steeltoe.Management.EndpointCore prior to version 3.4.0, all Steeltoe actuator endpoints default to `EndpointPermissions.Restricted`,…
AplazadaAlta (7.5)0.31%—Steeltoe Management EndpointAISteeltoe Management EndpointcoreAI17/6/202622/6/2026
Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. In Steeltoe.Management.Endpoint prior to version 4.2.0 and Steeltoe.Management.EndpointCore prior to version 3.4.0, the `Sanitizer` component in the Environment actuator redacts configuration…
AnalizadaMedia (6.8)0.69%—Langchain Langgraph-checkpoint16/6/202624/6/2026
LangGraph SQLite Checkpoint is an implementation of LangGraph CheckpointSaver that uses SQLite DB (both sync and async, via aiosqlite). In versions 4.1.0 and prior, the JsonPlusSerializer can reconstruct Python objects from JSON checkpoint payloads. Under conditions where someone could modify checkpoint bytes at rest…
AplazadaAlta (7.5)0.61%—LatepointAI16/6/202617/6/2026
The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Privilege Escalation to Administrator in versions up to, and including, 5.5.1. The plugin chains three independent flaws that together allow an authenticated Agent (Agent+) to overwrite a WordPress Administrator's…
AplazadaAlta (7.5)0.32%💥 PoCLatepointAI15/6/202617/6/2026
Contributor Privilege Escalation in LatePoint <= 5.5.1 versions.
AplazadaAlta (7.5)0.42%—Simply Schedule AppointmentsAI15/6/202617/6/2026
Unauthenticated Sensitive Data Exposure in Simply Schedule Appointments < 1.6.11.2 versions.
AplazadaAlta (7.5)0.39%—Easyappointments Easy AppointmentsAI15/6/202617/6/2026
Unauthenticated Broken Access Control in Easy Appointments <= 3.12.21 versions.
AplazadaCrítica (9.3)0.40%—Simply Schedule AppointmentsAI15/6/202617/6/2026
Unauthenticated SQL Injection in Simply Schedule Appointments <= 1.6.9.27 versions.
AplazadaAlta (7.1)0.25%—Simply Schedule AppointmentsAI15/6/202617/6/2026
Unauthenticated Cross Site Scripting (XSS) in Simply Schedule Appointments <= 1.6.10.6 versions.