Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
372 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 1.3% | — | Doctor Appointment System Project Doctor Appointment System | 1/3/2021 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in contactus.php in Doctor Appointment System 1.0 allows remote attackers to inject arbitrary web script or HTML via the comment parameter. | |
| Modificada | Media (6.5) | 5.8% | 💥 Exploit | Doctor Appointment System Project Doctor Appointment System | 18/2/2021 | 17/6/2026 | SQL injection in the expertise parameter in search_result.php in Doctor Appointment System v1.0 allows an authenticated patient user to dump the database credentials via a SQL injection attack. | |
| Modificada | Media (6.1) | 2.7% | 💥 Exploit | Onlineonly Phpjabbers Appointment Scheduler | 15/12/2020 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities exist in PHPJabbers Appointment Scheduler 2.3, in the index.php admin login webpage (with different request parameters), allows remote attackers to inject arbitrary web script or HTML. | |
| Modificada | Crítica (9.8) | 1.3% | — | Online Doctor Appointment Booking System PHP AND Mysql Project Online Doctor Appointment Booking System PHP AND Mysql | 2/12/2020 | 17/6/2026 | An SQL injection vulnerability was discovered in Online Doctor Appointment Booking System PHP and Mysql via the q parameter to getuser.php. | |
| Modificada | Media (6.1) | 1.7% | — | Snapappointments Bootstrap-select | 30/9/2020 | 17/6/2026 | bootstrap-select before 1.13.6 allows Cross-Site Scripting (XSS). It does not escape title values in OPTION elements. This may allow attackers to execute arbitrary JavaScript in a victim's browser. | |
| Modificada | Media (6.1) | 1.2% | — | Etoilewebdesign Ultimate Appointment Booking & Scheduling | 26/8/2020 | 17/6/2026 | Etoile Web Design Ultimate Appointment Booking & Scheduling WordPress Plugin v1.1.9 and lower does not sanitize the value of the "Appointment_ID" GET parameter before echoing it back out inside an input tag. This results in a reflected XSS vulnerability that attackers can exploit with a specially crafted URL. | |
| Modificada | Alta (7.5) | 1.3% | — | Easyappointments Easy!appointments | 16/3/2020 | 17/6/2026 | Easy!Appointments 1.3.0 has a Missing Authorization issue allowing retrieval of hashed passwords and salts. | |
| Modificada | Media (6.5) | 0.92% | — | Easyappointments Easy!appointments | 16/3/2020 | 17/6/2026 | Easy!Appointments 1.3.0 has a Guessable CAPTCHA issue. | |
| Modificada | Alta (7.8) | 8.6% | 💥 Exploit | Codepeople Appointment Booking Calendar | 4/3/2020 | 17/6/2026 | The Appointment Booking Calendar plugin before 1.3.35 for WordPress allows user input (in fields such as Description or Name) in any booking form to be any formula, which then could be exported via the Bookings list tab in /wp-admin/admin.php?page=cpabc_appointments.php. The attacker could achieve remote code… | |
| Modificada | Media (4.8) | 3.3% | 💥 Exploit | Codepeople Appointment Booking Calendar | 4/3/2020 | 17/6/2026 | Stored XSS exists in the Appointment Booking Calendar plugin before 1.3.35 for WordPress. In the cpabc_appointments.php file, the Calendar Name input could allow attackers to inject arbitrary JavaScript or HTML. | |
| Modificada | Media (5.3) | 1.5% | — | Easyappointments Easy!appointments | 11/9/2019 | 17/6/2026 | Easy!Appointments 1.3.2 plugin for WordPress allows Sensitive Information Disclosure (Username and Password Hash). | |
| Modificada | Crítica (9.8) | 1.8% | — | Codepeople Appointment Booking Calendar | 22/8/2019 | 17/6/2026 | The appointment-booking-calendar plugin before 1.1.24 for WordPress has SQL injection, a different vulnerability than CVE-2015-7319. | |
| Modificada | Media (6.1) | 1.4% | — | Codepeople Appointment Booking Calendar | 9/8/2019 | 17/6/2026 | The Appointment Booking Calendar plugin 1.3.18 for WordPress allows XSS via the wp-admin/admin-post.php editionarea parameter. | |
| Modificada | Media (6.1) | 1.4% | — | Dwbooster Appointment Hour Booking | 11/7/2019 | 17/6/2026 | The Appointment Hour Booking plugin 1.1.44 for WordPress allows XSS via the E-mail field, as demonstrated by email_1. | |
| Modificada | Crítica (9.8) | 3.1% | — | Joomlaextensions Component Appointment | 9/5/2019 | 17/6/2026 | https://www.joomlaextensions.co.in/ Joomla! Component Appointment 1.1 is affected by: SQL Injection. The impact is: Code execution (remote). The component is: com_appointment component. | |
| Modificada | Media (5.4) | 0.64% | — | PHP Appointment Booking Script Project PHP Appointment Booking Script | 23/2/2019 | 17/6/2026 | PHP Scripts Mall PHP Appointment Booking Script 3.0.3 allows HTML injection in a user profile. | |
| Modificada | Media (6.1) | 0.73% | — | Easy-appointments Easy Appointments | 23/10/2017 | 17/6/2026 | The Easy Appointments plugin before 1.12.0 for WordPress has XSS via a Settings values in the admin panel. | |
| Modificada | Media (4.3) | 2.1% | — | Codepeople Appointment Booking Calendar | 29/9/2015 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in cpabc_appointments_admin_int_bookings_list.inc.php in the Appointment Booking Calendar plugin before 1.1.8 for WordPress allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (7.5) | 2.4% | — | Codepeople Appointment Booking Calendar | 29/9/2015 | 17/6/2026 | SQL injection vulnerability in cpabc_appointments_admin_int_calendar_list.inc.php in the Appointment Booking Calendar plugin before 1.1.8 for WordPress allows remote attackers to execute arbitrary SQL commands via unspecified vectors related to updating the username. | |
| Modificada | Media (5) | 7.7% | 💥 Exploit | Phpjabbers Appointment Scheduler | 13/1/2015 | 17/6/2026 | Directory traversal vulnerability in PHPJabbers Appointment Scheduler 2.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the id parameter in a pjActionDownload action to the pjBackup controller. | |
| Modificada | Media (6.8) | 2.3% | 💥 Exploit | Phpjabbers Appointment Scheduler | 13/1/2015 | 17/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in PHPJabbers Appointment Scheduler 2.0 allow remote attackers to hijack the authentication of administrators for requests that (1) conduct cross-site scripting (XSS) attacks via the i18n[1][name] parameter in a pjActionCreate action to the pjAdminServices… | |
| Modificada | Media (4.3) | 1.6% | — | WP Appointments Schedules Project WP Appointments Schedules | 2/7/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in js/test.php in the Appointments Scheduler plugin 1.5 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the lang parameter. |