Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

372 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)1.3%—Doctor Appointment System Project Doctor Appointment System1/3/202117/6/2026
Cross Site Scripting (XSS) vulnerability in contactus.php in Doctor Appointment System 1.0 allows remote attackers to inject arbitrary web script or HTML via the comment parameter.
ModificadaMedia (6.5)5.8%💥 ExploitDoctor Appointment System Project Doctor Appointment System18/2/202117/6/2026
SQL injection in the expertise parameter in search_result.php in Doctor Appointment System v1.0 allows an authenticated patient user to dump the database credentials via a SQL injection attack.
ModificadaMedia (6.1)2.7%💥 ExploitOnlineonly Phpjabbers Appointment Scheduler15/12/202017/6/2026
Multiple cross-site scripting (XSS) vulnerabilities exist in PHPJabbers Appointment Scheduler 2.3, in the index.php admin login webpage (with different request parameters), allows remote attackers to inject arbitrary web script or HTML.
ModificadaCrítica (9.8)1.3%—Online Doctor Appointment Booking System PHP AND Mysql Project Online Doctor Appointment Booking System PHP AND Mysql2/12/202017/6/2026
An SQL injection vulnerability was discovered in Online Doctor Appointment Booking System PHP and Mysql via the q parameter to getuser.php.
ModificadaMedia (6.1)1.7%—Snapappointments Bootstrap-select30/9/202017/6/2026
bootstrap-select before 1.13.6 allows Cross-Site Scripting (XSS). It does not escape title values in OPTION elements. This may allow attackers to execute arbitrary JavaScript in a victim's browser.
ModificadaMedia (6.1)1.2%—Etoilewebdesign Ultimate Appointment Booking & Scheduling26/8/202017/6/2026
Etoile Web Design Ultimate Appointment Booking & Scheduling WordPress Plugin v1.1.9 and lower does not sanitize the value of the "Appointment_ID" GET parameter before echoing it back out inside an input tag. This results in a reflected XSS vulnerability that attackers can exploit with a specially crafted URL.
ModificadaAlta (7.5)1.3%—Easyappointments Easy!appointments16/3/202017/6/2026
Easy!Appointments 1.3.0 has a Missing Authorization issue allowing retrieval of hashed passwords and salts.
ModificadaMedia (6.5)0.92%—Easyappointments Easy!appointments16/3/202017/6/2026
Easy!Appointments 1.3.0 has a Guessable CAPTCHA issue.
ModificadaAlta (7.8)8.6%💥 ExploitCodepeople Appointment Booking Calendar4/3/202017/6/2026
The Appointment Booking Calendar plugin before 1.3.35 for WordPress allows user input (in fields such as Description or Name) in any booking form to be any formula, which then could be exported via the Bookings list tab in /wp-admin/admin.php?page=cpabc_appointments.php. The attacker could achieve remote code…
ModificadaMedia (4.8)3.3%💥 ExploitCodepeople Appointment Booking Calendar4/3/202017/6/2026
Stored XSS exists in the Appointment Booking Calendar plugin before 1.3.35 for WordPress. In the cpabc_appointments.php file, the Calendar Name input could allow attackers to inject arbitrary JavaScript or HTML.
ModificadaMedia (5.3)1.5%—Easyappointments Easy!appointments11/9/201917/6/2026
Easy!Appointments 1.3.2 plugin for WordPress allows Sensitive Information Disclosure (Username and Password Hash).
ModificadaCrítica (9.8)1.8%—Codepeople Appointment Booking Calendar22/8/201917/6/2026
The appointment-booking-calendar plugin before 1.1.24 for WordPress has SQL injection, a different vulnerability than CVE-2015-7319.
ModificadaMedia (6.1)1.4%—Codepeople Appointment Booking Calendar9/8/201917/6/2026
The Appointment Booking Calendar plugin 1.3.18 for WordPress allows XSS via the wp-admin/admin-post.php editionarea parameter.
ModificadaMedia (6.1)1.4%—Dwbooster Appointment Hour Booking11/7/201917/6/2026
The Appointment Hour Booking plugin 1.1.44 for WordPress allows XSS via the E-mail field, as demonstrated by email_1.
ModificadaCrítica (9.8)3.1%—Joomlaextensions Component Appointment9/5/201917/6/2026
https://www.joomlaextensions.co.in/ Joomla! Component Appointment 1.1 is affected by: SQL Injection. The impact is: Code execution (remote). The component is: com_appointment component.
ModificadaMedia (5.4)0.64%—PHP Appointment Booking Script Project PHP Appointment Booking Script23/2/201917/6/2026
PHP Scripts Mall PHP Appointment Booking Script 3.0.3 allows HTML injection in a user profile.
ModificadaMedia (6.1)0.73%—Easy-appointments Easy Appointments23/10/201717/6/2026
The Easy Appointments plugin before 1.12.0 for WordPress has XSS via a Settings values in the admin panel.
ModificadaMedia (4.3)2.1%—Codepeople Appointment Booking Calendar29/9/201517/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in cpabc_appointments_admin_int_bookings_list.inc.php in the Appointment Booking Calendar plugin before 1.1.8 for WordPress allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaAlta (7.5)2.4%—Codepeople Appointment Booking Calendar29/9/201517/6/2026
SQL injection vulnerability in cpabc_appointments_admin_int_calendar_list.inc.php in the Appointment Booking Calendar plugin before 1.1.8 for WordPress allows remote attackers to execute arbitrary SQL commands via unspecified vectors related to updating the username.
ModificadaMedia (5)7.7%💥 ExploitPhpjabbers Appointment Scheduler13/1/201517/6/2026
Directory traversal vulnerability in PHPJabbers Appointment Scheduler 2.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the id parameter in a pjActionDownload action to the pjBackup controller.
ModificadaMedia (6.8)2.3%💥 ExploitPhpjabbers Appointment Scheduler13/1/201517/6/2026
Multiple cross-site request forgery (CSRF) vulnerabilities in PHPJabbers Appointment Scheduler 2.0 allow remote attackers to hijack the authentication of administrators for requests that (1) conduct cross-site scripting (XSS) attacks via the i18n[1][name] parameter in a pjActionCreate action to the pjAdminServices…
ModificadaMedia (4.3)1.6%—WP Appointments Schedules Project WP Appointments Schedules2/7/201417/6/2026
Cross-site scripting (XSS) vulnerability in js/test.php in the Appointments Scheduler plugin 1.5 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the lang parameter.