Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
2544 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Baja (2.7) | 0.22% | — | HCL Bigfix RunbookaiAI | 6/5/2026 | 7/10/2026 | HCL BigFix RunBookAI is affected by a Continued availability of Less-Secure “Input Text” Vulnerability . A component contains a security weakness in its input handling implementation, increasing the risk of misconfiguration and operational errors. | |
| Pendiente de análisis | Alta (8.8) | 0.25% | — | HCL Bigfix RunbookaiAI | 6/5/2026 | 7/10/2026 | HCL BigFix RunBookAI is affected by a Unvalidated Command Input / Potential Command Smuggling vulnerability. A flaw in a component's input handling was identified that could permit unauthorized command execution. | |
| Aplazada | Alta (7.5) | 0.34% | — | Gravity Bookings PremiumAI | 6/5/2026 | 17/6/2026 | The Gravity Bookings Premium plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 2.5.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append… | |
| Aplazada | Media (5.5) | 0.59% | — | Usamak98 Python-notebook-mcpAI | 5/5/2026 | 17/6/2026 | A flaw has been found in UsamaK98 python-notebook-mcp up to a05a232815809a7e425b5fa7be26e0d4369894c2. Impacted is the function create_notebook/read_notebook/edit_cell/add_cell of the file server.py. This manipulation causes path traversal. It is possible to initiate the attack remotely. The exploit has been published… | |
| Aplazada | Alta (7.5) | 0.55% | — | Salonbookingsystem Salon Booking SystemAI | 2/5/2026 | 17/6/2026 | The Salon Booking System – Free Version plugin for WordPress is vulnerable to Arbitrary File Read in versions up to, and including, 10.30.25. This is due to the public booking flow accepting attacker-controlled file-field values and later using those stored values as trusted paths for email attachments. This makes it… | |
| Aplazada | Media (5.3) | 0.42% | — | Ameliabooking AmeliaAI | 2/5/2026 | 17/6/2026 | The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Improper Authorization in all versions up to, and including, 2.1.2. This is due to a logical short-circuit flaw in authorization logic that causes token validation to be entirely skipped when a booking has a 'waiting'… | |
| Aplazada | Media (5.3) | 0.53% | — | Saasproject Booking PackageAI | 28/4/2026 | 17/6/2026 | The Booking Package plugin for WordPress is vulnerable to Price Manipulation in versions up to, and including, 1.7.06 This is due to the intentForStripe() function passing user-controlled $_POST['amount'] directly to the Stripe PaymentIntent API without validation, and the commitStripe() function ignoring the… | |
| Aplazada | Crítica (9.3) | 0.28% | — | Directorist BookingAI | 27/4/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Directorist Booking allows SQL Injection.This issue affects Directorist Booking: from n/a before 3.0.2. | |
| Aplazada | Media (5.3) | 0.43% | — | Codepeople Booking Calendar Contact FormAI | 24/4/2026 | 17/6/2026 | The Booking Calendar Contact Form plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.2.63 via the dex_bccf_admin_int_calendar_list.inc.php file due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (5.3) | 0.42% | — | HM Books GalleryAI | 24/4/2026 | 17/6/2026 | The HM Books Gallery plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 4.8.0. This is due to the absence of capability checks and nonce verification in the admin_init hook that handles the permalink settings update at line 205-209 of wp-books-gallery.php. The vulnerable code… | |
| Aplazada | Alta (8.7) | 0.42% | — | Spicejet Booking APIAI | 23/4/2026 | 17/6/2026 | A vulnerability in SpiceJet’s booking API allows unauthenticated users to query passenger name records (PNRs) without any access controls. Because PNR identifiers follow a predictable pattern, an attacker could systematically enumerate valid records and obtain associated passenger names. This flaw stems from missing… | |
| Aplazada | Media (6.5) | 0.22% | — | Magepeople Taxi Booking Manager FOR WoocommerceAI | 23/4/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Magepeople inc. Taxi Booking Manager for WooCommerce allows Stored XSS.This issue affects Taxi Booking Manager for WooCommerce: from n/a through 2.0.0. | |
| Analizada | Media (6.1) | 0.31% | — | Dovestones AD Phonebook | 21/4/2026 | 17/6/2026 | Dovestones Softwares ADPhonebook <4.0.1.1 has a reflected cross-site scripting (XSS) vulnerability in the search parameter of the /ADPhonebook?Department=HR endpoint. User-supplied input is reflected in the HTTP response without proper input validation or output encoding, allowing execution of arbitrary JavaScript in… | |
| Aplazada | Media (5.5) | 0.53% | — | Pratham-jaiswal Hotel Booking Management SystemAI | 17/4/2026 | 2/8/2026 | A vulnerability was detected in arnobt78 Hotel Booking Management System up to f8922d0e0f6ac1cc761974c7616f44c2bbc04bea. The impacted element is an unknown function of the file /api/health/detailed of the component Health Check Endpoint. Performing a manipulation results in information disclosure. Remote exploitation… | |
| Aplazada | Baja (2) | 0.36% | — | ClassroombookingsAI | 17/4/2026 | 17/6/2026 | A vulnerability was detected in classroombookings up to 2.17.0. This impacts the function read of the file crbs-core/application/views/layout.php of the component User Display Name Handler. The manipulation of the argument displayname results in cross site scripting. The attack can be executed remotely. The exploit is… | |
| Aplazada | Media (5.3) | 0.89% | 💥 Exploit | 3D Flipbook PDF EmbedderAI | 15/4/2026 | 17/6/2026 | The 3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the send_post_pages_json() function in all versions up to, and including, 1.16.17. This makes it possible for unauthenticated attackers to… | |
| Aplazada | Media (6.4) | 0.15% | — | Surbma Booking COM ShortcodeAI | 14/4/2026 | 17/6/2026 | The Surbma | Booking.com Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `surbma-bookingcom` shortcode in all versions up to, and including, 2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Pendiente de análisis | Alta (8.4) | 0.21% | — | Dynabook Bluetooth Acpi DriversAI | 13/4/2026 | 17/6/2026 | Bluetooth ACPI Drivers provided by Dynabook Inc. contain a stack-based buffer overflow vulnerability. An attacker may execute arbitrary code by modifying certain registry values. | |
| Analizada | Media (6.1) | 0.38% | — | Altenar Sportsbook | 10/4/2026 | 17/6/2026 | Cross Site Scripting vulnerability in Altenar Sportsbook Software Platform (SB2) v.2.0 allows a remote attacker to obtain sensitive information and execute arbitrary code via the URL parameter | |
| Aplazada | Media (5.3) | 0.45% | — | Booking-wp-plugin BooklyAI | 9/4/2026 | 17/6/2026 | The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to price manipulation via the 'tips' parameter in all versions up to, and including, 27.0. This is due to the plugin trusting a user-supplied input without server-side validation against the configured price. This makes it… | |
| Pendiente de análisis | Alta (7.5) | 1.6% | 💥 PoC | Facebook React-server-dom-parcelAIFacebook React-server-dom-turbopackAIFacebook React-server-dom-webpackAI | 8/4/2026 | 25/7/2026 | A denial of service vulnerability exists in React Server Components, affecting the following packages: react-server-dom-parcel, react-server-dom-turbopack and react-server-dom-webpack (versions 19.0.0 through 19.0.4, 19.1.0 through 19.1.5, and 19.2.0 through 19.2.4). The vulnerability is triggered by sending specially… | |
| Aplazada | Media (5.3) | 0.26% | — | Dotonpaper Pinpoint Booking SystemAI | 8/4/2026 | 24/7/2026 | Missing Authorization vulnerability in DOTonPAPER Pinpoint Booking System booking-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Pinpoint Booking System: from n/a through <= 2.9.9.6.5. | |
| Aplazada | Media (5.3) | 0.31% | — | G5theme Book Previewer FOR WoocommerceAI | 8/4/2026 | 24/7/2026 | Missing Authorization vulnerability in g5theme Book Previewer for Woocommerce book-previewer-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Book Previewer for Woocommerce: from n/a through <= 1.0.6. | |
| Aplazada | Media (5.3) | 0.29% | — | Themetechmount TruebookerAI | 8/4/2026 | 24/7/2026 | Missing Authorization vulnerability in themetechmount TrueBooker truebooker-appointment-booking allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects TrueBooker: from n/a through <= 1.1.5. | |
| Aplazada | Media (5.3) | 0.26% | — | Igms Direct BookingAI | 8/4/2026 | 24/7/2026 | Missing Authorization vulnerability in igms iGMS Direct Booking igms-direct-booking allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects iGMS Direct Booking: from n/a through <= 1.3. |