Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2722▼ 518 respecto a la semana anterior
Críticas / altas1296▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

933 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)0.75%—Zabbix-agent218/12/202317/6/2026
The Zabbix Agent 2 item key smart.disk.get does not sanitize its parameters before passing them to a shell command resulting possible vulnerability for remote code execution.
ModificadaAlta (7.2)0.87%—Zabbix Server18/12/202317/6/2026
An attacker who has the privilege to configure Zabbix items can use function icmpping() with additional malicious command inside it to execute arbitrary code on the current Zabbix server.
ModificadaAlta (8.1)0.67%—Zabbix-agent18/12/202317/6/2026
The vulnerability is caused by improper check for check if RDLENGTH does not overflow the buffer in response from DNS server.
ModificadaAlta (8.8)0.85%—Zabbix ServerZabbix Frontend18/12/202317/6/2026
The website configured in the URL widget will receive a session cookie when testing or executing scheduled reports. The received session cookie can then be used to access the frontend as the particular user.
ModificadaAlta (8.8)0.26%—Softlabbd Integrate Google Drive17/12/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in SoftLab Integrate Google Drive.This issue affects Integrate Google Drive: from n/a through 1.3.4.
ModificadaMedia (6.1)0.39%—Softlabbd Integrate Google Drive7/12/202317/6/2026
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in SoftLab Integrate Google Drive – Browse, Upload, Download, Embed, Play, Share, Gallery, and Manage Your Google Drive Files Into Your WordPress Site.This issue affects Integrate Google Drive – Browse, Upload, Download, Embed, Play, Share, Gallery, and…
ModificadaAlta (8.8)1.2%—Phpjabbers Appointment Scheduler7/12/202317/6/2026
Appointment Scheduler 3.0 is vulnerable to CSV Injection via a Language > Labels > Export action.
ModificadaAlta (7.5)1.1%—Phpjabbers Appointment Scheduler7/12/202317/6/2026
A lack of rate limiting in pjActionAjaxSend in Appointment Scheduler 3.0 allows attackers to cause resource exhaustion.
ModificadaMedia (5.4)0.42%—Phpjabbers Appointment Scheduler7/12/202317/6/2026
Appointment Scheduler 3.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) issues via the name, plugin_sms_api_key, plugin_sms_country_code, calendar_id, title, country name, or customer_name parameter.
ModificadaMedia (5.4)0.46%—Phpjabbers Appointment Scheduler7/12/202317/6/2026
Appointment Scheduler 3.0 is vulnerable to Multiple HTML Injection issues via the SMS API Key or Default Country Code.
ModificadaMedia (5.4)0.46%—Phpjabbers CAR Rental Script7/12/202317/6/2026
Car Rental Script 3.0 is vulnerable to Multiple HTML Injection issues via SMS API Key or Default Country Code.
ModificadaMedia (5.4)0.46%—Phpjabbers CAR Rental Script7/12/202317/6/2026
Car Rental Script 3.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) issues via the name, plugin_sms_api_key, plugin_sms_country_code, calendar_id, title, country name, or customer_name parameter.
ModificadaAlta (8.8)1.2%—Phpjabbers CAR Rental Script7/12/202317/6/2026
Car Rental Script v3.0 is vulnerable to CSV Injection via a Language > Labels > Export action.
ModificadaAlta (7.5)1.1%—Phpjabbers CAR Rental Script7/12/202317/6/2026
A lack of rate limiting in pjActionAjaxSend in Car Rental v3.0 allows attackers to cause resource exhaustion.
ModificadaAlta (7.5)1.1%—Phpjabbers Time Slots Booking Calendar7/12/202317/6/2026
A lack of rate limiting in pjActionAJaxSend in Time Slots Booking Calendar 4.0 allows attackers to cause resource exhaustion.
ModificadaAlta (7.5)1.2%—Phpjabbers Availability Booking Calendar7/12/202317/6/2026
A lack of rate limiting in pjActionAJaxSend in Availability Booking Calendar 5.0 allows attackers to cause resource exhaustion.
ModificadaAlta (8.8)1.2%—Phpjabbers Shuttle Booking Software7/12/202317/6/2026
Shuttle Booking Software 2.0 is vulnerable to CSV Injection in the Languages section via an export.
ModificadaMedia (5.4)0.46%—Phpjabbers Time Slots Booking Calendar7/12/202317/6/2026
Time Slots Booking Calendar 4.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) issues via the name, plugin_sms_api_key, plugin_sms_country_code, calendar_id, title, country name, or customer_name parameter.
ModificadaMedia (5.4)0.46%—Phpjabbers Time Slots Booking Calendar7/12/202317/6/2026
Time Slots Booking Calendar 4.0 is vulnerable to Multiple HTML Injection issues via the name, plugin_sms_api_key, plugin_sms_country_code, calendar_id, title, country name, or customer_name parameter.
ModificadaAlta (8.8)1.2%—Phpjabbers Time Slots Booking Calendar7/12/202317/6/2026
Time Slots Booking Calendar 4.0 is vulnerable to CSV Injection via the unique ID field of the Reservations List.
ModificadaMedia (5.4)0.45%—Phpjabbers Availability Booking Calendar7/12/202317/6/2026
Availability Booking Calendar 5.0 is vulnerable to Multiple HTML Injection issues via SMS API Key or Default Country Code.
ModificadaMedia (6.1)0.50%—Phpjabbers Availability Booking Calendar7/12/202317/6/2026
A Cross Site Scripting vulnerability in Availability Booking Calendar 5.0 allows an attacker to inject JavaScript via the name, plugin_sms_api_key, plugin_sms_country_code, uuid, title, or country name parameter to index.php.
ModificadaAlta (8.8)1.2%—Phpjabbers Availability Booking Calendar7/12/202317/6/2026
Availability Booking Calendar 5.0 allows CSV injection via the unique ID field in the Reservations list component.
ModificadaMedia (5.4)0.72%—Phpjabbers Shuttle Booking Software7/12/202317/6/2026
A Cross Site Scripting (XSS) vulnerability in Shuttle Booking Software 2.0 allows a remote attacker to inject JavaScript via the name, description, title, or address parameter to index.php.
ModificadaMedia (5.2)0.29%—Abbott ID NOW Firmware14/11/202317/6/2026
The startup process and device configurations of the Abbott ID NOW device, before v7.1, can be interrupted and/or modified via physical access to an internal serial port. Direct physical access is required to exploit.
Orbitaley — Vulnerabilidades