Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
3076 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.64% | — | LatepointAI | 17/4/2026 | 17/6/2026 | The LatePoint plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.3.2. The vulnerability exists because the OsStripeConnectController::create_payment_intent_for_transaction action is registered as a public action (no authentication required) and loads invoices… | |
| Pendiente de análisis | Alta (8.4) | 0.38% | — | Sailpoint IdentityiqAI | 15/4/2026 | 17/6/2026 | IdentityIQ 8.5, all IdentityIQ 8.5 patch levels prior to 8.5p2, IdentityIQ 8.4, and all IdentityIQ 8.4 patch levels prior to 8.4p4 allow authenticated users assigned the Debug Pages Read Only capability or any custom capability with the ViewAccessDebugPage SPRight to incorrectly create new IdentityIQ objects. Until a… | |
| Analizada | Media (6.5) | 43% | ⚠ Explotación activa💥 PoC | Microsoft Sharepoint Server | 14/4/2026 | 17/6/2026 | Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. | |
| Analizada | Alta (7.8) | 0.47% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Powerpoint | 14/4/2026 | 17/6/2026 | Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally. | |
| Analizada | Media (5.4) | 19% | — | Microsoft Sharepoint Server | 14/4/2026 | 17/6/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | |
| Aplazada | Baja (2.7) | 0.31% | — | Sourcecodester Patient Appointment Scheduler SystemAI | 14/4/2026 | 17/6/2026 | SourceCodester Patient Appointment Scheduler System v1.0 is vulnerable to SQL Injection in the file /scheduler/admin/user/manage_user.php. | |
| Aplazada | Baja (2.7) | 0.31% | — | Sourcecodester Patient Appointment Scheduler SystemAI | 14/4/2026 | 17/6/2026 | SourceCodester Patient Appointment Scheduler System v1.0 is vulnerable to SQL Injection in the file /scheduler/admin/appointments/manage_appointment.php. | |
| Aplazada | Baja (2.7) | 0.31% | — | Sourcecodester Patient Appointment SchedulerAI | 14/4/2026 | 17/6/2026 | SourceCodester Patient Appointment Scheduler System v1.0 is vulnerable to SQL Injection in the file /scheduler/admin/appointments/view_details.php. | |
| Aplazada | Baja (2.7) | 0.39% | — | Sourcecodester Patient Appointment Scheduler SystemAI | 14/4/2026 | 17/6/2026 | SourceCodester Patient Appointment Scheduler System v1.0 is vulnerable to arbitrary code execution (RCE) via /scheduler/classes/SystemSettings.php?f=update_settings. | |
| Analizada | Alta (7.5) | 1.3% | — | Chargepoint Home Flex Cph50 Firmware | 11/4/2026 | 17/6/2026 | ChargePoint Home Flex revssh Service Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of ChargePoint Home Flex devices. Authentication is not required to exploit this vulnerability. The specific flaw exists… | |
| Analizada | Alta (7.5) | 0.41% | — | Chargepoint Home Flex Cph50 Firmware | 11/4/2026 | 17/6/2026 | ChargePoint Home Flex OCPP getpreq Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of ChargePoint Home Flex EV chargers. Authentication is not required to exploit this vulnerability. The specific… | |
| Analizada | Alta (7.5) | 0.68% | — | Chargepoint Home Flex Cph50 Firmware | 11/4/2026 | 17/6/2026 | ChargePoint Home Flex Inclusion of Sensitive Information in Source Code Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of ChargePoint Home Flex charging stations. Authentication is not required to exploit this vulnerability.… | |
| Aplazada | Media (5.3) | 0.26% | — | Nsquared Simply Schedule AppointmentsAI | 8/4/2026 | 24/7/2026 | Missing Authorization vulnerability in NSquared Simply Schedule Appointments simply-schedule-appointments allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simply Schedule Appointments: from n/a through <= 1.6.10.2. | |
| Aplazada | Media (5.3) | 0.26% | — | Dotonpaper Pinpoint Booking SystemAI | 8/4/2026 | 24/7/2026 | Missing Authorization vulnerability in DOTonPAPER Pinpoint Booking System booking-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Pinpoint Booking System: from n/a through <= 2.9.9.6.5. | |
| Aplazada | Crítica (9.6) | 0.20% | — | Priyanshumittal AppointmentAI | 8/4/2026 | 24/7/2026 | Cross-Site Request Forgery (CSRF) vulnerability in priyanshumittal Appointment appointment allows Upload a Web Shell to a Web Server.This issue affects Appointment: from n/a through <= 3.5.5. | |
| Aplazada | Alta (8.5) | 0.36% | — | Nsquared Simply Schedule AppointmentsAI | 8/4/2026 | 24/7/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NSquared Simply Schedule Appointments simply-schedule-appointments allows Blind SQL Injection.This issue affects Simply Schedule Appointments: from n/a through <= 1.6.9.27. | |
| Aplazada | Media (6.4) | 0.35% | — | LatepointAI | 8/4/2026 | 25/7/2026 | The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'button_caption' parameter in the [latepoint_resources] shortcode in versions up to and including 5.3.0. This is due to insufficient output escaping when the 'items' parameter… | |
| Analizada | Media (5.4) | 0.24% | — | Opensourcepos Open Source Point OF Sale | 7/4/2026 | 24/7/2026 | Open Source Point of Sale is a web based point-of-sale application written in PHP using CodeIgniter framework. Prior to 3.4.3, a Stored Cross-Site Scripting (XSS) vulnerability exists in the Daily Sales management table. The customer_name column is configured with escape: false in the bootstrap-table column… | |
| Analizada | Media (5.4) | 0.24% | — | Opensourcepos Open Source Point OF Sale | 7/4/2026 | 24/7/2026 | Open Source Point of Sale is a web based point-of-sale application written in PHP using CodeIgniter framework. Prior to 3.4.3, a Stored Cross-Site Scripting (XSS) vulnerability exists in the Stock Locations configuration feature. The application fails to properly sanitize user input supplied through the stock_location… | |
| Aplazada | Baja (2.1) | 0.35% | — | Sourcecodester Simple Doctors Appointment SystemAI | 31/3/2026 | 17/6/2026 | A vulnerability has been found in SourceCodester Simple Doctors Appointment System up to 1.0. This issue affects some unknown processing of the file /doctors_appointment/admin/ajax.php?action=save_category. Such manipulation of the argument img leads to unrestricted upload. The attack may be performed from remote. The… | |
| Aplazada | Media (5.5) | 0.41% | — | Sourcecodester Simple Doctors Appointment SystemAI | 31/3/2026 | 17/6/2026 | A flaw has been found in SourceCodester Simple Doctors Appointment System 1.0. This vulnerability affects unknown code of the file /admin/ajax.php?action=login2. This manipulation of the argument email causes sql injection. The attack is possible to be carried out remotely. The exploit has been published and may be… | |
| Aplazada | Media (5.5) | 0.41% | — | Sourcecodester Simple Doctors Appointment SystemAI | 31/3/2026 | 17/6/2026 | A vulnerability was detected in SourceCodester Simple Doctors Appointment System 1.0. This affects an unknown part of the file /admin/login.php. The manipulation of the argument Username results in sql injection. The attack can be executed remotely. The exploit is now public and may be used. | |
| Pendiente de análisis | Alta (7.8) | 0.16% | — | Symantec Data Loss Prevention Windows EndpointAI | 30/3/2026 | 17/6/2026 | Symantec Data Loss Prevention Windows Endpoint, prior to 25.1 MP1, 16.1 MP2, 16.0 RU2 HF9, 16.0 RU1 MP1 HF12, and 16.0 MP2 HF15, may be susceptible to a Elevation of Privilege vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to… | |
| Analizada | Media (6.5) | 0.35% | — | Opensourcepos Open Source Point OF Sale | 27/3/2026 | 17/6/2026 | Open Source Point of Sale (opensourcepos) is a web based point of sale application written in PHP using CodeIgniter framework. Prior to version 3.4.2, an Insecure Direct Object Reference (IDOR) vulnerability allows an authenticated low-privileged user to access the password change functionality of other users,… | |
| Pendiente de análisis | Media (6.9) | 0.46% | — | Ruckus Access PointAI | 26/3/2026 | 17/6/2026 | Ruckus Access Point products contain an arbitrary file read vulnerability in the command-line interface that allows authenticated remote attackers with administrative privileges to read arbitrary files from the underlying filesystem. Attackers can exploit this vulnerability to access sensitive information including… |