Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
–

796 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.5)0.30%—Booking FOR Appointments AND Events CalendarAI2/9/20263/9/2026
The Booking for Appointments and Events Calendar WordPress plugin before 2.4.9 does not require authentication or a valid request token before running the post-booking action chain, allowing an unauthenticated user to trigger booking notifications and integration callbacks for a booking by enumerating its identifier.
AplazadaBaja (2.7)0.28%—Booking FOR Appointments AND Events CalendarAI29/8/202631/8/2026
The Booking for Appointments and Events Calendar WordPress plugin before 2.4.9 does not check that a user holds the required capability before letting them change an appointment's status, allowing customers to set arbitrary statuses on appointments they are booked on, including approving their own bookings that were…
AplazadaAlta (7.5)0.36%—Appointment Booking Calendar Plugin AND Scheduling PluginAI29/8/202631/8/2026
The Appointment Booking Calendar Plugin and Scheduling Plugin WordPress plugin before 1.6.3 does not verify the amount actually paid against the server-side price staged for a booking when confirming an online payment, allowing unauthenticated users to have a paid appointment approved for a fraction of its price.
AplazadaAlta (7.5)0.42%💥 PoCDigital-peak DP CalendarAI28/8/202610/9/2026
Joomla Extension - digital-peak.com - Authenticated, privileged stored XSS in DP Calendar 7.0.0-8.19.5, 9.0.0-10.12.0 - Location title is rendered in data attribute without escaping leads to XSS, needs create permission in DPCalendar.
AplazadaMedia (6.9)0.37%💥 PoCDigital-peak DP CalendarAI28/8/202628/8/2026
Joomla Extension - digital-peak.com - Authenticated, privileged blind SQL injection in DP Calendar 5.5.0 - 10.11.2 - Saving an article can trigger a blind SQL injection with content plugin, needs update permission for articles.
AplazadaMedia (4.8)0.24%—SOY CalendarAI28/8/202628/8/2026
SOY Calendar contains a cross-site scripting vulnerability. An arbitrary script may be executed on the web browser of the user who is logging in to the product.
AplazadaMedia (4.8)0.24%—SOY CalendarAI28/8/202628/8/2026
SOY Calendar contains a cross-site scripting vulnerability. An arbitrary script may be executed on the web browser of the user who is logging in to the product.
AplazadaBaja (3.5)0.28%—Apple MailAIApple CalendarAIApple ContactsAIHCL TravelerAI26/8/202628/8/2026
The Apple profile generated for the Apple built-in Mail, Calendar and Contacts account to synchronize with HCL Traveler requires the Logon Name and Mail Address to be embedded in them. The values cannot be changed later on, so the Apple profile generation page asks for those values and reflects them back in the…
AplazadaMedia (6.5)0.30%—Booking FOR Appointments AND Events CalendarAI26/8/202626/8/2026
The Booking for Appointments and Events Calendar WordPress plugin before 2.4.7 does not require authentication before processing its pending notification queue, allowing an unauthenticated user to force the dispatch of queued notifications and integration callbacks.
AplazadaMedia (4.7)0.20%—Booking FOR Appointments AND Events CalendarAI26/8/202626/8/2026
The Booking for Appointments and Events Calendar WordPress plugin before 9.8 does not verify that an authenticated employee (provider) owns the provider account being updated, allowing any employee with an Employee Panel login to overwrite another employee's cabinet password and take over their account.
AplazadaAlta (7.5)0.63%—IcalendarAI25/8/20269/9/2026
icalendar is an RFC 5545 compatible parser and generator of iCalendar files for Python. From 7.1.0 until 7.1.3, the Component equality method in src/icalendar/cal/component.py compares nested subcomponents with two membership loops, and each membership test invokes the same method on child components, causing O(2^n)…
AplazadaMedia (5.3)0.47%—Events Calendar Manager Events ManagerAI25/8/202627/8/2026
The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 7.4.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to…
AplazadaCrítica (9.8)0.56%—Theeventscalendar THE Events CalendarAI24/8/202626/8/2026
Unauthenticated PHP Object Injection in The Events Calendar <= 6.17.2 versions.
AplazadaAlta (8.8)0.54%—Booking Calendar Appointment Booking SystemAI19/8/202626/8/2026
The Booking calendar, Appointment Booking System WordPress plugin through 3.2.36 does not properly sanitize uploaded SVG files, allowing unauthenticated attackers to upload a file that bypasses the Booking calendar, Appointment Booking System WordPress plugin through 3.2.36's script-stripping and executes arbitrary…
AplazadaCrítica (9.3)0.40%—Webnus Modern Events CalendarAI18/8/202620/8/2026
Unauthenticated SQL Injection in Modern Events Calendar < 7.35.0 versions.
AplazadaMedia (6.5)0.68%—Simply Schedule Appointments Appointment Booking CalendarAI16/8/202620/8/2026
The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.6.12.10 via the ssa_past_appointments due to missing validation on a user controlled key. This makes it possible for…
AplazadaMedia (5.3)0.55%—Booking CalendarAI15/8/202620/8/2026
The Booking calendar, Appointment Booking System plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.2.36. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to mark…
AplazadaAlta (7.2)0.40%—Vcita Online Booking Scheduling CalendarAI15/8/202620/8/2026
The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'business_id' parameter in all versions up to, and including, 4.6.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers…
AplazadaCrítica (9.2)0.39%—MOD Icagenda CalendarAIJoomlic IcagendaAI14/8/202626/8/2026
Joomla Extension - icagenda.com - Unauthenticated SQL injection in iCagenda < 4.0.0-4.0.11 - Unauthenticated SQL injection in mod_icagenda_calendar (iCagenda), reachable via com_ajax with no session, token or account.
AplazadaBaja (3.7)0.26%—Booking FOR Appointments AND Events CalendarAI13/8/202626/8/2026
The Booking for Appointments and Events Calendar WordPress plugin before 2.4.6 does not verify that an authenticated employee (provider) is assigned to the appointment being accessed, allowing any employee to read any appointment by its identifier and disclose the booked customer's personal data.
AplazadaBaja (3.8)0.26%—Booking FOR Appointments AND Events CalendarAI10/8/202626/8/2026
The Booking for Appointments and Events Calendar WordPress plugin before 9.7 does not verify that an authenticated employee (provider) is related to the customer whose record is being accessed, allowing any employee with an Employee Panel login to read and modify the stored personal data of any customer by enumerating…
AplazadaMedia (5.3)0.32%—Simple Google Calendar Outlook Events WidgetAI4/8/202626/8/2026
The Simple Google Calendar Outlook Events Widget WordPress plugin before 3.1.0 does not validate a user-supplied URL before performing a server-side request, allowing unauthenticated attackers to perform Server-Side Request Forgery attacks and, in some cases, read the response of the internal request.
AplazadaBaja (1.9)0.21%—Blix Email Blue Mail Calendar APPAIReact Native Receive Sharing IntentAI3/8/202612/8/2026
A vulnerability was detected in Blix Email Blue Mail Calendar App 2.2.305. Impacted is the function FileDirectory.getDataColumn/FileDirectory.getFileFromUri of the component react-native-receive-sharing-intent. The manipulation of the argument _display_name results in path traversal. The attack is only possible with…
AplazadaBaja (2.7)0.28%—Booking FOR Appointments AND Events CalendarAI1/8/202626/8/2026
The Booking for Appointments and Events Calendar WordPress plugin before 2.4.4 does not restrict which fields can be written through its customer import, allowing a user with the Amelia Manager role to modify arbitrary columns of any stored user record by supplying them in the import request.
AplazadaAlta (7.1)0.25%—Booking CalendarAI27/7/202627/7/2026
Unauthenticated Cross Site Scripting (XSS) in Booking Calendar <= 11.4.2 versions.
Orbitaley — Vulnerabilidades