Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3005▼ 69 respecto a la semana anterior
Críticas / altas1419▲ 52 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

38 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.5)0.58%💥 PoCEasyappointments Easy!appointments7/5/202517/6/2026
Booking logic flaw in Easy!Appointments v1.5.1 allows unauthenticated attackers to create appointments with excessively long durations, causing a denial of service by blocking all future booking availability.
ModificadaAlta (8.8)0.25%—Easyappointments Easy!appointments1/4/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in alextselegidis Easy!Appointments easyappointments allows Cross Site Request Forgery.This issue affects Easy!Appointments: from n/a through <= 1.4.2.
AnalizadaMedia (6.1)0.35%—Easy-appointments Easy Appointments9/12/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nikola Loncar Easy Appointments allows Stored XSS.This issue affects Easy Appointments: from n/a through 3.10.7.
AnalizadaMedia (6.3)0.51%—Easyappointments Easy!appointments11/4/202417/6/2026
Missing Authorization vulnerability in Alex Tselegidis Easy!Appointments.This issue affects Easy!Appointments: from n/a through 1.3.3.
ModificadaMedia (4.3)0.43%—Easy-appointments Easy Appointments29/3/202417/6/2026
The Easy Appointments plugin for WordPress is vulnerable to unauthorized modification of data due to insufficient user validation on the ajax_cancel_appointment() function in all versions up to, and including, 3.11.18. This makes it possible for unauthenticated attackers to cancel other users orders.
ModificadaMedia (5.4)0.32%—Easy-appointments Easy Appointments29/3/202417/6/2026
The Easy Appointments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ea_full_calendar' shortcode in all versions up to, and including, 3.11.18 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,…
ModificadaMedia (5.4)0.40%—Easyappointments Easy!appointments5/3/202417/6/2026
The Easy!Appointments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'easyappointments' shortcode in all versions up to, and including, 1.3.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers…
ModificadaAlta (8.8)0.26%—Easy-appointments Easy Appointments17/7/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Nikola Loncar Easy Appointments plugin <= 3.11.9 versions.
ModificadaMedia (5.4)0.47%—Easy-appointments Easy Appointments23/1/202317/6/2026
The Easy Appointments WordPress plugin before 3.11.2 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as…
ModificadaAlta (7.5)1.3%—Easyappointments Easy!appointments16/3/202017/6/2026
Easy!Appointments 1.3.0 has a Missing Authorization issue allowing retrieval of hashed passwords and salts.
ModificadaMedia (6.5)0.92%—Easyappointments Easy!appointments16/3/202017/6/2026
Easy!Appointments 1.3.0 has a Guessable CAPTCHA issue.
ModificadaMedia (5.3)1.5%—Easyappointments Easy!appointments11/9/201917/6/2026
Easy!Appointments 1.3.2 plugin for WordPress allows Sensitive Information Disclosure (Username and Password Hash).
ModificadaMedia (6.1)0.73%—Easy-appointments Easy Appointments23/10/201717/6/2026
The Easy Appointments plugin before 1.12.0 for WordPress has XSS via a Settings values in the admin panel.