Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3005▼ 69 respecto a la semana anterior
Críticas / altas1419▲ 52 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
38 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.58% | 💥 PoC | Easyappointments Easy!appointments | 7/5/2025 | 17/6/2026 | Booking logic flaw in Easy!Appointments v1.5.1 allows unauthenticated attackers to create appointments with excessively long durations, causing a denial of service by blocking all future booking availability. | |
| Modificada | Alta (8.8) | 0.25% | — | Easyappointments Easy!appointments | 1/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in alextselegidis Easy!Appointments easyappointments allows Cross Site Request Forgery.This issue affects Easy!Appointments: from n/a through <= 1.4.2. | |
| Analizada | Media (6.1) | 0.35% | — | Easy-appointments Easy Appointments | 9/12/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nikola Loncar Easy Appointments allows Stored XSS.This issue affects Easy Appointments: from n/a through 3.10.7. | |
| Analizada | Media (6.3) | 0.51% | — | Easyappointments Easy!appointments | 11/4/2024 | 17/6/2026 | Missing Authorization vulnerability in Alex Tselegidis Easy!Appointments.This issue affects Easy!Appointments: from n/a through 1.3.3. | |
| Modificada | Media (4.3) | 0.43% | — | Easy-appointments Easy Appointments | 29/3/2024 | 17/6/2026 | The Easy Appointments plugin for WordPress is vulnerable to unauthorized modification of data due to insufficient user validation on the ajax_cancel_appointment() function in all versions up to, and including, 3.11.18. This makes it possible for unauthenticated attackers to cancel other users orders. | |
| Modificada | Media (5.4) | 0.32% | — | Easy-appointments Easy Appointments | 29/3/2024 | 17/6/2026 | The Easy Appointments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ea_full_calendar' shortcode in all versions up to, and including, 3.11.18 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,… | |
| Modificada | Media (5.4) | 0.40% | — | Easyappointments Easy!appointments | 5/3/2024 | 17/6/2026 | The Easy!Appointments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'easyappointments' shortcode in all versions up to, and including, 1.3.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers… | |
| Modificada | Alta (8.8) | 0.26% | — | Easy-appointments Easy Appointments | 17/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Nikola Loncar Easy Appointments plugin <= 3.11.9 versions. | |
| Modificada | Media (5.4) | 0.47% | — | Easy-appointments Easy Appointments | 23/1/2023 | 17/6/2026 | The Easy Appointments WordPress plugin before 3.11.2 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as… | |
| Modificada | Alta (7.5) | 1.3% | — | Easyappointments Easy!appointments | 16/3/2020 | 17/6/2026 | Easy!Appointments 1.3.0 has a Missing Authorization issue allowing retrieval of hashed passwords and salts. | |
| Modificada | Media (6.5) | 0.92% | — | Easyappointments Easy!appointments | 16/3/2020 | 17/6/2026 | Easy!Appointments 1.3.0 has a Guessable CAPTCHA issue. | |
| Modificada | Media (5.3) | 1.5% | — | Easyappointments Easy!appointments | 11/9/2019 | 17/6/2026 | Easy!Appointments 1.3.2 plugin for WordPress allows Sensitive Information Disclosure (Username and Password Hash). | |
| Modificada | Media (6.1) | 0.73% | — | Easy-appointments Easy Appointments | 23/10/2017 | 17/6/2026 | The Easy Appointments plugin before 1.12.0 for WordPress has XSS via a Settings values in the admin panel. |