Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

59 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.5)0.24%—Easyappointments Easy AppointmentsAI6/11/202517/6/2026
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Easy Appointments Easy Appointments easy-appointments allows Code Injection.This issue affects Easy Appointments: from n/a through <= 3.12.14.
ModificadaAlta (8.1)0.36%💥 PoCEasyappointments Easy!appointments25/8/20255/7/2026
alextselegidis Easy!Appointments v1.5.1 was discovered to contain a SQL injection vulnerability via the order_by parameter.
AnalizadaAlta (7.5)0.58%💥 PoCEasyappointments Easy!appointments7/5/202517/6/2026
Booking logic flaw in Easy!Appointments v1.5.1 allows unauthenticated attackers to create appointments with excessively long durations, causing a denial of service by blocking all future booking availability.
ModificadaAlta (8.8)0.25%—Easyappointments Easy!appointments1/4/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in alextselegidis Easy!Appointments easyappointments allows Cross Site Request Forgery.This issue affects Easy!Appointments: from n/a through <= 1.4.2.
ModificadaCrítica (9.8)0.83%—Easyappointments12/2/202517/6/2026
An issue in Alex Tselegidis EasyAppointments v.1.5.0 allows a remote attacker to escalate privileges via the index.php file.
AnalizadaMedia (6.1)0.52%—Easyappointments12/2/202517/6/2026
Cross Site Scripting vulnerability in Alex Tselegidis EasyAppointments v.1.5.0 allows a remote attacker to execute arbitrary code via the legal_settings parameter.
ModificadaMedia (5)0.29%—Easyappointments9/7/202417/6/2026
A BOLA vulnerability in POST /customers allows a low privileged user to create a low privileged user (customer) in the system. This results in unauthorized data manipulation.
ModificadaMedia (6.5)0.33%—Easyappointments9/7/202417/6/2026
A BOLA vulnerability in POST /services allows a low privileged user to create a service for any user in the system (including admin). This results in unauthorized data manipulation.
ModificadaAlta (8.8)0.35%—Easyappointments9/7/202417/6/2026
A BOLA vulnerability in POST /providers allows a low privileged user to create a privileged user (provider) in the system. This results in privilege escalation.
ModificadaAlta (8.8)0.43%—Easyappointments9/7/202417/6/2026
A BOLA vulnerability in POST /admins allows a low privileged user to create a high privileged user (admin) in the system. This results in privilege escalation.
ModificadaMedia (6.5)0.33%—Easyappointments9/7/202417/6/2026
A BOLA vulnerability in POST /secretaries allows a low privileged user to create a low privileged user (secretary) in the system. This results in unauthorized data manipulation.
ModificadaAlta (8.1)0.39%—Easyappointments9/7/202417/6/2026
A BOLA vulnerability in GET, PUT, DELETE /services/{serviceId} allows a low privileged user to fetch, modify or delete the services of any user (including admin). This results in unauthorized access and unauthorized data manipulation.
ModificadaAlta (8.1)0.40%—Easyappointments9/7/202417/6/2026
A BOLA vulnerability in GET, PUT, DELETE /customers/{customerId} allows a low privileged user to fetch, modify or delete a low privileged user (customer). This results in unauthorized access and unauthorized data manipulation.
ModificadaAlta (8.1)0.40%—Easyappointments9/7/202417/6/2026
A BOLA vulnerability in GET, PUT, DELETE /settings/{settingName} allows a low privileged user to fetch, modify or delete the settings of any user (including admin). This results in unauthorized access and unauthorized data manipulation.
ModificadaAlta (8.1)0.40%—Easyappointments9/7/202417/6/2026
A BOLA vulnerability in GET, PUT, DELETE /admins/{adminId} allows a low privileged user to fetch, modify or delete a high privileged user (admin). This results in unauthorized access and unauthorized data manipulation.
ModificadaAlta (8.1)0.40%—Easyappointments9/7/202417/6/2026
A BOLA vulnerability in GET, PUT, DELETE /secretaries/{secretaryId} allows a low privileged user to fetch, modify or delete a low privileged user (secretary). This results in unauthorized access and unauthorized data manipulation.
ModificadaAlta (8.1)0.36%—Easyappointments9/7/202417/6/2026
A BOLA vulnerability in GET, PUT, DELETE /webhooks/{webhookId} allows a low privileged user to fetch, modify or delete a webhook of any user (including admin). This results in unauthorized access and unauthorized data manipulation.
ModificadaAlta (8.1)0.41%—Easyappointments9/7/202417/6/2026
A BOLA vulnerability in GET, PUT, DELETE /appointments/{appointmentId} allows a low privileged user to fetch, modify or delete an appointment of any user (including admin). This results in unauthorized access and unauthorized data manipulation.
ModificadaAlta (8.1)0.40%—Easyappointments9/7/202417/6/2026
A BOLA vulnerability in GET, PUT, DELETE /providers/{providerId} allows a low privileged user to fetch, modify or delete a privileged user (provider). This results in unauthorized access and unauthorized data manipulation.
ModificadaAlta (8.1)0.37%—Easyappointments9/7/202417/6/2026
A BOLA vulnerability in GET, PUT, DELETE /categories/{categoryId} allows a low privileged user to fetch, modify or delete the category of any user (including admin). This results in unauthorized access and unauthorized data manipulation.
AnalizadaMedia (6.3)0.51%—Easyappointments Easy!appointments11/4/202417/6/2026
Missing Authorization vulnerability in Alex Tselegidis Easy!Appointments.This issue affects Easy!Appointments: from n/a through 1.3.3.
ModificadaMedia (5.4)0.40%—Easyappointments Easy!appointments5/3/202417/6/2026
The Easy!Appointments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'easyappointments' shortcode in all versions up to, and including, 1.3.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers…
ModificadaMedia (4.3)0.44%—Easyappointments17/7/202317/6/2026
Authorization Bypass Through User-Controlled Key in GitHub repository alextselegidis/easyappointments prior to 1.5.0.
ModificadaAlta (8.8)0.67%—Easyappointments15/4/202317/6/2026
Session Fixation in GitHub repository alextselegidis/easyappointments prior to 1.5.0.
ModificadaMedia (5.4)0.45%—Easyappointments15/4/202317/6/2026
Improper Access Control in GitHub repository alextselegidis/easyappointments prior to 1.5.0.
Orbitaley — Vulnerabilidades