Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
59 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.24% | — | Easyappointments Easy AppointmentsAI | 6/11/2025 | 17/6/2026 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Easy Appointments Easy Appointments easy-appointments allows Code Injection.This issue affects Easy Appointments: from n/a through <= 3.12.14. | |
| Modificada | Alta (8.1) | 0.36% | 💥 PoC | Easyappointments Easy!appointments | 25/8/2025 | 5/7/2026 | alextselegidis Easy!Appointments v1.5.1 was discovered to contain a SQL injection vulnerability via the order_by parameter. | |
| Analizada | Alta (7.5) | 0.58% | 💥 PoC | Easyappointments Easy!appointments | 7/5/2025 | 17/6/2026 | Booking logic flaw in Easy!Appointments v1.5.1 allows unauthenticated attackers to create appointments with excessively long durations, causing a denial of service by blocking all future booking availability. | |
| Modificada | Alta (8.8) | 0.25% | — | Easyappointments Easy!appointments | 1/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in alextselegidis Easy!Appointments easyappointments allows Cross Site Request Forgery.This issue affects Easy!Appointments: from n/a through <= 1.4.2. | |
| Modificada | Crítica (9.8) | 0.83% | — | Easyappointments | 12/2/2025 | 17/6/2026 | An issue in Alex Tselegidis EasyAppointments v.1.5.0 allows a remote attacker to escalate privileges via the index.php file. | |
| Analizada | Media (6.1) | 0.52% | — | Easyappointments | 12/2/2025 | 17/6/2026 | Cross Site Scripting vulnerability in Alex Tselegidis EasyAppointments v.1.5.0 allows a remote attacker to execute arbitrary code via the legal_settings parameter. | |
| Modificada | Media (5) | 0.29% | — | Easyappointments | 9/7/2024 | 17/6/2026 | A BOLA vulnerability in POST /customers allows a low privileged user to create a low privileged user (customer) in the system. This results in unauthorized data manipulation. | |
| Modificada | Media (6.5) | 0.33% | — | Easyappointments | 9/7/2024 | 17/6/2026 | A BOLA vulnerability in POST /services allows a low privileged user to create a service for any user in the system (including admin). This results in unauthorized data manipulation. | |
| Modificada | Alta (8.8) | 0.35% | — | Easyappointments | 9/7/2024 | 17/6/2026 | A BOLA vulnerability in POST /providers allows a low privileged user to create a privileged user (provider) in the system. This results in privilege escalation. | |
| Modificada | Alta (8.8) | 0.43% | — | Easyappointments | 9/7/2024 | 17/6/2026 | A BOLA vulnerability in POST /admins allows a low privileged user to create a high privileged user (admin) in the system. This results in privilege escalation. | |
| Modificada | Media (6.5) | 0.33% | — | Easyappointments | 9/7/2024 | 17/6/2026 | A BOLA vulnerability in POST /secretaries allows a low privileged user to create a low privileged user (secretary) in the system. This results in unauthorized data manipulation. | |
| Modificada | Alta (8.1) | 0.39% | — | Easyappointments | 9/7/2024 | 17/6/2026 | A BOLA vulnerability in GET, PUT, DELETE /services/{serviceId} allows a low privileged user to fetch, modify or delete the services of any user (including admin). This results in unauthorized access and unauthorized data manipulation. | |
| Modificada | Alta (8.1) | 0.40% | — | Easyappointments | 9/7/2024 | 17/6/2026 | A BOLA vulnerability in GET, PUT, DELETE /customers/{customerId} allows a low privileged user to fetch, modify or delete a low privileged user (customer). This results in unauthorized access and unauthorized data manipulation. | |
| Modificada | Alta (8.1) | 0.40% | — | Easyappointments | 9/7/2024 | 17/6/2026 | A BOLA vulnerability in GET, PUT, DELETE /settings/{settingName} allows a low privileged user to fetch, modify or delete the settings of any user (including admin). This results in unauthorized access and unauthorized data manipulation. | |
| Modificada | Alta (8.1) | 0.40% | — | Easyappointments | 9/7/2024 | 17/6/2026 | A BOLA vulnerability in GET, PUT, DELETE /admins/{adminId} allows a low privileged user to fetch, modify or delete a high privileged user (admin). This results in unauthorized access and unauthorized data manipulation. | |
| Modificada | Alta (8.1) | 0.40% | — | Easyappointments | 9/7/2024 | 17/6/2026 | A BOLA vulnerability in GET, PUT, DELETE /secretaries/{secretaryId} allows a low privileged user to fetch, modify or delete a low privileged user (secretary). This results in unauthorized access and unauthorized data manipulation. | |
| Modificada | Alta (8.1) | 0.36% | — | Easyappointments | 9/7/2024 | 17/6/2026 | A BOLA vulnerability in GET, PUT, DELETE /webhooks/{webhookId} allows a low privileged user to fetch, modify or delete a webhook of any user (including admin). This results in unauthorized access and unauthorized data manipulation. | |
| Modificada | Alta (8.1) | 0.41% | — | Easyappointments | 9/7/2024 | 17/6/2026 | A BOLA vulnerability in GET, PUT, DELETE /appointments/{appointmentId} allows a low privileged user to fetch, modify or delete an appointment of any user (including admin). This results in unauthorized access and unauthorized data manipulation. | |
| Modificada | Alta (8.1) | 0.40% | — | Easyappointments | 9/7/2024 | 17/6/2026 | A BOLA vulnerability in GET, PUT, DELETE /providers/{providerId} allows a low privileged user to fetch, modify or delete a privileged user (provider). This results in unauthorized access and unauthorized data manipulation. | |
| Modificada | Alta (8.1) | 0.37% | — | Easyappointments | 9/7/2024 | 17/6/2026 | A BOLA vulnerability in GET, PUT, DELETE /categories/{categoryId} allows a low privileged user to fetch, modify or delete the category of any user (including admin). This results in unauthorized access and unauthorized data manipulation. | |
| Analizada | Media (6.3) | 0.51% | — | Easyappointments Easy!appointments | 11/4/2024 | 17/6/2026 | Missing Authorization vulnerability in Alex Tselegidis Easy!Appointments.This issue affects Easy!Appointments: from n/a through 1.3.3. | |
| Modificada | Media (5.4) | 0.40% | — | Easyappointments Easy!appointments | 5/3/2024 | 17/6/2026 | The Easy!Appointments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'easyappointments' shortcode in all versions up to, and including, 1.3.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers… | |
| Modificada | Media (4.3) | 0.44% | — | Easyappointments | 17/7/2023 | 17/6/2026 | Authorization Bypass Through User-Controlled Key in GitHub repository alextselegidis/easyappointments prior to 1.5.0. | |
| Modificada | Alta (8.8) | 0.67% | — | Easyappointments | 15/4/2023 | 17/6/2026 | Session Fixation in GitHub repository alextselegidis/easyappointments prior to 1.5.0. | |
| Modificada | Media (5.4) | 0.45% | — | Easyappointments | 15/4/2023 | 17/6/2026 | Improper Access Control in GitHub repository alextselegidis/easyappointments prior to 1.5.0. |