Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 554 respecto a la semana anterior
Críticas / altas1325▼ 178 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 242 respecto a la semana anterior
3072 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.2) | 0.19% | — | JetappointmentAI | 2/10/2026 | 2/10/2026 | The JetAppointment plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'friendlyTime' parameter in all versions up to, and including, 2.5.2.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages… | |
| Aplazada | Media (5.3) | 0.27% | — | Appointment Booking Plugin LatepointAI | 2/10/2026 | 3/10/2026 | The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 5.7.1 via the OsPaypalConnectController::create_order_for_transaction() action registered as a public (unauthenticated) route through… | |
| Aplazada | Alta (7.6) | 0.29% | — | Office Powerpoint MCP ServerAI | 1/10/2026 | 2/10/2026 | Office-PowerPoint-MCP-Server through 2.0.7 contains a path traversal vulnerability that allows MCP callers to write and read files outside the working directory by supplying absolute paths or ../ sequences. Attackers can steer an AI agent via prompt injection to abuse save_presentation, open_presentation, or… | |
| Aplazada | Alta (7.2) | 0.26% | — | Dwbooster Appointment Hour BookingAI | 1/10/2026 | 1/10/2026 | The Appointment Hour Booking – Booking Calendar plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via Booking Form Single-Line Field via Schedule Calendar List Renderer in all versions up to, and including, 1.5.97 due to insufficient input sanitization and output escaping. This makes it… | |
| Aplazada | Crítica (9.1) | 0.45% | 💥 PoC | LatepointAI | 1/10/2026 | 1/10/2026 | The The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.7.0. This is due to the software allowing users to execute an action that does not properly validate a value before running… | |
| Aplazada | Alta (7.5) | 0.43% | — | Simply Schedule AppointmentsAI | 1/10/2026 | 3/10/2026 | The Simply Schedule Appointments plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.6.12.32 via the 'recursive' parameter. This makes it possible for unauthenticated attackers to extract customer PII — including names, email addresses, phone numbers, and custom… | |
| Aplazada | Media (6.5) | 0.32% | — | Simply Schedule AppointmentsAI | 1/10/2026 | 3/10/2026 | The Simply Schedule Appointments plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.6.12.31 via the 'complete_group' parameter due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with subscriber-level access… | |
| Aplazada | Media (5.3) | 0.25% | — | Simply Schedule AppointmentsAI | 30/9/2026 | 30/9/2026 | Unauthenticated Insecure Direct Object References (IDOR) in Simply Schedule Appointments <= 1.6.12.31 versions. | |
| Aplazada | Media (6.5) | 0.21% | — | Simply Schedule AppointmentsAI | 30/9/2026 | 30/9/2026 | Unauthenticated Broken Access Control in Simply Schedule Appointments <= 1.6.12.29 versions. | |
| Aplazada | Alta (7.5) | 0.65% | — | Simply Schedule AppointmentsAI | 30/9/2026 | 30/9/2026 | The Simply Schedule Appointments plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.6.12.27 via the 'ssa_locale' parameter parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to include and execute arbitrary .php files… | |
| Pendiente de análisis | Alta (7.2) | 0.51% | — | HPE Networking Instant ON Access PointAI | 29/9/2026 | 6/10/2026 | A vulnerability in the API endpoint of HPE Networking Instant ON APs could allow an authenticated remote attacker with high privileges to conduct a server-side request forgery (SSRF) attack. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating… | |
| Aplazada | Crítica (9.3) | 0.27% | — | Watchguard Access PointAI | 28/9/2026 | 28/9/2026 | An improper access control vulnerability in an internal API service on WatchGuard Access Points allows an unauthenticated attacker with network access to the AP to obtain a valid API session. | |
| Pendiente de análisis | Crítica (9.6) | 0.19% | — | Sailpoint IdentityiqAI | 28/9/2026 | 30/9/2026 | This vulnerability impacts all versions of IdentityIQ and allows an unauthenticated user remote code execution on the IdentityIQ server due to improper input validation of submitted web service API content. | |
| Aplazada | Media (4.7) | 0.19% | — | Online Scheduling AND Appointment Booking SystemAI | 27/9/2026 | 28/9/2026 | The Online Scheduling and Appointment Booking System WordPress plugin before 28.3 does not prevent deserialization of untrusted input and does not correctly restrict a privileged maintenance feature to administrators, allowing users granted a custom booking-management capability, which an administrator must explicitly… | |
| Aplazada | Baja (3.8) | 0.15% | — | Online Scheduling AND Appointment Booking SystemAI | 27/9/2026 | 28/9/2026 | The Online Scheduling and Appointment Booking System WordPress plugin before 28.3 does not verify that appointment and payment records requested through its staff-role AJAX actions belong to the requesting staff member, allowing authenticated attackers with a staff-level account to view, modify and delete other staff… | |
| Aplazada | Alta (7.2) | 0.32% | — | PgpointcloudAI | 25/9/2026 | 30/9/2026 | pgPointcloud through 1.2.5 contains a heap out-of-bounds read vulnerability in dimensional patch WKB deserialization that allows authenticated database users to read adjacent heap memory. Attackers can supply crafted pcpatch values with attacker-controlled size fields to copy heap memory into stored patches for… | |
| Pendiente de análisis | Alta (7.9) | 0.29% | — | Forcepoint Security EngineAI | 23/9/2026 | 23/9/2026 | A Security Policy Bypass vulnerability exists in Forcepoint Security Engine (NGFW). This issue affects Forcepoint Security Engine (NGFW): from 7.1.0 through 7.1.13, from 7.3.0 through 7.3.1, 7.3.3, from 7.4.0 through 7.4.1, and 7.5.0. | |
| Aplazada | Media (4.3) | 0.15% | — | Wpswings Points AND Rewards FOR WoocommerceAI | 23/9/2026 | 23/9/2026 | The Points and Rewards for WooCommerce WordPress plugin before 2.10.4 does not validate the claimed reward amount or restrict who can call its Win Wheel claim handler, allowing authenticated users, Subscriber and above, to credit their own account with an arbitrary and unlimited amount of loyalty points and, where a… | |
| Analizada | Crítica (9.8) | 20% | ⚠ Explotación activa💥 PoC | Checkpoint Multi-domain Security ManagementCheckpoint Quantum Security Management | 22/9/2026 | 23/9/2026 | A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Management Server. | |
| Aplazada | Media (6.5) | 0.47% | — | Easyappointments Easy AppointmentsAI | 19/9/2026 | 21/9/2026 | The Easy Appointments plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.12.27 via the handle_customers_ajax. This makes it possible for authenticated attackers, with contributor-level access and above, to extract the full customer dataset from the ea_customers… | |
| Aplazada | Media (4.8) | 0.22% | — | Online Scheduling AND Appointment Booking SystemAI | 19/9/2026 | 21/9/2026 | The Online Scheduling and Appointment Booking System WordPress plugin before 28.2 does not verify that the requester owns the AI booking-assistant conversation named in its unauthenticated conversation actions, allowing any unauthenticated visitor to read another visitor's assistant messages and to inject messages… | |
| Aplazada | Media (4.3) | 0.33% | — | LatepointAI | 18/9/2026 | 18/9/2026 | The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.6.3 via the LatePointAbilityDeleteBooking::execute due to missing validation on a user controlled key. This makes it possible for attackers,… | |
| Aplazada | Baja (2.7) | 0.32% | — | Bookit Booking Appointment CalendarAI | 18/9/2026 | 18/9/2026 | The Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.5 does not perform an authorization check on one of its appointment-retrieval actions, allowing users with a low-privilege Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.5-specific role to read other users' appointment… | |
| Aplazada | Media (5.3) | 0.30% | — | Easyappointments Easy AppointmentsAI | 18/9/2026 | 18/9/2026 | The Easy Appointments WordPress plugin before 4.0.2.2 does not perform an ownership or authorization check on its unauthenticated appointment-reservation endpoint before updating an existing appointment identified by a request-supplied id, allowing unauthenticated attackers to overwrite, and through a follow-on… | |
| Aplazada | Media (4.8) | 0.27% | — | Easyappointments Easy AppointmentsAI | 18/9/2026 | 18/9/2026 | The Easy Appointments WordPress plugin before 4.0.2.2 does not use an unguessable token to authorize its mail-link appointment cancellation and confirmation action, deriving the token from a hardcoded source-embedded salt and the appointment's creation timestamp, so unauthenticated attackers who know or guess that… |