Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
244 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.1) | 0.25% | — | Simply Schedule AppointmentsAI | 27/7/2026 | 27/7/2026 | Simply Schedule Appointments is vulnerable to unauthenticated Stored Cross-Site Scripting in all versions up to and including 1.6.12.2. The root cause is a sanitization-ordering defect: the rendered notification content is decoded back into live HTML after it has already passed through the Simply Schedule Appointments… | |
| Aplazada | Media (6.3) | 0.69% | — | Grav Scheduler-webhookAI | 20/7/2026 | 21/7/2026 | Grav CMS scheduler-webhook plugin contains an authentication bypass vulnerability that allows unauthenticated remote attackers to trigger configured scheduled jobs by exploiting a short-circuit logic flaw in the webhook token validation. Attackers can send a single unauthenticated POST request to the scheduler webhook… | |
| Pendiente de análisis | Media (5.1) | 0.17% | — | Microsoft WindowsAIMicrosoft Task SchedulerAIMicrosoft DcomAI | 17/7/2026 | 21/7/2026 | A non-administrator interactive user can obtain full SYSTEM code execution through a DCOM/task scheduler logic chain — no network access, no memory corruption required (ITMS 8.7.3) | |
| Aplazada | Media (6.5) | 0.27% | — | Nsquared Simply Schedule AppointmentsAI | 13/7/2026 | 13/7/2026 | Missing Authorization vulnerability in NSquared Simply Schedule Appointments simply-schedule-appointments allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simply Schedule Appointments: from n/a through <= 1.6.11.11. | |
| Aplazada | Media (6.5) | 0.33% | — | Nsquared Simply Schedule AppointmentsAI | 13/7/2026 | 13/7/2026 | Missing Authorization vulnerability in NSquared Simply Schedule Appointments simply-schedule-appointments allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simply Schedule Appointments: from n/a through <= 1.6.12.4. | |
| Aplazada | Alta (7.1) | 0.23% | — | Simply Schedule AppointmentsAI | 26/6/2026 | 26/6/2026 | Unauthenticated Cross Site Scripting (XSS) in Simply Schedule Appointments <= 1.6.12.2 versions. | |
| Modificada | Media (6.5) | 0.55% | — | Apache Dolphinscheduler | 17/6/2026 | 17/6/2026 | Allow authenticated users to access alert instances associated with alert groups they do not have permission to access. in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes the issue. | |
| Modificada | Media (6.5) | 0.49% | — | Apache Dolphinscheduler | 17/6/2026 | 17/6/2026 | Incorrect Authorization vulnerability allows users to access workflow instance information belonging to projects they do not have permission to access. This issue affects Apache DolphinScheduler versions prior to 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes this issue. | |
| Analizada | Media (4.9) | 0.54% | — | Apache Dolphinscheduler | 17/6/2026 | 17/6/2026 | Incorrect Authorization vulnerability allows users with system login privileges to delete task definitions in unauthorized projects This issue affects Apache DolphinScheduler versions prior to 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes this issue. | |
| Modificada | Crítica (9.1) | 0.55% | — | Apache Dolphinscheduler | 17/6/2026 | 17/6/2026 | Incorrect Authorization vulnerability of `/v2` experimental interface in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes the issue. | |
| Modificada | Crítica (9.8) | 0.66% | — | Apache Dolphinscheduler | 17/6/2026 | 17/6/2026 | DataSource API Missing Authorization Check Leads to Arbitrary Data Source Metadata Disclosure in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes the issue. | |
| Aplazada | Alta (7.5) | 0.42% | — | Simply Schedule AppointmentsAI | 15/6/2026 | 17/6/2026 | Unauthenticated Sensitive Data Exposure in Simply Schedule Appointments < 1.6.11.2 versions. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Simply Schedule AppointmentsAI | 15/6/2026 | 17/6/2026 | Unauthenticated SQL Injection in Simply Schedule Appointments <= 1.6.9.27 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Simply Schedule AppointmentsAI | 15/6/2026 | 17/6/2026 | Unauthenticated Cross Site Scripting (XSS) in Simply Schedule Appointments <= 1.6.10.6 versions. | |
| Aplazada | Media (5.3) | 0.64% | — | Booking Calendar Simply Schedule AppointmentsAI | 28/5/2026 | 17/6/2026 | The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.6.11.8 due to the plugin not properly verifying that a user is authorized to perform an action via the bulk appointments REST API endpoint.… | |
| Aplazada | Alta (7.5) | 0.67% | — | Simplyscheduleappointments Appointment Booking CalendarAI | 28/5/2026 | 17/6/2026 | The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'append_where_sql' parameter in all versions up to, and including, 1.6.11.8 due to insufficient escaping on the user supplied parameter and lack of sufficient… | |
| Aplazada | Media (4.3) | 0.38% | — | Motopress Timetable AND Event ScheduleAI | 28/5/2026 | 17/6/2026 | The Timetable and Event Schedule by MotoPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.4.16 via the action_get_event_data due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with contributor-level… | |
| Aplazada | Media (5.3) | 0.44% | — | Simply Schedule AppointmentsAI | 27/5/2026 | 23/7/2026 | The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to denial of service in all versions up to, and including, 1.6.11.5. This is due to a publicly accessible REST API endpoint (/wp-json/ssa/v1/async) that calls PHP's sleep() function on a user-supplied… | |
| Aplazada | Alta (8.6) | 0.16% | — | Splinterware System Scheduler PROAI | 25/5/2026 | 23/7/2026 | Splinterware System Scheduler Pro 5.12 contains an insecure file permissions vulnerability that allows low-privilege users to escalate privileges by modifying service executable files. Attackers can rename the WService.exe file in the installation directory and replace it with a malicious executable that executes with… | |
| Aplazada | Crítica (9.8) | 1.0% | — | ApschedulerAI | 19/5/2026 | 24/7/2026 | The JSONSerializer and CBORSerializer in APScheduler (all versions including 3.10.x and 4.0.0a5) are vulnerable to Remote Code Execution (RCE) via Insecure Deserialization. The unmarshal_object function allows for arbitrary class instantiation and state injection by dynamically importing modules and calling… | |
| Aplazada | Media (5.5) | 0.36% | — | Schedule Post Changes With Publishpress FutureAI | 5/5/2026 | 17/6/2026 | The Schedule Post Changes With PublishPress Future plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wrapper' attribute of the [futureaction] shortcode in all versions up to, and including, 4.10.0. This is due to insufficient input sanitization on the wrapper attribute. The plugin uses… | |
| Analizada | Alta (8.1) | 0.45% | — | Apache Dolphinscheduler | 24/4/2026 | 17/6/2026 | Incorrect Authorization vulnerability in Apache DolphinScheduler allows authenticated users with system login permissions to use tenants that are not defined on the platform during workflow execution. This issue affects Apache DolphinScheduler versions prior to 3.4.1. Users are recommended to upgrade to version 3.4.1,… | |
| Analizada | Media (6.3) | 0.54% | — | Apache Dolphinscheduler | 24/4/2026 | 5/10/2026 | Deserialization of Untrusted Data vulnerability in Apache DolphinScheduler RPC module. This issue affects Apache DolphinScheduler: Version >= 3.2.0 and < 3.3.1. Attackers who can access the Master or Worker nodes can compromise the system by creating a StandardRpcRequest, injecting a malicious class type into it, and… | |
| Pendiente de análisis | Alta (7.7) | 0.24% | — | Nvidia KAI SchedulerAI | 21/4/2026 | 17/6/2026 | NVIDIA KAI Scheduler contains a vulnerability where an attacker could access API endpoints without authorization. A successful exploit of this vulnerability might lead to information disclosure. | |
| Pendiente de análisis | Media (4.3) | 0.19% | — | Nvidia KAI SchedulerAI | 21/4/2026 | 17/6/2026 | NVIDIA KAI Scheduler contains a vulnerability where an attacker could cause improper authorization through cross-namespace pod references. A successful exploit of this vulnerability might lead to data tampering. |