Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2989▼ 73 respecto a la semana anterior
Críticas / altas1415▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
145 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.7) | 0.31% | — | Sourcecodester Patient Appointment SchedulerAI | 14/4/2026 | 17/6/2026 | SourceCodester Patient Appointment Scheduler System v1.0 is vulnerable to SQL Injection in the file /scheduler/admin/appointments/view_details.php. | |
| Aplazada | Baja (2.7) | 0.39% | — | Sourcecodester Patient Appointment Scheduler SystemAI | 14/4/2026 | 17/6/2026 | SourceCodester Patient Appointment Scheduler System v1.0 is vulnerable to arbitrary code execution (RCE) via /scheduler/classes/SystemSettings.php?f=update_settings. | |
| Analizada | Alta (7.5) | 0.52% | — | Apache Dolphinscheduler | 9/4/2026 | 30/9/2026 | An Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists in Apache DolphinScheduler. This vulnerability may allow unauthorized actors to access sensitive information, including database credentials. This issue affects Apache DolphinScheduler versions 3.1.*. Users are recommended to upgrade… | |
| Aplazada | Media (6.1) | 0.20% | — | Auto Post SchedulerAI | 31/3/2026 | 17/6/2026 | The Auto Post Scheduler plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.84. This is due to missing nonce validation on the 'aps_options_page' function. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a… | |
| Aplazada | Media (5.4) | 0.33% | — | Scheduler WidgetAI | 14/2/2026 | 17/6/2026 | The Scheduler Widget plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 0.1.6. This is due to the `scheduler_widget_ajax_save_event()` function lacking proper authorization checks and ownership verification when updating events. This makes it possible for… | |
| Aplazada | Media (6.9) | 0.70% | — | Oracle SchedulerAI | 3/2/2026 | 17/6/2026 | Booked Scheduler 2.7.7 contains a directory traversal vulnerability in the manage_email_templates.php script that allows authenticated administrators to access unauthorized files. Attackers can exploit the vulnerable 'tn' parameter to read files outside the intended directory by manipulating directory path traversal… | |
| Aplazada | Media (5.5) | 0.11% | — | HCL Workload SchedulerAI | 11/12/2025 | 1/10/2026 | HCL Workload Scheduler stores user credentials in plain text which can be read by a local user. | |
| Aplazada | Media (4.4) | 0.24% | — | Task SchedulerAI | 15/10/2025 | 17/6/2026 | The Task Scheduler plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.6.3 via the “Check Website” task. This makes it possible for authenticated attackers, with Administrator-level access and above, to make web requests to arbitrary locations originating from the… | |
| Aplazada | Alta (8.2) | 0.38% | — | Obsidian SchedulerAI | 29/9/2025 | 17/6/2026 | A security vulnerability was identified in Obsidian Scheduler's REST API 5.0.0 thru 6.3.0. If an account is locked out due to not enrolling in MFA (e.g. after the 7-day enforcement window), the REST API still allows the use of Basic Authentication to authenticate and perform administrative actions. In particular, the… | |
| Modificada | Crítica (9.8) | 0.52% | — | Apache Dolphinscheduler | 3/9/2025 | 17/6/2026 | Incorrect Default Permissions vulnerability in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.2.2. Users are recommended to upgrade to version 3.3.1, which fixes the issue. | |
| Modificada | Alta (8.8) | 0.51% | — | Apache Dolphinscheduler | 3/9/2025 | 17/6/2026 | Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can execute any shell script server by alert script. This issue affects Apache DolphinScheduler: before 3.2.2. Users are recommended to upgrade to version 3.3.1, which fixes the issue. | |
| Aplazada | Media (6.4) | 0.29% | — | Myceliumdesign Conference SchedulerAI | 24/6/2025 | 17/6/2026 | The Conference Scheduler plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘className’ parameter in all versions up to, and including, 2.5.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above,… | |
| Aplazada | Alta (7.1) | 0.34% | — | Miunosoft Task SchedulerAI | 11/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in miunosoft Task Scheduler task-scheduler allows Reflected XSS.This issue affects Task Scheduler: from n/a through <= 1.6.3. | |
| Aplazada | Media (6.5) | 0.18% | — | Appointy Appointment SchedulerAI | 31/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in appointy Appointy Appointment Scheduler appointy-appointment-scheduler allows Cross Site Request Forgery.This issue affects Appointy Appointment Scheduler: from n/a through <= 4.2.1. | |
| Aplazada | Crítica (9.3) | 0.35% | — | Oracle SchedulerAI | 28/3/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in scheduler Schedule schedule allows Blind SQL Injection.This issue affects Schedule: from n/a through <= 1.0.0. | |
| Analizada | Alta (7.1) | 0.27% | — | Scheduler Schedule | 13/3/2025 | 17/6/2026 | The Schedule WordPress plugin through 1.0.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |
| Aplazada | Alta (7.2) | 1.0% | — | Database Backup AND Check Tables Automated With SchedulerAI | 1/3/2025 | 17/6/2026 | The Database Backup and check Tables Automated With Scheduler 2024 plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'database_backup_ajax_delete' function in all versions up to, and including, 2.35. This makes it possible for authenticated attackers, with… | |
| Aplazada | Alta (7.2) | 0.59% | — | Database Backup AND Check Tables Automated With Scheduler 2024AI | 1/3/2025 | 17/6/2026 | The Database Backup and check Tables Automated With Scheduler 2024 plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.35 via the /dashboard/backup.php file. This makes it possible for authenticated attackers, with Administrator-level access and above, to… | |
| Aplazada | Media (6.7) | 0.45% | — | Joomla SchedulerAI | 18/2/2025 | 17/6/2026 | Improperly built order clauses lead to a SQL injection vulnerability in the backend task list of com_scheduler. | |
| Aplazada | Media (6.1) | 0.28% | — | Slabiak Appointment SchedulerAI | 31/1/2025 | 17/6/2026 | A Host Header Poisoning Open Redirect issue in slabiak Appointment Scheduler v.1.0.5 allows a remote attacker to redirect users to a malicious website, leading to potential credential theft, malware distribution, or other malicious activities. | |
| Aplazada | Media (4.9) | 0.85% | — | Database Backup AND Check Tables Automated With SchedulerAI | 24/12/2024 | 17/6/2026 | The Database Backup and check Tables Automated With Scheduler 2024 plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.32 via the database_backup_ajax_download() function. This makes it possible for authenticated attackers, with administrator-level access and above, to… | |
| Analizada | Media (5.5) | 0.15% | — | IBM Workload Scheduler | 26/11/2024 | 17/6/2026 | IBM Workload Scheduler 9.5, 10.1, and 10.2 stores user credentials in plain text which can be read by a local user. | |
| Aplazada | Alta (8.8) | 0.37% | — | SchedulerAI | 26/9/2024 | 17/6/2026 | A host header injection vulnerability in scheduleR v0.0.18 allows attackers to obtain the password reset token via user interaction with a crafted password reset link. This allows attackers to arbitrarily reset other users' passwords and compromise their accounts. | |
| Analizada | Crítica (9.8) | 2.1% | 💥 PoC | Apache Dolphinscheduler | 20/8/2024 | 17/6/2026 | Exposure of Remote Code Execution in Apache Dolphinscheduler. This issue affects Apache DolphinScheduler: before 3.2.2. We recommend users to upgrade Apache DolphinScheduler to version 3.2.2, which fixes the issue. | |
| Modificada | Alta (8.1) | 6.0% | 💥 Exploit | Apache Dolphinscheduler | 12/8/2024 | 17/6/2026 | File read and write vulnerability in Apache DolphinScheduler , authenticated users can illegally access additional resource files. This issue affects Apache DolphinScheduler: from 3.1.0 before 3.2.2. Users are recommended to upgrade to version 3.2.2, which fixes the issue. |