Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2647▼ 688 respecto a la semana anterior
Críticas / altas1257▼ 290 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 277 respecto a la semana anterior
2549 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.25% | — | Vcita Online Booking & Scheduling Calendar | 9/12/2025 | 17/6/2026 | Missing Authorization vulnerability in vcita Online Booking & Scheduling Calendar for WordPress by vcita meeting-scheduler-by-vcita allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Online Booking & Scheduling Calendar for WordPress by vcita: from n/a through <= 4.5.5. | |
| Modificada | Alta (8.8) | 0.15% | — | Vcita Online Booking & Scheduling Calendar | 9/12/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in vcita Online Booking & Scheduling Calendar for WordPress by vcita meeting-scheduler-by-vcita allows Cross Site Request Forgery.This issue affects Online Booking & Scheduling Calendar for WordPress by vcita: from n/a through <= 4.5.5. | |
| Aplazada | Media (5.3) | 0.21% | — | Themetechmount TruebookerAI | 9/12/2025 | 8/10/2026 | Vulnerabilidad de autorización faltante en themetechmount TrueBooker truebooker-appointment-booking permite explotar niveles de seguridad de control de acceso configurados incorrectamente. Este problema afecta a TrueBooker: desde n/a hasta menor o igual que 1.1.0. | |
| Aplazada | Media (5.3) | 0.25% | — | Wpdevart Booking CalendarAI | 9/12/2025 | 8/10/2026 | Vulnerabilidad de autorización faltante en wpdevart Booking calendar, Appointment Booking System booking-calendar permite la explotación de niveles de seguridad de control de acceso configurados incorrectamente. Este problema afecta a Booking calendar, Appointment Booking System: desde n/a hasta menor o igual que… | |
| Aplazada | Media (4.3) | 0.16% | — | Salonbookingsystem Salon Booking SystemAI | 9/12/2025 | 7/10/2026 | Vulnerabilidad de falsificación de petición en sitios cruzados (CSRF) en el sistema de reservas de Dimitri Grassi Salon, salon-booking-system, permite la falsificación de petición en sitios cruzados. Este problema afecta al sistema de reservas Salon booking system: desde n/a hasta menor o igual que 10.30.3. | |
| Aplazada | Media (4.3) | 0.31% | — | Webba Booking LiteAI | 9/12/2025 | 7/10/2026 | Vulnerabilidad de Autorización Faltante en Webba Appointment Booking Webba Booking webba-booking-lite permite Explotar Niveles de Seguridad de Control de Acceso Incorrectamente Configurados. Este problema afecta a Webba Booking: desde n/a hasta menor o igual que 6.2.1. | |
| Aplazada | Media (4.3) | 0.26% | — | Thimpress WP Hotel BookingAI | 9/12/2025 | 7/10/2026 | Exposición de Información Sensible del Sistema a una Esfera de Control No Autorizada vulnerabilidad en ThimPress WP Hotel Booking wp-hotel-booking permite Recuperar Datos Sensibles Incrustados. Este problema afecta a WP Hotel Booking: desde n/a hasta menor o igual a 2.2.7. | |
| Aplazada | Media (4.3) | 0.13% | — | Thimpress WP Hotel BookingAI | 9/12/2025 | 7/10/2026 | Vulnerabilidad de falsificación de petición en sitios cruzados (CSRF) en ThimPress WP Hotel Booking wp-hotel-booking permite falsificación de petición en sitios cruzados. Este problema afecta a WP Hotel Booking: desde n/a hasta menor o igual a 2.2.7. | |
| Aplazada | Media (5.9) | 0.20% | — | Thimpress WP Hotel BookingAI | 9/12/2025 | 7/10/2026 | Neutralización Incorrecta de la Entrada Durante la Generación de Páginas Web ('cross-site scripting') vulnerabilidad en ThimPress WP Hotel Booking wp-hotel-booking permite XSS basado en DOM. Este problema afecta a WP Hotel Booking: desde n/a hasta menor o igual que 2.2.7. | |
| Aplazada | Media (4.3) | 0.13% | — | JK Social Photo Fetcher Facebook Photo FetcherAI | 9/12/2025 | 7/10/2026 | Vulnerabilidad de falsificación de petición en sitios cruzados (CSRF) en JK Social Photo Fetcher facebook-photo-fetcher permite la falsificación de petición en sitios cruzados. Este problema afecta a Social Photo Fetcher: desde n/a hasta menor o igual que 3.0.4. | |
| Aplazada | Media (6.4) | 0.18% | — | Booking CalendarAI | 5/12/2025 | 17/6/2026 | El plugin Booking Calendar para WordPress es vulnerable a cross-site scripting almacenado a través del shortcode 'bookingcalendar' del plugin en todas las versiones hasta la 10.14.6, inclusive, debido a una sanitización de entrada y un escape de salida insuficientes en los atributos proporcionados por el usuario. Esto… | |
| Analizada | Crítica (10) | 100% | ⚠ Explotación activa💥 Exploit | Facebook ReactVercel Next.js | 3/12/2025 | 8/10/2026 | A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely deserializes payloads from HTTP… | |
| Aplazada | Media (4.3) | 0.19% | — | Fluentbooking Fluent BookingAI | 3/12/2025 | 17/6/2026 | The Fluent Booking plugin for WordPress is vulnerable to unauthorized calendar import and management due to a missing capability check on the "importCalendar" function in all versions up to, and including, 1.9.11. This makes it possible for authenticated attackers, with subscriber level access and above, to import… | |
| Analizada | Media (5.3) | 0.29% | — | Facebook Proxygen | 2/12/2025 | 17/6/2026 | Sending an HTTP request/response body with greater than 2^31 bytes triggers an infinite loop in proxygen::coro::HTTPQuicCoroSession which blocks the backing event loop and unconditionally appends data to a std::vector per-loop iteration. This issue leads to unbounded memory growth and eventually causes the process to… | |
| Aplazada | Media (4.9) | 0.30% | — | Bylancer BookmeAI | 25/11/2025 | 17/6/2026 | The Bookme – Free Online Appointment Booking and Scheduling Plugin for WordPress is vulnerable to time-based SQL Injection via the `filter[status]` parameter in all versions up to, and including, 4.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL… | |
| Analizada | Baja (2.1) | 0.31% | — | Facebook-julykringcadayona Student Information System | 24/11/2025 | 8/10/2026 | Una vulnerabilidad fue identificada en itsourcecode Student Information System 1.0. Afectada por esta vulnerabilidad es una funcionalidad desconocida del archivo /schedule_edit1.php. Tal manipulación del argumento schedule_id conduce a inyección SQL. El ataque puede ser lanzado remotamente. El exploit está disponible… | |
| Aplazada | Media (5.3) | 0.30% | — | Codepeople Booking Calendar Contact FormAI | 22/11/2025 | 17/6/2026 | The Booking Calendar Contact Form plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.2.60. This is due to missing authorization checks and payment verification in the `dex_bccf_check_IPN_verification` function. This makes it possible for unauthenticated attackers to… | |
| Aplazada | Media (5.3) | 0.28% | — | Appointment Booking CalendarAI | 22/11/2025 | 17/6/2026 | The Appointment Booking Calendar plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.3.96. This is due to the plugin exposing an unauthenticated booking processing endpoint (cpabc_appointments_check_IPN_verification) that trusts attacker-supplied payment notifications… | |
| Aplazada | Media (4.3) | 0.18% | — | Sabuj Kundu CBX Bookmark AND FavoriteAI | 21/11/2025 | 17/6/2026 | Missing Authorization vulnerability in Sabuj Kundu CBX Bookmark & Favorite cbxwpbookmark allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CBX Bookmark & Favorite: from n/a through <= 2.0.1. | |
| Aplazada | Media (6.4) | 0.18% | — | Hotelrunner Booking WidgetAI | 21/11/2025 | 7/10/2026 | El plugin HotelRunner Booking Widget para WordPress es vulnerable a cross-site scripting almacenado a través del shortcode 'hotelrunner' del plugin en todas las versiones hasta la 5.2.4, inclusive, debido a la sanitización insuficiente de las entradas y al escape de las salidas en los atributos proporcionados por el… | |
| Aplazada | Alta (7.2) | 0.29% | 💥 PoC | Iqonic WpbookitAI | 21/11/2025 | 7/10/2026 | El plugin WPBookit para WordPress es vulnerable a Cross-Site Scripting Almacenado a través del parámetro 'css_code' en todas las versiones hasta la 1.0.6, inclusive, debido a una falta de verificación de capacidad en la función save_custome_code(). Esto posibilita que atacantes no autenticados inyecten scripts web… | |
| Aplazada | Media (5.3) | 0.29% | — | Booking Plugin FOR Wordpress Appointments Time SlotAI | 19/11/2025 | 17/6/2026 | The Booking Plugin for WordPress Appointments – Time Slot plugin for WordPress is vulnerable to unauthorized email sending in versions up to, and including, 1.4.7 due to missing validation on the tslot_appt_email AJAX action. This makes it possible for unauthenticated attackers to send appointment notification emails… | |
| Analizada | Baja (2.1) | 0.31% | — | Facebook-julykringcadayona Student Information System | 18/11/2025 | 17/6/2026 | A vulnerability was determined in itsourcecode Student Information System 1.0. The affected element is an unknown function of the file /enrollment_edit1.php. Executing manipulation of the argument en_id can lead to sql injection. The attack may be performed from remote. The exploit has been publicly disclosed and may… | |
| Modificada | Baja (2.1) | 0.32% | — | Bdtask Flight Booking Software | 16/11/2025 | 17/6/2026 | A weakness has been identified in Bdtask Flight Booking Software 4. Affected by this vulnerability is an unknown functionality of the file /agent/profile/edit of the component Edit Profile Page. This manipulation causes unrestricted upload. The attack may be initiated remotely. The exploit has been made available to… | |
| Aplazada | Alta (7.5) | 0.32% | — | Ameliabooking AmeliaAI | 16/11/2025 | 17/6/2026 | The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to SQL Injection via the ‘search’ parameter in all versions up to, and including, 1.2.35 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it… |