Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2723▼ 319 respecto a la semana anterior
Críticas / altas1277▼ 191 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)210▼ 117 respecto a la semana anterior
21.068 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.5) | 0.43% | — | Code-projects Doctor Appointment SystemAI | 3/9/2026 | 5/9/2026 | A vulnerability was identified in code-projects Doctor Appointment System 1.0. This vulnerability affects unknown code of the file /patient_login.php. The manipulation of the argument email leads to sql injection. The attack may be initiated remotely. The exploit is publicly available and might be used. | |
| Aplazada | Crítica (9.3) | 0.40% | — | VikappointmentsAI | 3/9/2026 | 3/9/2026 | Unauthenticated SQL Injection in VikAppointments Services Booking Calendar <= 1.2.20 versions. | |
| Aplazada | Alta (7) | 0.34% | — | BR Industrial Automation Gmbh Mapp AuditAIBR Industrial Automation Gmbh Mapp ServicesAI | 3/9/2026 | 3/9/2026 | Use of Weak Credentials vulnerability in B&R Industrial Automation GmbH mapp Audit used in mapp Services. This issue affects mapp Audit used in mapp Services: before 6.8.0. | |
| Aplazada | Baja (1.9) | 0.21% | — | Reader Tools PDF Reader APPAI | 2/9/2026 | 28/9/2026 | Se ha detectado una vulnerabilidad de seguridad en la aplicación Reader Tools PDF Reader App 98.8 para Android. El elemento afectado es la función ActSplashNew.handleDeeplink del componente File Handler. La manipulación del argumento _display_name conduce a un salto de ruta. Un ataque debe abordarse localmente. El… | |
| Analizada | Baja (2.3) | 0.23% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+17 | 2/9/2026 | 15/9/2026 | A vulnerability exists in an undisclosed BIG-IP Configuration utility page that may allow an attacker to spoof error messages Impact: An attacker may trick authenticated BIG-IP users into accessing malicious links and reflect a spoofed error message in the victim's BIG-IP Configuration utility web browser session.… | |
| Aplazada | Alta (8.8) | 0.20% | — | Simply Schedule AppointmentsAI | 2/9/2026 | 4/9/2026 | Unauthenticated Cross Site Request Forgery (CSRF) in Simply Schedule Appointments <= 1.6.12.23 versions. | |
| Aplazada | Alta (7.5) | 0.42% | — | Appchee Woocommerce Product AttachmentAI | 2/9/2026 | 2/9/2026 | Unauthenticated Sensitive Data Exposure in WooCommerce Product Attachment <= 2.3.3 versions. | |
| Aplazada | Media (5.3) | 0.22% | — | Motopress Appointment BookingAI | 2/9/2026 | 3/9/2026 | The MotoPress Appointment Booking WordPress plugin before 2.4.8 does not perform an authorization or ownership check when handling a user-supplied booking identifier on an unauthenticated endpoint, allowing unauthenticated attackers to permanently delete other users' reservations. This is an incomplete fix of… | |
| Aplazada | Media (6.5) | 0.30% | — | Booking FOR Appointments AND Events CalendarAI | 2/9/2026 | 3/9/2026 | The Booking for Appointments and Events Calendar WordPress plugin before 2.4.9 does not require authentication or a valid request token before running the post-booking action chain, allowing an unauthenticated user to trigger booking notifications and integration callbacks for a booking by enumerating its identifier. | |
| Aplazada | Baja (1.9) | 0.21% | — | Mapquest GET Directions APPAI | 2/9/2026 | 2/9/2026 | A vulnerability was identified in MapQuest Get Directions App 10.16.1 on Android. This vulnerability affects the function getDataColumn of the file ExpoShareIntentModule.kt of the component com.mapquest.android.ace. The manipulation leads to path traversal. An attack has to be approached locally. The exploit is… | |
| Aplazada | Baja (1.9) | 0.21% | — | Airasia Move APPAI | 2/9/2026 | 2/9/2026 | A vulnerability was detected in AirAsia MOVE App up to 12.47.1 on Android. This issue affects the function com.airasia.core.utils.RealPathUtil.getRealPath of the component com.airasia.mobile. Performing a manipulation of the argument _display_name results in path traversal. The attack requires a local approach. The… | |
| Aplazada | Crítica (9.3) | 0.47% | — | Bookstackapp BookstackAI | 2/9/2026 | 8/9/2026 | BookStack before 26.05.4 contains a stored cross-site scripting vulnerability in the drawing upload endpoint that accepts unvalidated base64 content and stores it without content inspection. Attackers with editor permissions can upload SVG files containing scripts that execute in administrator browsers when accessed… | |
| Aplazada | Media (6.9) | 0.19% | — | Appium-mcp-serverAI | 1/9/2026 | 8/9/2026 | appium-mcp-server through 0.1.61 fails to validate or normalize file paths in the write_file and write_files_batch tools, allowing attackers to write files outside the intended PROJECT_ROOT directory. Attackers can supply absolute paths or relative paths with parent directory segments to overwrite arbitrary files with… | |
| Analizada | Media (5.3) | 0.38% | — | Snipeitapp Snipe-it | 1/9/2026 | 29/9/2026 | Snipe-IT before 8.7.0 gates the bulk asset restore endpoint on the assets.edit permission instead of assets.delete, allowing users without delete rights to restore soft-deleted assets. Attackers with edit permissions can post asset identifiers to the bulk restore endpoint to undo administrator deletions and bypass… | |
| Aplazada | Media (6.4) | 0.26% | — | Bootstrapped WP Recipe MakerAI | 1/9/2026 | 1/9/2026 | The WP Recipe Maker Premium plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wprm-call-to-action' shortcode in all versions up to, and including, 10.5.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Aplazada | Alta (7.5) | 0.96% | 💥 PoC | Dynamiapps Frontend AdminAI | 1/9/2026 | 1/9/2026 | The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the move_folders function in all versions up to, and including, 3.29.12. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can… | |
| Aplazada | Media (6.4) | 0.20% | — | Dynamiapps Frontend AdminAI | 1/9/2026 | 1/9/2026 | The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'tag' Shortcode Attribute in all versions up to, and including, 3.29.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access… | |
| Aplazada | Media (4.6) | 0.29% | — | Wallosapp WallosAI | 31/8/2026 | 8/9/2026 | Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 5.0.0, Wallos allows authenticated users to inject arbitrary iCalendar properties and events into their exported .ics feed by embedding raw CRLF sequences in subscription names or notes. Because the input validation layer only… | |
| Aplazada | Media (4.3) | 0.33% | — | Wallosapp WallosAI | 31/8/2026 | 8/9/2026 | Wallos is an open-source, self-hostable personal subscription tracker. From version 2.0.0 to before version 5.0.0, any authenticated Wallos user (no admin rights required) can make the server open arbitrary outbound SMTP connections to internal/link-local addresses, by setting the SMTP host of their personal email… | |
| Aplazada | Baja (3.5) | 0.29% | — | PhpmailerAIWallosapp WallosAI | 31/8/2026 | 8/9/2026 | Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 5.0.0, Wallos lets any authenticated user store an arbitrary SMTP host — including private and cloud-metadata IP addresses — in their personal email notification settings, with no server-side SSRF validation. When the scheduled… | |
| Aplazada | Alta (8.2) | 0.43% | — | Wallosapp WallosAI | 31/8/2026 | 8/9/2026 | Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 5.0.0, the fix for CVE-2026-33407 (GHSA-hhjq-82f8-m6rc, "SSRF via HTTP Proxy Environment Variable") hardened endpoints/logos/search.php by disabling cURL proxying (CURLOPT_PROXY = '' + CURLOPT_NOPROXY = '*'). However, Wallos ships… | |
| Aplazada | Alta (8.1) | 0.53% | — | Wallosapp WallosAI | 31/8/2026 | 8/9/2026 | Wallos is an open-source, self-hostable personal subscription tracker. From version 4.0.0 to before version 4.9.6, Wallos's OIDC login links an incoming OIDC identity to an existing local account by matching the email claim alone, without verifying that the IdP marked that email as verified (email_verified). When… | |
| Aplazada | Alta (8.5) | 0.54% | — | Wallosapp WallosAI | 31/8/2026 | 8/9/2026 | Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.6, Admin-configured OIDC token_url and user_info_url in includes/oidc/handle_oidc_callback.php:18-49 are used directly in curl_init() with zero SSRF filtering. Unlike logo/webhook URLs which have… | |
| Aplazada | Alta (8.5) | 0.51% | — | Wallosapp WallosAI | 31/8/2026 | 8/9/2026 | Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.6, POST /endpoints/db/restore.php calls ZipArchive::extractTo() without validating entry names for ../ sequences. Admin uploads crafted zip with entry logos/../../endpoints/shell.php to write webshell to webroot. Extension… | |
| Aplazada | Alta (8.2) | 0.50% | — | Wallosapp WallosAI | 31/8/2026 | 8/9/2026 | Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.6, POST /endpoints/notifications/testemailnotifications.php accepts smtpaddress and smtpport from POST body with zero SSRF validation. PHPMailer connects to attacker-supplied host:port. Every other notification endpoint uses… |