Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
136 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.33% | — | Nsquared Simply Schedule AppointmentsAI | 13/7/2026 | 13/7/2026 | Missing Authorization vulnerability in NSquared Simply Schedule Appointments simply-schedule-appointments allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simply Schedule Appointments: from n/a through <= 1.6.12.4. | |
| Aplazada | Media (4.3) | 0.46% | — | Easyappointments Easy AppointmentsAI | 10/7/2026 | 10/7/2026 | The Easy Appointments plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.12.27. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with author-level access and above, to… | |
| Aplazada | Alta (7.1) | 0.23% | — | Simply Schedule AppointmentsAI | 26/6/2026 | 26/6/2026 | Unauthenticated Cross Site Scripting (XSS) in Simply Schedule Appointments <= 1.6.12.2 versions. | |
| Aplazada | Alta (7.5) | 0.42% | — | Simply Schedule AppointmentsAI | 15/6/2026 | 17/6/2026 | Unauthenticated Sensitive Data Exposure in Simply Schedule Appointments < 1.6.11.2 versions. | |
| Aplazada | Alta (7.5) | 0.39% | — | Easyappointments Easy AppointmentsAI | 15/6/2026 | 17/6/2026 | Unauthenticated Broken Access Control in Easy Appointments <= 3.12.21 versions. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Simply Schedule AppointmentsAI | 15/6/2026 | 17/6/2026 | Unauthenticated SQL Injection in Simply Schedule Appointments <= 1.6.9.27 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Simply Schedule AppointmentsAI | 15/6/2026 | 17/6/2026 | Unauthenticated Cross Site Scripting (XSS) in Simply Schedule Appointments <= 1.6.10.6 versions. | |
| Aplazada | Media (5.3) | 0.64% | — | Booking Calendar Simply Schedule AppointmentsAI | 28/5/2026 | 17/6/2026 | The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.6.11.8 due to the plugin not properly verifying that a user is authorized to perform an action via the bulk appointments REST API endpoint.… | |
| Aplazada | Alta (7.5) | 0.67% | — | Simplyscheduleappointments Appointment Booking CalendarAI | 28/5/2026 | 17/6/2026 | The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'append_where_sql' parameter in all versions up to, and including, 1.6.11.8 due to insufficient escaping on the user supplied parameter and lack of sufficient… | |
| Aplazada | Media (5.3) | 0.44% | — | Simply Schedule AppointmentsAI | 27/5/2026 | 23/7/2026 | The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to denial of service in all versions up to, and including, 1.6.11.5. This is due to a publicly accessible REST API endpoint (/wp-json/ssa/v1/async) that calls PHP's sleep() function on a user-supplied… | |
| Aplazada | Alta (7.5) | 2.4% | 💥 Exploit | Easyappointments Easy AppointmentsAI | 18/4/2026 | 17/6/2026 | The Easy Appointments plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.12.21 via the `/wp-json/wp/v2/eablocks/ea_appointments/` REST API endpoint. This is due to the endpoint being registered with `'permission_callback' => '__return_true'`, which allows… | |
| Aplazada | Media (5.3) | 0.26% | — | Nsquared Simply Schedule AppointmentsAI | 8/4/2026 | 24/7/2026 | Missing Authorization vulnerability in NSquared Simply Schedule Appointments simply-schedule-appointments allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simply Schedule Appointments: from n/a through <= 1.6.10.2. | |
| Aplazada | Alta (8.5) | 0.36% | — | Nsquared Simply Schedule AppointmentsAI | 8/4/2026 | 24/7/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NSquared Simply Schedule Appointments simply-schedule-appointments allows Blind SQL Injection.This issue affects Simply Schedule Appointments: from n/a through <= 1.6.9.27. | |
| Aplazada | Media (4.3) | 0.21% | — | Simply Schedule AppointmentsAI | 13/3/2026 | 17/6/2026 | The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.6.9.29. This is due to the `get_item_permissions_check` method granting access to users with the `ssa_manage_appointments`… | |
| Aplazada | Media (6.5) | 0.22% | — | Nsquared Simply Schedule AppointmentsAI | 22/1/2026 | 17/6/2026 | Missing Authorization vulnerability in NSquared Simply Schedule Appointments simply-schedule-appointments allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simply Schedule Appointments: from n/a through <= 1.6.9.15. | |
| Analizada | Alta (7.4) | 0.23% | — | Easyappointments Easy!appointments | 15/1/2026 | 17/6/2026 | Easy!Appointments is a self hosted appointment scheduler. In 1.5.2 and earlier, application/core/EA_Security.php::csrf_verify() only enforces CSRF for POST requests and returns early for non-POST methods. Several application endpoints perform state-changing operations while accepting parameters from GET (or… | |
| Aplazada | Media (5.3) | 0.35% | — | Simply Schedule AppointmentsAI | 19/12/2025 | 17/6/2026 | The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.6.9.16. This is due to the plugin exposing its admin embed endpoint at `/wp-json/ssa/v1/embed-inner-admin` without authentication, which… | |
| Aplazada | Media (5.3) | 0.29% | — | Booking Plugin FOR Wordpress Appointments Time SlotAI | 19/11/2025 | 17/6/2026 | The Booking Plugin for WordPress Appointments – Time Slot plugin for WordPress is vulnerable to unauthorized email sending in versions up to, and including, 1.4.7 due to missing validation on the tslot_appt_email AJAX action. This makes it possible for unauthenticated attackers to send appointment notification emails… | |
| Aplazada | Media (6.5) | 0.24% | — | Easyappointments Easy AppointmentsAI | 6/11/2025 | 17/6/2026 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Easy Appointments Easy Appointments easy-appointments allows Code Injection.This issue affects Easy Appointments: from n/a through <= 3.12.14. | |
| Aplazada | Alta (7.1) | 0.30% | — | GappointmentsAI | 22/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpcrunch gAppointments gAppointments allows Reflected XSS.This issue affects gAppointments: from n/a through <= 1.14.1. | |
| Analizada | Crítica (9.8) | 0.73% | — | Wpmudev Appointments | 18/10/2025 | 17/6/2026 | The Appointments plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.2.1 via deserialization of untrusted input from the `wpmudev_appointments` cookie. This allows unauthenticated attackers to inject a PHP Object. Attackers were actively exploiting this vulnerability with the… | |
| Modificada | Alta (8.1) | 0.36% | 💥 PoC | Easyappointments Easy!appointments | 25/8/2025 | 5/7/2026 | alextselegidis Easy!Appointments v1.5.1 was discovered to contain a SQL injection vulnerability via the order_by parameter. | |
| Aplazada | Media (6.4) | 0.29% | — | Simply Schedule Appointments Appointment Booking CalendarAI | 14/6/2025 | 17/6/2026 | The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ssa_admin_upcoming_appointments, ssa_admin_upcoming_appointments, and ssa_past_appointments shortcodes in all versions up to, and including, 1.6.8.30 due to… | |
| Analizada | Alta (7.5) | 0.58% | 💥 PoC | Easyappointments Easy!appointments | 7/5/2025 | 17/6/2026 | Booking logic flaw in Easy!Appointments v1.5.1 allows unauthenticated attackers to create appointments with excessively long durations, causing a denial of service by blocking all future booking availability. | |
| Modificada | Alta (8.8) | 0.25% | — | Easyappointments Easy!appointments | 1/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in alextselegidis Easy!Appointments easyappointments allows Cross Site Request Forgery.This issue affects Easy!Appointments: from n/a through <= 1.4.2. |