Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

2543 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.1)0.37%—Booking CalendarAI22/9/202622/9/2026
The Booking Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wpbc_auto_fill' parameter in all versions up to, and including, 11.8.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in…
AplazadaAlta (7.1)0.32%—Google Notebooklm MCPAI21/9/202624/9/2026
NotebookLM MCP is an MCP server and HTTP service for interacting with Google NotebookLM and exporting generated content to local vault directories. Versions 1.6.0 through 2.0.2 contain a path traversal vulnerability in the `POST /batch-to-vault` endpoint, also exposed through the `batch_to_vault` MCP tool beginning in…
AplazadaAlta (7.6)0.39%—Mayswind EzbookkeepingAI20/9/202624/9/2026
mayswind ezBookkeeping before 2.0.0 fails to invalidate TOTP passcodes after use, allowing attackers to replay captured codes within the acceptance window. Attackers with stolen credentials can authenticate and reuse a captured passcode against multiple authorization attempts for approximately 90 seconds without…
AplazadaMedia (6.4)0.19%—Real3d Flipbook LiteAI19/9/202621/9/2026
The Real3D Flipbook Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'lightboxtext' shortcode attribute (and other unsanitized attributes handled by on_shortcode()) in versions up to, and including, 5.1.1. This is due to insufficient input sanitization and output escaping in the…
AplazadaMedia (5.5)0.31%—Hydra BookingAI19/9/202621/9/2026
The Hydra Booking — Appointment Scheduling & Booking Calendar WordPress plugin before 1.2.4 does not perform object-level authorisation checks on several of its host-management operations, allowing users who hold its own administrator-assigned custom role to read, modify and permanently delete other hosts' records and…
AplazadaMedia (4.7)0.29%—Hydra BookingAI19/9/202621/9/2026
The Hydra Booking — Appointment Scheduling & Booking Calendar WordPress plugin before 1.2.3 does not verify that the host record being modified belongs to the user making the request, allowing authenticated users holding a Hydra Booking — Appointment Scheduling & Booking Calendar WordPress plugin before 1.2.3-assigned…
AplazadaBaja (3.8)0.32%—Hydra BookingAI19/9/202621/9/2026
The Hydra Booking — Appointment Scheduling & Booking Calendar WordPress plugin before 1.2.2 does not verify that a booking belongs to the requesting user before modifying or deleting it on two of its booking endpoints, allowing a booking-provider-level user to cancel and permanently delete other providers' bookings on…
AplazadaMedia (4.8)0.22%—Online Scheduling AND Appointment Booking SystemAI19/9/202621/9/2026
The Online Scheduling and Appointment Booking System WordPress plugin before 28.2 does not verify that the requester owns the AI booking-assistant conversation named in its unauthenticated conversation actions, allowing any unauthenticated visitor to read another visitor's assistant messages and to inject messages…
AplazadaAlta (7.2)0.66%—Booking CalendarAI18/9/202618/9/2026
The Booking Calendar plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 11.8.2 via the `wpbc_ajax_option_save` AJAX action. The vulnerability exists because the `handle_ajax_save()` function applies per-option safeguards only to names explicitly registered via…
AplazadaMedia (6.1)0.41%—Booking CalendarAI18/9/202618/9/2026
The Booking Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'options' parameter in all versions up to, and including, 11.8.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages…
AplazadaBaja (2.7)0.32%—Bookit Booking Appointment CalendarAI18/9/202618/9/2026
The Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.5 does not perform an authorization check on one of its appointment-retrieval actions, allowing users with a low-privilege Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.5-specific role to read other users' appointment…
AplazadaBaja (2.7)0.28%—Stylemixthemes BookitAI18/9/202618/9/2026
The Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.5 does not perform a capability check in one of its appointment-deletion functions, allowing users with its low-privileged custom Staff role to delete arbitrary appointments.
AplazadaAlta (8.8)0.51%—Igms Direct BookingAI18/9/202618/9/2026
The iGMS Direct Booking WordPress plugin before 2.0 does not authorise or escape its widget appearance settings, allowing unauthenticated users to store arbitrary web scripts that execute in the context of an administrator viewing the iGMS Direct Booking WordPress plugin before 2.0 settings, and in the browser of any…
AplazadaAlta (8.8)0.45%—VikbookingAI18/9/202618/9/2026
The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.8.15 does not restrict the type of files unauthenticated visitors may attach to its live chat, nor sanitize their contents, allowing them to store active content which is executed in the context of an administrator viewing the conversation.
AplazadaMedia (5.4)0.17%—Ameliabooking AmeliaAI17/9/202618/9/2026
The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing ownership verification on /users/customers/<id> endpoint in all versions up to, and including, 2.4.4. This makes it possible for authenticated attackers, with…
AplazadaCrítica (9.8)0.70%—Openreception Appointment Booking SoftwareAI17/9/202630/9/2026
OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to 1.1.1, POST /api/auth/passkeys accepts a request-body userId and attacker-supplied passkey without an authenticated session, does not call WebAuthnService.verifyRegistration, and does not bind…
AplazadaCrítica (9.8)0.61%—Eduadmin BookingAI17/9/202617/9/2026
Unauthenticated Broken Authentication in EduAdmin Booking <= 5.4.2 versions.
AplazadaMedia (5.3)0.29%—Booking CalendarAI17/9/202619/9/2026
Unauthenticated Broken Access Control in Booking Calendar <= 11.7 versions.
AplazadaMedia (4.9)0.38%—Event Booking ManagerAI17/9/202618/9/2026
The Event Booking Manager for WooCommerce WordPress plugin before 5.6.0 does not restrict who can view its stored payment gateway configuration, allowing users with Contributor-level access and above to read the site's PayPal and Stripe credentials, including their secret keys.
AplazadaBaja (3.7)0.26%—Event Booking Manager FOR WoocommerceAI17/9/202618/9/2026
The Event Booking Manager for WooCommerce WordPress plugin before 5.3.8 does not perform an ownership or authorization check before rendering booking confirmation details, allowing unauthenticated attackers to retrieve registered attendees' personal information (full name, email address, phone number, and custom…
AplazadaMedia (5.3)0.31%—Dwbooster Appointment Hour BookingAI16/9/202616/9/2026
The Appointment Hour Booking WordPress plugin before 1.5.95 does not check every appointment in a booking submission against the capacity configured for its own slot, allowing unauthenticated visitors to take slots that are already fully booked.
AplazadaMedia (5.3)0.34%—ROX Appointment BookingAI16/9/202617/9/2026
The Rox Appointment Booking WordPress plugin before 1.2.8 does not perform any authorization check on the endpoints that return booking service and category records, allowing unauthenticated attackers to read the private internal notes stored on each service and category.
AplazadaMedia (5.3)0.34%—ROX Appointment BookingAI16/9/202617/9/2026
The Rox Appointment Booking WordPress plugin before 1.2.8 does not perform any authorization check on the endpoint that returns booking agent (staff) records, allowing unauthenticated attackers to read staff email addresses, phone numbers, private internal notes and the linked WordPress account name for every agent.
AplazadaAlta (7.5)1.6%💥 ExploitBooking-wp-plugin BooklyAI16/9/202617/9/2026
The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 28.1 via the 'conversation_id' parameter due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to…
AplazadaCrítica (9.8)0.42%—Themetechmount TruebookerAI16/9/202616/9/2026
The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2.3. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to…