Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
–

3072 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (4.3)0.24%—LatepointAI17/9/202619/9/2026
The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.6.9 via the set_customer_object due to missing validation on a user controlled key. This makes it possible for unauthenticated…
AplazadaCrítica (9.8)0.70%—Openreception Appointment Booking SoftwareAI17/9/202630/9/2026
OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to 1.1.1, POST /api/auth/passkeys accepts a request-body userId and attacker-supplied passkey without an authenticated session, does not call WebAuthnService.verifyRegistration, and does not bind…
Pendiente de análisisMedia (5.9)0.44%—Steeltoe.management.endpointAI17/9/202623/9/2026
Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. Prior to 4.3.0, the Steeltoe.Management.Endpoint /actuator/httpexchanges endpoint passes recorded request URIs through MaskedUri, which masks URI user information but does not inspect query…
AplazadaMedia (5.3)0.31%—Dwbooster Appointment Hour BookingAI16/9/202616/9/2026
The Appointment Hour Booking WordPress plugin before 1.5.95 does not check every appointment in a booking submission against the capacity configured for its own slot, allowing unauthenticated visitors to take slots that are already fully booked.
AplazadaMedia (5.3)0.34%—ROX Appointment BookingAI16/9/202617/9/2026
The Rox Appointment Booking WordPress plugin before 1.2.8 does not perform any authorization check on the endpoints that return booking service and category records, allowing unauthenticated attackers to read the private internal notes stored on each service and category.
AplazadaMedia (5.3)0.34%—ROX Appointment BookingAI16/9/202617/9/2026
The Rox Appointment Booking WordPress plugin before 1.2.8 does not perform any authorization check on the endpoint that returns booking agent (staff) records, allowing unauthenticated attackers to read staff email addresses, phone numbers, private internal notes and the linked WordPress account name for every agent.
Pendiente de análisisAlta (7.7)0.53%—Langchain Langgraph-checkpoint-mongodbAILangchain Langgraph-store-mongodbAI14/9/202630/9/2026
LangChain MongoDB provides integrations between MongoDB, Atlas, LangChain, and LangGraph. Prior to langgraph-checkpoint-mongodb 0.3.0 and langgraph-store-mongodb 0.4.0, MongoDBSaver.list(), MongoDBSaver.alist(), and MongoDBStore.search() incorporate filter dictionaries into MongoDB queries without recursively…
AplazadaMedia (6.4)0.24%—Booking FOR Appointments AND Events CalendarAI12/9/202614/9/2026
The Booking for Appointments and Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple Elementor widgets in versions up to and including 2.4.9. This is due to insufficient input sanitization and output escaping on the 'load_manually' parameter in the render() methods of…
AplazadaMedia (5.3)0.32%—ROX Appointment BookingAI12/9/202614/9/2026
The Rox Appointment Booking WordPress plugin before 1.2.3 does not perform any authorization check on the endpoint that returns a booking's confirmation details, and each booking is addressed by a sequential numeric identifier, allowing unauthenticated attackers to read any customer's name, email, phone, booking…
AplazadaMedia (5.3)0.34%—ROX Appointment BookingAI12/9/202614/9/2026
The Rox Appointment Booking WordPress plugin before 1.2.0 does not verify the order total or the selected payment method against its own server-side pricing when creating a booking, allowing unauthenticated attackers to create confirmed bookings at an arbitrary price and to bypass the site's configured payment-method…
AplazadaMedia (6.5)0.34%—ROX Appointment BookingAI12/9/202614/9/2026
The Rox Appointment Booking WordPress plugin before 1.2.0 does not perform any capability or authorization check when saving its holiday schedule, allowing unauthenticated attackers to overwrite the dates the booking system treats as unavailable, which can block legitimate bookings or open dates the site owner…
AplazadaAlta (8.8)0.51%—BE Rest EndpointsAI12/9/202614/9/2026
The BE REST Endpoints WordPress plugin through 1.0.0 does not perform any authorization check before allowing widgets to be read, created, updated and deleted, and does not sanitize the values it stores in them, allowing unauthenticated users to inject arbitrary web scripts which will execute in the browser of any…
AplazadaAlta (7.2)0.46%—Ameliabooking Booking FOR Appointments AND Events CalendarAI12/9/202614/9/2026
The Booking for Appointments and Events Calendar WordPress plugin before 2.4.10 does not verify that the user editing a customer or employee record is entitled to modify the WordPress account linked to it, allowing users holding Amelia's customer or employee management permissions to set the password and email address…
AplazadaMedia (5.3)0.30%—Booking FOR Appointments AND Events CalendarAI12/9/202614/9/2026
The Booking for Appointments and Events Calendar WordPress plugin before 9.8.1 does not verify that a payment was actually taken before recording a booking as paid, trusting the payment gateway named in a public, unauthenticated booking request even when the site has never configured that gateway. This lets an…
Pendiente de análisisAlta (8.7)0.13%—Netskope Endpoint DLPAI10/9/202618/9/2026
Netskope was notified about a potential gap in Netskope Endpoint DLP (EPDLP) running on Windows systems. Successful exploitation of the gap could potentially allow a privileged user to send a crafted message to the EPDLP process port to trigger an integer overflow, leading to memory corruption. Successful exploitation…
Pendiente de análisisMedia (6)0.11%—Netskope ClientAINetskope Endpoint DLPAI10/9/202618/9/2026
Netskope was notified of an out-of-bounds heap read affecting the Endpoint DLP (EPDLP) service of the Netskope Client. A local standard user could potentially send a specially crafted message that is not properly validated with a bounds check, likely crashing the kernel driver handler. Successful exploitation could…
Pendiente de análisisCrítica (9.8)3.7%—Checkpoint Quantum Security ManagementAICheckpoint Quantum Security GatewayAI9/9/202610/9/2026
A heap-based buffer overflow in VPN certificate ASN.1 decoding may allow an unauthenticated remote attacker to execute arbitrary code on Check Point Quantum Security Management and Quantum Security Gateway systems.
AnalizadaCrítica (9.8)7.5%⚠ Explotación activa💥 PoCCheckpoint Gaia EmbeddedCheckpoint Gaia OS9/9/202623/9/2026
Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote attacker to execute arbitrary code on the Gateway.
AnalizadaMedia (5.5)0.54%—Microsoft 365 AppsMicrosoft 365Microsoft Office 2019Microsoft Office 2021+28/9/202617/9/2026
Out-of-bounds read in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.
AnalizadaMedia (6.5)0.97%—Microsoft 365 AppsMicrosoft 365Microsoft Office 2019Microsoft Office 2021+28/9/202617/9/2026
Out-of-bounds read in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information over a network.
AnalizadaMedia (6.5)0.92%—Microsoft 365 AppsMicrosoft 365Microsoft Office 2019Microsoft Office 2021+28/9/202617/9/2026
Out-of-bounds read in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information over a network.
AnalizadaBaja (3.5)0.58%—Microsoft Sharepoint Server8/9/20269/9/2026
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.
AnalizadaAlta (7.5)0.51%—Microsoft Sharepoint Server8/9/20269/9/2026
Time-of-check time-of-use (toctou) race condition in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
AnalizadaAlta (8.8)0.82%—Microsoft 365 AppsMicrosoft 365Microsoft Office 2019Microsoft Office 2021+28/9/202617/9/2026
Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code over a network.
AnalizadaAlta (8.8)0.82%—Microsoft 365 AppsMicrosoft 365Microsoft Office 2019Microsoft Office 2021+28/9/202617/9/2026
Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code over a network.