Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

244 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaBaja (2.7)0.31%—Sourcecodester Patient Appointment Scheduler SystemAI14/4/202617/6/2026
SourceCodester Patient Appointment Scheduler System v1.0 is vulnerable to SQL Injection in the file /scheduler/admin/user/manage_user.php.
AplazadaBaja (2.7)0.31%—Sourcecodester Patient Appointment Scheduler SystemAI14/4/202617/6/2026
SourceCodester Patient Appointment Scheduler System v1.0 is vulnerable to SQL Injection in the file /scheduler/admin/appointments/manage_appointment.php.
AplazadaBaja (2.7)0.31%—Sourcecodester Patient Appointment SchedulerAI14/4/202617/6/2026
SourceCodester Patient Appointment Scheduler System v1.0 is vulnerable to SQL Injection in the file /scheduler/admin/appointments/view_details.php.
AplazadaBaja (2.7)0.39%—Sourcecodester Patient Appointment Scheduler SystemAI14/4/202617/6/2026
SourceCodester Patient Appointment Scheduler System v1.0 is vulnerable to arbitrary code execution (RCE) via /scheduler/classes/SystemSettings.php?f=update_settings.
AnalizadaAlta (7.5)0.52%—Apache Dolphinscheduler9/4/202630/9/2026
An Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists in Apache DolphinScheduler. This vulnerability may allow unauthorized actors to access sensitive information, including database credentials. This issue affects Apache DolphinScheduler versions 3.1.*. Users are recommended to upgrade…
AplazadaMedia (5.3)0.26%—Nsquared Simply Schedule AppointmentsAI8/4/202624/7/2026
Missing Authorization vulnerability in NSquared Simply Schedule Appointments simply-schedule-appointments allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simply Schedule Appointments: from n/a through <= 1.6.10.2.
AplazadaAlta (8.5)0.36%—Nsquared Simply Schedule AppointmentsAI8/4/202624/7/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NSquared Simply Schedule Appointments simply-schedule-appointments allows Blind SQL Injection.This issue affects Simply Schedule Appointments: from n/a through <= 1.6.9.27.
AplazadaMedia (6.1)0.20%—Auto Post SchedulerAI31/3/202617/6/2026
The Auto Post Scheduler plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.84. This is due to missing nonce validation on the 'aps_options_page' function. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a…
AplazadaMedia (4.3)0.21%—Simply Schedule AppointmentsAI13/3/202617/6/2026
The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.6.9.29. This is due to the `get_item_permissions_check` method granting access to users with the `ssa_manage_appointments`…
AplazadaMedia (4.3)0.13%—Whatsiplus Scheduled Notification FOR WoocommerceAI19/2/202617/6/2026
The Whatsiplus Scheduled Notification for Woocommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.1. This is due to missing nonce validation on the 'wsnfw_save_users_settings' AJAX action. This makes it possible for unauthenticated attackers to modify…
AplazadaMedia (5.4)0.33%—Scheduler WidgetAI14/2/202617/6/2026
The Scheduler Widget plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 0.1.6. This is due to the `scheduler_widget_ajax_save_event()` function lacking proper authorization checks and ownership verification when updating events. This makes it possible for…
AplazadaMedia (6.9)0.70%—Oracle SchedulerAI3/2/202617/6/2026
Booked Scheduler 2.7.7 contains a directory traversal vulnerability in the manage_email_templates.php script that allows authenticated administrators to access unauthorized files. Attackers can exploit the vulnerable 'tn' parameter to read files outside the intended directory by manipulating directory path traversal…
AplazadaMedia (6.5)0.22%—Nsquared Simply Schedule AppointmentsAI22/1/202617/6/2026
Missing Authorization vulnerability in NSquared Simply Schedule Appointments simply-schedule-appointments allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simply Schedule Appointments: from n/a through <= 1.6.9.15.
AplazadaAlta (8.5)0.17%—Acer Backup ManagerAINTI IschedulesvcAI16/1/202617/6/2026
Acer Backup Manager 3.0.0.99 contains an unquoted service path vulnerability in the NTI IScheduleSvc service that allows local users to potentially execute arbitrary code. Attackers can exploit the unquoted path in C:\Program Files (x86)\NTI\Acer Backup Manager\ to inject malicious executables that would run with…
AplazadaMedia (5.3)0.35%—Simply Schedule AppointmentsAI19/12/202517/6/2026
The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.6.9.16. This is due to the plugin exposing its admin embed endpoint at `/wp-json/ssa/v1/embed-inner-admin` without authentication, which…
AplazadaMedia (4.3)0.26%—Publishpress Schedule Post ChangesAI16/12/202517/6/2026
The Schedule Post Changes With PublishPress Future: Unpublish, Delete, Change Status, Trash, Change Categories plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the getAuthors function in all versions up to, and including, 4.9.2. This makes it possible for…
AplazadaMedia (5.5)0.11%—HCL Workload SchedulerAI11/12/20251/10/2026
HCL Workload Scheduler stores user credentials in plain text which can be read by a local user.
AplazadaBaja (2.7)0.21%—Motopress Timetable AND Event ScheduleAI3/12/202517/6/2026
The Timetable and Event Schedule by MotoPress WordPress plugin before 2.4.16 does not verify a user has access to a specific event when duplicating, leading to arbitrary event disclosure when to users with a role as low as Contributor.
AplazadaMedia (4.3)0.19%—Schedule Post Changes With Publishpress FutureAI21/11/202517/6/2026
The Schedule Post Changes With PublishPress Future: Unpublish, Delete, Change Status, Trash, Change Categories plugin for WordPress is vulnerable to unauthorized modification of data due to a missing authorization check on the "saveFutureActionData" function in all versions up to, and including, 4.9.1. This makes it…
AplazadaMedia (6.5)0.17%—Coschedule Headline AnalyzerAI27/10/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CoSchedule Headline Analyzer headline-analyzer allows Stored XSS.This issue affects Headline Analyzer: from n/a through <= 1.3.7.
AplazadaMedia (5.3)0.35%—CoscheduleAI22/10/202517/6/2026
Missing Authorization vulnerability in CoSchedule CoSchedule coschedule-by-todaymade allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CoSchedule: from n/a through <= 3.4.0.
AplazadaMedia (4.4)0.24%—Task SchedulerAI15/10/202517/6/2026
The Task Scheduler plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.6.3 via the “Check Website” task. This makes it possible for authenticated attackers, with Administrator-level access and above, to make web requests to arbitrary locations originating from the…
AplazadaMedia (6.4)0.24%—Yoga Schedule MomoyogaAI30/9/202517/6/2026
The Yoga Schedule Momoyoga plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'momoyoga-schedule' shortcode in all versions up to, and including, 2.9.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated…
AplazadaAlta (8.2)0.38%—Obsidian SchedulerAI29/9/202517/6/2026
A security vulnerability was identified in Obsidian Scheduler's REST API 5.0.0 thru 6.3.0. If an account is locked out due to not enrolling in MFA (e.g. after the 7-day enforcement window), the REST API still allows the use of Basic Authentication to authenticate and perform administrative actions. In particular, the…
AplazadaMedia (5.3)0.31%—CoscheduleAI26/9/202517/6/2026
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in CoSchedule CoSchedule coschedule-by-todaymade allows Retrieve Embedded Sensitive Data.This issue affects CoSchedule: from n/a through <= 3.3.11.
Orbitaley — Vulnerabilidades