Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
136 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.3) | 0.55% | — | Simply Schedule AppointmentsAI | 13/3/2025 | 17/6/2026 | The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.6.8.5. This is due to the software allowing users to execute an action that does not properly validate a value before running… | |
| Analizada | Media (6.1) | 0.60% | 💥 Exploit | Wp-base WP Base Booking OF Appointments, Services AND Events | 26/2/2025 | 17/6/2026 | The WP BASE Booking of Appointments, Services and Events WordPress plugin before 5.0.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin. | |
| Modificada | Crítica (9.8) | 0.83% | — | Easyappointments | 12/2/2025 | 17/6/2026 | An issue in Alex Tselegidis EasyAppointments v.1.5.0 allows a remote attacker to escalate privileges via the index.php file. | |
| Analizada | Media (6.1) | 0.52% | — | Easyappointments | 12/2/2025 | 17/6/2026 | Cross Site Scripting vulnerability in Alex Tselegidis EasyAppointments v.1.5.0 allows a remote attacker to execute arbitrary code via the legal_settings parameter. | |
| Aplazada | Alta (7.1) | 0.26% | — | E4jvikwp VikappointmentsAI | 21/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e4jvikwp VikAppointments Services Booking Calendar vikappointments allows Stored XSS.This issue affects VikAppointments Services Booking Calendar: from n/a through <= 1.2.16. | |
| Aplazada | Media (6.5) | 1.3% | 💥 PoC | Wp-base Booking OF Appointments Services AND EventsAI | 21/12/2024 | 17/6/2026 | The WP BASE Booking of Appointments, Services and Events plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the export_db function in all versions up to, and including, 4.9.2. This makes it possible for authenticated attackers, with Subscriber-level access and above,… | |
| Analizada | Media (6.1) | 0.35% | — | Easy-appointments Easy Appointments | 9/12/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nikola Loncar Easy Appointments allows Stored XSS.This issue affects Easy Appointments: from n/a through 3.10.7. | |
| Analizada | Media (4.8) | 0.37% | — | Nsqua Simply Schedule Appointments | 5/11/2024 | 17/6/2026 | The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin WordPress plugin before 1.6.7.55 does not sanitise and escape some of its Notification settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed | |
| Analizada | Media (4.8) | 0.37% | — | Nsqua Simply Schedule Appointments | 5/11/2024 | 17/6/2026 | The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin WordPress plugin before 1.6.7.55 does not sanitise and escape some of its Appointment Type settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed | |
| Modificada | Alta (7.2) | 1.1% | — | Nsqua Simply Schedule Appointments | 13/9/2024 | 17/6/2026 | The Appointment Booking Calendar WordPress plugin before 1.6.7.43 does not escape template syntax provided via user input, leading to Twig Template Injection which further exploited can result to remote code Execution by high privilege such as admins | |
| Aplazada | Media (5.4) | 0.30% | — | Bookingultrapro Appointments Booking CalendarAI | 18/7/2024 | 17/6/2026 | The Booking Ultra Pro Appointments Booking Calendar Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the multiple functions called via AJAX like save_fields_settings, bup_delete_user_avatar, bup_crop_avatar_user_profile_image, and more in all versions… | |
| Modificada | Media (5) | 0.29% | — | Easyappointments | 9/7/2024 | 17/6/2026 | A BOLA vulnerability in POST /customers allows a low privileged user to create a low privileged user (customer) in the system. This results in unauthorized data manipulation. | |
| Modificada | Media (6.5) | 0.33% | — | Easyappointments | 9/7/2024 | 17/6/2026 | A BOLA vulnerability in POST /services allows a low privileged user to create a service for any user in the system (including admin). This results in unauthorized data manipulation. | |
| Modificada | Alta (8.8) | 0.35% | — | Easyappointments | 9/7/2024 | 17/6/2026 | A BOLA vulnerability in POST /providers allows a low privileged user to create a privileged user (provider) in the system. This results in privilege escalation. | |
| Modificada | Alta (8.8) | 0.43% | — | Easyappointments | 9/7/2024 | 17/6/2026 | A BOLA vulnerability in POST /admins allows a low privileged user to create a high privileged user (admin) in the system. This results in privilege escalation. | |
| Modificada | Media (6.5) | 0.33% | — | Easyappointments | 9/7/2024 | 17/6/2026 | A BOLA vulnerability in POST /secretaries allows a low privileged user to create a low privileged user (secretary) in the system. This results in unauthorized data manipulation. | |
| Modificada | Alta (8.1) | 0.39% | — | Easyappointments | 9/7/2024 | 17/6/2026 | A BOLA vulnerability in GET, PUT, DELETE /services/{serviceId} allows a low privileged user to fetch, modify or delete the services of any user (including admin). This results in unauthorized access and unauthorized data manipulation. | |
| Modificada | Alta (8.1) | 0.40% | — | Easyappointments | 9/7/2024 | 17/6/2026 | A BOLA vulnerability in GET, PUT, DELETE /customers/{customerId} allows a low privileged user to fetch, modify or delete a low privileged user (customer). This results in unauthorized access and unauthorized data manipulation. | |
| Modificada | Alta (8.1) | 0.40% | — | Easyappointments | 9/7/2024 | 17/6/2026 | A BOLA vulnerability in GET, PUT, DELETE /settings/{settingName} allows a low privileged user to fetch, modify or delete the settings of any user (including admin). This results in unauthorized access and unauthorized data manipulation. | |
| Modificada | Alta (8.1) | 0.40% | — | Easyappointments | 9/7/2024 | 17/6/2026 | A BOLA vulnerability in GET, PUT, DELETE /admins/{adminId} allows a low privileged user to fetch, modify or delete a high privileged user (admin). This results in unauthorized access and unauthorized data manipulation. | |
| Modificada | Alta (8.1) | 0.40% | — | Easyappointments | 9/7/2024 | 17/6/2026 | A BOLA vulnerability in GET, PUT, DELETE /secretaries/{secretaryId} allows a low privileged user to fetch, modify or delete a low privileged user (secretary). This results in unauthorized access and unauthorized data manipulation. | |
| Modificada | Alta (8.1) | 0.36% | — | Easyappointments | 9/7/2024 | 17/6/2026 | A BOLA vulnerability in GET, PUT, DELETE /webhooks/{webhookId} allows a low privileged user to fetch, modify or delete a webhook of any user (including admin). This results in unauthorized access and unauthorized data manipulation. | |
| Modificada | Alta (8.1) | 0.41% | — | Easyappointments | 9/7/2024 | 17/6/2026 | A BOLA vulnerability in GET, PUT, DELETE /appointments/{appointmentId} allows a low privileged user to fetch, modify or delete an appointment of any user (including admin). This results in unauthorized access and unauthorized data manipulation. | |
| Modificada | Alta (8.1) | 0.40% | — | Easyappointments | 9/7/2024 | 17/6/2026 | A BOLA vulnerability in GET, PUT, DELETE /providers/{providerId} allows a low privileged user to fetch, modify or delete a privileged user (provider). This results in unauthorized access and unauthorized data manipulation. | |
| Modificada | Alta (8.1) | 0.37% | — | Easyappointments | 9/7/2024 | 17/6/2026 | A BOLA vulnerability in GET, PUT, DELETE /categories/{categoryId} allows a low privileged user to fetch, modify or delete the category of any user (including admin). This results in unauthorized access and unauthorized data manipulation. |