Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
150 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.4) | 0.30% | — | Bookingultrapro Appointments Booking CalendarAI | 18/7/2024 | 17/6/2026 | The Booking Ultra Pro Appointments Booking Calendar Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the multiple functions called via AJAX like save_fields_settings, bup_delete_user_avatar, bup_crop_avatar_user_profile_image, and more in all versions… | |
| Analizada | Crítica (9.8) | 0.35% | — | Wpdevart Booking Calendar | 3/6/2024 | 17/6/2026 | External Control of Assumed-Immutable Web Parameter vulnerability in WpDevArt Booking calendar, Appointment Booking System allows Manipulating Hidden Fields.This issue affects Booking calendar, Appointment Booking System: from n/a through 3.2.3. | |
| Aplazada | Alta (7.6) | 0.52% | — | Wpdevelop Booking CalendarAI | 26/3/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPdevelop / Oplugins Booking Calendar allows SQL Injection.This issue affects Booking Calendar: from n/a through 9.4.3. | |
| Analizada | Alta (8.8) | 0.38% | — | Codepeople Appointment Booking Calendar | 20/3/2024 | 17/6/2026 | The Appointment Booking Calendar WordPress plugin before 1.3.83 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks such as adding a booking to the calendar without paying. | |
| Modificada | Media (4.3) | 0.20% | — | Wpsimplebookingcalendar WP Simple Booking Calendar | 15/3/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Veribo, Roland Murg WP Simple Booking Calendar.This issue affects WP Simple Booking Calendar: from n/a through 2.0.8.4. | |
| Modificada | Crítica (9.8) | 3.2% | 💥 PoC | Wpbookingcalendar Booking Calendar | 8/2/2024 | 17/6/2026 | The WP Booking Calendar plugin for WordPress is vulnerable to SQL Injection via the 'calendar_request_params[dates_ddmmyy_csv]' parameter in all versions up to, and including, 9.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it… | |
| Modificada | Media (5.4) | 0.33% | — | Wpbookingcalendar Booking Calendar | 1/2/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPdevelop / Oplugins WP Booking Calendar allows Stored XSS.This issue affects WP Booking Calendar: from n/a before 9.7.4. | |
| Modificada | Alta (7.5) | 1.1% | — | Phpjabbers Time Slots Booking Calendar | 7/12/2023 | 17/6/2026 | A lack of rate limiting in pjActionAJaxSend in Time Slots Booking Calendar 4.0 allows attackers to cause resource exhaustion. | |
| Modificada | Alta (7.5) | 1.2% | — | Phpjabbers Availability Booking Calendar | 7/12/2023 | 17/6/2026 | A lack of rate limiting in pjActionAJaxSend in Availability Booking Calendar 5.0 allows attackers to cause resource exhaustion. | |
| Modificada | Media (5.4) | 0.46% | — | Phpjabbers Time Slots Booking Calendar | 7/12/2023 | 17/6/2026 | Time Slots Booking Calendar 4.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) issues via the name, plugin_sms_api_key, plugin_sms_country_code, calendar_id, title, country name, or customer_name parameter. | |
| Modificada | Media (5.4) | 0.46% | — | Phpjabbers Time Slots Booking Calendar | 7/12/2023 | 17/6/2026 | Time Slots Booking Calendar 4.0 is vulnerable to Multiple HTML Injection issues via the name, plugin_sms_api_key, plugin_sms_country_code, calendar_id, title, country name, or customer_name parameter. | |
| Modificada | Alta (8.8) | 1.2% | — | Phpjabbers Time Slots Booking Calendar | 7/12/2023 | 17/6/2026 | Time Slots Booking Calendar 4.0 is vulnerable to CSV Injection via the unique ID field of the Reservations List. | |
| Modificada | Media (5.4) | 0.45% | — | Phpjabbers Availability Booking Calendar | 7/12/2023 | 17/6/2026 | Availability Booking Calendar 5.0 is vulnerable to Multiple HTML Injection issues via SMS API Key or Default Country Code. | |
| Modificada | Media (6.1) | 0.50% | — | Phpjabbers Availability Booking Calendar | 7/12/2023 | 17/6/2026 | A Cross Site Scripting vulnerability in Availability Booking Calendar 5.0 allows an attacker to inject JavaScript via the name, plugin_sms_api_key, plugin_sms_country_code, uuid, title, or country name parameter to index.php. | |
| Modificada | Alta (8.8) | 1.2% | — | Phpjabbers Availability Booking Calendar | 7/12/2023 | 17/6/2026 | Availability Booking Calendar 5.0 allows CSV injection via the unique ID field in the Reservations list component. | |
| Modificada | Crítica (9.8) | 0.68% | — | Wpdevart Booking Calendar | 6/11/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WpDevArt Booking calendar, Appointment Booking System allows SQL Injection.This issue affects Booking calendar, Appointment Booking System: from n/a through 3.2.7. | |
| Modificada | Media (6.1) | 0.56% | — | Wpbookingcalendar Booking Calendar | 16/10/2023 | 17/6/2026 | The Booking Calendar WordPress plugin before 9.7.3.1 does not sanitize and escape some of its booking from data, allowing unauthenticated users to perform Stored Cross-Site Scripting attacks against administrators | |
| Modificada | Crítica (9.8) | 0.89% | — | Phpjabbers Event Booking Calendar | 28/8/2023 | 17/6/2026 | User enumeration is found in PHPJabbers Event Booking Calendar v4.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users. | |
| Modificada | Media (6.1) | 0.38% | — | Bookingultrapro Booking Ultra PRO Appointments Booking Calendar | 24/8/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Booking Ultra Pro Booking Ultra Pro Appointments Booking Calendar Plugin plugin <= 1.1.8 versions. | |
| Modificada | Media (6.1) | 0.38% | — | Bookingultrapro Appointments Booking Calendar | 23/8/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Booking Ultra Pro Booking Ultra Pro Appointments Booking Calendar Plugin <= 1.1.8 versions. | |
| Modificada | Crítica (9.8) | 0.89% | — | Phpjabbers Availability Booking Calendar | 4/8/2023 | 17/6/2026 | PHPJabbers Availability Booking Calendar 5.0 is vulnerable to User Account Takeover through username/password change. | |
| Modificada | Crítica (9.8) | 0.89% | — | Phpjabbers Availability Booking Calendar | 4/8/2023 | 17/6/2026 | PHP Jabbers Availability Booking Calendar 5.0 is vulnerable to Incorrect Access Control. | |
| Modificada | Crítica (9.8) | 0.89% | — | Phpjabbers Availability Booking Calendar | 4/8/2023 | 17/6/2026 | PHPJabbers Availability Booking Calendar 5.0 is vulnerable to Incorrect Access Control due to improper input validation of password parameter. | |
| Modificada | Media (6.1) | 3.1% | 💥 Exploit | Phpjabbers Rental Property Booking Calendar | 3/8/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in PHP Jabbers Rental Property Booking 2.0. Affected by this issue is some unknown functionality of the file /index.php. The manipulation of the argument index leads to cross site scripting. The attack may be launched remotely. The identifier of this… | |
| Modificada | Media (6.1) | 1.8% | 💥 Exploit | Phpjabbers Availability Booking Calendar | 3/8/2023 | 17/6/2026 | A vulnerability has been found in PHP Jabbers Availability Booking Calendar 5.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /index.php. The manipulation of the argument session_id leads to cross site scripting. The attack can be launched remotely. The… |