Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
–

244 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)0.52%—Apache Dolphinscheduler3/9/202517/6/2026
Incorrect Default Permissions vulnerability in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.2.2. Users are recommended to upgrade to version 3.3.1, which fixes the issue.
ModificadaAlta (8.8)0.51%—Apache Dolphinscheduler3/9/202517/6/2026
Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can execute any shell script server by alert script. This issue affects Apache DolphinScheduler: before 3.2.2. Users are recommended to upgrade to version 3.3.1, which fixes the issue.
AplazadaMedia (6.4)0.29%—Myceliumdesign Conference SchedulerAI24/6/202517/6/2026
The Conference Scheduler plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘className’ parameter in all versions up to, and including, 2.5.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above,…
AplazadaMedia (6.4)0.29%—Simply Schedule Appointments Appointment Booking CalendarAI14/6/202517/6/2026
The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ssa_admin_upcoming_appointments, ssa_admin_upcoming_appointments, and ssa_past_appointments shortcodes in all versions up to, and including, 1.6.8.30 due to…
ModificadaAlta (7.1)0.31%—Hijiriworld Advanced Schedule Posts15/5/202517/6/2026
The Advanced Schedule Posts WordPress plugin through 2.1.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admins.
AplazadaAlta (7.1)0.34%—Miunosoft Task SchedulerAI11/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in miunosoft Task Scheduler task-scheduler allows Reflected XSS.This issue affects Task Scheduler: from n/a through <= 1.6.3.
AplazadaAlta (7.1)0.21%—Bhoogterp ScheduledAI9/4/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in bhoogterp Scheduled scheduled allows Stored XSS.This issue affects Scheduled: from n/a through <= 1.0.
AplazadaMedia (6.5)0.18%—Appointy Appointment SchedulerAI31/3/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in appointy Appointy Appointment Scheduler appointy-appointment-scheduler allows Cross Site Request Forgery.This issue affects Appointy Appointment Scheduler: from n/a through <= 4.2.1.
AplazadaCrítica (9.3)0.35%—Oracle SchedulerAI28/3/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in scheduler Schedule schedule allows Blind SQL Injection.This issue affects Schedule: from n/a through <= 1.0.0.
AplazadaMedia (4.7)0.46%—Wpfactory Scheduled Automatic Order Status Controller FOR WoocommerceAI27/3/202517/6/2026
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in WPFactory Scheduled & Automatic Order Status Controller for WooCommerce order-status-rules-for-woocommerce allows Phishing.This issue affects Scheduled & Automatic Order Status Controller for WooCommerce: from n/a through <= 3.7.1.
AplazadaAlta (7.3)0.55%—Simply Schedule AppointmentsAI13/3/202517/6/2026
The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.6.8.5. This is due to the software allowing users to execute an action that does not properly validate a value before running…
AnalizadaAlta (7.1)0.27%—Scheduler Schedule13/3/202517/6/2026
The Schedule WordPress plugin through 1.0.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
AplazadaAlta (7.2)1.0%—Database Backup AND Check Tables Automated With SchedulerAI1/3/202517/6/2026
The Database Backup and check Tables Automated With Scheduler 2024 plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'database_backup_ajax_delete' function in all versions up to, and including, 2.35. This makes it possible for authenticated attackers, with…
AplazadaAlta (7.2)0.59%—Database Backup AND Check Tables Automated With Scheduler 2024AI1/3/202517/6/2026
The Database Backup and check Tables Automated With Scheduler 2024 plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.35 via the /dashboard/backup.php file. This makes it possible for authenticated attackers, with Administrator-level access and above, to…
AplazadaMedia (6.7)0.45%—Joomla SchedulerAI18/2/202517/6/2026
Improperly built order clauses lead to a SQL injection vulnerability in the backend task list of com_scheduler.
AplazadaMedia (6.1)0.28%—Slabiak Appointment SchedulerAI31/1/202517/6/2026
A Host Header Poisoning Open Redirect issue in slabiak Appointment Scheduler v.1.0.5 allows a remote attacker to redirect users to a malicious website, leading to potential credential theft, malware distribution, or other malicious activities.
AplazadaMedia (6.5)0.32%—Coschedule Headline AnalyzerAI2/1/202517/6/2026
Missing Authorization vulnerability in CoSchedule Headline Analyzer headline-analyzer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Headline Analyzer: from n/a through <= 1.3.1.
AplazadaMedia (4.9)0.85%—Database Backup AND Check Tables Automated With SchedulerAI24/12/202417/6/2026
The Database Backup and check Tables Automated With Scheduler 2024 plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.32 via the database_backup_ajax_download() function. This makes it possible for authenticated attackers, with administrator-level access and above, to…
AnalizadaMedia (5.5)0.15%—IBM Workload Scheduler26/11/202417/6/2026
IBM Workload Scheduler 9.5, 10.1, and 10.2 stores user credentials in plain text which can be read by a local user.
AnalizadaMedia (4.8)0.37%—Nsqua Simply Schedule Appointments5/11/202417/6/2026
The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin WordPress plugin before 1.6.7.55 does not sanitise and escape some of its Notification settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed
AnalizadaMedia (4.8)0.37%—Nsqua Simply Schedule Appointments5/11/202417/6/2026
The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin WordPress plugin before 1.6.7.55 does not sanitise and escape some of its Appointment Type settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed
AnalizadaCrítica (9.8)0.41%—Motopress Timetable AND Event Schedule16/10/202417/6/2026
The Timetable and Event Schedule by MotoPress plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the wp_ajax_route_url() function called via a nopriv AJAX action in versions up to, and including, 2.3.8. This makes it possible for unauthenticated attackers to call that…
AnalizadaMedia (5.5)0.18%—Fortra Robot Schedule9/10/202417/6/2026
Fortra's Robot Schedule Enterprise Agent prior to version 3.05 writes FTP username and password information to the agent log file when detailed logging is enabled.
AplazadaAlta (8.8)0.37%—SchedulerAI26/9/202417/6/2026
A host header injection vulnerability in scheduleR v0.0.18 allows attackers to obtain the password reset token via user interaction with a crafted password reset link. This allows attackers to arbitrarily reset other users' passwords and compromise their accounts.
ModificadaAlta (7.2)1.1%—Nsqua Simply Schedule Appointments13/9/202417/6/2026
The Appointment Booking Calendar WordPress plugin before 1.6.7.43 does not escape template syntax provided via user input, leading to Twig Template Injection which further exploited can result to remote code Execution by high privilege such as admins
Orbitaley — Vulnerabilidades