Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
244 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.52% | — | Apache Dolphinscheduler | 3/9/2025 | 17/6/2026 | Incorrect Default Permissions vulnerability in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.2.2. Users are recommended to upgrade to version 3.3.1, which fixes the issue. | |
| Modificada | Alta (8.8) | 0.51% | — | Apache Dolphinscheduler | 3/9/2025 | 17/6/2026 | Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can execute any shell script server by alert script. This issue affects Apache DolphinScheduler: before 3.2.2. Users are recommended to upgrade to version 3.3.1, which fixes the issue. | |
| Aplazada | Media (6.4) | 0.29% | — | Myceliumdesign Conference SchedulerAI | 24/6/2025 | 17/6/2026 | The Conference Scheduler plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘className’ parameter in all versions up to, and including, 2.5.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above,… | |
| Aplazada | Media (6.4) | 0.29% | — | Simply Schedule Appointments Appointment Booking CalendarAI | 14/6/2025 | 17/6/2026 | The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ssa_admin_upcoming_appointments, ssa_admin_upcoming_appointments, and ssa_past_appointments shortcodes in all versions up to, and including, 1.6.8.30 due to… | |
| Modificada | Alta (7.1) | 0.31% | — | Hijiriworld Advanced Schedule Posts | 15/5/2025 | 17/6/2026 | The Advanced Schedule Posts WordPress plugin through 2.1.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admins. | |
| Aplazada | Alta (7.1) | 0.34% | — | Miunosoft Task SchedulerAI | 11/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in miunosoft Task Scheduler task-scheduler allows Reflected XSS.This issue affects Task Scheduler: from n/a through <= 1.6.3. | |
| Aplazada | Alta (7.1) | 0.21% | — | Bhoogterp ScheduledAI | 9/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in bhoogterp Scheduled scheduled allows Stored XSS.This issue affects Scheduled: from n/a through <= 1.0. | |
| Aplazada | Media (6.5) | 0.18% | — | Appointy Appointment SchedulerAI | 31/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in appointy Appointy Appointment Scheduler appointy-appointment-scheduler allows Cross Site Request Forgery.This issue affects Appointy Appointment Scheduler: from n/a through <= 4.2.1. | |
| Aplazada | Crítica (9.3) | 0.35% | — | Oracle SchedulerAI | 28/3/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in scheduler Schedule schedule allows Blind SQL Injection.This issue affects Schedule: from n/a through <= 1.0.0. | |
| Aplazada | Media (4.7) | 0.46% | — | Wpfactory Scheduled Automatic Order Status Controller FOR WoocommerceAI | 27/3/2025 | 17/6/2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in WPFactory Scheduled & Automatic Order Status Controller for WooCommerce order-status-rules-for-woocommerce allows Phishing.This issue affects Scheduled & Automatic Order Status Controller for WooCommerce: from n/a through <= 3.7.1. | |
| Aplazada | Alta (7.3) | 0.55% | — | Simply Schedule AppointmentsAI | 13/3/2025 | 17/6/2026 | The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.6.8.5. This is due to the software allowing users to execute an action that does not properly validate a value before running… | |
| Analizada | Alta (7.1) | 0.27% | — | Scheduler Schedule | 13/3/2025 | 17/6/2026 | The Schedule WordPress plugin through 1.0.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |
| Aplazada | Alta (7.2) | 1.0% | — | Database Backup AND Check Tables Automated With SchedulerAI | 1/3/2025 | 17/6/2026 | The Database Backup and check Tables Automated With Scheduler 2024 plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'database_backup_ajax_delete' function in all versions up to, and including, 2.35. This makes it possible for authenticated attackers, with… | |
| Aplazada | Alta (7.2) | 0.59% | — | Database Backup AND Check Tables Automated With Scheduler 2024AI | 1/3/2025 | 17/6/2026 | The Database Backup and check Tables Automated With Scheduler 2024 plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.35 via the /dashboard/backup.php file. This makes it possible for authenticated attackers, with Administrator-level access and above, to… | |
| Aplazada | Media (6.7) | 0.45% | — | Joomla SchedulerAI | 18/2/2025 | 17/6/2026 | Improperly built order clauses lead to a SQL injection vulnerability in the backend task list of com_scheduler. | |
| Aplazada | Media (6.1) | 0.28% | — | Slabiak Appointment SchedulerAI | 31/1/2025 | 17/6/2026 | A Host Header Poisoning Open Redirect issue in slabiak Appointment Scheduler v.1.0.5 allows a remote attacker to redirect users to a malicious website, leading to potential credential theft, malware distribution, or other malicious activities. | |
| Aplazada | Media (6.5) | 0.32% | — | Coschedule Headline AnalyzerAI | 2/1/2025 | 17/6/2026 | Missing Authorization vulnerability in CoSchedule Headline Analyzer headline-analyzer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Headline Analyzer: from n/a through <= 1.3.1. | |
| Aplazada | Media (4.9) | 0.85% | — | Database Backup AND Check Tables Automated With SchedulerAI | 24/12/2024 | 17/6/2026 | The Database Backup and check Tables Automated With Scheduler 2024 plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.32 via the database_backup_ajax_download() function. This makes it possible for authenticated attackers, with administrator-level access and above, to… | |
| Analizada | Media (5.5) | 0.15% | — | IBM Workload Scheduler | 26/11/2024 | 17/6/2026 | IBM Workload Scheduler 9.5, 10.1, and 10.2 stores user credentials in plain text which can be read by a local user. | |
| Analizada | Media (4.8) | 0.37% | — | Nsqua Simply Schedule Appointments | 5/11/2024 | 17/6/2026 | The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin WordPress plugin before 1.6.7.55 does not sanitise and escape some of its Notification settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed | |
| Analizada | Media (4.8) | 0.37% | — | Nsqua Simply Schedule Appointments | 5/11/2024 | 17/6/2026 | The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin WordPress plugin before 1.6.7.55 does not sanitise and escape some of its Appointment Type settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed | |
| Analizada | Crítica (9.8) | 0.41% | — | Motopress Timetable AND Event Schedule | 16/10/2024 | 17/6/2026 | The Timetable and Event Schedule by MotoPress plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the wp_ajax_route_url() function called via a nopriv AJAX action in versions up to, and including, 2.3.8. This makes it possible for unauthenticated attackers to call that… | |
| Analizada | Media (5.5) | 0.18% | — | Fortra Robot Schedule | 9/10/2024 | 17/6/2026 | Fortra's Robot Schedule Enterprise Agent prior to version 3.05 writes FTP username and password information to the agent log file when detailed logging is enabled. | |
| Aplazada | Alta (8.8) | 0.37% | — | SchedulerAI | 26/9/2024 | 17/6/2026 | A host header injection vulnerability in scheduleR v0.0.18 allows attackers to obtain the password reset token via user interaction with a crafted password reset link. This allows attackers to arbitrarily reset other users' passwords and compromise their accounts. | |
| Modificada | Alta (7.2) | 1.1% | — | Nsqua Simply Schedule Appointments | 13/9/2024 | 17/6/2026 | The Appointment Booking Calendar WordPress plugin before 1.6.7.43 does not escape template syntax provided via user input, leading to Twig Template Injection which further exploited can result to remote code Execution by high privilege such as admins |