Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

1060 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.5)0.22%—WpbookinglyAI13/8/202614/8/2026
Customer Cross Site Scripting (XSS) in WpBookingly <= 1.3.2 versions.
AplazadaCrítica (9.8)0.61%—Salonbookingsystem Salon Booking SystemAI13/8/202614/8/2026
Unauthenticated Broken Authentication in Salon booking system <= 10.30.26 versions.
AplazadaCrítica (10)0.69%—Wp-base BookingAI13/8/202614/8/2026
Unauthenticated Arbitrary Code Execution in WP BASE Booking <= 6.3.0 versions.
AplazadaAlta (7.3)0.30%—Hydra BookingAI13/8/202614/8/2026
Unauthenticated Broken Access Control in Hydra Booking <= 1.2.2 versions.
AplazadaAlta (8.8)0.46%—Booking ActivitiesAI13/8/202614/8/2026
Unauthenticated PHP Object Injection in Booking Activities <= 1.18.4 versions.
AplazadaAlta (8.8)0.42%—Service Finder BookingAI13/8/202614/8/2026
Subscriber Privilege Escalation in Service Finder Booking <= 6.2 versions.
AplazadaMedia (6.5)0.37%—Service Finder BookingAI13/8/202614/8/2026
Subscriber Broken Access Control in Service Finder Booking <= 6.2 versions.
AplazadaAlta (7.5)0.35%—Taxi Booking ManagerAI13/8/202614/8/2026
Unauthenticated Broken Access Control in Taxi Booking Manager for WooCommerce <= 2.0.3 versions.
AplazadaBaja (3.7)0.26%—Booking FOR Appointments AND Events CalendarAI13/8/202626/8/2026
The Booking for Appointments and Events Calendar WordPress plugin before 2.4.6 does not verify that an authenticated employee (provider) is assigned to the appointment being accessed, allowing any employee to read any appointment by its identifier and disclose the booked customer's personal data.
AplazadaAlta (8.7)0.42%—Mrbs Meeting Room Booking SystemAI13/8/20269/9/2026
The Meeting Room Booking System (MRBS) is a PHP-based application for booking meeting rooms. Prior to version 1.12.2, a user-supplied private/local URI can be made to be fetched without checks. Version 1.12.2 contains a fix. No known workarounds are available.
AplazadaMedia (4.8)0.27%—Salonbookingsystem Salon Booking SystemAI10/8/202626/8/2026
The Salon Booking System WordPress plugin through 10.30.33 does not perform any capability check or validate an OAuth state value on its Google Calendar authorization callback, which is also hooked for unauthenticated users, allowing an unauthenticated attacker to overwrite the site's stored Google Calendar connection…
AplazadaAlta (7.5)0.43%—Salonbookingsystem Salon Booking SystemAI10/8/202626/8/2026
The Salon Booking System WordPress plugin before 10.30.34 does not properly validate a booking's ownership token before loading it in its booking-wizard confirmation steps, allowing unauthenticated attackers to disclose other customers' booking records, including personal information, by supplying a sequential booking…
AplazadaMedia (5.3)0.30%—Salonbookingsystem Salon Booking SystemAI10/8/202626/8/2026
The Salon Booking System WordPress plugin before 10.30.34 does not properly restrict access to some of its booking-modification AJAX actions and does not verify ownership of the targeted booking, allowing unauthenticated users to tamper with the stored total of arbitrary bookings.
AplazadaMedia (4.3)0.27%—Salonbookingsystem Salon Booking SystemAI10/8/202626/8/2026
The Salon Booking System WordPress plugin through 10.31.0 does not verify that a requested booking belongs to the caller on one of its REST API endpoints, requiring only a basic read capability, allowing any authenticated user (including a Subscriber or self-registered customer account) to disclose any customer's…
AplazadaMedia (5.4)0.23%—Motopress Hotel BookingAI10/8/202626/8/2026
The MotoPress Hotel Booking WordPress plugin before 6.2.3 does not verify record ownership before updating customer records, allowing any authenticated user with a low-privileged account (Subscriber and above) to modify or overwrite the personal data of any customer by supplying an arbitrary identifier.
AplazadaMedia (5.3)0.30%—Motopress Hotel BookingAI10/8/202626/8/2026
The MotoPress Hotel Booking WordPress plugin before 6.2.3 does not perform any authorization or ownership check on a REST endpoint that creates payment records, allowing unauthenticated users to create completed payment records against arbitrary bookings and falsely mark them as paid.
AplazadaMedia (5.3)0.30%—Pinpoint Booking SystemAI10/8/202626/8/2026
The Pinpoint Booking System WordPress plugin through 2.9.9.7.1 does not validate the booking price on the server side, allowing unauthenticated users to create bookings at an arbitrary price (including zero) and, by selecting a specific payment method, obtain an instantly-approved reservation.
AplazadaBaja (3.8)0.26%—Booking FOR Appointments AND Events CalendarAI10/8/202626/8/2026
The Booking for Appointments and Events Calendar WordPress plugin before 9.7 does not verify that an authenticated employee (provider) is related to the customer whose record is being accessed, allowing any employee with an Employee Panel login to read and modify the stored personal data of any customer by enumerating…
AplazadaMedia (5.3)0.30%—Dwbooster Appointment Hour BookingAI8/8/202626/8/2026
The Appointment Hour Booking WordPress plugin before 1.5.88 does not validate a client-supplied booking price against the server-side configured service price, allowing unauthenticated users to submit an arbitrary final price (including zero or negative) that is stored as the authoritative booking price, corrupting…
AplazadaCrítica (9.4)0.38%—Openreception Appointment Booking SoftwareAI6/8/20268/9/2026
OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.4, the route `POST /api/tenants/{tenantId}/staff/{staffId}/crypto` accepts and stores attacker-controlled ML-KEM-768 public keys against any tenant on the platform without authentication.…
AplazadaCrítica (9.8)0.57%—Openreception Appointment Booking SoftwareAI6/8/20268/9/2026
OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, the registration handler at `POST /api/auth/register/{userId}` validates the relationship between the WebAuthn challenge and the registration cookie's email but never validates that the…
AplazadaCrítica (9.9)0.44%—Openreception Appointment Booking SoftwareAI6/8/20268/9/2026
OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, a TENANT_ADMIN promotes themselves to platform-wide GLOBAL_ADMIN through a single PUT request. The role-update handler accepts the `GLOBAL_ADMIN` enum value from any tenant admin updating…
AplazadaAlta (7.4)0.39%—Openreception Appointment Booking SoftwareAI6/8/20268/9/2026
OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Versions prior to 1.0.2 don't throttle failed passphrase login attempts. An attacker can submit unlimited wrong passphrase guesses against any known email address, capped only by the Argon2 verification cost…
AplazadaMedia (6.5)0.36%—Openreception Appointment Booking SoftwareAI6/8/20268/9/2026
OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, the `/api/log` endpoint accepts unauthenticated POST requests, applies no schema validation to the message body, writes attacker-controlled content directly into the application's stdout…
AplazadaBaja (3.7)0.39%—Openreception Appointment Booking SoftwareAI6/8/20268/9/2026
OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.6, the bootstrap challenge endpoint at `/api/tenants/{id}/appointments/bootstrap-challenge` issues a SHA-256 proof-of-work with `difficulty=4` hex zeros, equivalent to 16 bits of work.…