Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
150 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.50% | — | Phpjabbers Time Slots Booking Calendar | 1/8/2023 | 17/6/2026 | There is a Cross Site Scripting (XSS) vulnerability in the "theme" parameter of preview.php in PHPJabbers Time Slots Booking Calendar v3.3. | |
| Modificada | Alta (8.8) | 0.76% | — | Phpjabbers Time Slots Booking Calendar | 1/8/2023 | 17/6/2026 | In PHP Jabbers Time Slots Booking Calendar 3.3 , lack of verification when changing an email address and/or password (on the Profile Page) allows remote attackers to take over accounts. | |
| Modificada | Crítica (9.8) | 0.77% | — | Phpjabbers Time Slots Booking Calendar | 1/8/2023 | 17/6/2026 | User enumeration is found in in PHP Jabbers Time Slots Booking Calendar v3.3. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users. | |
| Modificada | Crítica (9.8) | 0.99% | — | Phpjabbers Time Slots Booking Calendar | 1/8/2023 | 17/6/2026 | Improper input validation of password parameter in PHP Jabbers Time Slots Booking Calendar v 3.3 results in insecure passwords. | |
| Modificada | Media (6.1) | 0.50% | — | Phpjabbers Time Slots Booking Calendar | 1/8/2023 | 17/6/2026 | There is a Cross Site Scripting (XSS) vulnerability in "cid" parameter of preview.php in PHPJabbers Time Slots Booking Calendar v3.3. | |
| Modificada | Media (5.4) | 0.56% | — | Gzscripts Availability Booking Calendar PHP | 27/7/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in GZ Scripts Availability Booking Calendar PHP 1.0. This affects an unknown part of the file /index.php?controller=GzUser&action=edit&id=1 of the component Image Handler. The manipulation of the argument img leads to cross site scripting. It is possible… | |
| Modificada | Media (5.4) | 0.56% | — | Gzscripts Availability Booking Calendar PHP | 27/7/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in GZ Scripts Availability Booking Calendar PHP 1.0. Affected by this issue is some unknown functionality of the file index.php of the component HTTP POST Request Handler. The manipulation of the argument promo_code leads to cross site scripting. The… | |
| Modificada | Media (6.1) | 0.41% | — | Booking Calendar Project Booking Calendar | 18/7/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in CodePeople Booking Calendar Contact Form plugin <= 1.2.40 versions. | |
| Modificada | Media (5.4) | 0.51% | — | Gzscripts Event Booking Calendar | 10/7/2023 | 17/6/2026 | A vulnerability classified as problematic has been found in GZ Scripts Event Booking Calendar 1.8. Affected is an unknown function of the file /load.php. The manipulation of the argument first_name/second_name/phone/address_1/country leads to cross site scripting. It is possible to launch the attack remotely. The… | |
| Modificada | Media (6.1) | 0.39% | — | Gzscripts Time Slot Booking Calendar PHP | 7/7/2023 | 17/6/2026 | A vulnerability was found in GZ Scripts Time Slot Booking Calendar PHP 1.8. It has been declared as problematic. This vulnerability affects unknown code of the file /load.php. The manipulation of the argument first_name/second_name/phone/address_1/country leads to cross site scripting. The attack can be initiated… | |
| Modificada | Media (6.1) | 0.39% | — | Gzscripts Availability Booking Calendar PHP | 7/7/2023 | 17/6/2026 | A vulnerability was found in GZ Scripts Availability Booking Calendar PHP 1.8. It has been classified as problematic. This affects an unknown part of the file load.php of the component HTTP POST Request Handler. The manipulation of the argument cid/first_name/second_name/address_1/country leads to cross site… | |
| Modificada | Alta (8.8) | 0.26% | — | Bookingultrapro Booking Ultra PRO Appointments Booking Calendar | 24/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Booking Ultra Pro Appointments Booking Calendar Plugin plugin <= 1.1.4 versions. | |
| Modificada | Media (5.4) | 0.38% | — | Wpdevart Booking Calendar | 29/3/2023 | 17/6/2026 | Auth. (editor+) Stored Cross-Site Scripting (XSS) vulnerability in WpDevArt Booking calendar, Appointment Booking System plugin <= 3.2.3 versions. | |
| Modificada | Media (5.4) | 0.23% | — | Wpdevart Booking Calendar | 17/2/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WpDevArt Booking calendar, Appointment Booking System plugin <= 3.2.3 versions affects plugin forms actions (create, duplicate, edit, delete). | |
| Modificada | Crítica (9.8) | 4.5% | 💥 Exploit | Wpdevart Booking Calendar | 12/12/2022 | 17/6/2026 | The Booking calendar, Appointment Booking System WordPress plugin before 3.2.2 does not validate uploaded files, which could allow unauthenticated users to upload arbitrary files, such as PHP and achieve RCE | |
| Modificada | Media (6.5) | 0.25% | — | Elbtide Advanced Booking Calendar | 5/12/2022 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Advanced Booking Calendar plugin <= 1.7.1 on WordPress. | |
| Modificada | Crítica (9.8) | 0.81% | — | Elbtide Advanced Booking Calendar | 5/12/2022 | 17/6/2026 | Unauth. SQL Injection (SQLi) vulnerability in Advanced Booking Calendar plugin <= 1.7.1 on WordPress. | |
| Modificada | Alta (8.8) | 0.54% | — | Codepeople Appointment Booking Calendar | 18/11/2022 | 17/6/2026 | Missing Authorization vulnerability in Appointment Booking Calendar plugin <= 1.3.69 on WordPress. | |
| Modificada | Media (6.1) | 0.27% | — | Bookingultrapro Booking Ultra PRO Appointments Booking Calendar | 30/9/2022 | 17/6/2026 | Cross-Site Scripting (XSS) via Cross-Site Request Forgery (CSRF) vulnerability in Booking Ultra Pro plugin <= 1.1.4 at WordPress. | |
| Modificada | Alta (8.8) | 0.34% | — | Bookingultrapro Booking Ultra PRO Appointments Booking Calendar | 30/9/2022 | 17/6/2026 | Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in Booking Ultra Pro plugin <= 1.1.4 at WordPress. | |
| Modificada | Media (4.3) | 0.32% | — | Wpbookingcalendar Booking Calendar | 6/9/2022 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WPdevelop/Oplugins Booking Calendar plugin <= 9.2.1 at WordPress leading to Translations Update. | |
| Modificada | Alta (8.8) | 1.7% | — | Booking Calendar Project Booking Calendar | 10/5/2022 | 17/6/2026 | The Booking Calendar plugin for WordPress is vulnerable to PHP Object Injection via the [bookingflextimeline] shortcode in versions up to, and including, 9.1. This could be exploited by subscriber-level users and above to call arbitrary PHP objects on a vulnerable site. | |
| Modificada | Media (6.1) | 1.9% | 💥 Exploit | Elbtide Advanced Booking Calendar | 11/4/2022 | 17/6/2026 | The Advanced Booking Calendar WordPress plugin before 1.7.1 does not sanitise and escape the room parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting issue | |
| Modificada | Alta (7.2) | 1.5% | — | Elbtide Advanced Booking Calendar | 11/4/2022 | 17/6/2026 | The Advanced Booking Calendar WordPress plugin before 1.7.1 does not sanitise and escape the id parameter when editing Calendars, which could allow high privilege users such as admin to perform SQL injection attacks | |
| Modificada | Crítica (9.8) | 1.8% | — | Elbtide Advanced Booking Calendar | 21/3/2022 | 17/6/2026 | The Advanced Booking Calendar WordPress plugin before 1.7.0 does not validate and escape the calendar parameter before using it in a SQL statement via the abc_booking_getSingleCalendar AJAX action (available to both unauthenticated and authenticated users), leading to an unauthenticated SQL injection |