Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
3072 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 0.20% | — | Simply Schedule AppointmentsAI | 2/9/2026 | 4/9/2026 | Unauthenticated Cross Site Request Forgery (CSRF) in Simply Schedule Appointments <= 1.6.12.23 versions. | |
| Aplazada | Media (5.3) | 0.22% | — | Motopress Appointment BookingAI | 2/9/2026 | 3/9/2026 | The MotoPress Appointment Booking WordPress plugin before 2.4.8 does not perform an authorization or ownership check when handling a user-supplied booking identifier on an unauthenticated endpoint, allowing unauthenticated attackers to permanently delete other users' reservations. This is an incomplete fix of… | |
| Aplazada | Media (6.5) | 0.30% | — | Booking FOR Appointments AND Events CalendarAI | 2/9/2026 | 3/9/2026 | The Booking for Appointments and Events Calendar WordPress plugin before 2.4.9 does not require authentication or a valid request token before running the post-booking action chain, allowing an unauthenticated user to trigger booking notifications and integration callbacks for a booking by enumerating its identifier. | |
| Aplazada | Baja (2.7) | 0.28% | — | Booking FOR Appointments AND Events CalendarAI | 29/8/2026 | 31/8/2026 | The Booking for Appointments and Events Calendar WordPress plugin before 2.4.9 does not check that a user holds the required capability before letting them change an appointment's status, allowing customers to set arbitrary statuses on appointments they are booked on, including approving their own bookings that were… | |
| Aplazada | Alta (7.5) | 0.36% | — | Appointment Booking Calendar Plugin AND Scheduling PluginAI | 29/8/2026 | 31/8/2026 | The Appointment Booking Calendar Plugin and Scheduling Plugin WordPress plugin before 1.6.3 does not verify the amount actually paid against the server-side price staged for a booking when confirming an online payment, allowing unauthenticated users to have a paid appointment approved for a fraction of its price. | |
| Aplazada | Media (6.5) | 0.30% | — | Booking FOR Appointments AND Events CalendarAI | 26/8/2026 | 26/8/2026 | The Booking for Appointments and Events Calendar WordPress plugin before 2.4.7 does not require authentication before processing its pending notification queue, allowing an unauthenticated user to force the dispatch of queued notifications and integration callbacks. | |
| Aplazada | Media (4.7) | 0.20% | — | Booking FOR Appointments AND Events CalendarAI | 26/8/2026 | 26/8/2026 | The Booking for Appointments and Events Calendar WordPress plugin before 9.8 does not verify that an authenticated employee (provider) owns the provider account being updated, allowing any employee with an Employee Panel login to overwrite another employee's cabinet password and take over their account. | |
| Aplazada | Media (4.6) | 0.14% | — | Myna PointAI | 26/8/2026 | 28/8/2026 | Android application "Myna Point" is vulnerable to Improper Authorization in Handler for Custom URL Scheme (CWE-939). A malicious application installed on the user's Android device may exploit the affected application's functionality through an Intent, potentially allowing arbitrary JavaScript to be executed within the… | |
| Analizada | Crítica (10) | 0.23% | — | Google Nest Wifi Router FirmwareGoogle Nest Wifi Point FirmwareGoogle Nest Wifi PRO Firmware | 24/8/2026 | 7/10/2026 | Multiple vulnerabilities exist in OpenThread's handling of MLE packets. An authenticated attacker on the same Thread network could send specially crafted packets to cause a denial of service. These issues include triggerable assertion failures and a stack-based buffer overflow. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Bookingpress Appointment Booking PROAI | 20/8/2026 | 20/8/2026 | Unauthenticated SQL Injection in BookingPress Appointment Booking Pro <= 6.0.2 versions. | |
| Pendiente de análisis | Alta (7.2) | 2.0% | — | Dell Recoverpoint FOR VMSAI | 19/8/2026 | 20/8/2026 | Dell RecoverPoint for VMs, versions 6.0.3 and 6.0.3.1, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution. | |
| Aplazada | Baja (2.7) | 0.32% | — | Easyappointments Easy AppointmentsAI | 19/8/2026 | 26/8/2026 | The Easy Appointments WordPress plugin before 4.0.1 does not restrict one of its appointment-listing REST endpoints to the records belonging to the requesting user, allowing users with contributor-level access to read all bookings on the site, including customer names, schedules, and statuses. | |
| Aplazada | Alta (8.8) | 0.54% | — | Booking Calendar Appointment Booking SystemAI | 19/8/2026 | 26/8/2026 | The Booking calendar, Appointment Booking System WordPress plugin through 3.2.36 does not properly sanitize uploaded SVG files, allowing unauthenticated attackers to upload a file that bypasses the Booking calendar, Appointment Booking System WordPress plugin through 3.2.36's script-stripping and executes arbitrary… | |
| Aplazada | Media (6.5) | 0.33% | — | Appointment Booking SystemAI | 18/8/2026 | 20/8/2026 | Unauthenticated Insecure Direct Object References (IDOR) in Booking calendar, Appointment Booking System <= 3.2.36 versions. | |
| Aplazada | Crítica (9.3) | 0.40% | — | JetappointmentAI | 18/8/2026 | 20/8/2026 | Unauthenticated SQL Injection in JetAppointment <= 2.5.2 versions. | |
| Aplazada | Media (6.5) | 0.35% | — | Dwbooster Appointment Hour BookingAI | 18/8/2026 | 20/8/2026 | Unauthenticated Broken Access Control in Appointment Hour Booking <= 1.5.91 versions. | |
| Pendiente de análisis | Alta (7.3) | 0.13% | — | Beyondtrust Endpoint Privilege ManagementAI | 17/8/2026 | 18/8/2026 | A memory-corruption vulnerability exists in a kernel-mode component of BeyondTrust Endpoint Privilege Management (Windows deployments) prior to version 26.1.2. Insufficient validation of input processed by the component may result in memory being accessed outside its intended bounds. | |
| Aplazada | Media (6.5) | 0.68% | — | Simply Schedule Appointments Appointment Booking CalendarAI | 16/8/2026 | 20/8/2026 | The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.6.12.10 via the ssa_past_appointments due to missing validation on a user controlled key. This makes it possible for… | |
| Aplazada | Baja (2.9) | 0.63% | — | Opensourcepos Open Source Point OF SaleAI | 15/8/2026 | 20/8/2026 | A vulnerability was detected in opensourcepos Open Source Point of Sale up to 3.4.2. This affects the function Login::index of the file app/Config/Filters.php of the component Login Endpoint. The manipulation results in improper restriction of excessive authentication attempts. The attack may be launched remotely. The… | |
| Aplazada | Media (6.5) | 0.37% | — | Simply Schedule AppointmentsAI | 15/8/2026 | 26/8/2026 | The Simply Schedule Appointments WordPress plugin before 1.6.12.17 does not restrict the user records returned by some of its REST endpoints to those the requester is entitled to see, allowing users with a low-privileged staff role to disclose the names and email addresses of arbitrary registered users. | |
| Aplazada | Media (5.3) | 0.61% | — | Pinpoint Booking SystemAI | 15/8/2026 | 20/8/2026 | The Pinpoint Booking System – Version 2 plugin for WordPress is vulnerable to Price Manipulation via the `cart_data` parameter in all versions up to, and including, 2.9.9.6.8. This is due to the `dopbsp_woocommerce_add_to_cart` AJAX action being registered via `wp_ajax_nopriv_*` with no authentication, no nonce… | |
| Aplazada | Baja (2) | 0.40% | — | Sourcecodester Simple Doctors Appointment SystemAI | 14/8/2026 | 18/8/2026 | A vulnerability was detected in SourceCodester Simple Doctors Appointment System 1.0. This issue affects the function save_doctor of the file /save_file.php. The manipulation results in unrestricted upload. The attack can be executed remotely. The exploit is now public and may be used. | |
| Pendiente de análisis | Media (5.7) | 0.11% | — | Elan Trackpoint DriverAI | 13/8/2026 | 24/8/2026 | ELAN reported a potential out-of-bounds write vulnerability in the ELAN TrackPoint driver that, under certain circumstances, could allow a local authenticated user to cause a system crash. | |
| Aplazada | Alta (7.5) | 0.42% | — | Woocommerce AppointmentsAI | 13/8/2026 | 14/8/2026 | Unauthenticated Sensitive Data Exposure in WooCommerce Appointments <= 5.3.8 versions. | |
| Pendiente de análisis | Media (4.8) | 0.16% | — | Forcepoint ONE EndpointAI | 13/8/2026 | 3/9/2026 | This vulnerability allows a normal (non-admin) user to disable the Forcepoint One Endpoint SafariExtension and bypass DLP protection in F1E Mac OS before v26.04.5758. |