Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 572 respecto a la semana anterior
Críticas / altas1301▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
244 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 2.1% | 💥 PoC | Apache Dolphinscheduler | 20/8/2024 | 17/6/2026 | Exposure of Remote Code Execution in Apache Dolphinscheduler. This issue affects Apache DolphinScheduler: before 3.2.2. We recommend users to upgrade Apache DolphinScheduler to version 3.2.2, which fixes the issue. | |
| Modificada | Alta (8.1) | 6.0% | 💥 Exploit | Apache Dolphinscheduler | 12/8/2024 | 17/6/2026 | File read and write vulnerability in Apache DolphinScheduler , authenticated users can illegally access additional resource files. This issue affects Apache DolphinScheduler: from 3.1.0 before 3.2.2. Users are recommended to upgrade to version 3.2.2, which fixes the issue. | |
| Analizada | Alta (8.8) | 1.2% | — | Apache Dolphinscheduler | 12/8/2024 | 17/6/2026 | Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can cause arbitrary, unsandboxed javascript to be executed on the server. If you are using the switch task plugin, please upgrade to version 3.2.2. | |
| Aplazada | Media (5.5) | 0.30% | — | Motopress Timetable AND Event ScheduleAI | 1/8/2024 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in MotoPress Timetable and Event Schedule allows Object Injection.This issue affects Timetable and Event Schedule: from n/a through 2.4.13. | |
| Aplazada | Media (5.3) | 0.44% | — | SchedulepressAI | 16/7/2024 | 17/6/2026 | The SchedulePress – Auto Post & Publish, Auto Social Share, Schedule Posts with Editorial Calendar & Missed Schedule Post Publisher plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 5.1.3. This is due the plugin utilizing the wpdeveloper library and leaving the demo files… | |
| Aplazada | Media (5.3) | 0.33% | — | Jupyter SchedulerAI | 23/5/2024 | 17/6/2026 | Jupyter Scheduler is collection of extensions for programming jobs to run now or run on a schedule. The list of conda environments of `jupyter-scheduler` users maybe be exposed, potentially revealing information about projects that a specific user may be working on. This vulnerability has been patched in version(s)… | |
| Modificada | Media (5.4) | 0.32% | — | Nsquared Simply Schedule Appointments | 16/5/2024 | 17/6/2026 | The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘link’ parameter in versions up to, and including, 1.6.7.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| Aplazada | Media (5.4) | 0.23% | — | Revmakx Wpcal.io Easy Meeting SchedulerAI | 14/5/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Revmakx WPCal.Io – Easy Meeting Scheduler.This issue affects WPCal.Io – Easy Meeting Scheduler: from n/a through 0.9.5.8. | |
| Aplazada | Media (6.5) | 0.60% | — | Wpdeveloper SchedulepressAI | 14/5/2024 | 17/6/2026 | Missing Authorization vulnerability in WPDeveloper SchedulePress.This issue affects SchedulePress: from n/a through 5.0.8. | |
| Aplazada | Media (6.6) | 0.33% | 💥 PoC | Quest Kace Agent FOR WindowsAIQuest KschedulersvcAIQuest Kuser AlertAIQuest RunkbotAI | 30/4/2024 | 17/6/2026 | An issue was discovered in Quest KACE Agent for Windows 12.0.38 and 13.1.23.0. An Arbitrary file create vulnerability exists in the KSchedulerSvc.exe, KUserAlert.exe, and Runkbot.exe components. This allows local attackers to create any file of their choice with NT Authority\SYSTEM privileges. | |
| Aplazada | Crítica (9.9) | 0.56% | — | Motopress Timetable AND Event ScheduleAI | 27/4/2024 | 17/6/2026 | The Timetable and Event Schedule by MotoPress plugin for WordPress is vulnerable to SQL Injection via the 'events' attribute of the 'mp-timetable' shortcode in all versions up to, and including, 2.4.11 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL… | |
| Aplazada | Media (4.3) | 0.20% | — | Coschedule Headline AnalyzerAI | 24/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in CoSchedule Headline Analyzer.This issue affects Headline Analyzer: from n/a through 1.3.3. | |
| Aplazada | Media (4.3) | 0.20% | — | Revmakx Wpcal.io Easy Meeting SchedulerAI | 24/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Revmakx WPCal.Io – Easy Meeting Scheduler.This issue affects WPCal.Io – Easy Meeting Scheduler: from n/a through 0.9.5.8. | |
| Aplazada | Media (6.5) | 0.31% | — | Yoga Schedule MomoyogaAI | 17/4/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Momoyoga Yoga Schedule Momoyoga allows Stored XSS.This issue affects Yoga Schedule Momoyoga: from n/a through 2.7.0. | |
| Modificada | Alta (8.8) | 0.59% | — | Nsquared Simply Schedule Appointments | 9/4/2024 | 17/6/2026 | The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to SQL Injection via the customer_id parameter in all versions up to, and including, 1.6.7.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing… | |
| Modificada | Media (6.5) | 0.60% | — | Nsquared Simply Schedule Appointments | 9/4/2024 | 17/6/2026 | The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to SQL Injection via the keys parameter in all versions up to, and including, 1.6.7.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL… | |
| Aplazada | Alta (7.1) | 0.35% | — | Pulsar WEB Design Weekly Class ScheduleAI | 31/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pulsar Web Design Weekly Class Schedule allows Reflected XSS.This issue affects Weekly Class Schedule: from n/a through 3.19. | |
| Analizada | Alta (7.3) | 0.28% | — | Fortra Robot Schedule | 28/3/2024 | 17/6/2026 | Fortra's Robot Schedule Enterprise Agent for Windows prior to version 3.04 is susceptible to privilege escalation. A low-privileged user can overwrite the service executable. When the service is restarted, the replaced binary runs with local system privileges, allowing a low-privileged user to gain elevated privileges. | |
| Aplazada | Alta (7.1) | 0.35% | — | Nsquared Simply Schedule AppointmentsAI | 27/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in N Squared Simply Schedule Appointments allows Reflected XSS.This issue affects Simply Schedule Appointments: from n/a through 1.6.6.20. | |
| Modificada | Media (4.7) | 0.27% | — | Nsquared Simply Schedule Appointments | 6/3/2024 | 17/6/2026 | The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.6.6.20. This is due to missing or incorrect nonce validation on the ssa_factory_reset() function. This makes it possible for… | |
| Analizada | Alta (8.8) | 1.4% | — | Apache Dolphinscheduler | 23/2/2024 | 17/6/2026 | Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can cause arbitrary, unsandboxed javascript to be executed on the server. This issue is a legacy of CVE-2023-49299. We didn't fix it completely in CVE-2023-49299, and we added one more patch to fix it. This issue affects Apache… | |
| Modificada | Alta (7.5) | 1.2% | 💥 PoC | Apache Dolphinscheduler | 20/2/2024 | 17/6/2026 | Arbitrary File Read Vulnerability in Apache Dolphinscheduler. This issue affects Apache DolphinScheduler: before 3.2.1. We recommend users to upgrade Apache DolphinScheduler to version 3.2.1, which fixes the issue. | |
| Analizada | Media (6.5) | 1.3% | — | Apache Dolphinscheduler | 20/2/2024 | 17/6/2026 | Session Fixation Apache DolphinScheduler before version 3.2.0, which session is still valid after the password change. Users are recommended to upgrade to version 3.2.1, which fixes this issue. | |
| Analizada | Alta (7.3) | 0.70% | — | Apache Dolphinscheduler | 20/2/2024 | 17/6/2026 | Because the HttpUtils class did not verify certificates, an attacker that could perform a Man-in-the-Middle (MITM) attack on outgoing https connections could impersonate the server. This issue affects Apache DolphinScheduler: before 3.2.0. Users are recommended to upgrade to version 3.2.1, which fixes the issue. | |
| Analizada | Crítica (9.8) | 2.3% | 💥 PoC | Apache Dolphinscheduler | 20/2/2024 | 17/6/2026 | Exposure of Remote Code Execution in Apache Dolphinscheduler. This issue affects Apache DolphinScheduler: before 3.2.1. We recommend users to upgrade Apache DolphinScheduler to version 3.2.1, which fixes the issue. |