Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
136 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.34% | — | Bookingultrapro Booking Ultra PRO Appointments Booking Calendar | 30/9/2022 | 17/6/2026 | Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in Booking Ultra Pro plugin <= 1.1.4 at WordPress. | |
| Modificada | Media (4.8) | 0.68% | — | Nsqua Simply Schedule Appointments | 29/8/2022 | 17/6/2026 | The Simply Schedule Appointments WordPress plugin before 1.5.7.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Media (5.3) | 1.9% | 💥 Exploit | Nsqua Simply Schedule Appointments | 29/8/2022 | 17/6/2026 | The Simply Schedule Appointments WordPress plugin before 1.5.7.7 is missing authorisation in a REST endpoint, allowing unauthenticated users to retrieve WordPress users details such as name and email address | |
| Modificada | Alta (8.8) | 1.2% | — | Easyappointments | 10/5/2022 | 17/6/2026 | API Privilege Escalation in GitHub repository alextselegidis/easyappointments prior to 1.5.0. Full system takeover. | |
| Modificada | Crítica (9.1) | 44% | 💥 Exploit | Easyappointments | 9/3/2022 | 17/6/2026 | Exposure of Private Personal Information to an Unauthorized Actor in GitHub repository alextselegidis/easyappointments prior to 1.4.3. | |
| Modificada | Media (6.1) | 1.7% | — | Snapappointments Bootstrap-select | 30/9/2020 | 17/6/2026 | bootstrap-select before 1.13.6 allows Cross-Site Scripting (XSS). It does not escape title values in OPTION elements. This may allow attackers to execute arbitrary JavaScript in a victim's browser. | |
| Modificada | Alta (7.5) | 1.3% | — | Easyappointments Easy!appointments | 16/3/2020 | 17/6/2026 | Easy!Appointments 1.3.0 has a Missing Authorization issue allowing retrieval of hashed passwords and salts. | |
| Modificada | Media (6.5) | 0.92% | — | Easyappointments Easy!appointments | 16/3/2020 | 17/6/2026 | Easy!Appointments 1.3.0 has a Guessable CAPTCHA issue. | |
| Modificada | Media (5.3) | 1.5% | — | Easyappointments Easy!appointments | 11/9/2019 | 17/6/2026 | Easy!Appointments 1.3.2 plugin for WordPress allows Sensitive Information Disclosure (Username and Password Hash). | |
| Modificada | Media (6.1) | 0.73% | — | Easy-appointments Easy Appointments | 23/10/2017 | 17/6/2026 | The Easy Appointments plugin before 1.12.0 for WordPress has XSS via a Settings values in the admin panel. | |
| Modificada | Media (4.3) | 1.6% | — | WP Appointments Schedules Project WP Appointments Schedules | 2/7/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in js/test.php in the Appointments Scheduler plugin 1.5 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the lang parameter. |