Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 546 respecto a la semana anterior
Críticas / altas1325▼ 174 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 241 respecto a la semana anterior
2544 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.61% | — | Pinpoint Booking SystemAI | 15/8/2026 | 20/8/2026 | The Pinpoint Booking System – Version 2 plugin for WordPress is vulnerable to Price Manipulation via the `cart_data` parameter in all versions up to, and including, 2.9.9.6.8. This is due to the `dopbsp_woocommerce_add_to_cart` AJAX action being registered via `wp_ajax_nopriv_*` with no authentication, no nonce… | |
| Aplazada | Media (4.3) | 0.18% | — | Astro Booking EngineAI | 14/8/2026 | 29/9/2026 | The Astro Booking Engine plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.0. This is due to missing nonce validation on the options deletion functionality. This makes it possible for unauthenticated attackers to delete all plugin settings via a forged request… | |
| Aplazada | Media (6.5) | 0.22% | — | WpbookinglyAI | 13/8/2026 | 14/8/2026 | Customer Cross Site Scripting (XSS) in WpBookingly <= 1.3.2 versions. | |
| Aplazada | Crítica (9.8) | 0.61% | — | Salonbookingsystem Salon Booking SystemAI | 13/8/2026 | 14/8/2026 | Unauthenticated Broken Authentication in Salon booking system <= 10.30.26 versions. | |
| Aplazada | Crítica (10) | 0.69% | — | Wp-base BookingAI | 13/8/2026 | 14/8/2026 | Unauthenticated Arbitrary Code Execution in WP BASE Booking <= 6.3.0 versions. | |
| Aplazada | Alta (7.3) | 0.30% | — | Hydra BookingAI | 13/8/2026 | 14/8/2026 | Unauthenticated Broken Access Control in Hydra Booking <= 1.2.2 versions. | |
| Aplazada | Alta (8.8) | 0.46% | — | Booking ActivitiesAI | 13/8/2026 | 14/8/2026 | Unauthenticated PHP Object Injection in Booking Activities <= 1.18.4 versions. | |
| Aplazada | Alta (8.8) | 0.42% | — | Service Finder BookingAI | 13/8/2026 | 14/8/2026 | Subscriber Privilege Escalation in Service Finder Booking <= 6.2 versions. | |
| Aplazada | Media (6.5) | 0.37% | — | Service Finder BookingAI | 13/8/2026 | 14/8/2026 | Subscriber Broken Access Control in Service Finder Booking <= 6.2 versions. | |
| Aplazada | Alta (8.5) | 0.36% | — | Arraytics BookticsAI | 13/8/2026 | 14/8/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Arraytics Booktics allows Blind SQL Injection. This issue affects Booktics: from n/a through 1.0.22. | |
| Aplazada | Alta (7.5) | 0.35% | — | Taxi Booking ManagerAI | 13/8/2026 | 14/8/2026 | Unauthenticated Broken Access Control in Taxi Booking Manager for WooCommerce <= 2.0.3 versions. | |
| Aplazada | Baja (3.7) | 0.26% | — | Booking FOR Appointments AND Events CalendarAI | 13/8/2026 | 26/8/2026 | The Booking for Appointments and Events Calendar WordPress plugin before 2.4.6 does not verify that an authenticated employee (provider) is assigned to the appointment being accessed, allowing any employee to read any appointment by its identifier and disclose the booked customer's personal data. | |
| Aplazada | Alta (8.7) | 0.42% | — | Mrbs Meeting Room Booking SystemAI | 13/8/2026 | 9/9/2026 | The Meeting Room Booking System (MRBS) is a PHP-based application for booking meeting rooms. Prior to version 1.12.2, a user-supplied private/local URI can be made to be fetched without checks. Version 1.12.2 contains a fix. No known workarounds are available. | |
| Aplazada | Alta (7.5) | 0.44% | — | Calibre-ebook CalibreAI | 11/8/2026 | 9/9/2026 | calibre is an e-book manager. Prior to 9.12.0, the calibre Content Server endpoint POST /book-update-annotations/{library_id}/{book_id}/{fmt} in src/calibre/srv/books.py omits needs_db_write=True, causing Router.dispatch() to skip ctx.check_for_write_access() before update_annotations() passes attacker-controlled JSON… | |
| Aplazada | Alta (8.5) | 0.20% | — | Calibre-ebook CalibreAI | 11/8/2026 | 9/9/2026 | calibre is an e-book manager. Prior to 9.12.0, calibre processes attacker-controlled composite_template metadata from a malicious EPUB, OPF, PDF, or similar file through program: and a nested template() call whose formatter does not inherit allow_python_templates=False, allowing a nested python: template to reach… | |
| Aplazada | Media (5.3) | 0.46% | — | AudiobookshelfAI | 11/8/2026 | 9/9/2026 | Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.36.0, the jwtAuthCheck function in server/auth/TokenManager.js treats JWTs with the refresh token type as bearer access tokens on API and WebSocket resource endpoints such as /api/me instead of restricting them to /auth/refresh, allowing refresh… | |
| Aplazada | Media (4.3) | 0.25% | — | FoodboxbookerAI | 10/8/2026 | 26/8/2026 | The FoodBoxBooker WordPress plugin before 1.0.8 does not verify that the user account being updated belongs to the user making the request, allowing authenticated users, with Subscriber-level access and above, to modify the profile details of arbitrary users, including administrators. | |
| Aplazada | Media (4.8) | 0.27% | — | Salonbookingsystem Salon Booking SystemAI | 10/8/2026 | 26/8/2026 | The Salon Booking System WordPress plugin through 10.30.33 does not perform any capability check or validate an OAuth state value on its Google Calendar authorization callback, which is also hooked for unauthenticated users, allowing an unauthenticated attacker to overwrite the site's stored Google Calendar connection… | |
| Aplazada | Alta (7.5) | 0.43% | — | Salonbookingsystem Salon Booking SystemAI | 10/8/2026 | 26/8/2026 | The Salon Booking System WordPress plugin before 10.30.34 does not properly validate a booking's ownership token before loading it in its booking-wizard confirmation steps, allowing unauthenticated attackers to disclose other customers' booking records, including personal information, by supplying a sequential booking… | |
| Aplazada | Media (5.3) | 0.30% | — | Salonbookingsystem Salon Booking SystemAI | 10/8/2026 | 26/8/2026 | The Salon Booking System WordPress plugin before 10.30.34 does not properly restrict access to some of its booking-modification AJAX actions and does not verify ownership of the targeted booking, allowing unauthenticated users to tamper with the stored total of arbitrary bookings. | |
| Aplazada | Media (4.3) | 0.27% | — | Salonbookingsystem Salon Booking SystemAI | 10/8/2026 | 26/8/2026 | The Salon Booking System WordPress plugin through 10.31.0 does not verify that a requested booking belongs to the caller on one of its REST API endpoints, requiring only a basic read capability, allowing any authenticated user (including a Subscriber or self-registered customer account) to disclose any customer's… | |
| Aplazada | Crítica (9.8) | 0.50% | — | FoodboxbookerAI | 10/8/2026 | 26/8/2026 | The FoodBoxBooker WordPress plugin before 1.0.7 does not properly validate the password reset request, allowing unauthenticated attackers to reset the password of arbitrary users, including administrators, which could lead to a full site takeover. | |
| Aplazada | Media (5.4) | 0.23% | — | Motopress Hotel BookingAI | 10/8/2026 | 26/8/2026 | The MotoPress Hotel Booking WordPress plugin before 6.2.3 does not verify record ownership before updating customer records, allowing any authenticated user with a low-privileged account (Subscriber and above) to modify or overwrite the personal data of any customer by supplying an arbitrary identifier. | |
| Aplazada | Media (5.3) | 0.30% | — | Motopress Hotel BookingAI | 10/8/2026 | 26/8/2026 | The MotoPress Hotel Booking WordPress plugin before 6.2.3 does not perform any authorization or ownership check on a REST endpoint that creates payment records, allowing unauthenticated users to create completed payment records against arbitrary bookings and falsely mark them as paid. | |
| Aplazada | Media (5.3) | 0.30% | — | Pinpoint Booking SystemAI | 10/8/2026 | 26/8/2026 | The Pinpoint Booking System WordPress plugin through 2.9.9.7.1 does not validate the booking price on the server side, allowing unauthenticated users to create bookings at an arbitrary price (including zero) and, by selecting a specific payment method, obtain an instantly-approved reservation. |