Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

3072 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8)0.47%—Openreception Appointment Booking SoftwareAI6/8/20268/9/2026
OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, the `GET /api/tenants/{id}` endpoint returns the full tenant record to any authenticated `TENANT_ADMIN` of that tenant, including the `databaseUrl` field. This field contains the live…
AplazadaAlta (7.4)0.50%—Openreception Appointment Booking SoftwareAI6/8/20268/9/2026
OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, when a user navigates to the `/logout` page, the page's server-side load handler deletes the `access_token` cookie before calling `/api/auth/logout` via an internal `event.fetch()`. The…
AplazadaMedia (5.3)0.34%—Openreception Appointment Booking SoftwareAI6/8/20268/9/2026
OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.5, the unauthenticated `/api/tenants/{id}/schedule` endpoint returns every non-archived channel for a tenant regardless of the channel's `isPublic` flag. Channels marked `isPublic = false`…
AplazadaMedia (5.3)0.43%—Openreception Appointment Booking SoftwareAI6/8/20268/9/2026
OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.1.0, the GET handler at `/api/tenants/{id}/appointments/{appointmentId}` performs no authorization check before returning the appointment record. Any party who knows or obtains a valid…
AplazadaMedia (6.5)0.33%—Openreception Appointment Booking SoftwareAI6/8/20268/9/2026
OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. The new-client booking flow in versions 1.0.1 and prior consists of three calls: `bootstrap-challenge` (returns a 16-bit PoW challenge with `difficulty=4` leading hex zeroes), `bootstrap-verify` (validates the…
AplazadaMedia (6.5)0.42%—Openreception Appointment Booking SoftwareAI6/8/20268/9/2026
OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.5, the `add-to-tunnel` endpoint creates a new appointment row in any client tunnel without any caller authentication. A request that supplies any valid `tunnelId` and any valid `emailHash`…
AplazadaBaja (2.7)0.29%—Openreception Appointment Booking SoftwareAI6/8/20268/9/2026
OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.6, when a TENANT_ADMIN deletes an existing staff user, the underlying `StaffService.deleteStaffMember()` runs an additional invite cleanup that deletes from the central `user_invite` table…
AplazadaMedia (5.8)0.40%—Openreception Appointment Booking SoftwareAI6/8/20268/9/2026
OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.4, the PIN-type challenge throttle uses `emailHash` as the only key. The throttle rows live in the central `challenge_throttle` table, which is shared across all tenants. Every tenant's…
Pendiente de análisisCrítica (9.3)0.18%—Sophos Endpoint FOR MacosAISophos Home FOR MacosAI6/8/20261/9/2026
A privilege escalation vulnerability allows local users to execute arbitrary code as root via Sophos Endpoint for macOS older than version 2026.1.1 and Sophos Home for macOS older than version 10.11.6.
AplazadaBaja (2.7)0.32%—Easyappointments Easy AppointmentsAI6/8/202626/8/2026
The Easy Appointments WordPress plugin before 3.12.28 does not correctly validate shortcode input in one of its block-rendering actions, checking only the first tag of the supplied string against an allowlist while rendering the entire string, allowing users with contributor-level access to execute arbitrary…
AplazadaAlta (7.1)0.25%—Simply Schedule AppointmentsAI6/8/202612/8/2026
Unauthenticated Cross Site Scripting (XSS) in Simply Schedule Appointments <= 1.6.12.10 versions.
AplazadaCrítica (9.3)0.40%—Simply Schedule AppointmentsAI6/8/202612/8/2026
Unauthenticated SQL Injection in Simply Schedule Appointments <= 1.6.12.10 versions.
AplazadaMedia (6.4)0.26%—LatepointAI6/8/202612/8/2026
The LatePoint plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'btn_wrapper_classes' attribute of the 'latepoint_resources' shortcode in all versions up to, and including, 5.3.2. This is due to insufficient input sanitization and output escaping in the 'locations' branch of the…
AplazadaAlta (7.5)0.54%—VikappointmentsAI5/8/202612/8/2026
VikAppointments Service Booking Calendar wordpress plugin is vulnerable to unauthenticated SQL injection due to one of the parameters that controls how the public reviews list is sorted is taken from the incoming request and used to build a database query without proper validation or sanitization. Because this value…
Pendiente de análisisCrítica (9.3)1.4%—Keysight Ixchariot EndpointAI4/8/202626/8/2026
Keysight IxChariot Endpoint and associated products contain a stack-based buffer overflow. An unauthenticated remote attacker can send a specially crafted packet and execute arbitrary code with administrative privileges.
Pendiente de análisisCrítica (9.3)1.3%—Keysight Ixchariot EndpointAI4/8/202626/8/2026
Keysight IxChariot Endpoint before 9.5.102 contains a stack-based buffer overflow. An unauthenticated remote attacker can send a specially crafted packet to crash the endpoint or potentially execute arbitrary code.
Pendiente de análisisCrítica (9.3)1.3%—Keysight Ixchariot EndpointAI4/8/202626/8/2026
Keysight IxChariot Endpoint before 9.5.102 contains a heap-based buffer overflow. An unauthenticated remote attacker can send a specially crafted packet to crash the endpoint or potentially execute arbitrary code.
Pendiente de análisisMedia (6.7)0.36%💥 PoCLangchain Langgraph-checkpoint-mongodbAI4/8/20269/9/2026
@langchain/langgraph-checkpoint-mongodb provides a LangGraph.js CheckpointSaver implementation that uses MongoDB for storage. Versions 1.3.0 and below are vulnerable to NoSQL injection: checkpoint identifiers (thread_id, checkpoint_ns, checkpoint_id) from config.configurable are passed into MongoDB find() queries in…
Pendiente de análisisCrítica (9.3)0.89%💥 PoCCheckpoint Security Management ServerAICheckpoint Multi Domain Security Management ServerAI3/8/20265/8/2026
An authentication bypass vulnerability in Check Point Security Management Server and Multi-Domain Security Management Server (MDS) could allow an unauthenticated remote attacker with network access to Management services to execute arbitrary commands on the Security Management Server. Successful exploitation could…
AplazadaMedia (6.5)0.34%—Simply Schedule AppointmentsAI3/8/202626/8/2026
The Simply Schedule Appointments WordPress plugin before 1.6.12.11 does not perform a capability check on an administrative appointment-listing shortcode, and its per-user result scoping fails open for non-staff users, allowing users with the Contributor role and above to disclose all customers' appointment records,…
AplazadaAlta (7.5)0.41%💥 PoCSimply Schedule AppointmentsAI2/8/202626/8/2026
The Simply Schedule Appointments WordPress plugin before 1.6.12.6 does not correctly restrict a bulk appointment operation to the requester's own records, allowing unauthenticated users to retrieve the personal data of all appointments across the site and, on premium editions, to permanently delete them.
AplazadaBaja (2.7)0.28%—Booking FOR Appointments AND Events CalendarAI1/8/202626/8/2026
The Booking for Appointments and Events Calendar WordPress plugin before 2.4.4 does not restrict which fields can be written through its customer import, allowing a user with the Amelia Manager role to modify arbitrary columns of any stored user record by supplying them in the import request.
AplazadaMedia (4.9)0.44%—Pinpoint Booking SystemAI1/8/202612/8/2026
The Pinpoint Booking System – Version 2 plugin for WordPress is vulnerable to blind SQL Injection via the 'field' parameter in all versions up to, and including, 2.9.9.6.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible…
AplazadaMedia (5.3)0.34%—Appointment Booking PluginAI30/7/202630/7/2026
The Appointment Booking Plugin WordPress plugin before 5.6.8 does not restrict which booking fields an unauthenticated visitor can set through its public booking funnel, allowing an unauthenticated user to assign a privileged booking field such as the approval status and thereby bypass the site's booking approval…
AplazadaMedia (4.3)0.29%—Easyappointments Easy AppointmentsAI30/7/202610/8/2026
The Easy Appointments WordPress plugin before 3.12.28 does not require a sufficient capability on one of its appointment-listing REST endpoints, restricting it only to a capability that every authenticated user holds, allowing users with subscriber-level access to read all bookings on the site, including customer…