Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
2544 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.7) | 0.80% | — | Livebook | 5/8/2026 | 10/8/2026 | Not Failing Securely ('Failing Open') vulnerability in livebook-dev livebook allows an unauthenticated network client to obtain full access to a Livebook server that enforces identity through Livebook Teams. A Livebook Agent or App Server connected to Livebook Teams caches the identifier of the deployment group it… | |
| Analizada | Media (6.8) | 0.24% | — | Livebook | 5/8/2026 | 10/8/2026 | Cross-Site Request Forgery (CSRF) vulnerability in livebook-dev livebook allows an attacker to authenticate a victim's browser session under the attacker's own Livebook Teams identity. When Livebook is configured to use Livebook Teams for identity, Livebook.ZTA.LivebookTeams.handle_request/4 in… | |
| Analizada | Alta (7) | 0.61% | — | Livebook | 5/8/2026 | 10/8/2026 | Relative Path Traversal vulnerability in livebook-dev livebook allows an attacker-authored notebook to write a file with attacker-controlled content to an arbitrary path. A .livemd notebook can declare file_entries metadata, each entry carrying a name. Every path that creates a file entry through the user interface… | |
| Analizada | Alta (8.6) | 0.27% | — | Livebook | 5/8/2026 | 10/8/2026 | Origin Validation Error vulnerability in livebook-dev livebook allows untrusted notebook output JavaScript to trigger session-wide keyboard shortcuts, including forced evaluation of all cells and runtime restart. Livebook's JS-view feature renders notebook-defined JavaScript inside a sandboxed, cross-origin iframe… | |
| Analizada | Media (5) | 2.4% | — | Livebook | 5/8/2026 | 10/8/2026 | Improper Neutralization of Special Elements used in an OS Command (OS Command Injection) vulnerability in livebook-dev livebook allows command injection into generated deployment setup commands. LivebookWeb.Hub.Teams.DeploymentGroupAgentComponent.docker_instructions/2 and… | |
| Aplazada | Alta (7.5) | 0.48% | — | Book-management-systemAI | 5/8/2026 | 26/8/2026 | Book-Management-System's Flask API endpoints /student, /record, /books, /find_stu_book, and /find_not_return_book are missing the @login_required decorator that protects sibling routes (/search_student, /storage) in the same file. Because card_id values are sequential integers, the entire student database can be… | |
| Aplazada | Alta (7.5) | 1.9% | 💥 Exploit | AudiobookshelfAI | 5/8/2026 | 26/8/2026 | audiobookshelf's authentication-exemption check (server/routers/Auth.js) matches unauthenticated-allowed GET routes against req.path via a regex requiring a literal /items/:id/cover or /authors/:id/image shape, where req.path retains %2F sequences URL-encoded. CacheManager.handleCoverCache then joins this decoded… | |
| Aplazada | Media (5.4) | 0.23% | — | Event Booking ManagerAI | 2/8/2026 | 26/8/2026 | The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not properly verify authorization on the object being modified when quick-editing events, only checking a global capability, allowing users with the Contributor role and above to modify the title and publication status of arbitrary posts and… | |
| Aplazada | Media (5.4) | 0.23% | — | Event Booking ManagerAI | 2/8/2026 | 26/8/2026 | The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not sanitise or escape event timeline content submitted by users with post-editing access before storing it and rendering it on the public event page, allowing users with the Author role and above to inject arbitrary JavaScript that executes… | |
| Aplazada | Media (6.6) | 0.59% | — | Event Booking ManagerAI | 2/8/2026 | 26/8/2026 | The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not prevent the deserialization of user-controlled input in some of its event content fields, allowing users with Contributor-level access and above to inject PHP objects. No POP chain is present in the Event Booking Manager for WooCommerce… | |
| Aplazada | Baja (2.7) | 0.28% | — | Booking FOR Appointments AND Events CalendarAI | 1/8/2026 | 26/8/2026 | The Booking for Appointments and Events Calendar WordPress plugin before 2.4.4 does not restrict which fields can be written through its customer import, allowing a user with the Amelia Manager role to modify arbitrary columns of any stored user record by supplying them in the import request. | |
| Aplazada | Media (4.9) | 0.44% | — | Pinpoint Booking SystemAI | 1/8/2026 | 12/8/2026 | The Pinpoint Booking System – Version 2 plugin for WordPress is vulnerable to blind SQL Injection via the 'field' parameter in all versions up to, and including, 2.9.9.6.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible… | |
| Aplazada | Media (5.3) | 0.34% | — | Appointment Booking PluginAI | 30/7/2026 | 30/7/2026 | The Appointment Booking Plugin WordPress plugin before 5.6.8 does not restrict which booking fields an unauthenticated visitor can set through its public booking funnel, allowing an unauthenticated user to assign a privileged booking field such as the approval status and thereby bypass the site's booking approval… | |
| Aplazada | Media (4.3) | 0.29% | — | Motopress Hotel BookingAI | 30/7/2026 | 30/7/2026 | The MotoPress Hotel Booking WordPress plugin before 6.0.4 does not perform a capability check before returning a booking's full customer details in one of its AJAX actions, allowing any authenticated user with a low-privileged account (Subscriber and above) to read the personal data, including name, email, phone, and… | |
| Aplazada | Media (6.8) | 0.39% | — | Thimpress WP Hotel BookingAI | 30/7/2026 | 30/7/2026 | The WP Hotel Booking WordPress plugin before 2.3.2 does not sanitise and escape a search parameter on an administrative listing before using it in a SQL query, allowing users holding the WP Hotel Booking WordPress plugin before 2.3.2's booking-management roles to perform SQL injection attacks. | |
| Aplazada | Alta (8.6) | 0.45% | — | Online Scheduling AND Appointment Booking SystemAI | 30/7/2026 | 30/7/2026 | The Online Scheduling and Appointment Booking System WordPress plugin before 27.8 does not sanitize or properly cast a user-supplied parameter from its unauthenticated front-end booking requests before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection attacks and extract sensitive… | |
| Aplazada | Media (6.4) | 0.42% | — | Booking System TrafftAI | 29/7/2026 | 30/7/2026 | The Booking System Trafft plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `bookingWebsiteUrl` setting in all versions up to, and including, 1.0.17 due to a missing capability check on the `set_options` AJAX action when the plugin is operating in agency mode. The `trafftSetOptions()` handler… | |
| Aplazada | Media (4.3) | 0.40% | — | Eventbooking Event Booking Manager FOR WoocommerceAI | 29/7/2026 | 30/7/2026 | The Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP & Event Calendar plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.3.7. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it… | |
| Aplazada | Alta (7.5) | 0.48% | — | Booking-wp-plugin BooklyAI | 28/7/2026 | 28/7/2026 | The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to time-based SQL Injection via the 'staff_ids' parameter in all versions up to, and including, 27.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.… | |
| Aplazada | Alta (7.5) | 0.77% | — | Themetechmount TruebookerAI | 28/7/2026 | 28/7/2026 | The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to generic SQL Injection via the 'alldata[truebooker_user]' parameter in all versions up to, and including, 1.2.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing… | |
| Aplazada | Crítica (9.8) | 0.50% | — | Themetechmount TruebookerAI | 28/7/2026 | 28/7/2026 | The TrueBooker WordPress plugin before 1.2.4 does not validate account ownership when resetting a user's password through one of its front-end account handlers, allowing unauthenticated attackers to set an arbitrary password on any account, including an administrator, and take over the site. | |
| Aplazada | Alta (7.1) | 0.25% | — | Booking CalendarAI | 27/7/2026 | 27/7/2026 | Unauthenticated Cross Site Scripting (XSS) in Booking Calendar <= 11.4.2 versions. | |
| Aplazada | Alta (7.2) | 0.27% | — | 3dflipbook PDF Viewer AND EmbedderAI | 27/7/2026 | 27/7/2026 | Unauthenticated Server Side Request Forgery (SSRF) in 3D Flipbook PDF Viewer & Embedder <= 1.4.2 versions. | |
| Aplazada | Alta (7.5) | 0.42% | — | Byteflows Travel & Hotel BookingAI | 27/7/2026 | 27/7/2026 | Unauthenticated Sensitive Data Exposure in Byteflows Travel & Hotel Booking <= 1.0.0 versions. | |
| Aplazada | Alta (7.5) | 0.37% | — | Booking AND Rental ManagerAI | 27/7/2026 | 27/7/2026 | Unauthenticated Other Vulnerability Type in Booking and Rental Manager <= 2.7.2 versions. |