Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

3072 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (4.3)0.27%—Easyappointments Easy AppointmentsAI30/7/202610/8/2026
The Easy Appointments WordPress plugin before 3.12.28 does not verify ownership or capability when returning stored customer details, allowing users with subscriber-level access to read any customer's personal information by iterating an identifier.
AplazadaBaja (3.8)0.32%—Easyappointments Easy AppointmentsAI30/7/202610/8/2026
The Easy Appointments WordPress plugin before 3.12.28 does not perform any capability or nonce check in one of its connection-deletion actions, allowing users with contributor-level access to delete the booking configuration and disable the booking system.
AplazadaBaja (3.8)0.26%—Easyappointments Easy AppointmentsAI30/7/202610/8/2026
The Easy Appointments WordPress plugin through 4.0 does not perform capability checks in several of its appointment-management actions, relying only on a nonce that any authenticated user can obtain, allowing users with contributor-level access to read all customers' appointment details and to create, modify, and…
AplazadaBaja (2.7)0.32%—Easyappointments Easy AppointmentsAI30/7/202610/8/2026
The Easy Appointments WordPress plugin before 3.12.28 does not perform a per-request capability or nonce check on one of its customer-listing handlers, allowing authenticated users with contributor-level access to read every stored customer's personal information.
AplazadaAlta (8.6)0.45%—Online Scheduling AND Appointment Booking SystemAI30/7/202630/7/2026
The Online Scheduling and Appointment Booking System WordPress plugin before 27.8 does not sanitize or properly cast a user-supplied parameter from its unauthenticated front-end booking requests before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection attacks and extract sensitive…
AplazadaMedia (5.9)0.29%—Weblizar Points AND Rewards FOR WoocommerceAIWeblizar Wallet System FOR WoocommerceAI30/7/202630/7/2026
The Points and Rewards for WooCommerce WordPress plugin before 2.10.1 does not have authorisation checks in place on a wallet and points update action that is available to unauthenticated users, and does not verify that the requester owns the account being changed, allowing unauthenticated attackers to arbitrarily…
AplazadaMedia (5.4)0.23%—Easyappointments Easy AppointmentsAI29/7/202610/8/2026
The Easy Appointments WordPress plugin before 3.12.28 does not verify that the appointment targeted by its customer-data update action belongs to the current user; the action only checks a shared nonce that any authenticated user can obtain from their own appointment's edit form. A subscriber-level user with an…
AnalizadaMedia (5.9)0.26%—Blackberry Unified Endpoint Manager28/7/202614/8/2026
An Improper Input Validation in the BlackBerry UEM Management Console of BlackBerry UEM 12.23.0 QF8 and earlier allows Arbitrary File Download and Potential Denial of Service.
AnalizadaAlta (8.6)0.25%—Blackberry Unified Endpoint Manager28/7/202614/8/2026
Improper Neutralization of Input During Web Page Generation vulnerability in BlackBerry UEM Management Console of BlackBerry UEM allows Cross-Site Scripting (XSS). This issue affects UEM: 12.23.0 QF8 or earlier.
AplazadaAlta (8.6)1.7%—Elecom Wireless LAN RoutersAIElecom Access PointsAI28/7/202628/7/2026
ELECOM wireless LAN routers and access points devices contain an OS Command Injection vulnerability in Restore Settings. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.
AplazadaAlta (8.6)1.7%—Elecom Wireless LAN RoutersAIElecom Wireless LAN Access PointsAI28/7/202628/7/2026
ELECOM wireless LAN routers and access points devices contain an OS Command Injection vulnerability in WebUI. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.
AplazadaMedia (5.1)0.24%—Elecom Wireless LAN RouterAIElecom Wireless LAN Access PointAI28/7/202628/7/2026
ELECOM wireless LAN routers and access points devices contain a reflected cross-site scripting vulnerability in WebUI. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.
AplazadaCrítica (9.1)1.2%💥 ExploitEasyappointmentsAICodeigniterAI27/7/202630/7/2026
SQL injection vulnerability exists in the order_by parameter of the /customers/search endpoint in Alex Tselegidis EasyAppointments <= 1.5.1. The vulnerability arises from unsanitized user input passed to the order_by method of the CodeIgniter Query Builder, enabling attackers to perform time-based queries and schema…
AplazadaAlta (8.2)0.43%💥 PoCBookingpress Appointment Booking PROAI27/7/202627/7/2026
The bookingpress-appointment-booking-pro WordPress plugin before 5.7.3 does not correctly invoke its REST permission callback, leaving every route in one of its API namespaces reachable without authentication and allowing unauthenticated attackers to read customer booking data and modify other users' bookings.
AplazadaMedia (6.1)0.25%—Simply Schedule AppointmentsAI27/7/202627/7/2026
Simply Schedule Appointments is vulnerable to unauthenticated Stored Cross-Site Scripting in all versions up to and including 1.6.12.2. The root cause is a sanitization-ordering defect: the rendered notification content is decoded back into live HTML after it has already passed through the Simply Schedule Appointments…
AplazadaAlta (8.1)0.40%—Easyappointments Easy AppointmentsAI24/7/202624/7/2026
The Easy Appointments plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce verification on the `ea_delete_multiple_connections` AJAX action in all versions up to, and including, 3.12.27. This makes it possible for authenticated attackers, with…
AplazadaMedia (6.5)0.22%—Dwbooster Appointment Hour BookingAI23/7/202623/7/2026
Contributor Cross Site Scripting (XSS) in Appointment Hour Booking <= 1.5.86 versions.
AplazadaMedia (6.5)0.33%💥 PoCEasyappointments Easy AppointmentsAI23/7/202623/7/2026
Unauthenticated Insecure Direct Object References (IDOR) in Easy Appointments <= 3.12.27 versions.
AplazadaAlta (7.2)0.32%—Fantasticplugins Sumo Reward PointsAI23/7/202623/7/2026
The SUMO Reward Points plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting via the REST API endpoint `/wp-json/wc-srp/v1/earning` in versions up to, and including, 32.7.0. This is due to the `user_has_cap` filter in the `SRP_REST_Earning_Controller` class unconditionally granting the…
Pendiente de análisisAlta (7.5)0.39%—Checkpoint Gaia PortalAI22/7/202624/7/2026
A vulnerability in Check Point Gaia Portal allows an authenticated attacker with read-only Gaia Portal privileges to execute commands with root privileges.
Pendiente de análisisCrítica (9.1)1.0%—Checkpoint Security ManagementAICheckpoint Multi-domain Security ManagementAI22/7/202624/7/2026
An authentication bypass vulnerability in Check Point Security Management and Multi-Domain Security Management allows an unauthenticated remote attacker to execute administrative commands on the Management Server. Successful exploitation may also allow command execution on managed Security Gateways. Exploitation…
AnalizadaCrítica (9.3)78%⚠ Explotación activa💥 ExploitCheckpoint Multi-domain Security ManagementCheckpoint Quantum Security Management22/7/202610/8/2026
An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successful exploitation allows the attacker to modify security policies and security…
AnalizadaMedia (4.3)0.27%—Oracle Retail Xstore Point OF Service21/7/20267/8/2026
Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Xstore Mobile). The supported version that is affected is 21.0.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Retail Xstore Point of…
AnalizadaBaja (3.3)0.14%—Oracle Retail Xstore Point OF Service21/7/20267/8/2026
Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Xstore Mobile). The supported version that is affected is 21.0.3. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Retail Xstore Point of Service…
Pendiente de análisisMedia (4.3)0.65%—Zohocorp Manageengine Endpoint CentralAI21/7/202621/7/2026
Zohocorp ManageEngine Endpoint Central versions before 11.4.2528.34 are affected by cleartext transmission of sensitive information vulnerability.