Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▲ 32 respecto a la semana anterior
Críticas / altas1474▲ 364 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 464 respecto a la semana anterior
21.015 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.2) | — | — | JetappointmentAI | 2/10/2026 | 2/10/2026 | The JetAppointment plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'friendlyTime' parameter in all versions up to, and including, 2.5.2.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages… | |
| Aplazada | Crítica (9.8) | 0.49% | — | Amauri Wpmobile.appAI | 2/10/2026 | 2/10/2026 | The WPMobile.App – Android and iOS App Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 11.82 This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to exfiltrate… | |
| Aplazada | Media (5.3) | 0.27% | — | Appointment Booking Plugin LatepointAI | 2/10/2026 | 2/10/2026 | The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 5.7.1 via the OsPaypalConnectController::create_order_for_transaction() action registered as a public (unauthenticated) route through… | |
| Aplazada | Media (6.9) | 0.26% | — | Wormhole.appAI | 1/10/2026 | 1/10/2026 | Wormhole.app as deployed before 2026-08-22 misconfigures the coturn TURN server and does not properly restrict TCP relay peers, allowing an unauthenticated attacker to access instance metadata or to source TCP connections from the Wormhole relay's IP. | |
| Aplazada | Alta (7.2) | 0.26% | — | Dwbooster Appointment Hour BookingAI | 1/10/2026 | 1/10/2026 | The Appointment Hour Booking – Booking Calendar plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via Booking Form Single-Line Field via Schedule Calendar List Renderer in all versions up to, and including, 1.5.97 due to insufficient input sanitization and output escaping. This makes it… | |
| Aplazada | Alta (7.5) | 0.43% | — | Simply Schedule AppointmentsAI | 1/10/2026 | 1/10/2026 | The Simply Schedule Appointments plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.6.12.32 via the 'recursive' parameter. This makes it possible for unauthenticated attackers to extract customer PII — including names, email addresses, phone numbers, and custom… | |
| Aplazada | Media (6.5) | 0.32% | — | Simply Schedule AppointmentsAI | 1/10/2026 | 1/10/2026 | The Simply Schedule Appointments plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.6.12.31 via the 'complete_group' parameter due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with subscriber-level access… | |
| Aplazada | Media (5.1) | 0.19% | — | Webkul QloappsAI | 30/9/2026 | 1/10/2026 | QloApps through 1.7.0 contains a reflected cross-site scripting vulnerability in the back-office room type editor's length of stay fields. Attackers can induce authenticated administrators to submit crafted POST requests with malicious payloads in restriction_min_los and restriction_max_los parameters, executing… | |
| Aplazada | Media (5.1) | 0.19% | — | Webkul QloappsAI | 30/9/2026 | 1/10/2026 | QloApps through 1.7.0 contains a reflected cross-site scripting vulnerability in the back-office room type editor that fails to escape room_num, floor, and comment field values in input attributes. Attackers can induce authenticated back-office users to submit crafted POST requests with malicious payloads to execute… | |
| Aplazada | Media (5.1) | 0.18% | — | Webkul QloappsAI | 30/9/2026 | 30/9/2026 | QloApps through 1.7.0 contains a reflected cross-site scripting vulnerability in the exceptions field of the back-office Transplant a module form. Attackers can craft a malicious link containing JavaScript payload in the exceptions parameter that executes in an authenticated administrator's session when the victim… | |
| Aplazada | Media (5.1) | 0.18% | — | Webkul QloappsAI | 30/9/2026 | 1/10/2026 | QloApps through 1.7.0 contains a reflected cross-site scripting vulnerability in the back-office Hotel Reservation System Book Now search, where date_to and id_room_type parameters are copied into template variables without validation. Attackers can craft a malicious link containing JavaScript payload in these… | |
| Pendiente de análisis | Alta (7.4) | 0.32% | — | Tenable ApplianceAI | 30/9/2026 | 1/10/2026 | A Kiteworks appliance setup interface did not confine a user-supplied file path to its intended directory, which could allow an unauthenticated attacker to write a file to any location writable by the affected service account, potentially compromising the integrity of the appliance or rendering it unavailable until an… | |
| Aplazada | Alta (7.1) | 0.18% | — | HappyformsAI | 30/9/2026 | 30/9/2026 | Unauthenticated Cross Site Scripting (XSS) in Happyforms <= 1.26.15 versions. | |
| Aplazada | Media (5.3) | 0.25% | — | Simply Schedule AppointmentsAI | 30/9/2026 | 30/9/2026 | Unauthenticated Insecure Direct Object References (IDOR) in Simply Schedule Appointments <= 1.6.12.31 versions. | |
| Aplazada | Alta (8.5) | 0.26% | — | Fatcatapps Easy Pricing TablesAI | 30/9/2026 | 30/9/2026 | Contributor SQL Injection in Easy Pricing Tables <= 4.1.2 versions. | |
| Aplazada | Media (6.5) | 0.21% | — | Simply Schedule AppointmentsAI | 30/9/2026 | 30/9/2026 | Unauthenticated Broken Access Control in Simply Schedule Appointments <= 1.6.12.29 versions. | |
| Aplazada | Media (6.5) | 0.18% | — | Happy AddonsAI | 30/9/2026 | 30/9/2026 | Contributor Cross Site Scripting (XSS) in Happy Addons for Elementor <= 3.23.1 versions. | |
| Aplazada | Media (6.9) | 0.24% | — | Amauri IO Wpmobile APPAI | 30/9/2026 | 30/9/2026 | Missing Authorization vulnerability in Amauri.IO WPMobile.App wpappninja allows Retrieve Embedded Sensitive Data.This issue affects WPMobile.App: from n/a through 11.83. | |
| Aplazada | Alta (7.5) | 0.90% | — | Product Designer APPAI | 30/9/2026 | 30/9/2026 | The Product Designer App plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.1.3 via the 'svg' parameter parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. The… | |
| Aplazada | Alta (7.5) | 0.65% | — | Simply Schedule AppointmentsAI | 30/9/2026 | 30/9/2026 | The Simply Schedule Appointments plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.6.12.27 via the 'ssa_locale' parameter parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to include and execute arbitrary .php files… | |
| Aplazada | Media (5.3) | 0.23% | — | Wpexperts NEW User ApproveAI | 30/9/2026 | 30/9/2026 | The New User Approve WordPress plugin before 3.2.10 does not properly verify authentication on a set of integration REST API routes when the integration is unconfigured, allowing unauthenticated attackers to retrieve personal data (id, username, email address and registration date) of registered users. | |
| Analizada | Alta (8.8) | 1.2% | ⚠ Explotación activa | Apple IpadosApple Iphone OSApple Macos | 28/9/2026 | 1/10/2026 | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and iPadOS 26.7.1, macOS Sequoia 15.8.1, macOS Tahoe 26.7.1. Processing a maliciously crafted file may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an… | |
| Pendiente de análisis | Crítica (9.4) | 0.36% | — | Google Cloud Application IntegrationAI | 28/9/2026 | 30/9/2026 | A Deserialization of Untrusted Data vulnerability in the JavaScript Task in Google Cloud Application Integration versions prior to 2026-06-28 on Google Cloud Platform allows an authenticated user with standard permissions to run arbitrary code on the shared production servers using a specially crafted script bypassing… | |
| Pendiente de análisis | Alta (8.3) | 0.32% | — | Google Cloud Application IntegrationAI | 28/9/2026 | 29/9/2026 | A Confused Deputy vulnerability in the EmailTask component in Google Cloud Application Integration versions prior to 2026-06-30 on Google Cloud Platform allows an authenticated attacker to read and exfiltrate arbitrary Google-internal files via a crafted attachment file path. This vulnerability was patched on 30 June… | |
| Pendiente de análisis | Crítica (9.4) | 0.24% | — | Google Cloud Application IntegrationAI | 28/9/2026 | 29/9/2026 | An Incorrect Authorization vulnerability in the task configuration in Google Cloud Application Integration versions prior to 2026-06-17 on Google Cloud Platform allows an authenticated Google Cloud user to execute arbitrary internal RPCs from inside Google's production network under a privileged identity using an… |