Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▲ 32 respecto a la semana anterior
Críticas / altas1474▲ 364 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 464 respecto a la semana anterior
–

21.015 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.2)——JetappointmentAI2/10/20262/10/2026
The JetAppointment plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'friendlyTime' parameter in all versions up to, and including, 2.5.2.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages…
AplazadaCrítica (9.8)0.49%—Amauri Wpmobile.appAI2/10/20262/10/2026
The WPMobile.App – Android and iOS App Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 11.82 This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to exfiltrate…
AplazadaMedia (5.3)0.27%—Appointment Booking Plugin LatepointAI2/10/20262/10/2026
The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 5.7.1 via the OsPaypalConnectController::create_order_for_transaction() action registered as a public (unauthenticated) route through…
AplazadaMedia (6.9)0.26%—Wormhole.appAI1/10/20261/10/2026
Wormhole.app as deployed before 2026-08-22 misconfigures the coturn TURN server and does not properly restrict TCP relay peers, allowing an unauthenticated attacker to access instance metadata or to source TCP connections from the Wormhole relay's IP.
AplazadaAlta (7.2)0.26%—Dwbooster Appointment Hour BookingAI1/10/20261/10/2026
The Appointment Hour Booking – Booking Calendar plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via Booking Form Single-Line Field via Schedule Calendar List Renderer in all versions up to, and including, 1.5.97 due to insufficient input sanitization and output escaping. This makes it…
AplazadaAlta (7.5)0.43%—Simply Schedule AppointmentsAI1/10/20261/10/2026
The Simply Schedule Appointments plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.6.12.32 via the 'recursive' parameter. This makes it possible for unauthenticated attackers to extract customer PII — including names, email addresses, phone numbers, and custom…
AplazadaMedia (6.5)0.32%—Simply Schedule AppointmentsAI1/10/20261/10/2026
The Simply Schedule Appointments plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.6.12.31 via the 'complete_group' parameter due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with subscriber-level access…
AplazadaMedia (5.1)0.19%—Webkul QloappsAI30/9/20261/10/2026
QloApps through 1.7.0 contains a reflected cross-site scripting vulnerability in the back-office room type editor's length of stay fields. Attackers can induce authenticated administrators to submit crafted POST requests with malicious payloads in restriction_min_los and restriction_max_los parameters, executing…
AplazadaMedia (5.1)0.19%—Webkul QloappsAI30/9/20261/10/2026
QloApps through 1.7.0 contains a reflected cross-site scripting vulnerability in the back-office room type editor that fails to escape room_num, floor, and comment field values in input attributes. Attackers can induce authenticated back-office users to submit crafted POST requests with malicious payloads to execute…
AplazadaMedia (5.1)0.18%—Webkul QloappsAI30/9/202630/9/2026
QloApps through 1.7.0 contains a reflected cross-site scripting vulnerability in the exceptions field of the back-office Transplant a module form. Attackers can craft a malicious link containing JavaScript payload in the exceptions parameter that executes in an authenticated administrator's session when the victim…
AplazadaMedia (5.1)0.18%—Webkul QloappsAI30/9/20261/10/2026
QloApps through 1.7.0 contains a reflected cross-site scripting vulnerability in the back-office Hotel Reservation System Book Now search, where date_to and id_room_type parameters are copied into template variables without validation. Attackers can craft a malicious link containing JavaScript payload in these…
Pendiente de análisisAlta (7.4)0.32%—Tenable ApplianceAI30/9/20261/10/2026
A Kiteworks appliance setup interface did not confine a user-supplied file path to its intended directory, which could allow an unauthenticated attacker to write a file to any location writable by the affected service account, potentially compromising the integrity of the appliance or rendering it unavailable until an…
AplazadaAlta (7.1)0.18%—HappyformsAI30/9/202630/9/2026
Unauthenticated Cross Site Scripting (XSS) in Happyforms <= 1.26.15 versions.
AplazadaMedia (5.3)0.25%—Simply Schedule AppointmentsAI30/9/202630/9/2026
Unauthenticated Insecure Direct Object References (IDOR) in Simply Schedule Appointments <= 1.6.12.31 versions.
AplazadaAlta (8.5)0.26%—Fatcatapps Easy Pricing TablesAI30/9/202630/9/2026
Contributor SQL Injection in Easy Pricing Tables <= 4.1.2 versions.
AplazadaMedia (6.5)0.21%—Simply Schedule AppointmentsAI30/9/202630/9/2026
Unauthenticated Broken Access Control in Simply Schedule Appointments <= 1.6.12.29 versions.
AplazadaMedia (6.5)0.18%—Happy AddonsAI30/9/202630/9/2026
Contributor Cross Site Scripting (XSS) in Happy Addons for Elementor <= 3.23.1 versions.
AplazadaMedia (6.9)0.24%—Amauri IO Wpmobile APPAI30/9/202630/9/2026
Missing Authorization vulnerability in Amauri.IO WPMobile.App wpappninja allows Retrieve Embedded Sensitive Data.This issue affects WPMobile.App: from n/a through 11.83.
AplazadaAlta (7.5)0.90%—Product Designer APPAI30/9/202630/9/2026
The Product Designer App plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.1.3 via the 'svg' parameter parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. The…
AplazadaAlta (7.5)0.65%—Simply Schedule AppointmentsAI30/9/202630/9/2026
The Simply Schedule Appointments plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.6.12.27 via the 'ssa_locale' parameter parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to include and execute arbitrary .php files…
AplazadaMedia (5.3)0.23%—Wpexperts NEW User ApproveAI30/9/202630/9/2026
The New User Approve WordPress plugin before 3.2.10 does not properly verify authentication on a set of integration REST API routes when the integration is unconfigured, allowing unauthenticated attackers to retrieve personal data (id, username, email address and registration date) of registered users.
AnalizadaAlta (8.8)1.2%⚠ Explotación activaApple IpadosApple Iphone OSApple Macos28/9/20261/10/2026
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and iPadOS 26.7.1, macOS Sequoia 15.8.1, macOS Tahoe 26.7.1. Processing a maliciously crafted file may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an…
Pendiente de análisisCrítica (9.4)0.36%—Google Cloud Application IntegrationAI28/9/202630/9/2026
A Deserialization of Untrusted Data vulnerability in the JavaScript Task in Google Cloud Application Integration versions prior to 2026-06-28 on Google Cloud Platform allows an authenticated user with standard permissions to run arbitrary code on the shared production servers using a specially crafted script bypassing…
Pendiente de análisisAlta (8.3)0.32%—Google Cloud Application IntegrationAI28/9/202629/9/2026
A Confused Deputy vulnerability in the EmailTask component in Google Cloud Application Integration versions prior to 2026-06-30 on Google Cloud Platform allows an authenticated attacker to read and exfiltrate arbitrary Google-internal files via a crafted attachment file path. This vulnerability was patched on 30 June…
Pendiente de análisisCrítica (9.4)0.24%—Google Cloud Application IntegrationAI28/9/202629/9/2026
An Incorrect Authorization vulnerability in the task configuration in Google Cloud Application Integration versions prior to 2026-06-17 on Google Cloud Platform allows an authenticated Google Cloud user to execute arbitrary internal RPCs from inside Google's production network under a privileged identity using an…