Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2568▼ 334 respecto a la semana anterior
Críticas / altas1340▲ 73 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)93▼ 434 respecto a la semana anterior
–

8 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.5)0.17%—BookedAI2/7/20262/7/2026
Unauthenticated Cross Site Request Forgery (CSRF) in Booked <= 3.0.0 versions.
AplazadaAlta (7.1)0.29%—BookedAI2/7/20262/7/2026
Subscriber Broken Access Control in Booked <= 3.0.0 versions.
AplazadaMedia (6.7)0.37%—Case-themes BookedAI20/2/202617/6/2026
Authentication Bypass Using an Alternate Path or Channel vulnerability in Case-Themes Booked booked allows Authentication Abuse.This issue affects Booked: from n/a through <= 3.0.0.
AplazadaMedia (5.4)0.14%—MD ABU Jubayer Hossain Easy BookedAI27/3/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in MD Abu Jubayer Hossain Easy Booked – Appointment Booking and Scheduling Management System for WordPress easy-booked allows Cross Site Request Forgery.This issue affects Easy Booked – Appointment Booking and Scheduling Management System for WordPress: from n/a through…
ModificadaAlta (7.5)0.53%—Boxystudio Booked28/12/202317/6/2026
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in BoxyStudio Booked - Appointment Booking for WordPress | Calendars.This issue affects Booked - Appointment Booking for WordPress | Calendars: from n/a before 2.4.4.
ModificadaMedia (4.3)0.99%—Twinkletoessoftware Booked22/1/202317/6/2026
Booked Scheduler 2.5.5 allows authenticated users to create and schedule events for any other user via a modified userId value to reservation_save.php. NOTE: 2.5.5 is a version from 2014; the latest version of Booked Scheduler is not affected. However, LabArchives Scheduler (Sep 6, 2022 Feature Release) is affected.
ModificadaMedia (6.1)0.63%—Twinkletoessoftware Booked26/7/202217/6/2026
Open redirect vulnerability in Booked versions prior to 3.3 allows a remote unauthenticated attacker to redirect a user to an arbitrary web site and conduct a phishing attack by having a user to access a specially crafted URL.
ModificadaAlta (8.8)13%—Twinkletoessoftware Booked6/3/201917/6/2026
phpscheduleit Booked Scheduler 2.7.5 allows arbitrary file upload via the Favicon field, leading to execution of arbitrary Web/custom-favicon.php PHP code, because Presenters/Admin/ManageThemePresenter.php does not ensure an image file extension.