Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2720▼ 598 respecto a la semana anterior
Críticas / altas1299▼ 202 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
3066 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (6.2) | 0.13% | — | Elastic EndpointAI | 6/10/2026 | 7/10/2026 | Uncaught Exception (CWE-248) in Elastic Endpoint can lead to denial of service via a specially crafted file name. When Elastic Defend's Elastic Endpoint component processes a file name under certain system locale configurations (including Chinese, Japanese, and Korean locales) on Windows, an unhandled exception can… | |
| Pendiente de análisis | Alta (7.1) | 0.28% | — | Arista WI FI Access PointAI | 6/10/2026 | 7/10/2026 | On affected Arista Wi-Fi access points with Captive Portal enabled, an unauthenticated wireless client connected to a captive-portal-enabled SSID can crash the portal service with a crafted HTTP request. The service automatically restarts, but a sustained low-rate attack can cause a persistent denial of service of the… | |
| Pendiente de análisis | Alta (7.1) | 0.28% | — | Arista Wi-fi Access PointAI | 6/10/2026 | 7/10/2026 | On affected Arista Wi-Fi access points with Captive Portal enabled, an unauthenticated wireless client connected to a Captive-Portal-enabled SSID can crash the portal service with a crafted HTTP request. This results in a temporary denial of service until the service automatically restarts. Remote code execution is… | |
| Pendiente de análisis | Crítica (9) | 0.23% | — | Arista WI FI Access PointAI | 6/10/2026 | 7/10/2026 | On affected Arista Wi-Fi access points, a memory corruption vulnerability exists in access point's wired uplink network endpoints. An unauthenticated attacker can crash the sensor service or potentially achieve remote code execution. Exploitation requires the attacker to be on the same network segment as the access… | |
| Pendiente de análisis | Alta (7.7) | 0.24% | — | Arista WI FI Access PointAI | 6/10/2026 | 7/10/2026 | On affected Arista Wi-Fi access points, an unauthenticated attacker with network access to the capture service can send a crafted packet to cause the service to crash or potentially achieve remote code execution. This exploit requires an uncommonly used non-default streaming mode. | |
| Pendiente de análisis | Baja (2.3) | 0.19% | — | Arista Access PointAI | 6/10/2026 | 7/10/2026 | On affected Arista access points configured with VXLAN tunnelling and L2-proxy (a specific configuration unique to the VESPA use-case), a wireless client associated to the tunnelled SSID can send a crafted packet, causing the access point to reveal memory contents in network traffic. No write primitive or remote code… | |
| Pendiente de análisis | Alta (8.7) | 0.31% | — | Arista Access PointAI | 6/10/2026 | 7/10/2026 | On affected Arista access points with Wireless Intrusion Prevention System (WIPS) active, an unauthenticated attacker within radio frequency (RF) proximity can send a crafted frame to crash the sensor service, disabling WIPS monitoring on the access point, or potentially achieve remote code execution. No wireless… | |
| Pendiente de análisis | Crítica (9.4) | 0.25% | — | Arista Wi-fi Access PointsAI | 6/10/2026 | 7/10/2026 | On affected Arista Wi-Fi access points with captive portal, or application firewall enabled on at least one SSID, a vulnerability in the wireless gateway service could allow an unauthenticated network-adjacent attacker to send a crafted packet that triggers a stack overflow, resulting in a denial-of-service condition… | |
| Aplazada | Media (6.5) | 0.26% | — | WappointmentAI | 6/10/2026 | 6/10/2026 | Unauthenticated Insecure Direct Object References (IDOR) in Wappointment <= 2.7.7 versions. | |
| Aplazada | Crítica (9.3) | 0.38% | — | Woocommerce AppointmentsAI | 6/10/2026 | 6/10/2026 | Unauthenticated SQL Injection in WooCommerce Appointments <= 5.3.2 versions. | |
| Aplazada | Baja (2.1) | 0.20% | — | Anisha Online Appointment Booking SystemAI | 5/10/2026 | 6/10/2026 | A weakness has been identified in girishsaraf Online-Appointment-Booking-System up to f427b4757128ca253d33d0cc4e87bbb9c999a4d5. The affected element is an unknown function of the file book.php of the component Booking Handler. This manipulation of the argument Doctor/appointment causes sql injection. The attack is… | |
| Aplazada | Media (5.5) | 0.26% | — | Anisha Online Appointment Booking SystemAI | 5/10/2026 | 6/10/2026 | A security flaw has been discovered in girishsaraf Online-Appointment-Booking-System up to f427b4757128ca253d33d0cc4e87bbb9c999a4d5. Impacted is an unknown function of the file signup.php of the component Registration Handler. The manipulation of the argument fname results in sql injection. The attack can be executed… | |
| Aplazada | Media (5.5) | 0.26% | — | Anisha Online Appointment Booking SystemAI | 5/10/2026 | 6/10/2026 | A vulnerability was identified in girishsaraf Online-Appointment-Booking-System up to f427b4757128ca253d33d0cc4e87bbb9c999a4d5. This issue affects the function mysqli_query of the file locateus.php of the component Doctor Search Endpoint. The manipulation of the argument doctorname leads to sql injection. Remote… | |
| Aplazada | Media (5.5) | 0.33% | — | Anisha Online Appointment Booking SystemAI | 5/10/2026 | 6/10/2026 | A vulnerability was determined in girishsaraf Online-Appointment-Booking-System up to f427b4757128ca253d33d0cc4e87bbb9c999a4d5. This vulnerability affects unknown code of the file get_town.php of the component AJAX Endpoint. Executing a manipulation of the argument countryid/townid/cid/didval/cidval can lead to sql… | |
| Aplazada | Media (5.5) | 0.26% | — | Anisha Online Appointment Booking SystemAI | 5/10/2026 | 6/10/2026 | A vulnerability was found in girishsaraf Online-Appointment-Booking-System up to f427b4757128ca253d33d0cc4e87bbb9c999a4d5. This affects the function mysqli_query of the file Admin/mlogin.php of the component Login Handler. Performing a manipulation of the argument uname/pass results in sql injection. The attack may be… | |
| Aplazada | Media (5.5) | 0.33% | — | Anisha Online Appointment Booking SystemAI | 5/10/2026 | 6/10/2026 | A security flaw has been discovered in girishsaraf Online-Appointment-Booking-System up to f427b4757128ca253d33d0cc4e87bbb9c999a4d5. This affects the function mysqli_query of the file cover.php of the component Patient Login Handler. The manipulation of the argument uname/psw results in sql injection. It is possible… | |
| Aplazada | Media (6.5) | 0.13% | — | Themepoints Logo ShowcaseAI | 5/10/2026 | 6/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themepoints Logo Showcase logo-showcase allows Stored XSS.This issue affects Logo Showcase: from n/a through 4.0.4. | |
| Aplazada | Crítica (9.1) | 0.88% | — | Vikappointments Services Booking CalendarAI | 3/10/2026 | 6/10/2026 | The VikAppointments Services Booking Calendar plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the extract function in all versions up to, and including, 1.2.21. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which… | |
| Aplazada | Alta (7.2) | 0.19% | — | JetappointmentAI | 2/10/2026 | 2/10/2026 | The JetAppointment plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'friendlyTime' parameter in all versions up to, and including, 2.5.2.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages… | |
| Aplazada | Media (5.3) | 0.27% | — | Appointment Booking Plugin LatepointAI | 2/10/2026 | 3/10/2026 | The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 5.7.1 via the OsPaypalConnectController::create_order_for_transaction() action registered as a public (unauthenticated) route through… | |
| Aplazada | Alta (7.6) | 0.29% | — | Office Powerpoint MCP ServerAI | 1/10/2026 | 2/10/2026 | Office-PowerPoint-MCP-Server through 2.0.7 contains a path traversal vulnerability that allows MCP callers to write and read files outside the working directory by supplying absolute paths or ../ sequences. Attackers can steer an AI agent via prompt injection to abuse save_presentation, open_presentation, or… | |
| Aplazada | Alta (7.2) | 0.26% | — | Dwbooster Appointment Hour BookingAI | 1/10/2026 | 1/10/2026 | The Appointment Hour Booking – Booking Calendar plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via Booking Form Single-Line Field via Schedule Calendar List Renderer in all versions up to, and including, 1.5.97 due to insufficient input sanitization and output escaping. This makes it… | |
| Aplazada | Crítica (9.1) | 0.45% | 💥 PoC | LatepointAI | 1/10/2026 | 1/10/2026 | The The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.7.0. This is due to the software allowing users to execute an action that does not properly validate a value before running… | |
| Aplazada | Alta (7.5) | 0.43% | — | Simply Schedule AppointmentsAI | 1/10/2026 | 3/10/2026 | The Simply Schedule Appointments plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.6.12.32 via the 'recursive' parameter. This makes it possible for unauthenticated attackers to extract customer PII — including names, email addresses, phone numbers, and custom… | |
| Aplazada | Media (6.5) | 0.32% | — | Simply Schedule AppointmentsAI | 1/10/2026 | 3/10/2026 | The Simply Schedule Appointments plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.6.12.31 via the 'complete_group' parameter due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with subscriber-level access… |