Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2882▼ 181 respecto a la semana anterior
Críticas / altas1279▼ 60 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)487▼ 22 respecto a la semana anterior
–

244 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.5)0.43%—Simply Schedule AppointmentsAI1/10/20263/10/2026
The Simply Schedule Appointments plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.6.12.32 via the 'recursive' parameter. This makes it possible for unauthenticated attackers to extract customer PII — including names, email addresses, phone numbers, and custom…
AplazadaMedia (6.5)0.32%—Simply Schedule AppointmentsAI1/10/20263/10/2026
The Simply Schedule Appointments plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.6.12.31 via the 'complete_group' parameter due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with subscriber-level access…
AplazadaMedia (5.3)0.25%—Simply Schedule AppointmentsAI30/9/202630/9/2026
Unauthenticated Insecure Direct Object References (IDOR) in Simply Schedule Appointments <= 1.6.12.31 versions.
AplazadaMedia (6.5)0.21%—Simply Schedule AppointmentsAI30/9/202630/9/2026
Unauthenticated Broken Access Control in Simply Schedule Appointments <= 1.6.12.29 versions.
AplazadaAlta (7.5)0.65%—Simply Schedule AppointmentsAI30/9/202630/9/2026
The Simply Schedule Appointments plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.6.12.27 via the 'ssa_locale' parameter parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to include and execute arbitrary .php files…
AplazadaMedia (4.3)0.23%—Apache DolphinschedulerAI29/9/202629/9/2026
An improper authorization vulnerability exists in the handling of sub-workflow tasks. An authenticated user who does not have permission to access a target project can reference and invoke a workflow belonging to that project through a sub-workflow task. The system does not properly verify whether the user has…
AplazadaMedia (5.3)0.35%—Apache DolphinschedulerAI29/9/202629/9/2026
An authentication bypass vulnerability exists in the protection of Actuator endpoints. The application determines whether authentication is required by matching the incoming request path against protected Actuator paths. By sending a specially crafted request containing a percent-encoded path, a remote unauthenticated…
AplazadaMedia (6.5)0.23%—Apache DolphinschedulerAI29/9/20261/10/2026
A missing authorization vulnerability exists in the `query-dynamic-sub-workflows` API of Apache DolphinScheduler. The API does not properly verify whether the authenticated user has permission to access the workflows being queried. An authenticated user who does not have permission to access a specific project can…
AplazadaMedia (4.3)0.18%—Apache DolphinschedulerAI29/9/202629/9/2026
An incorrect authorization check in Apache DolphinScheduler allows an authenticated user with only read permission for a project to modify a workflow instance in that project through the PUT /projects/{projectCode}/workflow-instances/{id} endpoint. The endpoint does not enforce the write permission required for this…
AplazadaMedia (4.3)0.18%—Apache DolphinschedulerAI29/9/202629/9/2026
An improper authorization check in Apache DolphinScheduler allows an authenticated user to use the batch-copy and batch-move endpoints to operate on workflows in projects for which they lack the required permissions. This may allow the user to copy or move workflows from unauthorized projects. This issue affects…
AplazadaAlta (8.8)0.50%—Apache DolphinschedulerAI29/9/202629/9/2026
The scriptPath parameter is incorporated into a /bin/sh -c command without sufficient neutralization of shell metacharacters, allowing shell command substitution and execution. An authenticated user can exploit this behavior by creating a resource whose filename contains shell command substitution syntax, such as…
AnalizadaMedia (6.5)0.23%—Apache Dolphinscheduler29/9/20266/10/2026
The /datasources/unauth-datasource endpoint does not properly enforce data source authorization. An authenticated user can invoke this endpoint to obtain information about data sources they are not authorized to access. This may expose data source configuration and other sensitive metadata, depending on the fields…
Pendiente de análisisAlta (8.1)0.23%—Apache DolphinschedulerAI24/9/202624/9/2026
A missing authorization vulnerability exists in the Task Group APIs of Apache DolphinScheduler. The affected APIs do not properly verify whether the authenticated user has permission to access the project associated with the target Task Group. This issue affects Apache DolphinScheduler: before 3.4.3. Users are…
AplazadaAlta (8.6)0.45%—TZ Weekly Radio ScheduleAI18/9/202618/9/2026
The Tz Weekly Radio Schedule WordPress plugin through 1.8.1 does not sanitize and escape a parameter before using it to build a SQL query on an AJAX action available to unauthenticated users, allowing unauthenticated attackers to perform SQL injection attacks and extract sensitive data from the database.
AplazadaAlta (8.6)0.45%—TZ Weekly Radio ScheduleAI18/9/202618/9/2026
The Tz Weekly Radio Schedule WordPress plugin through 1.8.1 does not sanitize and escape a parameter before using it to build a SQL query on an AJAX action available to unauthenticated users, allowing unauthenticated attackers to perform SQL injection attacks and extract sensitive data from the database.
AplazadaMedia (6.4)0.26%—Ninja Forms Scheduled ExportsAI10/9/202611/9/2026
The Ninja Forms - Scheduled Exports plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API Parameters (interval, format, emailTo) in all versions up to, and including, 3.0.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
AplazadaAlta (8.8)0.20%—Simply Schedule AppointmentsAI2/9/20264/9/2026
Unauthenticated Cross Site Request Forgery (CSRF) in Simply Schedule Appointments <= 1.6.12.23 versions.
AnalizadaAlta (8.8)0.58%—Apache Dolphinscheduler25/8/202628/9/2026
General user can mint admin access tokens via /access-tokens This issue affects Apache DolphinScheduler: before 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes the issue.
AplazadaMedia (6.5)0.68%—Simply Schedule Appointments Appointment Booking CalendarAI16/8/202620/8/2026
The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.6.12.10 via the ssa_past_appointments due to missing validation on a user controlled key. This makes it possible for…
AplazadaMedia (6.5)0.37%—Simply Schedule AppointmentsAI15/8/202626/8/2026
The Simply Schedule Appointments WordPress plugin before 1.6.12.17 does not restrict the user records returned by some of its REST endpoints to those the requester is entitled to see, allowing users with a low-privileged staff role to disclose the names and email addresses of arbitrary registered users.
AplazadaMedia (6.9)0.96%—Grav Scheduler-webhookAI7/8/202631/8/2026
Grav CMS's scheduler-webhook plugin contains an authentication bypass in the webhook token check. When the webhook feature is enabled but no webhookToken is configured, a compound conditional short-circuits and skips token validation, so an unauthenticated remote attacker who can reach POST /scheduler/webhook can…
AplazadaAlta (7.1)0.25%—Simply Schedule AppointmentsAI6/8/202612/8/2026
Unauthenticated Cross Site Scripting (XSS) in Simply Schedule Appointments <= 1.6.12.10 versions.
AplazadaCrítica (9.3)0.40%—Simply Schedule AppointmentsAI6/8/202612/8/2026
Unauthenticated SQL Injection in Simply Schedule Appointments <= 1.6.12.10 versions.
AplazadaMedia (6.5)0.34%—Simply Schedule AppointmentsAI3/8/202626/8/2026
The Simply Schedule Appointments WordPress plugin before 1.6.12.11 does not perform a capability check on an administrative appointment-listing shortcode, and its per-user result scoping fails open for non-staff users, allowing users with the Contributor role and above to disclose all customers' appointment records,…
AplazadaAlta (7.5)0.41%—Simply Schedule AppointmentsAI2/8/202626/8/2026
The Simply Schedule Appointments WordPress plugin before 1.6.12.6 does not correctly restrict a bulk appointment operation to the requester's own records, allowing unauthenticated users to retrieve the personal data of all appointments across the site and, on premium editions, to permanently delete them.