Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▲ 14 respecto a la semana anterior
Críticas / altas1459▲ 324 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
14 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.33% | — | TimeticsAI | 3/9/2026 | 3/9/2026 | Unauthenticated Broken Access Control in Timetics <= 1.0.61 versions. | |
| Aplazada | Baja (3.8) | 0.22% | — | TimeticsAI | 2/9/2026 | 3/9/2026 | The Timetics WordPress plugin through 1.0.61 does not enforce per-object ownership when updating appointments through its REST API, allowing users with its custom staff role to modify, disable, or take over appointments belonging to other staff members. | |
| Aplazada | Alta (7.1) | 0.25% | — | TimeticsAI | 2/7/2026 | 2/7/2026 | Unauthenticated Cross Site Scripting (XSS) in Timetics <= 1.0.58 versions. | |
| Aplazada | Alta (8.2) | 0.34% | — | Arraytics TimeticsAI | 12/5/2026 | 17/6/2026 | Missing Authorization vulnerability in Arraytics Timetics allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Timetics: from n/a through 1.0.53. | |
| Aplazada | Media (4.3) | 0.16% | — | TimeticsAI | 12/3/2026 | 17/6/2026 | The Timetics WordPress plugin before 1.0.52 does not have authorization in a REST endpoint, allowing unauthenticated users to arbitrarily change a booking's payment status and post status for the "timetics-booking" custom post type. | |
| Aplazada | Alta (8.8) | 0.43% | — | Arraytics TimeticsAI | 8/1/2026 | 30/9/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Arraytics Timetics timetics allows Authentication Abuse.This issue affects Timetics: from n/a through <= 1.0.46. | |
| Aplazada | Media (6.5) | 0.24% | — | Arraytics WP TimeticsAI | 6/1/2026 | 30/9/2026 | The Appointment Booking and Scheduling Calendar Plugin – WP Timetics plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on the update and register_routes functions in all versions up to, and including, 1.0.36. This makes it possible for unauthenticated… | |
| Aplazada | Alta (7.5) | 0.34% | — | Arraytics TimeticsAI | 18/12/2025 | 25/9/2026 | Missing Authorization vulnerability in Arraytics Timetics timetics allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Timetics: from n/a through <= 1.0.44. | |
| Aplazada | Media (5.3) | 0.45% | — | Arraytics TimeticsAI | 27/3/2025 | 17/6/2026 | Missing Authorization vulnerability in Arraytics Timetics timetics allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Timetics: from n/a through <= 1.0.29. | |
| Aplazada | Media (4.3) | 0.34% | — | Arraytics WP TimeticsAI | 13/12/2024 | 17/6/2026 | The WP Timetics- AI-powered Appointment Booking Calendar and Online Scheduling Plugin plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the /wp-json/timetics/v1/customers/ REST API endpoint in all versions up to, and including, 1.0.27. This makes it possible for… | |
| Analizada | Crítica (9.8) | 0.53% | — | Arraytics WP Timetics | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in Arraytics Timetics allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Timetics: from n/a through 1.0.23. | |
| Aplazada | Media (5.3) | 0.34% | — | Arraytics TimeticsAI | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in Arraytics Timetics allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Timetics: from n/a through 1.0.21. | |
| Aplazada | Crítica (9.8) | 1.1% | — | Arraytics WP TimeticsAI | 17/10/2024 | 17/6/2026 | The WP Timetics- AI-powered Appointment Booking Calendar and Online Scheduling Plugin plugin for WordPress is vulnerable to Account Takeover/Privilege Escalation via Insecure Direct Object Reference in all versions up to, and including, 1.0.25 via the save() due to missing validation on a user controlled key. This… | |
| Aplazada | Alta (7.3) | 0.54% | — | TimeticsAI | 14/6/2024 | 17/6/2026 | The Timetics- AI-powered Appointment Booking with Visual Seat Plan and ultimate Calendar Scheduling plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the make_staff() function in all versions up to, and including, 1.0.21. This makes it possible for… |