Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▲ 14 respecto a la semana anterior
Críticas / altas1459▲ 324 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
–

14 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.5)0.33%—TimeticsAI3/9/20263/9/2026
Unauthenticated Broken Access Control in Timetics <= 1.0.61 versions.
AplazadaBaja (3.8)0.22%—TimeticsAI2/9/20263/9/2026
The Timetics WordPress plugin through 1.0.61 does not enforce per-object ownership when updating appointments through its REST API, allowing users with its custom staff role to modify, disable, or take over appointments belonging to other staff members.
AplazadaAlta (7.1)0.25%—TimeticsAI2/7/20262/7/2026
Unauthenticated Cross Site Scripting (XSS) in Timetics <= 1.0.58 versions.
AplazadaAlta (8.2)0.34%—Arraytics TimeticsAI12/5/202617/6/2026
Missing Authorization vulnerability in Arraytics Timetics allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Timetics: from n/a through 1.0.53.
AplazadaMedia (4.3)0.16%—TimeticsAI12/3/202617/6/2026
The Timetics WordPress plugin before 1.0.52 does not have authorization in a REST endpoint, allowing unauthenticated users to arbitrarily change a booking's payment status and post status for the "timetics-booking" custom post type.
AplazadaAlta (8.8)0.43%—Arraytics TimeticsAI8/1/202630/9/2026
Authentication Bypass Using an Alternate Path or Channel vulnerability in Arraytics Timetics timetics allows Authentication Abuse.This issue affects Timetics: from n/a through <= 1.0.46.
AplazadaMedia (6.5)0.24%—Arraytics WP TimeticsAI6/1/202630/9/2026
The Appointment Booking and Scheduling Calendar Plugin – WP Timetics plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on the update and register_routes functions in all versions up to, and including, 1.0.36. This makes it possible for unauthenticated…
AplazadaAlta (7.5)0.34%—Arraytics TimeticsAI18/12/202525/9/2026
Missing Authorization vulnerability in Arraytics Timetics timetics allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Timetics: from n/a through <= 1.0.44.
AplazadaMedia (5.3)0.45%—Arraytics TimeticsAI27/3/202517/6/2026
Missing Authorization vulnerability in Arraytics Timetics timetics allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Timetics: from n/a through <= 1.0.29.
AplazadaMedia (4.3)0.34%—Arraytics WP TimeticsAI13/12/202417/6/2026
The WP Timetics- AI-powered Appointment Booking Calendar and Online Scheduling Plugin plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the /wp-json/timetics/v1/customers/ REST API endpoint in all versions up to, and including, 1.0.27. This makes it possible for…
AnalizadaCrítica (9.8)0.53%—Arraytics WP Timetics1/11/202417/6/2026
Missing Authorization vulnerability in Arraytics Timetics allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Timetics: from n/a through 1.0.23.
AplazadaMedia (5.3)0.34%—Arraytics TimeticsAI1/11/202417/6/2026
Missing Authorization vulnerability in Arraytics Timetics allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Timetics: from n/a through 1.0.21.
AplazadaCrítica (9.8)1.1%—Arraytics WP TimeticsAI17/10/202417/6/2026
The WP Timetics- AI-powered Appointment Booking Calendar and Online Scheduling Plugin plugin for WordPress is vulnerable to Account Takeover/Privilege Escalation via Insecure Direct Object Reference in all versions up to, and including, 1.0.25 via the save() due to missing validation on a user controlled key. This…
AplazadaAlta (7.3)0.54%—TimeticsAI14/6/202417/6/2026
The Timetics- AI-powered Appointment Booking with Visual Seat Plan and ultimate Calendar Scheduling plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the make_staff() function in all versions up to, and including, 1.0.21. This makes it possible for…