Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
9 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.4) | 0.17% | — | Magepeople WptravellyAI | 1/10/2026 | 1/10/2026 | Missing Authorization vulnerability in Magepeople inc. WpTravelly tour-booking-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WpTravelly: from n/a through 2.3.1. | |
| Aplazada | Alta (7.5) | 0.39% | — | WptravellyAI | 15/6/2026 | 17/6/2026 | Unauthenticated Bypass Vulnerability in WpTravelly <= 2.1.7 versions. | |
| Aplazada | Media (6.3) | 0.26% | — | Magepeople WptravellyAI | 26/5/2026 | 24/7/2026 | Missing Authorization vulnerability in Magepeople inc. WpTravelly allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WpTravelly: from n/a through 2.1.5. | |
| Aplazada | Media (4.3) | 0.23% | — | Magepeopleteam Wptravelly Tour-booking-managerAI | 8/4/2026 | 20/7/2026 | Missing Authorization vulnerability in magepeopleteam WpTravelly tour-booking-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WpTravelly: from n/a through <= 2.1.7. | |
| Aplazada | Alta (8.8) | 0.67% | — | Magepeopleteam WptravellyAI | 27/3/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in magepeopleteam WpTravelly tour-booking-manager allows PHP Local File Inclusion.This issue affects WpTravelly: from n/a through <= 1.8.7. | |
| Aplazada | Media (5.3) | 0.35% | — | Magepeopleteam WptravellyAI | 15/1/2025 | 17/6/2026 | Missing Authorization vulnerability in magepeopleteam WpTravelly tour-booking-manager allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WpTravelly: from n/a through <= 1.8.5. | |
| Aplazada | Alta (7.5) | 0.56% | — | Magepeople WptravellyAI | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in MagePeople Team WpTravelly allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WpTravelly: from n/a through 1.7.7. | |
| Aplazada | Media (5.3) | 0.39% | — | WptravellyAI | 29/5/2024 | 17/6/2026 | The WordPress Tour & Travel Booking Plugin for WooCommerce – WpTravelly plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ttbm_new_place_save' function in all versions up to, and including, 1.7.1. This makes it possible for unauthenticated attackers to… | |
| Aplazada | Media (4.3) | 0.21% | — | Magepeople WptravellyAI | 15/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in MagePeople Team WpTravelly.This issue affects WpTravelly: from n/a through 1.6.0. |