Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2750▲ 27 respecto a la semana anterior
Críticas / altas1468▲ 334 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
2525 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Crítica (9.1) | — | — | Vikappointments Services Booking CalendarAI | 3/10/2026 | 3/10/2026 | The VikAppointments Services Booking Calendar plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the extract function in all versions up to, and including, 1.2.21. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which… | |
| Aplazada | Baja (3.7) | — | — | Wpdevelop Booking CalendarAI | 2/10/2026 | 2/10/2026 | Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in WPdevelop Booking Calendar booking allows Leveraging Race Conditions.This issue affects Booking Calendar: from n/a through 11.8.4. | |
| Aplazada | Media (5.3) | 0.27% | — | Appointment Booking Plugin LatepointAI | 2/10/2026 | 2/10/2026 | The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 5.7.1 via the OsPaypalConnectController::create_order_for_transaction() action registered as a public (unauthenticated) route through… | |
| Aplazada | Alta (7.2) | 0.31% | — | Ba-booking BA Book EverythingAI | 2/10/2026 | 2/10/2026 | The BA Book Everything plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'booking_service_qty' parameter in all versions up to, and including, 1.8.28 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts… | |
| Aplazada | Media (6.5) | 0.24% | — | Mage-people BUS Ticket Booking With Seat ReservationAI | 1/10/2026 | 1/10/2026 | Unauthenticated Insecure Direct Object References (IDOR) in Bus Ticket Booking with Seat Reservation <= 5.9.3 versions. | |
| Aplazada | Alta (7.2) | 0.26% | — | Dwbooster Appointment Hour BookingAI | 1/10/2026 | 1/10/2026 | The Appointment Hour Booking – Booking Calendar plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via Booking Form Single-Line Field via Schedule Calendar List Renderer in all versions up to, and including, 1.5.97 due to insufficient input sanitization and output escaping. This makes it… | |
| Aplazada | Crítica (9.8) | 0.39% | — | Booking ActivitiesAI | 30/9/2026 | 30/9/2026 | Unauthenticated PHP Object Injection in Booking Activities <= 1.18.7.1 versions. | |
| Aplazada | Media (4.3) | 0.28% | — | Webba-booking Webba BookingAI | 30/9/2026 | 30/9/2026 | Subscriber Insecure Direct Object References (IDOR) in Webba Booking <= 6.5.0 versions. | |
| Aplazada | Crítica (9.3) | 0.29% | — | Books GalleryAI | 30/9/2026 | 30/9/2026 | Unauthenticated SQL Injection in Books Gallery <= 4.8.3 versions. | |
| Aplazada | Alta (7.5) | 0.27% | — | Booking-wp-plugin BooklyAI | 30/9/2026 | 30/9/2026 | Unauthenticated Broken Access Control in Bookly <= 28.2 versions. | |
| Aplazada | Media (6.5) | 0.28% | — | Booking-wp-plugin BooklyAI | 30/9/2026 | 30/9/2026 | Subscriber Insecure Direct Object References (IDOR) in Bookly <= 28.2 versions. | |
| Aplazada | Media (5.3) | 0.21% | — | Course Booking SystemAI | 30/9/2026 | 30/9/2026 | The Course Booking System WordPress plugin before 7.0.9 does not restrict access to its booking export, allowing unauthenticated users to download the name, email address and billing address of every customer who has booked a course. | |
| Pendiente de análisis | Alta (8.1) | 0.20% | — | JupyterlabAIJupyter NotebookAIJupyterlite CoreAI | 29/9/2026 | 2/10/2026 | JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From JupyterLab 4.5.0 until 4.5.11 and 4.6.4, from Notebook 7.5.0 until 7.6.3, and from JupyterLite Core 0.7.0 until 0.8.4, the system clipboard cell-paste path accepts attacker-controlled… | |
| Aplazada | Media (5.3) | 0.25% | — | Facebook ProxygenAI | 28/9/2026 | 30/9/2026 | In proxygen from v2024.10.28.00 until v2026.09.28.00, the HTTPTransaction::onWebTransportUniStream and HTTPTransaction::onWebTransportBidiStream APIs could return stream handles that the stream handler had already freed. HQSession then installed those handles as transport read callbacks, which could lead to use of… | |
| Aplazada | Alta (7.3) | 0.19% | — | Facebook ProxygenAI | 28/9/2026 | 1/10/2026 | In proxygen from v2026.04.06.00 until v2026.09.28.00, QuicWtSession::closeSession accesses its member fields after calling the base QuicWtSessionBase::closeSession method. The base method notifies the session handler, which may release the last reference to the session and destroy it. | |
| Analizada | Media (5.3) | 0.15% | — | Ordasoft Book Library | 28/9/2026 | 1/10/2026 | Joomla Extension - ordasoft.com - Reflected Cross-Site Scripting in Book Library (Free) < 6.4.6 - The public book-detail page template, site/views/view_book/tmpl/default.php, echoes the raw title request parameter directly into a double-quoted HTML attribute with no escaping function of any kind (echo… | |
| En análisis | Crítica (9.3) | 0.28% | — | Ordasoft Book LibraryAI | 28/9/2026 | 30/9/2026 | Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Book Library (Free) < 6.4.6 - site/booklibrary.php’s books() function reads the field and direction request parameters and passes each through a function called protectInjectionWithoutQuote(), whose only real protection is a keyword blacklist that, on… | |
| Aplazada | Media (5.3) | 0.22% | — | Booking-wp-plugin BooklyAI | 28/9/2026 | 28/9/2026 | The Bookly WordPress plugin before 28.3 does not validate client-supplied booking quantity values on the server before computing the appointment total, allowing unauthenticated users to reduce the total to zero and book paid services for free while bypassing the payment step. | |
| Aplazada | Media (4.7) | 0.19% | — | Online Scheduling AND Appointment Booking SystemAI | 27/9/2026 | 28/9/2026 | The Online Scheduling and Appointment Booking System WordPress plugin before 28.3 does not prevent deserialization of untrusted input and does not correctly restrict a privileged maintenance feature to administrators, allowing users granted a custom booking-management capability, which an administrator must explicitly… | |
| Aplazada | Baja (3.8) | 0.15% | — | Online Scheduling AND Appointment Booking SystemAI | 27/9/2026 | 28/9/2026 | The Online Scheduling and Appointment Booking System WordPress plugin before 28.3 does not verify that appointment and payment records requested through its staff-role AJAX actions belong to the requesting staff member, allowing authenticated attackers with a staff-level account to view, modify and delete other staff… | |
| Aplazada | Media (5.3) | 0.18% | — | Booking-wp-plugin BooklyAI | 25/9/2026 | 25/9/2026 | The Bookly WordPress plugin before 28.3 does not properly verify a customer's identity before updating their stored details, allowing unauthenticated attackers who know a customer's primary identifier to overwrite that customer's stored personal information such as name, email and address. | |
| Aplazada | Alta (7.2) | 0.24% | — | Ba-booking BA Book EverythingAI | 25/9/2026 | 25/9/2026 | The BA Book Everything plugin for WordPress is vulnerable to Stored Cross-Site Scripting via first_name Parameter in all versions up to, and including, 1.8.27 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that… | |
| Aplazada | Crítica (9.1) | 0.37% | — | Booking-wp-plugin BooklyAI | 25/9/2026 | 26/9/2026 | The Bookly plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 28.2 via the 'bookly_get_form_id', 'bookly_render_complete', 'bookly_add_to_calendar' and 'bookly_rollback_order' AJAX actions. This is due to the 'bookly_get_form_id' handler blindly storing the… | |
| Aplazada | Media (5.3) | 0.32% | — | Booking-wp-plugin BooklyAI | 25/9/2026 | 25/9/2026 | The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Authorization Bypass via PHP Type Juggling in all versions up to, and including, 28.2. This is due to the `postValidateCustomer()` function using a loose PHP inequality operator (`!=`) to compare the session-stored… | |
| Aplazada | Alta (7.5) | 0.26% | — | Vcita Online Booking Scheduling CalendarAI | 23/9/2026 | 23/9/2026 | Unauthenticated Broken Access Control in Online Booking & Scheduling Calendar for WordPress by vcita <= 4.6.0 versions. |