Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2624▼ 224 respecto a la semana anterior
Críticas / altas1373▲ 143 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
–

796 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
RecibidaCrítica (9.1)——Vikappointments Services Booking CalendarAI3/10/20263/10/2026
The VikAppointments Services Booking Calendar plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the extract function in all versions up to, and including, 1.2.21. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which…
AplazadaBaja (3.7)——Wpdevelop Booking CalendarAI2/10/20262/10/2026
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in WPdevelop Booking Calendar booking allows Leveraging Race Conditions.This issue affects Booking Calendar: from n/a through 11.8.4.
AplazadaMedia (6.5)0.22%—Theeventscalendar THE Events CalendarAI2/10/20262/10/2026
The Events Calendar WordPress plugin before 6.17.5.1 does not validate or sanitise data submitted to an unauthenticated AJAX action before merging it into its rendering context, allowing unauthenticated users to execute arbitrary shortcodes registered on the site.
AplazadaMedia (5.4)0.20%—Theeventscalendar THE Events CalendarAI30/9/202630/9/2026
Contributor Broken Access Control in The Events Calendar <= 6.17.5 versions.
AplazadaAlta (7.5)0.26%—Vcita Online Booking Scheduling CalendarAI23/9/202623/9/2026
Unauthenticated Broken Access Control in Online Booking & Scheduling Calendar for WordPress by vcita <= 4.6.0 versions.
AplazadaBaja (3.8)0.23%—Theeventscalendar THE Events CalendarAI23/9/202623/9/2026
The Events Calendar WordPress plugin before 6.17.5 does not perform a per-object capability check on one family of its REST write routes, allowing users with a low-privilege role such as contributor to modify, unpublish, trash and take ownership of records belonging to other users, including administrators.
AplazadaBaja (2.7)0.23%—Modern Tribe THE Events CalendarAI23/9/202623/9/2026
The Events Calendar WordPress plugin before 6.17.5 does not check the capability required to publish content before creating or updating it through its REST API, allowing users with a role that cannot normally publish, such as contributor, to publish content directly and bypass editorial review.
AplazadaMedia (5.3)0.25%—Theeventscalendar THE Events CalendarAI23/9/202623/9/2026
The Events Calendar WordPress plugin before 6.17.5 does not check the post status of linked records before embedding their stored details into a public REST API response, allowing unauthenticated users to read the contents of records that have never been published.
Pendiente de análisisMedia (6.5)0.31%—IcalendarAI22/9/202623/9/2026
icalendar is an RFC 5545 compatible parser and generator of iCalendar files for Python. From 6.1.0 until 7.2.2, vInt.from_ical accepts an attacker-controlled VALARM REPEAT value and applications that request alarm times can eagerly expand it without an application-level limit. Alarms.times and Alarms.active reach the…
AplazadaMedia (6.1)0.37%—Booking CalendarAI22/9/202622/9/2026
The Booking Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wpbc_auto_fill' parameter in all versions up to, and including, 11.8.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in…
AplazadaAlta (7.2)0.66%—Booking CalendarAI18/9/202618/9/2026
The Booking Calendar plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 11.8.2 via the `wpbc_ajax_option_save` AJAX action. The vulnerability exists because the `handle_ajax_save()` function applies per-option safeguards only to names explicitly registered via…
AplazadaMedia (6.1)0.41%—Booking CalendarAI18/9/202618/9/2026
The Booking Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'options' parameter in all versions up to, and including, 11.8.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages…
AplazadaBaja (2.7)0.32%—Bookit Booking Appointment CalendarAI18/9/202618/9/2026
The Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.5 does not perform an authorization check on one of its appointment-retrieval actions, allowing users with a low-privilege Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.5-specific role to read other users' appointment…
AplazadaMedia (5.3)0.29%—Booking CalendarAI17/9/202619/9/2026
Unauthenticated Broken Access Control in Booking Calendar <= 11.7 versions.
AplazadaAlta (7.1)0.28%—Oracle Common Applications CalendarAI15/9/202617/9/2026
Vulnerability in the Oracle Common Applications Calendar product of Oracle E-Business Suite (component: Applications Calendar). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Common Applications…
AplazadaAlta (7.1)0.34%—Oracle Common Applications CalendarAI15/9/202617/9/2026
Vulnerability in the Oracle Common Applications Calendar product of Oracle E-Business Suite (component: Applications Calendar). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Common Applications…
AplazadaAlta (7.1)0.29%—Oracle E-business SuiteAIOracle Common Applications CalendarAI15/9/202617/9/2026
Vulnerability in the Oracle Common Applications Calendar product of Oracle E-Business Suite (component: Applications Calendar). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Common…
AplazadaMedia (6.4)0.24%—Booking FOR Appointments AND Events CalendarAI12/9/202614/9/2026
The Booking for Appointments and Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple Elementor widgets in versions up to and including 2.4.9. This is due to insufficient input sanitization and output escaping on the 'load_manually' parameter in the render() methods of…
AplazadaCrítica (9.8)1.4%—Theeventscalendar THE Events CalendarAI12/9/202614/9/2026
The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.3 via the parse_array function. This is due to insufficient validation of the widget 'classes' map, allowing a plain-array payload to bypass the is_safe_widget_instance() object check and…
AplazadaCrítica (9.8)1.5%—Theeventscalendar THE Events CalendarAI12/9/202614/9/2026
The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.4 via the is_safe_widget_instance function. This is due to insufficient protection in is_safe_widget_instance, which can be bypassed because PHP fires magic methods during its pre-parse,…
AplazadaAlta (7.2)0.46%—Ameliabooking Booking FOR Appointments AND Events CalendarAI12/9/202614/9/2026
The Booking for Appointments and Events Calendar WordPress plugin before 2.4.10 does not verify that the user editing a customer or employee record is entitled to modify the WordPress account linked to it, allowing users holding Amelia's customer or employee management permissions to set the password and email address…
AplazadaMedia (5.3)0.30%—Booking FOR Appointments AND Events CalendarAI12/9/202614/9/2026
The Booking for Appointments and Events Calendar WordPress plugin before 9.8.1 does not verify that a payment was actually taken before recording a booking as paid, trusting the payment gateway named in a public, unauthenticated booking request even when the site has never configured that gateway. This lets an…
AplazadaMedia (6.4)0.33%—MY CalendarAI9/9/202611/9/2026
The My Calendar – Accessible Event Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'before' and 'after' Shortcode Attributes in all versions up to, and including, 3.8.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
AplazadaMedia (6.4)0.36%—MY CalendarAI9/9/20269/9/2026
The My Calendar – Accessible Event Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'fallback' Shortcode Attribute in all versions up to, and including, 3.8.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
AplazadaBaja (2.7)0.32%—Theeventscalendar THE Events CalendarAI5/9/20268/9/2026
The Events Calendar WordPress plugin before 6.17.3.1 does not restrict non-public content to the users entitled to read it on its public REST archives, allowing users with a low-privilege role such as contributor to read the full contents of every unpublished record on the site, including other users'.