Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
298 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.1) | 2.0% | — | Wp-kama Kama Click Counter | 13/9/2019 | 17/6/2026 | The kama-clic-counter plugin 3.4.9 for WordPress has SQL injection via the admin.php order parameter. | |
| Modificada | Alta (8.8) | 0.80% | — | Tribulant ONE Click SSL | 30/8/2019 | 17/6/2026 | The one-click-ssl plugin before 1.4.7 for WordPress has CSRF. | |
| Modificada | Media (5.3) | 1.7% | — | Clickhouse | 15/8/2019 | 17/6/2026 | In ClickHouse before 18.12.13, functions for loading CatBoost models allowed path traversal and reading arbitrary files through error messages. | |
| Modificada | Crítica (9.8) | 3.4% | — | Clickhouse | 15/8/2019 | 17/6/2026 | In ClickHouse before 18.10.3, unixODBC allowed loading arbitrary shared objects from the file system which led to a Remote Code Execution vulnerability. | |
| Modificada | Crítica (9.8) | 1.8% | — | Clickhouse | 15/8/2019 | 17/6/2026 | Incorrect configuration in deb package in ClickHouse before 1.1.54131 could lead to unauthorized use of the database. | |
| Modificada | Alta (7.5) | 1.7% | — | Clickhouse | 15/8/2019 | 17/6/2026 | ClickHouse MySQL client before versions 1.1.54390 had "LOAD DATA LOCAL INFILE" functionality enabled that allowed a malicious MySQL database read arbitrary files from the connected ClickHouse server. | |
| Modificada | Alta (8.8) | 0.72% | — | Clickhouse | 15/8/2019 | 17/6/2026 | In ClickHouse before 1.1.54388, "remote" table function allowed arbitrary symbols in "user", "password" and "default_database" fields which led to Cross Protocol Request Forgery Attacks. | |
| Modificada | Crítica (9.8) | 2.0% | — | Mlmsoftwarez ADD Clicking MLM SoftwareMlmsoftwarez Autopool MLM SoftwareMlmsoftwarez Bidding MLM SoftwareMlmsoftwarez Binary MLM Software+6 | 24/5/2019 | 17/6/2026 | SQL injection exists in ADD Clicking MLM Software 1.0, Binary MLM Software 1.0, Level MLM Software 1.0, Singleleg MLM Software 1.0, Autopool MLM Software 1.0, Investment MLM Software 1.0, Bidding MLM Software 1.0, Moneyorder MLM Software 1.0, Repurchase MLM Software 1.0, and Gift MLM Software 1.0 via the… | |
| Modificada | Media (5.4) | 0.53% | — | Clickstudios Passwordstate | 1/8/2018 | 17/6/2026 | Click Studios Passwordstate before 8.3 Build 8397 allows XSS by authenticated users via an uploaded HTML document. | |
| Modificada | Alta (7.8) | 0.91% | — | Portrait Display SDKFujitsu Displayview ClickFujitsu Displayview Click SuiteHP Display Assistant+2 | 24/7/2018 | 17/6/2026 | Applications developed using the Portrait Display SDK, versions 2.30 through 2.34, default to insecure configurations which allow arbitrary code execution. A number of applications developed using the Portrait Displays SDK do not use secure permissions when running. These applications run the component pdiservice.exe… | |
| Modificada | Alta (7.5) | 1.1% | — | Barco Clickshare Cse-200 FirmwareBarco Clickshare Cs-100 Firmware | 10/7/2018 | 17/6/2026 | An issue was discovered on Barco ClickShare CSE-200 and CS-100 Base Units with firmware before 1.6.0.3. Sending an arbitrary unexpected string to TCP port 7100 respecting a certain frequency timing disconnects all clients and results in a crash of the Unit. | |
| Modificada | Crítica (9.8) | 3.5% | — | Ezpz-one-click-backup Project Ezpz-one-click-backup | 10/4/2018 | 17/6/2026 | The EZPZ One Click Backup (ezpz-one-click-backup) plugin 12.03.10 and earlier for WordPress allows remote attackers to execute arbitrary commands via the cmd parameter to functions/ezpz-archive-cmd.php. | |
| Modificada | Media (6.1) | 1.6% | — | Affiliate ADS FOR Clickbank Products | 1/1/2018 | 17/6/2026 | The MyCBGenie Affiliate Ads for Clickbank Products plugin through 1.6 for WordPress has XSS via the text_ads_ajax.php border_color parameter. | |
| Modificada | Alta (7.8) | 1.1% | — | Automationdirect Click PLC FirmwareAutomationdirect C-more PLC FirmwareAutomationdirect C-more Micro FirmwareAutomationdirect GS Drives Fimware+1 | 13/11/2017 | 17/6/2026 | In AutomationDirect CLICK Programming Software (Part Number C0-PGMSW) Versions 2.10 and prior; C-More Programming Software (Part Number EA9-PGMSW) Versions 6.30 and prior; C-More Micro (Part Number EA-PGMSW) Versions 4.20.01.0 and prior; Do-more Designer Software (Part Number DM-PGMSW) Versions 2.0.3 and prior; GS… | |
| Modificada | Alta (8.8) | 4.3% | — | Barco Clickshare Csm-1 FirmwareBarco Clickshare Csc-1 Firmware | 30/10/2017 | 17/6/2026 | A command injection was identified on Barco ClickShare Base Unit devices with CSM-1 firmware before 1.7.0.3 and CSC-1 firmware before 1.10.0.10. An attacker with access to the product's web API can exploit this vulnerability to completely compromise the vulnerable device. | |
| Modificada | Media (5.4) | 0.64% | — | Barco Clickshare Csm-1 FirmwareBarco Clickshare Csc-1 Firmware | 30/10/2017 | 17/6/2026 | An issue was discovered in Barco ClickShare CSM-1 firmware before v1.7.0.3 and CSC-1 firmware before v1.10.0.10. An authenticated user can manage the wallpaper collection in the webUI to be shown as background on the ClickShare product. By uploading a wallpaper with a specially crafted name, an HTML injection can be… | |
| Modificada | Media (6.1) | 1.1% | — | Clickfraud-monitoring Adsense-click-fraud-monitoringPhpwhois Project Phpwhois | 17/5/2017 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in phpwhois 4.2.5, as used in the adsense-click-fraud-monitoring plugin 1.7.5 for WordPress, allows remote attackers to inject arbitrary web script or HTML via the query parameter to whois.php. | |
| Modificada | Crítica (9.8) | 2.7% | — | Click Project ClickCanonical Ubuntu Linux | 13/2/2017 | 17/6/2026 | click/install.py in click does not require files in package filesystem tarballs to start with ./ (dot slash), which allows remote attackers to install an alternate security policy and gain privileges via a crafted package, as demonstrated by the test.mmrow app for Ubuntu phone. | |
| Modificada | Crítica (9.8) | 2.8% | — | Barco Clickshare Csc-1 Firmware | 12/1/2017 | 17/6/2026 | Barco ClickShare CSC-1 devices with firmware before 01.09.03 allow remote attackers to obtain the root password by downloading and extracting the firmware image. | |
| Modificada | Alta (7.5) | 4.3% | — | Barco Clickshare Csc-1 FirmwareBarco Clickshare Csm-1 FirmwareBarco Clickshare Cse-200 Firmware | 12/1/2017 | 17/6/2026 | Directory traversal vulnerability in the wallpaper parsing functionality in Barco ClickShare CSC-1 devices with firmware before 01.09.03, CSM-1 devices with firmware before 01.06.02, and CSE-200 devices with firmware before 01.03.02 allows remote attackers to read /etc/shadow via unspecified vectors. | |
| Modificada | Media (6.1) | 1.3% | — | Barco Clickshare Csc-1 FirmwareBarco Clickshare Cse-200 Firmware | 12/1/2017 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in wallpaper.php in the Base Unit in Barco ClickShare CSC-1 devices with firmware before 01.09.03, CSM-1 devices with firmware before 01.06.02, and CSE-200 devices with firmware before 01.03.02 allows remote attackers to inject arbitrary web script or HTML via unspecified… | |
| Modificada | Crítica (9.8) | 7.7% | — | Barco Clickshare Csc-1 FirmwareBarco Clickshare Csm-1 Firmware | 12/1/2017 | 17/6/2026 | Barco ClickShare CSC-1 devices with firmware before 01.09.03 and CSM-1 devices with firmware before 01.06.02 allow remote attackers to execute arbitrary code via unspecified vectors. | |
| Modificada | Media (6.8) | 1.1% | 💥 Exploit | Labsmedia Clickheat | 18/6/2015 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in ClickHeat 1.14 and earlier allows remote attackers to hijack the authentication of administrators for requests that change the administrator password via a config action to index.php. | |
| Modificada | Media (5.4) | 0.27% | — | Flexymind President Clicker | 21/10/2014 | 17/6/2026 | The President Clicker (aka com.flexymind.pclicker) application 1.0.4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Baja (3.5) | 0.95% | — | Drupal Doubleclick FOR Publishers | 13/10/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Google Doubleclick for Publishers (DFP) module 7.x-1.x before 7.x-1.2 for Drupal allows remote authenticated users with the "administer dfp" permission to inject arbitrary web script or HTML via a slot name. |