Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

298 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.1)2.0%—Wp-kama Kama Click Counter13/9/201917/6/2026
The kama-clic-counter plugin 3.4.9 for WordPress has SQL injection via the admin.php order parameter.
ModificadaAlta (8.8)0.80%—Tribulant ONE Click SSL30/8/201917/6/2026
The one-click-ssl plugin before 1.4.7 for WordPress has CSRF.
ModificadaMedia (5.3)1.7%—Clickhouse15/8/201917/6/2026
In ClickHouse before 18.12.13, functions for loading CatBoost models allowed path traversal and reading arbitrary files through error messages.
ModificadaCrítica (9.8)3.4%—Clickhouse15/8/201917/6/2026
In ClickHouse before 18.10.3, unixODBC allowed loading arbitrary shared objects from the file system which led to a Remote Code Execution vulnerability.
ModificadaCrítica (9.8)1.8%—Clickhouse15/8/201917/6/2026
Incorrect configuration in deb package in ClickHouse before 1.1.54131 could lead to unauthorized use of the database.
ModificadaAlta (7.5)1.7%—Clickhouse15/8/201917/6/2026
ClickHouse MySQL client before versions 1.1.54390 had "LOAD DATA LOCAL INFILE" functionality enabled that allowed a malicious MySQL database read arbitrary files from the connected ClickHouse server.
ModificadaAlta (8.8)0.72%—Clickhouse15/8/201917/6/2026
In ClickHouse before 1.1.54388, "remote" table function allowed arbitrary symbols in "user", "password" and "default_database" fields which led to Cross Protocol Request Forgery Attacks.
ModificadaCrítica (9.8)2.0%—Mlmsoftwarez ADD Clicking MLM SoftwareMlmsoftwarez Autopool MLM SoftwareMlmsoftwarez Bidding MLM SoftwareMlmsoftwarez Binary MLM Software+624/5/201917/6/2026
SQL injection exists in ADD Clicking MLM Software 1.0, Binary MLM Software 1.0, Level MLM Software 1.0, Singleleg MLM Software 1.0, Autopool MLM Software 1.0, Investment MLM Software 1.0, Bidding MLM Software 1.0, Moneyorder MLM Software 1.0, Repurchase MLM Software 1.0, and Gift MLM Software 1.0 via the…
ModificadaMedia (5.4)0.53%—Clickstudios Passwordstate1/8/201817/6/2026
Click Studios Passwordstate before 8.3 Build 8397 allows XSS by authenticated users via an uploaded HTML document.
ModificadaAlta (7.8)0.91%—Portrait Display SDKFujitsu Displayview ClickFujitsu Displayview Click SuiteHP Display Assistant+224/7/201817/6/2026
Applications developed using the Portrait Display SDK, versions 2.30 through 2.34, default to insecure configurations which allow arbitrary code execution. A number of applications developed using the Portrait Displays SDK do not use secure permissions when running. These applications run the component pdiservice.exe…
ModificadaAlta (7.5)1.1%—Barco Clickshare Cse-200 FirmwareBarco Clickshare Cs-100 Firmware10/7/201817/6/2026
An issue was discovered on Barco ClickShare CSE-200 and CS-100 Base Units with firmware before 1.6.0.3. Sending an arbitrary unexpected string to TCP port 7100 respecting a certain frequency timing disconnects all clients and results in a crash of the Unit.
ModificadaCrítica (9.8)3.5%—Ezpz-one-click-backup Project Ezpz-one-click-backup10/4/201817/6/2026
The EZPZ One Click Backup (ezpz-one-click-backup) plugin 12.03.10 and earlier for WordPress allows remote attackers to execute arbitrary commands via the cmd parameter to functions/ezpz-archive-cmd.php.
ModificadaMedia (6.1)1.6%—Affiliate ADS FOR Clickbank Products1/1/201817/6/2026
The MyCBGenie Affiliate Ads for Clickbank Products plugin through 1.6 for WordPress has XSS via the text_ads_ajax.php border_color parameter.
ModificadaAlta (7.8)1.1%—Automationdirect Click PLC FirmwareAutomationdirect C-more PLC FirmwareAutomationdirect C-more Micro FirmwareAutomationdirect GS Drives Fimware+113/11/201717/6/2026
In AutomationDirect CLICK Programming Software (Part Number C0-PGMSW) Versions 2.10 and prior; C-More Programming Software (Part Number EA9-PGMSW) Versions 6.30 and prior; C-More Micro (Part Number EA-PGMSW) Versions 4.20.01.0 and prior; Do-more Designer Software (Part Number DM-PGMSW) Versions 2.0.3 and prior; GS…
ModificadaAlta (8.8)4.3%—Barco Clickshare Csm-1 FirmwareBarco Clickshare Csc-1 Firmware30/10/201717/6/2026
A command injection was identified on Barco ClickShare Base Unit devices with CSM-1 firmware before 1.7.0.3 and CSC-1 firmware before 1.10.0.10. An attacker with access to the product's web API can exploit this vulnerability to completely compromise the vulnerable device.
ModificadaMedia (5.4)0.64%—Barco Clickshare Csm-1 FirmwareBarco Clickshare Csc-1 Firmware30/10/201717/6/2026
An issue was discovered in Barco ClickShare CSM-1 firmware before v1.7.0.3 and CSC-1 firmware before v1.10.0.10. An authenticated user can manage the wallpaper collection in the webUI to be shown as background on the ClickShare product. By uploading a wallpaper with a specially crafted name, an HTML injection can be…
ModificadaMedia (6.1)1.1%—Clickfraud-monitoring Adsense-click-fraud-monitoringPhpwhois Project Phpwhois17/5/201717/6/2026
Cross-site scripting (XSS) vulnerability in phpwhois 4.2.5, as used in the adsense-click-fraud-monitoring plugin 1.7.5 for WordPress, allows remote attackers to inject arbitrary web script or HTML via the query parameter to whois.php.
ModificadaCrítica (9.8)2.7%—Click Project ClickCanonical Ubuntu Linux13/2/201717/6/2026
click/install.py in click does not require files in package filesystem tarballs to start with ./ (dot slash), which allows remote attackers to install an alternate security policy and gain privileges via a crafted package, as demonstrated by the test.mmrow app for Ubuntu phone.
ModificadaCrítica (9.8)2.8%—Barco Clickshare Csc-1 Firmware12/1/201717/6/2026
Barco ClickShare CSC-1 devices with firmware before 01.09.03 allow remote attackers to obtain the root password by downloading and extracting the firmware image.
ModificadaAlta (7.5)4.3%—Barco Clickshare Csc-1 FirmwareBarco Clickshare Csm-1 FirmwareBarco Clickshare Cse-200 Firmware12/1/201717/6/2026
Directory traversal vulnerability in the wallpaper parsing functionality in Barco ClickShare CSC-1 devices with firmware before 01.09.03, CSM-1 devices with firmware before 01.06.02, and CSE-200 devices with firmware before 01.03.02 allows remote attackers to read /etc/shadow via unspecified vectors.
ModificadaMedia (6.1)1.3%—Barco Clickshare Csc-1 FirmwareBarco Clickshare Cse-200 Firmware12/1/201717/6/2026
Cross-site scripting (XSS) vulnerability in wallpaper.php in the Base Unit in Barco ClickShare CSC-1 devices with firmware before 01.09.03, CSM-1 devices with firmware before 01.06.02, and CSE-200 devices with firmware before 01.03.02 allows remote attackers to inject arbitrary web script or HTML via unspecified…
ModificadaCrítica (9.8)7.7%—Barco Clickshare Csc-1 FirmwareBarco Clickshare Csm-1 Firmware12/1/201717/6/2026
Barco ClickShare CSC-1 devices with firmware before 01.09.03 and CSM-1 devices with firmware before 01.06.02 allow remote attackers to execute arbitrary code via unspecified vectors.
ModificadaMedia (6.8)1.1%💥 ExploitLabsmedia Clickheat18/6/201517/6/2026
Cross-site request forgery (CSRF) vulnerability in ClickHeat 1.14 and earlier allows remote attackers to hijack the authentication of administrators for requests that change the administrator password via a config action to index.php.
ModificadaMedia (5.4)0.27%—Flexymind President Clicker21/10/201417/6/2026
The President Clicker (aka com.flexymind.pclicker) application 1.0.4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaBaja (3.5)0.95%—Drupal Doubleclick FOR Publishers13/10/201417/6/2026
Cross-site scripting (XSS) vulnerability in the Google Doubleclick for Publishers (DFP) module 7.x-1.x before 7.x-1.2 for Drupal allows remote authenticated users with the "administer dfp" permission to inject arbitrary web script or HTML via a slot name.
Orbitaley — Vulnerabilidades