Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

298 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)0.94%—External Links Click Statistics Project External Links Click Statistics3/10/201417/6/2026
Cross-site scripting (XSS) vulnerability in the External links click statistics (outstats) extension 0.0.3 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (4.3)1.2%—Click2sell Suite Module25/9/201316/6/2026
Cross-site scripting (XSS) vulnerability in the Click2Sell Suite module 6.x-1.x for Drupal allows remote attackers to inject arbitrary web script or HTML via a confirmation form.
ModificadaMedia (6.8)0.64%—Click2sell Suite Module25/9/201316/6/2026
Cross-site request forgery (CSRF) vulnerability in the Click2Sell Suite module 6.x-1.x for Drupal allows remote attackers to hijack the authentication of administrators for requests that delete database information via vectors involving the Drupal Form API.
ModificadaMedia (4.3)1.8%💥 ExploitEliteweaver Xclick Cart1/10/201216/6/2026
Cross-site scripting (XSS) vulnerability in webscr.php in xClick Cart 1.0.1 and 1.0.2 allows remote attackers to inject arbitrary web script or HTML via the shopping_url parameter.
ModificadaMedia (4.3)10%💥 ExploitClickdesk Live Support-live Chat Plugin20/9/201216/6/2026
Cross-site scripting (XSS) vulnerability in clickdesk.php in ClickDesk Live Support - Live Chat plugin 2.0 for WordPress allows remote attackers to inject arbitrary web script or HTML via the cdwidgetid parameter. NOTE: some of these details are obtained from third party information.
ModificadaMedia (6.4)1.8%—Sami Kiminki Redirecting Click Bouncer17/9/201216/6/2026
Open redirect vulnerability in the Redirecting click bouncer module for Drupal allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
ModificadaMedia (4.3)5.8%💥 ExploitPpfeufer 2-click-social-media-buttons13/8/201216/6/2026
Cross-site scripting (XSS) vulnerability in libs/xing.php in the 2 Click Social Media Buttons plugin before 0.34 for WordPress allows remote attackers to inject arbitrary web script or HTML via the xing-url parameter.
ModificadaMedia (4.3)1.6%—Ppfeufer 2-click-social-media-buttons13/8/201216/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the 2 Click Social Media Buttons plugin before 0.34 for WordPress allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to the "processing of the buttons of Xing and Pinterest".
ModificadaMedia (5)1.1%—Oneclickorgs ONE Click Orgs6/12/201116/6/2026
The password reset feature in One Click Orgs before 1.2.3 generates different error messages for failed reset attempts depending on whether the e-mail address is registered, which allows remote attackers to enumerate user accounts via a series of requests.
ModificadaAlta (7.5)1.3%—Oneclickorgs ONE Click Orgs6/12/201116/6/2026
One Click Orgs before 1.2.3 does not have an off autocomplete attribute for authentication fields, which makes it easier for remote attackers to obtain access by leveraging an unattended workstation.
ModificadaMedia (4)0.88%—Oneclickorgs ONE Click Orgs6/12/201116/6/2026
One Click Orgs before 1.2.3 does not require unique e-mail addresses for user accounts, which allows remote authenticated users to cause a denial of service (login disruption) or spoof votes or comments by selecting a conflicting e-mail address.
ModificadaMedia (5.5)0.88%—Oneclickorgs ONE Click Orgs6/12/201116/6/2026
One Click Orgs before 1.2.3 allows remote authenticated users to trigger crafted SMTP traffic via (1) " (double quote) and newline characters in an org name or (2) " (double quote) characters in an e-mail address, related to a "2nd Order SMTP Injection" issue.
ModificadaMedia (5.8)0.95%—Oneclickorgs ONE Click Orgs6/12/201116/6/2026
Multiple open redirect vulnerabilities in One Click Orgs before 1.2.3 allow (1) remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the return_to parameter, and allow (2) remote authenticated users to redirect users to arbitrary web sites and conduct phishing attacks via crafted…
ModificadaMedia (4.3)0.84%—Oneclickorgs ONE Click Orgs6/12/201116/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in One Click Orgs before 1.2.3 allow remote attackers to inject arbitrary web script or HTML via the description field of (1) a new vote or (2) the eject member proposal feature.
ModificadaMedia (4.3)1.2%💥 ExploitEdgephp Clickbank Affiliate Marketplace Script12/7/201016/6/2026
Cross-site scripting (XSS) vulnerability in index.php in Edge PHP Clickbank Affiliate Marketplace Script (CBQuick) allows remote attackers to inject arbitrary web script or HTML via the search parameter.
ModificadaAlta (7.5)0.96%💥 ExploitEdgephp Clickbank Affiliate Marketplace Script12/7/201016/6/2026
SQL injection vulnerability in index.php in Edge PHP Clickbank Affiliate Marketplace Script (CBQuick) allows remote attackers to execute arbitrary SQL commands via the search parameter.
ModificadaMedia (5)3.0%💥 ExploitClicknet CMS5/7/200916/6/2026
Directory traversal vulnerability in index.php in Clicknet CMS 2.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the side parameter.
ModificadaAlta (7.5)0.99%💥 ExploitClicktech Clickcart10/2/200916/6/2026
Multiple SQL injection vulnerabilities in customer_login_check.asp in ClickTech ClickCart 6.0 allow remote attackers to execute arbitrary SQL commands via (1) the txtEmail parameter (aka E-MAIL field) or (2) the txtPassword parameter (aka password field) to customer_login.asp. NOTE: some of these details are obtained…
ModificadaAlta (7.5)2.1%💥 ExploitClicktech Clickauction27/1/200916/6/2026
SQL injection vulnerability in login_check.asp in ClickAuction allows remote attackers to execute arbitrary SQL commands via the (1) txtEmail and (2) txtPassword parameters. NOTE: some of these details are obtained from third party information.
ModificadaBaja (2.6)1.6%💥 ExploitIcash Click&email12/1/200916/6/2026
Cross-site scripting (XSS) vulnerability in admin_dblayers.asp in ClickAndEmail allows remote attackers to inject arbitrary web script or HTML via the tablename parameter in an update action.
ModificadaAlta (7.5)0.97%💥 ExploitIcash Click&email12/1/200916/6/2026
Multiple SQL injection vulnerabilities in ClickAndEmail allow remote attackers to execute arbitrary SQL commands via (1) the ID parameter to admin_dblayers.asp in an update action, (2) the adminid parameter to admin_loginCheck.asp (aka the USERNAME field in admin_main.asp), and (3) the PassWord parameter to…
ModificadaMedia (4.3)1.2%💥 ExploitIcash Click&rank12/1/200916/6/2026
Cross-site scripting (XSS) vulnerability in user.asp in Click&Rank allows remote attackers to inject arbitrary web script or HTML via the action parameter.
ModificadaAlta (7.5)0.97%💥 ExploitIcash Click&rank12/1/200916/6/2026
Multiple SQL injection vulnerabilities in Click&Rank allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) hitcounter.asp, (2) user_delete.asp, and (3) user_update.asp; (4) the userid parameter to admin_login.asp (aka the USERNAME field in admin.asp); and (5) the PassWord parameter to…
ModificadaMedia (6.8)24%💥 ExploitRecly Clickheat-heatmap31/12/200816/6/2026
Multiple PHP remote file inclusion vulnerabilities in the Clickheat - Heatmap stats (com_clickheat) component 1.0.1 for Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the (1) GLOBALS[mosConfig_absolute_path] parameter to (a) install.clickheat.php, (b) Cache.php and (c) Clickheat_Heatmap.php…
ModificadaMedia (4.3)1.4%💥 ExploitED Putal Clickbank Portal22/10/200816/6/2026
Cross-site scripting (XSS) vulnerability in search.php in Ed Pudol Clickbank Portal allows remote attackers to inject arbitrary web script or HTML via the search box. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Orbitaley — Vulnerabilidades