Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
298 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 0.94% | — | External Links Click Statistics Project External Links Click Statistics | 3/10/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the External links click statistics (outstats) extension 0.0.3 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (4.3) | 1.2% | — | Click2sell Suite Module | 25/9/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Click2Sell Suite module 6.x-1.x for Drupal allows remote attackers to inject arbitrary web script or HTML via a confirmation form. | |
| Modificada | Media (6.8) | 0.64% | — | Click2sell Suite Module | 25/9/2013 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in the Click2Sell Suite module 6.x-1.x for Drupal allows remote attackers to hijack the authentication of administrators for requests that delete database information via vectors involving the Drupal Form API. | |
| Modificada | Media (4.3) | 1.8% | 💥 Exploit | Eliteweaver Xclick Cart | 1/10/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in webscr.php in xClick Cart 1.0.1 and 1.0.2 allows remote attackers to inject arbitrary web script or HTML via the shopping_url parameter. | |
| Modificada | Media (4.3) | 10% | 💥 Exploit | Clickdesk Live Support-live Chat Plugin | 20/9/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in clickdesk.php in ClickDesk Live Support - Live Chat plugin 2.0 for WordPress allows remote attackers to inject arbitrary web script or HTML via the cdwidgetid parameter. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (6.4) | 1.8% | — | Sami Kiminki Redirecting Click Bouncer | 17/9/2012 | 16/6/2026 | Open redirect vulnerability in the Redirecting click bouncer module for Drupal allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors. | |
| Modificada | Media (4.3) | 5.8% | 💥 Exploit | Ppfeufer 2-click-social-media-buttons | 13/8/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in libs/xing.php in the 2 Click Social Media Buttons plugin before 0.34 for WordPress allows remote attackers to inject arbitrary web script or HTML via the xing-url parameter. | |
| Modificada | Media (4.3) | 1.6% | — | Ppfeufer 2-click-social-media-buttons | 13/8/2012 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the 2 Click Social Media Buttons plugin before 0.34 for WordPress allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to the "processing of the buttons of Xing and Pinterest". | |
| Modificada | Media (5) | 1.1% | — | Oneclickorgs ONE Click Orgs | 6/12/2011 | 16/6/2026 | The password reset feature in One Click Orgs before 1.2.3 generates different error messages for failed reset attempts depending on whether the e-mail address is registered, which allows remote attackers to enumerate user accounts via a series of requests. | |
| Modificada | Alta (7.5) | 1.3% | — | Oneclickorgs ONE Click Orgs | 6/12/2011 | 16/6/2026 | One Click Orgs before 1.2.3 does not have an off autocomplete attribute for authentication fields, which makes it easier for remote attackers to obtain access by leveraging an unattended workstation. | |
| Modificada | Media (4) | 0.88% | — | Oneclickorgs ONE Click Orgs | 6/12/2011 | 16/6/2026 | One Click Orgs before 1.2.3 does not require unique e-mail addresses for user accounts, which allows remote authenticated users to cause a denial of service (login disruption) or spoof votes or comments by selecting a conflicting e-mail address. | |
| Modificada | Media (5.5) | 0.88% | — | Oneclickorgs ONE Click Orgs | 6/12/2011 | 16/6/2026 | One Click Orgs before 1.2.3 allows remote authenticated users to trigger crafted SMTP traffic via (1) " (double quote) and newline characters in an org name or (2) " (double quote) characters in an e-mail address, related to a "2nd Order SMTP Injection" issue. | |
| Modificada | Media (5.8) | 0.95% | — | Oneclickorgs ONE Click Orgs | 6/12/2011 | 16/6/2026 | Multiple open redirect vulnerabilities in One Click Orgs before 1.2.3 allow (1) remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the return_to parameter, and allow (2) remote authenticated users to redirect users to arbitrary web sites and conduct phishing attacks via crafted… | |
| Modificada | Media (4.3) | 0.84% | — | Oneclickorgs ONE Click Orgs | 6/12/2011 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in One Click Orgs before 1.2.3 allow remote attackers to inject arbitrary web script or HTML via the description field of (1) a new vote or (2) the eject member proposal feature. | |
| Modificada | Media (4.3) | 1.2% | 💥 Exploit | Edgephp Clickbank Affiliate Marketplace Script | 12/7/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in Edge PHP Clickbank Affiliate Marketplace Script (CBQuick) allows remote attackers to inject arbitrary web script or HTML via the search parameter. | |
| Modificada | Alta (7.5) | 0.96% | 💥 Exploit | Edgephp Clickbank Affiliate Marketplace Script | 12/7/2010 | 16/6/2026 | SQL injection vulnerability in index.php in Edge PHP Clickbank Affiliate Marketplace Script (CBQuick) allows remote attackers to execute arbitrary SQL commands via the search parameter. | |
| Modificada | Media (5) | 3.0% | 💥 Exploit | Clicknet CMS | 5/7/2009 | 16/6/2026 | Directory traversal vulnerability in index.php in Clicknet CMS 2.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the side parameter. | |
| Modificada | Alta (7.5) | 0.99% | 💥 Exploit | Clicktech Clickcart | 10/2/2009 | 16/6/2026 | Multiple SQL injection vulnerabilities in customer_login_check.asp in ClickTech ClickCart 6.0 allow remote attackers to execute arbitrary SQL commands via (1) the txtEmail parameter (aka E-MAIL field) or (2) the txtPassword parameter (aka password field) to customer_login.asp. NOTE: some of these details are obtained… | |
| Modificada | Alta (7.5) | 2.1% | 💥 Exploit | Clicktech Clickauction | 27/1/2009 | 16/6/2026 | SQL injection vulnerability in login_check.asp in ClickAuction allows remote attackers to execute arbitrary SQL commands via the (1) txtEmail and (2) txtPassword parameters. NOTE: some of these details are obtained from third party information. | |
| Modificada | Baja (2.6) | 1.6% | 💥 Exploit | Icash Click&email | 12/1/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in admin_dblayers.asp in ClickAndEmail allows remote attackers to inject arbitrary web script or HTML via the tablename parameter in an update action. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Icash Click&email | 12/1/2009 | 16/6/2026 | Multiple SQL injection vulnerabilities in ClickAndEmail allow remote attackers to execute arbitrary SQL commands via (1) the ID parameter to admin_dblayers.asp in an update action, (2) the adminid parameter to admin_loginCheck.asp (aka the USERNAME field in admin_main.asp), and (3) the PassWord parameter to… | |
| Modificada | Media (4.3) | 1.2% | 💥 Exploit | Icash Click&rank | 12/1/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in user.asp in Click&Rank allows remote attackers to inject arbitrary web script or HTML via the action parameter. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Icash Click&rank | 12/1/2009 | 16/6/2026 | Multiple SQL injection vulnerabilities in Click&Rank allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) hitcounter.asp, (2) user_delete.asp, and (3) user_update.asp; (4) the userid parameter to admin_login.asp (aka the USERNAME field in admin.asp); and (5) the PassWord parameter to… | |
| Modificada | Media (6.8) | 24% | 💥 Exploit | Recly Clickheat-heatmap | 31/12/2008 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in the Clickheat - Heatmap stats (com_clickheat) component 1.0.1 for Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the (1) GLOBALS[mosConfig_absolute_path] parameter to (a) install.clickheat.php, (b) Cache.php and (c) Clickheat_Heatmap.php… | |
| Modificada | Media (4.3) | 1.4% | 💥 Exploit | ED Putal Clickbank Portal | 22/10/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in search.php in Ed Pudol Clickbank Portal allows remote attackers to inject arbitrary web script or HTML via the search box. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. |