Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
298 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (9.3) | 3.6% | 💥 Exploit | Ftrsoft Fast Click SQL Lite | 21/10/2008 | 16/6/2026 | PHP remote file inclusion vulnerability in init.php in Fast Click SQL Lite 1.1.7, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the CFG[CDIR] parameter. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Oneclick CMS | 7/7/2008 | 16/6/2026 | SQL injection vulnerability in index.php in OneClick CMS (aka Sisplet CMS) 2008-01-24 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Alta (7.5) | 1.1% | — | Clicktech Clickgallery | 26/6/2007 | 16/6/2026 | SQL injection vulnerability in edit_image.asp in ClickGallery Server 5.1 and earlier allows remote attackers to execute arbitrary SQL commands via the image_id parameter. | |
| Modificada | Media (4.3) | 1.0% | — | Clicktech Clickgallery | 26/6/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in edit_image.asp in ClickGallery Server 5.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the from parameter. | |
| Modificada | Alta (7.5) | 2.8% | 💥 Exploit | Oneclick CMSSisplet CMS | 27/4/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in main/forum/komentar.php in OneClick CMS (aka Sisplet CMS) 05.10 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the site_path parameter. | |
| Modificada | Alta (7.5) | 2.9% | 💥 Exploit | Acgvclick | 30/1/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in function.inc.php in ACGVclick 0.2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the path parameter. | |
| Modificada | Alta (10) | 1.9% | 💥 Exploit | Website Designs FOR Less Click N Print Coupons | 31/12/2006 | 16/6/2026 | SQL injection vulnerability in coupon_detail.asp in Website Designs For Less Click N' Print Coupons 2005.01 and earlier allows remote attackers to execute arbitrary SQL commands via the key parameter. | |
| Modificada | Alta (7.5) | 1.4% | — | Clicktech Clickgallery | 1/12/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in ClickTech Click Gallery allow remote attackers to execute arbitrary SQL commands via the (1) currentpage or (2) gallery_id parameter to (a) view_gallery.asp, the (3) image_id parameter to (b) download_image.asp, the currentpage or (5) orderby parameter to (c) gallery.asp, or… | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Clicktech Clickblog | 1/12/2006 | 16/6/2026 | SQL injection vulnerability in displayCalendar.asp in ClickTech Click Blog allows remote attackers to execute arbitrary SQL commands via the date parameter. | |
| Modificada | Media (4.3) | 1.4% | — | Clicktech Clickgallery | 1/12/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in view_search.asp in ClickTech Click Gallery allows remote attackers to inject arbitrary web script or HTML via the txtKeyWord parameter. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Clicktech Clickcontact | 1/12/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in default.asp in ClickTech ClickContact allow remote attackers to execute arbitrary SQL commands via the (1) AlphaSort, (2) In, and (3) orderby parameters. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Clicktech Texas Rankem | 22/11/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in ClickTech Texas Rank'em allow remote attackers to execute arbitrary SQL commands via the (1) selPlayer parameter to player.asp or the (2) tournament_id parameter to tournaments.asp. | |
| Modificada | Alta (7.5) | 2.5% | 💥 Exploit | Clicktech Clickblog | 19/9/2006 | 16/6/2026 | SQL injection vulnerability in default.asp (aka the login page) in ClickTech ClickBlog 2.0 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) form_codeword (aka the Password field) parameters. | |
| Modificada | Media (4.3) | 1.8% | — | Clicktech Clickgallery | 15/6/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in ClickGallery 5.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) gallery_id parameter in gallery.asp and (2) parentcurrentpage parameter in view_gallery.asp. | |
| Modificada | Media (4.3) | 1.8% | — | Clicktech Clickcart | 15/6/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in default.asp in ClickTech Clickcart 6.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the cat parameter. | |
| Modificada | Media (6.4) | 3.8% | 💥 Exploit | Ftrainsoft Fast Click | 9/5/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in show.php in Fast Click SQL Lite 1.1.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the path parameter. NOTE: This is a different vulnerability than CVE-2006-2175. | |
| Modificada | Media (6.4) | 8.9% | 💥 Exploit | Ftrainsoft Fast Click | 4/5/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in FtrainSoft Fast Click 2.3.8 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the path parameter to (1) show.php or (2) top.php. | |
| Modificada | Alta (7.5) | 1.3% | — | Phpfreebies.com Free Clickbank | 31/12/2005 | 16/6/2026 | SQL injection vulnerability in search.php in Free ClickBank 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the keywords parameter. | |
| Modificada | Media (4.3) | 2.0% | 💥 Exploit | Kryptronic Clickcartpro | 16/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in cp-app.cgi in ClickCartPro (CCP) 5.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the affl parameter. | |
| Modificada | Alta (7.8) | 2.3% | — | First Virtual Communications Click TO Meet ExpressFirst Virtual Communications Click TO Meet PremierFirst Virtual Communications Conference ServerFirst Virtual Communications V-gate | 31/12/2004 | 16/6/2026 | Multiple vulnerabilities in the H.323 protocol implementation for First Virtual Communications Click to Meet Express (when used with H.323 conferencing endpoints), Click to Meet Premier, Conference Server, and V-Gate allow remote attackers to cause a denial of service, as demonstrated by the NISCC/OUSPG PROTOS test… | |
| Modificada | Media (5) | 1.4% | — | Click2learn Ingenium Learning Management System | 31/12/2002 | 16/6/2026 | Click2Learn Ingenium Learning Management System 5.1 and 6.1 stores the hashed administrative password in a config.txt file under the htdocs directory, which allows remote attackers to obtain the administrative password. | |
| Modificada | Media (5) | 1.3% | — | Kryptronic Clickcartpro | 31/12/2002 | 16/6/2026 | ClickCartPro 4.0 stores the admin_user.db data file under the web document root with insufficient access control on servers other than Apache, which allows remote attackers to obtain usernames and passwords. | |
| Modificada | Alta (7.5) | 6.3% | 💥 Exploit | Click-2 Ingenium Learning Management System | 31/12/2002 | 16/6/2026 | Click2Learn Ingenium Learning Management System 5.1 and 6.1 uses weak encryption for passwords (reversible algorithm), which allows attackers to obtain passwords. |