Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

298 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (9.3)3.6%💥 ExploitFtrsoft Fast Click SQL Lite21/10/200816/6/2026
PHP remote file inclusion vulnerability in init.php in Fast Click SQL Lite 1.1.7, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the CFG[CDIR] parameter.
ModificadaAlta (7.5)0.97%💥 ExploitOneclick CMS7/7/200816/6/2026
SQL injection vulnerability in index.php in OneClick CMS (aka Sisplet CMS) 2008-01-24 allows remote attackers to execute arbitrary SQL commands via the id parameter.
ModificadaAlta (7.5)1.1%—Clicktech Clickgallery26/6/200716/6/2026
SQL injection vulnerability in edit_image.asp in ClickGallery Server 5.1 and earlier allows remote attackers to execute arbitrary SQL commands via the image_id parameter.
ModificadaMedia (4.3)1.0%—Clicktech Clickgallery26/6/200716/6/2026
Cross-site scripting (XSS) vulnerability in edit_image.asp in ClickGallery Server 5.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the from parameter.
ModificadaAlta (7.5)2.8%💥 ExploitOneclick CMSSisplet CMS27/4/200716/6/2026
PHP remote file inclusion vulnerability in main/forum/komentar.php in OneClick CMS (aka Sisplet CMS) 05.10 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the site_path parameter.
ModificadaAlta (7.5)2.9%💥 ExploitAcgvclick30/1/200716/6/2026
PHP remote file inclusion vulnerability in function.inc.php in ACGVclick 0.2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the path parameter.
ModificadaAlta (10)1.9%💥 ExploitWebsite Designs FOR Less Click N Print Coupons31/12/200616/6/2026
SQL injection vulnerability in coupon_detail.asp in Website Designs For Less Click N' Print Coupons 2005.01 and earlier allows remote attackers to execute arbitrary SQL commands via the key parameter.
ModificadaAlta (7.5)1.4%—Clicktech Clickgallery1/12/200616/6/2026
Multiple SQL injection vulnerabilities in ClickTech Click Gallery allow remote attackers to execute arbitrary SQL commands via the (1) currentpage or (2) gallery_id parameter to (a) view_gallery.asp, the (3) image_id parameter to (b) download_image.asp, the currentpage or (5) orderby parameter to (c) gallery.asp, or…
ModificadaAlta (7.5)1.1%💥 ExploitClicktech Clickblog1/12/200616/6/2026
SQL injection vulnerability in displayCalendar.asp in ClickTech Click Blog allows remote attackers to execute arbitrary SQL commands via the date parameter.
ModificadaMedia (4.3)1.4%—Clicktech Clickgallery1/12/200616/6/2026
Cross-site scripting (XSS) vulnerability in view_search.asp in ClickTech Click Gallery allows remote attackers to inject arbitrary web script or HTML via the txtKeyWord parameter. NOTE: some of these details are obtained from third party information.
ModificadaAlta (7.5)1.2%💥 ExploitClicktech Clickcontact1/12/200616/6/2026
Multiple SQL injection vulnerabilities in default.asp in ClickTech ClickContact allow remote attackers to execute arbitrary SQL commands via the (1) AlphaSort, (2) In, and (3) orderby parameters.
ModificadaAlta (7.5)1.1%💥 ExploitClicktech Texas Rankem22/11/200616/6/2026
Multiple SQL injection vulnerabilities in ClickTech Texas Rank'em allow remote attackers to execute arbitrary SQL commands via the (1) selPlayer parameter to player.asp or the (2) tournament_id parameter to tournaments.asp.
ModificadaAlta (7.5)2.5%💥 ExploitClicktech Clickblog19/9/200616/6/2026
SQL injection vulnerability in default.asp (aka the login page) in ClickTech ClickBlog 2.0 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) form_codeword (aka the Password field) parameters.
ModificadaMedia (4.3)1.8%—Clicktech Clickgallery15/6/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in ClickGallery 5.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) gallery_id parameter in gallery.asp and (2) parentcurrentpage parameter in view_gallery.asp.
ModificadaMedia (4.3)1.8%—Clicktech Clickcart15/6/200616/6/2026
Cross-site scripting (XSS) vulnerability in default.asp in ClickTech Clickcart 6.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the cat parameter.
ModificadaMedia (6.4)3.8%💥 ExploitFtrainsoft Fast Click9/5/200616/6/2026
PHP remote file inclusion vulnerability in show.php in Fast Click SQL Lite 1.1.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the path parameter. NOTE: This is a different vulnerability than CVE-2006-2175.
ModificadaMedia (6.4)8.9%💥 ExploitFtrainsoft Fast Click4/5/200616/6/2026
PHP remote file inclusion vulnerability in FtrainSoft Fast Click 2.3.8 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the path parameter to (1) show.php or (2) top.php.
ModificadaAlta (7.5)1.3%—Phpfreebies.com Free Clickbank31/12/200516/6/2026
SQL injection vulnerability in search.php in Free ClickBank 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the keywords parameter.
ModificadaMedia (4.3)2.0%💥 ExploitKryptronic Clickcartpro16/12/200516/6/2026
Cross-site scripting (XSS) vulnerability in cp-app.cgi in ClickCartPro (CCP) 5.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the affl parameter.
ModificadaAlta (7.8)2.3%—First Virtual Communications Click TO Meet ExpressFirst Virtual Communications Click TO Meet PremierFirst Virtual Communications Conference ServerFirst Virtual Communications V-gate31/12/200416/6/2026
Multiple vulnerabilities in the H.323 protocol implementation for First Virtual Communications Click to Meet Express (when used with H.323 conferencing endpoints), Click to Meet Premier, Conference Server, and V-Gate allow remote attackers to cause a denial of service, as demonstrated by the NISCC/OUSPG PROTOS test…
ModificadaMedia (5)1.4%—Click2learn Ingenium Learning Management System31/12/200216/6/2026
Click2Learn Ingenium Learning Management System 5.1 and 6.1 stores the hashed administrative password in a config.txt file under the htdocs directory, which allows remote attackers to obtain the administrative password.
ModificadaMedia (5)1.3%—Kryptronic Clickcartpro31/12/200216/6/2026
ClickCartPro 4.0 stores the admin_user.db data file under the web document root with insufficient access control on servers other than Apache, which allows remote attackers to obtain usernames and passwords.
ModificadaAlta (7.5)6.3%💥 ExploitClick-2 Ingenium Learning Management System31/12/200216/6/2026
Click2Learn Ingenium Learning Management System 5.1 and 6.1 uses weak encryption for passwords (reversible algorithm), which allows attackers to obtain passwords.
Orbitaley — Vulnerabilidades