Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2976▼ 107 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

50 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.3)0.36%—Radiustheme Classified Listing25/2/202517/6/2026
The Classified Listing – Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.0.4 via the rtcl_taxonomy_settings_export function. This makes it possible for unauthenticated attackers to extract sensitive data including…
ModificadaAlta (8.8)0.26%—Webcodingplace Ultimate Classified Listings20/2/202517/6/2026
The Ultimate Classified Listings plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5. This is due to missing or incorrect nonce validation on the update_profile function. This makes it possible for unauthenticated attackers to modify victim's email via a forged…
AnalizadaMedia (4.8)0.23%—Webcodingplace Ultimate Classified Listings20/2/202517/6/2026
The Ultimate Classified Listings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Title parameter in all versions up to, and including, 1.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject…
AplazadaMedia (6.5)0.31%—Webcodingplace Ultimate Classified ListingsAI2/12/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webcodingplace Ultimate Classified Listings ultimate-classified-listings allows Stored XSS.This issue affects Ultimate Classified Listings: from n/a through <= 1.7.
AplazadaAlta (7.5)0.57%—Webcodingplace Ultimate Classified ListingsAI20/11/202417/6/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in webcodingplace Ultimate Classified Listings ultimate-classified-listings allows PHP Local File Inclusion.This issue affects Ultimate Classified Listings: from n/a through <= 1.7.
AplazadaAlta (8.8)0.56%—Radiustheme Classified ListingAI19/11/202417/6/2026
The Classified Listing – Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a misconfigured check on the 'rtcl_import_settings' function in all versions up to, and including, 3.1.15.1. This makes it possible…
AplazadaMedia (5.3)0.47%—Radiustheme Classified ListingAI16/11/202417/6/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in RadiusTheme Classified Listing classified-listing allows PHP Local File Inclusion.This issue affects Classified Listing: from n/a through <= 3.1.16.
AnalizadaMedia (4.3)0.29%—Radiustheme Classified Listing13/9/202417/6/2026
The Classified Listing – Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several functions like export_forms(), import_forms(), update_fb_options(), and many more in all versions up to, and including, 3.1.7. This makes it…
AnalizadaAlta (7.1)0.96%💥 PoCWebcodingplace Ultimate Classified Listings1/8/202417/6/2026
The Ultimate Classified Listings WordPress plugin before 1.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
AnalizadaMedia (4.7)0.38%—Webcodingplace Ultimate Classified Listings29/7/202417/6/2026
The Ultimate Classified Listings WordPress plugin before 1.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
AnalizadaAlta (7.5)0.76%—Webcodingplace Ultimate Classified Listings29/7/202417/6/2026
The Ultimate Classified Listings WordPress plugin before 1.3 does not validate the `ucl_page` and `layout` parameters allowing unauthenticated users to access PHP files on the server from the listings page
ModificadaMedia (4.3)0.36%—Radiustheme Classified Listing25/4/202417/6/2026
The Classified Listing – Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the rtcl_fb_gallery_image_delete AJAX action in all versions up to, and including, 3.0.10.3. This makes it possible for authenticated attackers, with…
ModificadaMedia (5.3)0.55%—Radiustheme Classified Listing9/4/202417/6/2026
The Classified Listing – Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to unauthorized access & modification of data due to a missing capability check on the rtcl_import_location() rtcl_import_category() functions in all versions up to, and including, 3.0.4. This makes it possible for…
ModificadaAlta (8.8)0.45%—Radiustheme Classified Listing9/4/202417/6/2026
The Classified Listing – Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0.4. This is due to missing or incorrect nonce validation on the 'rtcl_update_user_account' function. This makes it possible for unauthenticated…
ModificadaAlta (8.8)0.25%—Radiustheme Classified Listing18/7/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in RadiusTheme Classified Listing plugin <= 2.4.5 versions.
ModificadaMedia (6.1)0.70%—Radiustheme Classified Listing16/9/202217/6/2026
The Classified Listing Pro WordPress plugin before 2.0.20 does not escape a generated URL before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting
ModificadaMedia (6.1)0.62%—Radiustheme Classified ListingRadiustheme Classified Listing Store & MembershipRadiustheme ClassimaRadiustheme Classima Core16/9/202217/6/2026
The Classima WordPress theme before 2.1.11 and some of its required plugins (Classified Listing before 2.2.14, Classified Listing Pro before 2.0.20, Classified Listing Store & Membership before 1.4.20 and Classima Core before 1.10) do not escape a parameter before outputting it back in attributes, leading to Reflected…
ModificadaMedia (4.3)0.93%—Preprojects PRE Classified Listings ASP13/4/201016/6/2026
Cross-site scripting (XSS) vulnerability in signup.asp in Pre Classified Listings ASP allows remote attackers to inject arbitrary web script or HTML via the address parameter.
ModificadaAlta (7.5)1.1%—Preprojects PRE Classified Listings ASP13/4/201016/6/2026
SQL injection vulnerability in detailad.asp in Pre Classified Listings ASP allows remote attackers to execute arbitrary SQL commands via the siteid parameter.
ModificadaAlta (7.5)0.97%💥 ExploitPreprojects PRE Classified Listings ASP13/4/201016/6/2026
SQL injection vulnerability in signup.asp in Pre Classified Listings ASP allows remote attackers to execute arbitrary SQL commands via the email parameter.
ModificadaMedia (4.3)1.5%💥 ExploitPreprojects PRE Classified Listings3/8/200916/6/2026
Cross-site scripting (XSS) vulnerability in signup.asp in Pre Classified Listings 1.0 allows remote attackers to inject arbitrary web script or HTML via the address parameter.
ModificadaAlta (7.5)0.99%💥 ExploitPreprojects PRE Classified Listings3/8/200916/6/2026
SQL injection vulnerability in detailad.asp in Pre Classified Listings 1.0 allows remote attackers to execute arbitrary SQL commands via the siteid parameter.
ModificadaAlta (7.5)2.9%💥 ExploitPreprojects PRE Classified Listings20/2/200916/6/2026
Pre Classified Listing PHP allows remote attackers to bypass authentication and gain administrative access by setting the (1) adminname and the (2) adminid cookies to "admin".
ModificadaAlta (7.5)0.99%💥 ExploitDmxready Classified Listings Manager5/2/200916/6/2026
SQL injection vulnerability in CategoryManager/upload_image_category.asp in DMXReady Classified Listings Manager 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the cid parameter.
ModificadaMedia (5)1.1%—Preprojects PRE Classified Listings4/2/200916/6/2026
PreProjects Pre Classified Listings stores pclasp.mdb under the web root with insufficient access control, which allows remote attackers to obtain passwords via a direct request.
Orbitaley — Vulnerabilidades