Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
158 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.62% | — | Pixelemu Terraclassifieds | 29/12/2023 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Pixelemu TerraClassifieds – Simple Classifieds Plugin.This issue affects TerraClassifieds – Simple Classifieds Plugin: from n/a through 2.0.3. | |
| Modificada | Alta (7.5) | 0.51% | — | Stylemixthemes Motors - CAR Dealer, Classifieds & Listing | 13/11/2023 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in StylemixThemes Motors – Car Dealer, Classifieds & Listing.This issue affects Motors – Car Dealer, Classifieds & Listing: from n/a through 1.4.6. | |
| Modificada | Media (6.1) | 0.33% | — | Stylemixthemes Motors - CAR Dealer, Classifieds & Listing | 27/10/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in StylemixThemes Motors – Car Dealer, Classifieds & Listing plugin <= 1.4.6 versions. | |
| Modificada | Alta (8.8) | 0.25% | — | Strategy11 AWP Classifieds | 6/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in AWP Classifieds Team Ad Directory & Listings by AWP Classifieds plugin <= 4.3 versions. | |
| Modificada | Alta (8.8) | 0.25% | — | Stylemixthemes Motors - CAR Dealer, Classifieds & Listing | 25/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in StylemixThemes Motors – Car Dealer, Classifieds & Listing plugin <= 1.4.4 versions. | |
| Modificada | Alta (8.8) | 1.1% | — | Stylemixthemes Motors - CAR Dealer, Classifieds & Listing | 12/12/2022 | 17/6/2026 | The Motors WordPress plugin before 1.4.4 does not properly validate uploaded files for dangerous file types (such as .php) in an AJAX action, allowing an attacker to sign up on a victim's WordPress instance, upload a malicious PHP file and attempt to launch a brute-force attack to discover the uploaded payload. | |
| Modificada | Crítica (9.8) | 5.6% | 💥 Exploit | Strategy11 AWP Classifieds | 31/10/2022 | 17/6/2026 | The WordPress Classifieds Plugin WordPress plugin before 4.3 does not properly sanitise and escape some parameters before using them in a SQL statement via an AJAX action available to unauthenticated users and when a specific premium module is active, leading to a SQL injection | |
| Modificada | Alta (7.5) | 0.76% | — | Itechscripts Classifieds Script | 16/7/2022 | 17/6/2026 | A vulnerability classified as critical has been found in Itech Classifieds Script 7.27. Affected is an unknown function of the file /subpage.php. The manipulation of the argument scat with the input =51' AND 4941=4941 AND 'hoCP'='hoCP leads to sql injection. It is possible to launch the attack remotely. The exploit… | |
| Modificada | Crítica (9.8) | 15% | 💥 Exploit | Cars-seller-auto-classifieds-script Project Cars-seller-auto-classifieds-script | 14/5/2021 | 17/6/2026 | The request_list_request AJAX call of the Car Seller - Auto Classifieds Script WordPress plugin through 2.1.0, available to both authenticated and unauthenticated users, does not sanitise, validate or escape the order_id POST parameter before using it in a SQL statement, leading to a SQL Injection issue. | |
| Modificada | Media (6.1) | 1.4% | — | Stylemixthemes Motors - CAR Dealer, Classifieds & Listing | 24/2/2020 | 17/6/2026 | includes/options.php in the motors-car-dealership-classified-listings (aka Motors - Car Dealer & Classified Ads) plugin through 1.4.0 for WordPress has multiple stored XSS issues. | |
| Modificada | Media (6.5) | 1.2% | 💥 Exploit | Stylemixthemes Motors - CAR Dealer, Classifieds & Listing | 24/2/2020 | 17/6/2026 | includes/options.php in the motors-car-dealership-classified-listings (aka Motors - Car Dealer & Classified Ads) plugin through 1.4.0 for WordPress allows unauthenticated options changes. | |
| Modificada | Crítica (9.8) | 3.6% | — | Ambittechnologies Itech B2B ScriptAmbittechnologies Itech Business Networking ScriptAmbittechnologies Itech Caregiver ScriptAmbittechnologies Itech Classifieds Script+8 | 9/5/2019 | 17/6/2026 | Certain Ambit Technologies Pvt. Ltd products are affected by: SQL Injection. This affects iTech B2B Script 4.42i and Tech Business Networking Script 8.26i and Tech Caregiver Script 2.71i and Tech Classifieds Script 7.41i and Tech Dating Script 3.40i and Tech Freelancer Script 5.27i and Tech Image Sharing Script 4.13i… | |
| Modificada | Crítica (9.8) | 3.0% | 💥 Exploit | Phpautoclassifiedscript BUS Booking Script | 18/12/2017 | 17/6/2026 | Bus Booking Script 1.0 has SQL Injection via the txtname parameter to admin/index.php. | |
| Modificada | Media (6.1) | 0.67% | — | Scubez Posty Readymade Classifieds | 13/12/2017 | 17/6/2026 | Scubez Posty Readymade Classifieds has XSS via the admin/user_activate_submit.php ID parameter. | |
| Modificada | Alta (7.5) | 1.4% | — | Scubez Posty Readymade Classifieds | 13/12/2017 | 17/6/2026 | Scubez Posty Readymade Classifieds has Incorrect Access Control for visiting admin/user_activate_submit.php (aka the backend PHP script), which might allow remote attackers to obtain sensitive information via a direct request. | |
| Modificada | Alta (7.5) | 1.1% | — | Scubez Posty Readymade Classifieds | 13/12/2017 | 17/6/2026 | Scubez Posty Readymade Classifieds has SQL Injection via the admin/user_activate_submit.php ID parameter. | |
| Modificada | Crítica (9.8) | 8.8% | 💥 Exploit | Scubez Posty Readymade Classifieds | 11/12/2017 | 17/6/2026 | Posty Readymade Classifieds Script 1.0 allows an attacker to inject SQL commands via a listings.php?catid= or ads-details.php?ID= request. | |
| Modificada | Media (4.3) | 3.2% | 💥 Exploit | Cmsjunkie J-classifiedsmanager | 4/2/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the CMSJunkie J-ClassifiedsManager component for Joomla! allows remote attackers to inject arbitrary web script or HTML via the view parameter to /classifieds. | |
| Modificada | Alta (7.5) | 2.4% | 💥 Exploit | Cmsjunkie J-classifiedsmanager | 4/2/2015 | 17/6/2026 | SQL injection vulnerability in the CMSJunkie J-ClassifiedsManager component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a viewad task to classifieds/offerring-ads. | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Itechscripts Itechclassifieds | 13/1/2015 | 17/6/2026 | SQL injection vulnerability in ChangeEmail.php in iTechClassifieds 3.03.057 allows remote attackers to execute arbitrary SQL commands via the PreviewNum parameter. NOTE: the CatID parameter is already covered by CVE-2008-0685. | |
| Modificada | Alta (7.5) | 4.6% | 💥 Exploit | Strategy11 AWP Classifieds | 13/1/2015 | 17/6/2026 | SQL injection vulnerability in the Another WordPress Classifieds Plugin plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the keywordphrase parameter in a dosearch action. | |
| Modificada | Media (4.3) | 1.6% | — | Strategy11 AWP Classifieds | 13/1/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Another WordPress Classifieds Plugin plugin for WordPress allows remote attackers to inject arbitrary web script or HTML via the query string to the default URI. | |
| Modificada | Media (4.3) | 1.2% | — | Openclassifieds Open Classifieds 2 | 14/3/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in classes/controller/error.php in Open Classifieds 2 before 2.1.3 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to shared-apartments-rooms/. | |
| Modificada | Alta (7.5) | 1.3% | — | Etoshop Classifieds Creator | 24/12/2013 | 17/6/2026 | Multiple SQL injection vulnerabilities in Classifieds Creator 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) ID parameter to demo/classifieds/product.asp, or (2) UserID or (3) Password field to demo/classifieds/admin.asp. | |
| Modificada | Media (5.8) | 0.57% | — | Opensourceclassifieds | 4/11/2012 | 16/6/2026 | Open Source Classifieds does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate, related to use of the PHP fsockopen function. |