Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3034▼ 62 respecto a la semana anterior
Críticas / altas1427▲ 61 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
298 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.9) | 0.19% | — | Nextclickventures Realtyscript | 16/3/2026 | 17/6/2026 | Next Click Ventures RealtyScript 4.0.2 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to create unauthorized user accounts and administrative users by crafting malicious forms. Attackers can submit hidden form data to /admin/addusers.php and /admin/editadmins.php endpoints to… | |
| Analizada | Media (5.1) | 0.24% | — | Nextclickventures Realtyscript | 16/3/2026 | 17/6/2026 | Next Click Ventures RealtyScript 4.0.2 fails to properly sanitize CSV file uploads, allowing attackers to inject malicious scripts through filename parameters in multipart form data. Attackers can upload files with XSS payloads in the filename field to execute arbitrary JavaScript in users' browsers when the file is… | |
| Analizada | Media (5.1) | 0.27% | — | Nextclickventures Realtyscript | 16/3/2026 | 17/6/2026 | Next Click Ventures RealtyScript 4.0.2 fails to properly sanitize file uploads, allowing attackers to store malicious scripts through the file POST parameter in admin/tools.php. Attackers can upload files containing JavaScript code that executes in the context of admin/tools.php when accessed by other users. | |
| Analizada | Media (5.1) | 0.27% | — | Nextclickventures Realtyscript | 16/3/2026 | 17/6/2026 | Next Click Ventures RealtyScript 4.0.2 contains a cross-site scripting vulnerability that allows attackers to execute arbitrary HTML and script code by injecting malicious input through multiple parameters that are not properly sanitized. Attackers can craft requests with injected script payloads in vulnerable… | |
| Analizada | Media (6.9) | 0.18% | — | Nextclickventures Realtyscript | 16/3/2026 | 17/6/2026 | Next Click Ventures RealtyScript 4.0.2 contains cross-site request forgery and persistent cross-site scripting vulnerabilities that allow attackers to perform administrative actions and inject malicious scripts. Attackers can craft malicious web pages that execute unauthorized actions when logged-in users visit them,… | |
| Aplazada | Baja (2.7) | 0.33% | — | Oneclick Chat TO OrderAI | 19/2/2026 | 17/6/2026 | The OneClick Chat to Order plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 1.0.9. This is due to the plugin not properly verifying that a user is authorized to perform an action in the wa_order_number_save_number_field function. This makes it possible for authenticated… | |
| Aplazada | Media (6.4) | 0.21% | — | Video OnclickAI | 7/2/2026 | 17/6/2026 | The Video Onclick plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `youtube` shortcode in all versions up to, and including, 0.4.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (5.1) | 0.28% | — | Click2magicAI | 25/1/2026 | 17/6/2026 | Click2Magic 1.1.5 contains a stored cross-site scripting vulnerability that allows attackers to inject malicious scripts in the chat name input. Attackers can craft a malicious payload in the chat name to capture administrator cookies when the admin processes user requests. | |
| Aplazada | Media (6.1) | 0.29% | — | JustclickAI | 24/1/2026 | 17/6/2026 | The JustClick registration plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 0.1. This is due to insufficient input sanitization and output escaping on the `PHP_SELF` server variable. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Aplazada | Media (5.3) | 0.31% | — | Clickdatos Proteccion DE Datos RgpdAI | 23/1/2026 | 17/6/2026 | Missing Authorization vulnerability in ABCdatos Protección de datos – RGPD proteccion-datos-rgpd allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Protección de datos – RGPD: from n/a through <= 0.68. | |
| Aplazada | Media (5.9) | 0.21% | — | Riyadh Ahmed Make Section Column Clickable FOR ElementorAI | 9/12/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Riyadh Ahmed Make Section & Column Clickable For Elementor make-section-column-clickable-elementor allows Stored XSS.This issue affects Make Section & Column Clickable For Elementor: from n/a through <= 2.4. | |
| Aplazada | Media (4.8) | 0.29% | — | Sanoma ClickeduAI | 1/12/2025 | 17/6/2026 | Reflected Cross-site Scripting (XSS) vulnerability in Sanoma's Clickedu. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending them a malicious URL in '/students/carpetes_varies.php'. This vulnerability can be exploited to steal sensitive user data, such as session… | |
| Aplazada | Alta (7.5) | 0.36% | — | Oneclick Chat TO OrderAI | 22/11/2025 | 17/6/2026 | The OneClick Chat to Order plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.0.8 via the 'wa_order_thank_you_override' function due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to view sensitive… | |
| Aplazada | Media (4.3) | 0.25% | — | Clicksend SMS Contact Form 7 NotificationsAI | 27/10/2025 | 17/6/2026 | Missing Authorization vulnerability in clicksend SMS Contact Form 7 Notifications by ClickSend clicksend-contactform7 allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SMS Contact Form 7 Notifications by ClickSend: from n/a through <= 1.4.0. | |
| Aplazada | Alta (7.1) | 0.24% | — | Mithra62 Wp-click-trackerAI | 22/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mithra62 WP-Click-Tracker wp-click-track allows Reflected XSS.This issue affects WP-Click-Tracker: from n/a through <= 0.7.3. | |
| Aplazada | Media (5.5) | 0.22% | — | Interactive Human Anatomy With Clickable Body PartsAI | 3/10/2025 | 17/6/2026 | The Interactive Human Anatomy with Clickable Body Parts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level… | |
| Aplazada | Media (5.9) | 0.18% | — | Space Studio Click AND TweetAI | 26/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Space Studio Click & Tweet allows Stored XSS. This issue affects Click & Tweet: from n/a through 0.8.9. | |
| Aplazada | Alta (8.2) | 0.35% | — | Click Plus C2-03cpu-2AIClick Programming SoftwareAI | 23/9/2025 | 17/6/2026 | An improper resource shutdown or release vulnerability has been identified in the Click Plus C2-03CPU-2 device running firmware version 3.60. The vulnerability allows an unauthenticated attacker to perform a denial-of-service attack by exhausting all available device sessions of the Click Programming Software. | |
| Aplazada | Alta (8.2) | 0.33% | — | Click Plus C2-03cpu-2AI | 23/9/2025 | 17/6/2026 | An improper resource shutdown or release vulnerability has been identified in the Click Plus C2-03CPU-2 device running firmware version 3.60. The vulnerability allows an unauthenticated attacker to perform a denial-of-service attack by exhausting all available device sessions in the Remote PLC application. | |
| Aplazada | Alta (8.7) | 0.31% | — | Click Plus PLCAI | 23/9/2025 | 17/6/2026 | A predictable seed in pseudo-random number generator vulnerability has been discovered in firmware version 3.60 of the Click Plus PLC. The vulnerability relies on the fact that the software implements a predictable seed for its pseudo-random number generator, which compromises the security of the generated private… | |
| Aplazada | Alta (7.6) | 0.25% | — | Click Plus C2-03cpu2AIClick Plus Remote PLCAI | 23/9/2025 | 17/6/2026 | An authorization bypass vulnerability has been discovered in the Click Plus C2-03CPU2 device firmware version 3.60. Through the KOPR protocol utilized by the Remote PLC application, authenticated users with low-level access permissions can exploit this vulnerability to read and modify PLC variables beyond their… | |
| Aplazada | Alta (8.7) | 0.12% | — | Click Plus PLCAI | 23/9/2025 | 17/6/2026 | The use of a broken or risky cryptographic algorithm was discovered in firmware version 3.60 of the Click Plus PLC. The vulnerability relies on the fact that the software uses an insecure implementation of the RSA encryption algorithm. | |
| Aplazada | Media (6.9) | 0.26% | — | Click Plus PLCAI | 23/9/2025 | 17/6/2026 | The use of a hard-coded cryptographic key was discovered in firmware version 3.60 of the Click Plus PLC. The vulnerability relies on the fact that the software contains a hard-coded AES key used to protect the initial messages of a new KOPS session. | |
| Aplazada | Media (4.1) | 0.10% | — | Click Programming SoftwareAI | 23/9/2025 | 17/6/2026 | Cleartext storage of sensitive information was discovered in Click Programming Software version v3.60. The vulnerability can be exploited by a local user with access to the file system, while an administrator session is active, to steal credentials stored in clear text. | |
| Aplazada | Media (6.5) | 0.17% | — | Fernando Acosta Make Column Clickable ElementorAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fernando Acosta Make Column Clickable Elementor make-column-clickable-elementor allows Stored XSS.This issue affects Make Column Clickable Elementor: from n/a through <= 1.6.0. |