Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
254 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.57% | — | Webcodingplace Ultimate Classified ListingsAI | 20/11/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in webcodingplace Ultimate Classified Listings ultimate-classified-listings allows PHP Local File Inclusion.This issue affects Ultimate Classified Listings: from n/a through <= 1.7. | |
| Aplazada | Alta (8.8) | 0.56% | — | Radiustheme Classified ListingAI | 19/11/2024 | 17/6/2026 | The Classified Listing – Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a misconfigured check on the 'rtcl_import_settings' function in all versions up to, and including, 3.1.15.1. This makes it possible… | |
| Aplazada | Media (5.3) | 0.47% | — | Radiustheme Classified ListingAI | 16/11/2024 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in RadiusTheme Classified Listing classified-listing allows PHP Local File Inclusion.This issue affects Classified Listing: from n/a through <= 3.1.16. | |
| Analizada | Media (4.3) | 0.29% | — | Radiustheme Classified Listing | 13/9/2024 | 17/6/2026 | The Classified Listing – Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several functions like export_forms(), import_forms(), update_fb_options(), and many more in all versions up to, and including, 3.1.7. This makes it… | |
| Analizada | Alta (7.1) | 0.96% | 💥 PoC | Webcodingplace Ultimate Classified Listings | 1/8/2024 | 17/6/2026 | The Ultimate Classified Listings WordPress plugin before 1.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |
| Analizada | Media (4.7) | 0.38% | — | Webcodingplace Ultimate Classified Listings | 29/7/2024 | 17/6/2026 | The Ultimate Classified Listings WordPress plugin before 1.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |
| Analizada | Alta (7.5) | 0.76% | — | Webcodingplace Ultimate Classified Listings | 29/7/2024 | 17/6/2026 | The Ultimate Classified Listings WordPress plugin before 1.3 does not validate the `ucl_page` and `layout` parameters allowing unauthenticated users to access PHP files on the server from the listings page | |
| Aplazada | Alta (8.5) | 0.51% | — | Pluginsware Advanced Classifieds AND Directory PROAI | 9/7/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in PluginsWare Advanced Classifieds & Directory Pro allows Path Traversal.This issue affects Advanced Classifieds & Directory Pro: from n/a through 3.1.3. | |
| Modificada | Media (5.3) | 0.33% | — | Stylemixthemes Motors - CAR Dealer, Classifieds & Listing | 2/7/2024 | 17/6/2026 | The Motors – Car Dealer, Classifieds & Listing plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the stm_edit_delete_user_car function in all versions up to, and including, 1.4.8. This makes it possible for unauthenticated attackers to unpublish arbitrary… | |
| Modificada | Alta (8.8) | 0.32% | — | Strategy11 AWP Classifieds | 9/6/2024 | 17/6/2026 | Missing Authorization vulnerability in AWP Classifieds Team AWP Classifieds.This issue affects AWP Classifieds: from n/a through 4.3.1. | |
| Modificada | Media (4.3) | 0.36% | — | Radiustheme Classified Listing | 25/4/2024 | 17/6/2026 | The Classified Listing – Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the rtcl_fb_gallery_image_delete AJAX action in all versions up to, and including, 3.0.10.3. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (4.3) | 0.21% | — | Strategy11 AWP ClassifiedsAI | 15/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in AWP Classifieds Team AWP Classifieds.This issue affects AWP Classifieds: from n/a through 4.3.1. | |
| Aplazada | Media (4.3) | 0.54% | — | Advanced Classifieds Directory PROAI | 9/4/2024 | 17/6/2026 | The Advanced Classifieds & Directory Pro plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the ajax_callback_delete_attachment function in all versions up to, and including, 3.0.0. This makes it possible for authenticated attackers, with subscriber access or higher,… | |
| Modificada | Media (5.3) | 0.55% | — | Radiustheme Classified Listing | 9/4/2024 | 17/6/2026 | The Classified Listing – Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to unauthorized access & modification of data due to a missing capability check on the rtcl_import_location() rtcl_import_category() functions in all versions up to, and including, 3.0.4. This makes it possible for… | |
| Modificada | Alta (8.8) | 0.45% | — | Radiustheme Classified Listing | 9/4/2024 | 17/6/2026 | The Classified Listing – Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0.4. This is due to missing or incorrect nonce validation on the 'rtcl_update_user_account' function. This makes it possible for unauthenticated… | |
| Aplazada | Alta (8.8) | 0.26% | — | Pixelemu TerraclassifiedsAI | 16/3/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Pixelemu TerraClassifieds.This issue affects TerraClassifieds: from n/a through 2.0.3. | |
| Modificada | Crítica (9.8) | 0.62% | — | Pixelemu Terraclassifieds | 29/12/2023 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Pixelemu TerraClassifieds – Simple Classifieds Plugin.This issue affects TerraClassifieds – Simple Classifieds Plugin: from n/a through 2.0.3. | |
| Modificada | Alta (7.5) | 0.51% | — | Stylemixthemes Motors - CAR Dealer, Classifieds & Listing | 13/11/2023 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in StylemixThemes Motors – Car Dealer, Classifieds & Listing.This issue affects Motors – Car Dealer, Classifieds & Listing: from n/a through 1.4.6. | |
| Modificada | Media (6.1) | 0.33% | — | Stylemixthemes Motors - CAR Dealer, Classifieds & Listing | 27/10/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in StylemixThemes Motors – Car Dealer, Classifieds & Listing plugin <= 1.4.6 versions. | |
| Modificada | Alta (8.8) | 0.25% | — | Strategy11 AWP Classifieds | 6/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in AWP Classifieds Team Ad Directory & Listings by AWP Classifieds plugin <= 4.3 versions. | |
| Modificada | Alta (8.8) | 0.25% | — | Radiustheme Classified Listing | 18/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in RadiusTheme Classified Listing plugin <= 2.4.5 versions. | |
| Modificada | Media (6.1) | 0.50% | — | Simplephpscripts Classified ADS Script PHP | 29/6/2023 | 17/6/2026 | A vulnerability was found in SimplePHPscripts Classified Ads Script 1.8. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file user.php of the component HTTP POST Request Handler. The manipulation of the argument title leads to cross site scripting. The attack can… | |
| Modificada | Media (6.1) | 0.50% | — | Simplephpscripts Classified ADS Script PHP | 29/6/2023 | 17/6/2026 | A vulnerability was found in SimplePHPscripts Classified Ads Script 1.8. It has been classified as problematic. Affected is an unknown function of the file /preview.php of the component URL Parameter Handler. The manipulation of the argument p leads to cross site scripting. It is possible to launch the attack… | |
| Modificada | Alta (8.8) | 0.25% | — | Stylemixthemes Motors - CAR Dealer, Classifieds & Listing | 25/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in StylemixThemes Motors – Car Dealer, Classifieds & Listing plugin <= 1.4.4 versions. | |
| Modificada | Alta (8.8) | 1.1% | — | Stylemixthemes Motors - CAR Dealer, Classifieds & Listing | 12/12/2022 | 17/6/2026 | The Motors WordPress plugin before 1.4.4 does not properly validate uploaded files for dangerous file types (such as .php) in an AJAX action, allowing an attacker to sign up on a victim's WordPress instance, upload a malicious PHP file and attempt to launch a brute-force attack to discover the uploaded payload. |