Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
224 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.39% | — | Phpscriptsmall Fiverr Clone Script | 20/2/2026 | 17/6/2026 | Fiverr Clone Script 1.2.2 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the page parameter. Attackers can supply malicious SQL syntax in the page parameter to extract sensitive database information or modify database contents. | |
| Modificada | Crítica (10) | 0.33% | — | Eclipse Cyclone Data Distribution Service | 23/12/2025 | 5/7/2026 | Improper verification of the time certificate in Eclipse Cyclone DDS before v0.10.5 allows attackers to bypass certificate checks and execute commands with System privileges. | |
| Aplazada | Alta (8.4) | 0.15% | — | Elecom Clone FOR WindowsAI | 9/12/2025 | 1/10/2026 | Clone for Windows provided by ELECOM CO.,LTD. registers a Windows service with an unquoted file path. A user with the write permission on the root directory of the system drive may execute arbitrary code with SYSTEM privilege. | |
| Aplazada | Media (5.3) | 0.25% | — | Evan Herman Post ClonerAI | 9/12/2025 | 5/10/2026 | Missing Authorization vulnerability in Evan Herman Post Cloner post-cloner allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Post Cloner: from n/a through <= 1.0.0. | |
| Aplazada | Media (4.3) | 0.12% | — | XclonerAI | 5/12/2025 | 17/6/2026 | The Backup, Restore and Migrate your sites with XCloner plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.8.2. This is due to missing or incorrect nonce validation on the Xcloner_Remote_Storage:save() function. This makes it possible for unauthenticated attackers… | |
| Aplazada | Alta (7.5) | 0.37% | — | Cyclonedx-core-javaAI | 10/11/2025 | 17/6/2026 | The CycloneDX core module provides a model representation of the SBOM along with utilities to assist in creating, validating, and parsing SBOMs. Starting in version 2.1.0 and prior to version 11.0.1, the XML `Validator` used by cyclonedx-core-java was not configured securely, making the library vulnerable to XML… | |
| Aplazada | Alta (7.1) | 0.25% | — | Globalis Multisite Clone DuplicatorAI | 22/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Globalis MultiSite Clone Duplicator multisite-clone-duplicator allows Reflected XSS.This issue affects MultiSite Clone Duplicator: from n/a through <= 1.5.3. | |
| Analizada | Media (6.1) | 0.26% | — | Realme Clone Phone | 18/9/2025 | 17/6/2026 | In realme BackupRestore app v15.1.12_2810c08_250314, improper URI scheme handling in com.coloros.pc.PcToolMainActivity allows local attackers to cause a crash and potential XSS via crafted ADB intents. | |
| Aplazada | Media (5.4) | 0.24% | — | Cyclonedx SunshineAI | 13/8/2025 | 17/6/2026 | CycloneDX Sunshine v0.9 is vulnerable to CSV Formula Injection via a crafted JSON file | |
| Aplazada | Alta (7.4) | 0.27% | — | Oppo Clone PhoneAI | 23/6/2025 | 17/6/2026 | OPPO Clone Phone uses a weak password WiFi hotspot to transfer files, resulting in Information disclosure. | |
| Aplazada | Crítica (9.4) | 0.22% | — | Cyclone Matrix TRF Smart Keyless Entry SystemAIKIA SolutoAI | 13/6/2025 | 17/6/2026 | Use of fixed learning codes, one code to lock the car and the other code to unlock it, in the Key Fob Transmitter in Cyclone Matrix TRF Smart Keyless Entry System, which allows a replay attack. Research was completed on the 2024 KIA Soluto. Attack confirmed on other KIA Models in Ecuador. | |
| Aplazada | Media (5.3) | 0.37% | — | Galaxyweblinks WP Clone ANY Post TypeAI | 1/4/2025 | 17/6/2026 | Missing Authorization vulnerability in Galaxy Weblinks WP Clone any post type wp-clone-any-post-type allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Clone any post type: from n/a through <= 3.6. | |
| Aplazada | Media (4.7) | 0.36% | — | Galaxyweblinks WP Clone ANY Post TypeAI | 1/4/2025 | 17/6/2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Galaxy Weblinks WP Clone any post type wp-clone-any-post-type allows Phishing.This issue affects WP Clone any post type: from n/a through <= 3.6. | |
| Aplazada | Media (4.9) | 0.39% | — | Code CloneAI | 22/3/2025 | 17/6/2026 | The Code Clone plugin for WordPress is vulnerable to time-based SQL Injection via the ‘snippetId’ parameter in all versions up to, and including, 0.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated… | |
| Analizada | Alta (8.8) | 0.95% | — | Eclipse Cyclone Data Distribution Service | 12/3/2025 | 17/6/2026 | An integer underflow during deserialization may allow any unauthenticated user to read out of bounds heap memory. This may result into secret data or pointers revealing the layout of the address space to be included into a deserialized data structure, which may potentially lead to thread crashes or cause denial of… | |
| Aplazada | Media (4.3) | 0.34% | — | Xfinitysoft Content ClonerAIXfinitysoft Super SEO Content ClonerAI | 3/2/2025 | 17/6/2026 | Missing Authorization vulnerability in Xfinitysoft Content Cloner super-seo-content-cloner allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Content Cloner: from n/a through <= 1.0.1. | |
| Analizada | Media (4.3) | 0.31% | — | Content Entity Clone Project Content Entity Clone | 9/1/2025 | 17/6/2026 | Incorrect Authorization vulnerability in Drupal Content Entity Clone allows Forceful Browsing.This issue affects Content Entity Clone: from 0.0.0 before 1.0.4. | |
| Aplazada | Crítica (9.8) | 3.5% | — | Ibroid Super Backup CloneAI | 13/12/2024 | 17/6/2026 | The Super Backup & Clone - Migrate for WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation and a missing capability check on the ibk_restore_migrate_check() function in all versions up to, and including, 2.3.3. This makes it possible for unauthenticated attackers… | |
| Analizada | Crítica (9.8) | 0.64% | — | Jigar-sable Flipkart-clone-php | 9/12/2024 | 17/6/2026 | SQL Injection vulnerability in Flipkart-Clone-PHP version 1.0 in entry.php in product_title parameter, allows attackers to execute arbitrary code. | |
| Aplazada | Media (4.3) | 0.54% | — | Migrate CloneAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Migrate Clone allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Clone: from n/a through 2.3.7. | |
| Aplazada | Alta (8.8) | 0.66% | — | CloneAI | 20/11/2024 | 17/6/2026 | The Clone plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.4.6 via deserialization of untrusted input in the 'recursive_unserialized_replace' function. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the… | |
| Aplazada | Media (5.4) | 0.24% | — | RcloneAI | 15/11/2024 | 17/6/2026 | Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Insecure handling of symlinks with --links and --metadata in rclone while copying to local disk allows unprivileged users to indirectly modify ownership and permissions on symlink target files when a superuser… | |
| Analizada | Alta (8.8) | 0.45% | — | Backupbliss Clone | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in Migrate Clone allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Clone: from n/a through 2.4.5. | |
| Analizada | Alta (8.8) | 0.45% | — | Backupbliss Clone | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in Migrate Clone allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Clone: from n/a through 2.4.5. | |
| Aplazada | Alta (7.2) | 0.85% | — | Cyclonedx CdxgenAI | 27/10/2024 | 17/6/2026 | CycloneDX cdxgen through 10.10.7, when run against an untrusted codebase, may execute code contained within build-related files such as build.gradle.kts, a similar issue to CVE-2022-24441. cdxgen is used by, for example, OWASP dep-scan. NOTE: this has been characterized as a design limitation, rather than an… |