Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

224 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)0.39%—Phpscriptsmall Fiverr Clone Script20/2/202617/6/2026
Fiverr Clone Script 1.2.2 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the page parameter. Attackers can supply malicious SQL syntax in the page parameter to extract sensitive database information or modify database contents.
ModificadaCrítica (10)0.33%—Eclipse Cyclone Data Distribution Service23/12/20255/7/2026
Improper verification of the time certificate in Eclipse Cyclone DDS before v0.10.5 allows attackers to bypass certificate checks and execute commands with System privileges.
AplazadaAlta (8.4)0.15%—Elecom Clone FOR WindowsAI9/12/20251/10/2026
Clone for Windows provided by ELECOM CO.,LTD. registers a Windows service with an unquoted file path. A user with the write permission on the root directory of the system drive may execute arbitrary code with SYSTEM privilege.
AplazadaMedia (5.3)0.25%—Evan Herman Post ClonerAI9/12/20255/10/2026
Missing Authorization vulnerability in Evan Herman Post Cloner post-cloner allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Post Cloner: from n/a through <= 1.0.0.
AplazadaMedia (4.3)0.12%—XclonerAI5/12/202517/6/2026
The Backup, Restore and Migrate your sites with XCloner plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.8.2. This is due to missing or incorrect nonce validation on the Xcloner_Remote_Storage:save() function. This makes it possible for unauthenticated attackers…
AplazadaAlta (7.5)0.37%—Cyclonedx-core-javaAI10/11/202517/6/2026
The CycloneDX core module provides a model representation of the SBOM along with utilities to assist in creating, validating, and parsing SBOMs. Starting in version 2.1.0 and prior to version 11.0.1, the XML `Validator` used by cyclonedx-core-java was not configured securely, making the library vulnerable to XML…
AplazadaAlta (7.1)0.25%—Globalis Multisite Clone DuplicatorAI22/10/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Globalis MultiSite Clone Duplicator multisite-clone-duplicator allows Reflected XSS.This issue affects MultiSite Clone Duplicator: from n/a through <= 1.5.3.
AnalizadaMedia (6.1)0.26%—Realme Clone Phone18/9/202517/6/2026
In realme BackupRestore app v15.1.12_2810c08_250314, improper URI scheme handling in com.coloros.pc.PcToolMainActivity allows local attackers to cause a crash and potential XSS via crafted ADB intents.
AplazadaMedia (5.4)0.24%—Cyclonedx SunshineAI13/8/202517/6/2026
CycloneDX Sunshine v0.9 is vulnerable to CSV Formula Injection via a crafted JSON file
AplazadaAlta (7.4)0.27%—Oppo Clone PhoneAI23/6/202517/6/2026
OPPO Clone Phone uses a weak password WiFi hotspot to transfer files, resulting in Information disclosure.
AplazadaCrítica (9.4)0.22%—Cyclone Matrix TRF Smart Keyless Entry SystemAIKIA SolutoAI13/6/202517/6/2026
Use of fixed learning codes, one code to lock the car and the other code to unlock it, in the Key Fob Transmitter in Cyclone Matrix TRF Smart Keyless Entry System, which allows a replay attack. Research was completed on the 2024 KIA Soluto. Attack confirmed on other KIA Models in Ecuador.
AplazadaMedia (5.3)0.37%—Galaxyweblinks WP Clone ANY Post TypeAI1/4/202517/6/2026
Missing Authorization vulnerability in Galaxy Weblinks WP Clone any post type wp-clone-any-post-type allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Clone any post type: from n/a through <= 3.6.
AplazadaMedia (4.7)0.36%—Galaxyweblinks WP Clone ANY Post TypeAI1/4/202517/6/2026
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Galaxy Weblinks WP Clone any post type wp-clone-any-post-type allows Phishing.This issue affects WP Clone any post type: from n/a through <= 3.6.
AplazadaMedia (4.9)0.39%—Code CloneAI22/3/202517/6/2026
The Code Clone plugin for WordPress is vulnerable to time-based SQL Injection via the ‘snippetId’ parameter in all versions up to, and including, 0.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated…
AnalizadaAlta (8.8)0.95%—Eclipse Cyclone Data Distribution Service12/3/202517/6/2026
An integer underflow during deserialization may allow any unauthenticated user to read out of bounds heap memory. This may result into secret data or pointers revealing the layout of the address space to be included into a deserialized data structure, which may potentially lead to thread crashes or cause denial of…
AplazadaMedia (4.3)0.34%—Xfinitysoft Content ClonerAIXfinitysoft Super SEO Content ClonerAI3/2/202517/6/2026
Missing Authorization vulnerability in Xfinitysoft Content Cloner super-seo-content-cloner allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Content Cloner: from n/a through <= 1.0.1.
AnalizadaMedia (4.3)0.31%—Content Entity Clone Project Content Entity Clone9/1/202517/6/2026
Incorrect Authorization vulnerability in Drupal Content Entity Clone allows Forceful Browsing.This issue affects Content Entity Clone: from 0.0.0 before 1.0.4.
AplazadaCrítica (9.8)3.5%—Ibroid Super Backup CloneAI13/12/202417/6/2026
The Super Backup & Clone - Migrate for WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation and a missing capability check on the ibk_restore_migrate_check() function in all versions up to, and including, 2.3.3. This makes it possible for unauthenticated attackers…
AnalizadaCrítica (9.8)0.64%—Jigar-sable Flipkart-clone-php9/12/202417/6/2026
SQL Injection vulnerability in Flipkart-Clone-PHP version 1.0 in entry.php in product_title parameter, allows attackers to execute arbitrary code.
AplazadaMedia (4.3)0.54%—Migrate CloneAI9/12/202417/6/2026
Missing Authorization vulnerability in Migrate Clone allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Clone: from n/a through 2.3.7.
AplazadaAlta (8.8)0.66%—CloneAI20/11/202417/6/2026
The Clone plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.4.6 via deserialization of untrusted input in the 'recursive_unserialized_replace' function. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the…
AplazadaMedia (5.4)0.24%—RcloneAI15/11/202417/6/2026
Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Insecure handling of symlinks with --links and --metadata in rclone while copying to local disk allows unprivileged users to indirectly modify ownership and permissions on symlink target files when a superuser…
AnalizadaAlta (8.8)0.45%—Backupbliss Clone1/11/202417/6/2026
Missing Authorization vulnerability in Migrate Clone allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Clone: from n/a through 2.4.5.
AnalizadaAlta (8.8)0.45%—Backupbliss Clone1/11/202417/6/2026
Missing Authorization vulnerability in Migrate Clone allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Clone: from n/a through 2.4.5.
AplazadaAlta (7.2)0.85%—Cyclonedx CdxgenAI27/10/202417/6/2026
CycloneDX cdxgen through 10.10.7, when run against an untrusted codebase, may execute code contained within build-related files such as build.gradle.kts, a similar issue to CVE-2022-24441. cdxgen is used by, for example, OWASP dep-scan. NOTE: this has been characterized as a design limitation, rather than an…