Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
254 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 5.6% | 💥 Exploit | Strategy11 AWP Classifieds | 31/10/2022 | 17/6/2026 | The WordPress Classifieds Plugin WordPress plugin before 4.3 does not properly sanitise and escape some parameters before using them in a SQL statement via an AJAX action available to unauthenticated users and when a specific premium module is active, leading to a SQL injection | |
| Modificada | Media (6.1) | 0.70% | — | Radiustheme Classified Listing | 16/9/2022 | 17/6/2026 | The Classified Listing Pro WordPress plugin before 2.0.20 does not escape a generated URL before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting | |
| Modificada | Media (6.1) | 0.62% | — | Radiustheme Classified ListingRadiustheme Classified Listing Store & MembershipRadiustheme ClassimaRadiustheme Classima Core | 16/9/2022 | 17/6/2026 | The Classima WordPress theme before 2.1.11 and some of its required plugins (Classified Listing before 2.2.14, Classified Listing Pro before 2.0.20, Classified Listing Store & Membership before 1.4.20 and Classima Core before 1.10) do not escape a parameter before outputting it back in attributes, leading to Reflected… | |
| Modificada | Alta (7.5) | 0.76% | — | Itechscripts Classifieds Script | 16/7/2022 | 17/6/2026 | A vulnerability classified as critical has been found in Itech Classifieds Script 7.27. Affected is an unknown function of the file /subpage.php. The manipulation of the argument scat with the input =51' AND 4941=4941 AND 'hoCP'='hoCP leads to sql injection. It is possible to launch the attack remotely. The exploit… | |
| Modificada | Crítica (9.8) | 15% | 💥 Exploit | Cars-seller-auto-classifieds-script Project Cars-seller-auto-classifieds-script | 14/5/2021 | 17/6/2026 | The request_list_request AJAX call of the Car Seller - Auto Classifieds Script WordPress plugin through 2.1.0, available to both authenticated and unauthenticated users, does not sanitise, validate or escape the order_id POST parameter before using it in a SQL statement, leading to a SQL Injection issue. | |
| Modificada | Media (6.1) | 1.4% | — | Stylemixthemes Motors - CAR Dealer, Classifieds & Listing | 24/2/2020 | 17/6/2026 | includes/options.php in the motors-car-dealership-classified-listings (aka Motors - Car Dealer & Classified Ads) plugin through 1.4.0 for WordPress has multiple stored XSS issues. | |
| Modificada | Media (6.5) | 1.2% | 💥 Exploit | Stylemixthemes Motors - CAR Dealer, Classifieds & Listing | 24/2/2020 | 17/6/2026 | includes/options.php in the motors-car-dealership-classified-listings (aka Motors - Car Dealer & Classified Ads) plugin through 1.4.0 for WordPress allows unauthenticated options changes. | |
| Modificada | Crítica (9.8) | 3.6% | — | Ambittechnologies Itech B2B ScriptAmbittechnologies Itech Business Networking ScriptAmbittechnologies Itech Caregiver ScriptAmbittechnologies Itech Classifieds Script+8 | 9/5/2019 | 17/6/2026 | Certain Ambit Technologies Pvt. Ltd products are affected by: SQL Injection. This affects iTech B2B Script 4.42i and Tech Business Networking Script 8.26i and Tech Caregiver Script 2.71i and Tech Classifieds Script 7.41i and Tech Dating Script 3.40i and Tech Freelancer Script 5.27i and Tech Image Sharing Script 4.13i… | |
| Modificada | Media (6.1) | 0.85% | — | Opensource Classified ADS Script Project Opensource Classified ADS Script | 21/3/2019 | 17/6/2026 | PHP Scripts Mall Opensource Classified Ads Script 3.2.2 has reflected Cross-Site Scripting (XSS) via the Search field. | |
| Modificada | Media (6.5) | 1.4% | — | Opensource Classified ADS Script Project Opensource Classified ADS Script | 21/3/2019 | 17/6/2026 | PHP Scripts Mall Opensource Classified Ads Script 3.2.2 has directory traversal via a direct request for a listing of an uploads directory. | |
| Modificada | Media (5.3) | 1.0% | — | Opensource Classified ADS Script Project Opensource Classified ADS Script | 21/3/2019 | 17/6/2026 | PHP Scripts Mall Opensource Classified Ads Script 3.2.2 has reflected HTML injection via the Search Form. | |
| Modificada | Crítica (9.8) | 2.7% | 💥 Exploit | Jextn Classified | 2/2/2018 | 17/6/2026 | SQL Injection exists in the JEXTN Classified 1.0.0 component for Joomla! via a view=boutique&sid= request. | |
| Modificada | Crítica (9.8) | 3.0% | 💥 Exploit | Phpautoclassifiedscript BUS Booking Script | 18/12/2017 | 17/6/2026 | Bus Booking Script 1.0 has SQL Injection via the txtname parameter to admin/index.php. | |
| Modificada | Crítica (9.8) | 3.0% | 💥 Exploit | Readymade PHP Classified Script Project Readymade PHP Classified Script | 13/12/2017 | 17/6/2026 | Readymade PHP Classified Script 3.3 has SQL Injection via the /categories subctid or mctid parameter. | |
| Modificada | Crítica (9.8) | 3.0% | 💥 Exploit | Opensource Classified ADS Script Project Opensource Classified ADS Script | 13/12/2017 | 17/6/2026 | Opensource Classified Ads Script 3.2 has SQL Injection via the advance_result.php keyword parameter. | |
| Modificada | Media (6.1) | 0.67% | — | Scubez Posty Readymade Classifieds | 13/12/2017 | 17/6/2026 | Scubez Posty Readymade Classifieds has XSS via the admin/user_activate_submit.php ID parameter. | |
| Modificada | Alta (7.5) | 1.4% | — | Scubez Posty Readymade Classifieds | 13/12/2017 | 17/6/2026 | Scubez Posty Readymade Classifieds has Incorrect Access Control for visiting admin/user_activate_submit.php (aka the backend PHP script), which might allow remote attackers to obtain sensitive information via a direct request. | |
| Modificada | Alta (7.5) | 1.1% | — | Scubez Posty Readymade Classifieds | 13/12/2017 | 17/6/2026 | Scubez Posty Readymade Classifieds has SQL Injection via the admin/user_activate_submit.php ID parameter. | |
| Modificada | Crítica (9.8) | 8.8% | 💥 Exploit | Scubez Posty Readymade Classifieds | 11/12/2017 | 17/6/2026 | Posty Readymade Classifieds Script 1.0 allows an attacker to inject SQL commands via a listings.php?catid= or ads-details.php?ID= request. | |
| Modificada | Baja (3.5) | 0.95% | — | Osinet Classified ADS | 21/4/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the administration user interface in the Classified Ads module before 6.x-3.1 and 7.x-3.x before 7.x-3.1 for Drupal allows remote authenticated users with the "administer taxonomy" permission to inject arbitrary web script or HTML via a category name. | |
| Modificada | Media (4.3) | 3.2% | 💥 Exploit | Cmsjunkie J-classifiedsmanager | 4/2/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the CMSJunkie J-ClassifiedsManager component for Joomla! allows remote attackers to inject arbitrary web script or HTML via the view parameter to /classifieds. | |
| Modificada | Alta (7.5) | 2.4% | 💥 Exploit | Cmsjunkie J-classifiedsmanager | 4/2/2015 | 17/6/2026 | SQL injection vulnerability in the CMSJunkie J-ClassifiedsManager component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a viewad task to classifieds/offerring-ads. | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Itechscripts Itechclassifieds | 13/1/2015 | 17/6/2026 | SQL injection vulnerability in ChangeEmail.php in iTechClassifieds 3.03.057 allows remote attackers to execute arbitrary SQL commands via the PreviewNum parameter. NOTE: the CatID parameter is already covered by CVE-2008-0685. | |
| Modificada | Alta (7.5) | 4.6% | 💥 Exploit | Strategy11 AWP Classifieds | 13/1/2015 | 17/6/2026 | SQL injection vulnerability in the Another WordPress Classifieds Plugin plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the keywordphrase parameter in a dosearch action. | |
| Modificada | Media (4.3) | 1.6% | — | Strategy11 AWP Classifieds | 13/1/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Another WordPress Classifieds Plugin plugin for WordPress allows remote attackers to inject arbitrary web script or HTML via the query string to the default URI. |