Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 554 respecto a la semana anterior
Críticas / altas1325▼ 178 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 242 respecto a la semana anterior
105 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.86% | — | Wpclever WPC Smart Wishlist FOR Woocommerce | 16/5/2022 | 17/6/2026 | The WPC Smart Wishlist for WooCommerce WordPress plugin before 2.9.9 does not sanitise and escape a parameter before outputting it back in an attribute via an AJAX action, leading to a Reflected Cross-Site Scripting issue. | |
| Modificada | Media (5.4) | 0.60% | — | Wpclever WPC Smart Wishlist FOR Woocommerce | 28/3/2022 | 17/6/2026 | The WPC Smart Wishlist for WooCommerce WordPress plugin before 2.9.4 does not sanitise and escape the key parameter before outputting it back in the wishlist_quickview AJAX action's response (available to any authenticated user), leading to a Reflected Cross-Site Scripting | |
| Modificada | Alta (7.2) | 1.5% | — | Cleverplugins SEO Booster | 13/12/2021 | 17/6/2026 | The SEO Booster WordPress plugin before 3.8 allows for authenticated SQL injection via the "fn_my_ajaxified_dataloader_ajax" AJAX request as the $_REQUEST['order'][0]['dir'] parameter is not properly escaped leading to blind and error-based SQL injections. | |
| Modificada | Media (5.4) | 0.59% | — | Cleversoft Clever Addons FOR Elementor | 5/5/2021 | 17/6/2026 | The “Clever Addons for Elementor” WordPress Plugin before 2.1.0 has several widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method. | |
| Modificada | Media (5.3) | 2.1% | 💥 Exploit | Thrivethemes FocusblogThrivethemes IgnitionThrivethemes LuxeThrivethemes Minus+16 | 12/4/2021 | 17/6/2026 | The Thrive Optimize WordPress plugin before 1.4.13.3, Thrive Comments WordPress plugin before 1.4.15.3, Thrive Headline Optimizer WordPress plugin before 1.3.7.3, Thrive Leads WordPress plugin before 2.3.9.4, Thrive Ultimatum WordPress plugin before 2.3.9.4, Thrive Quiz Builder WordPress plugin before 2.3.9.4, Thrive… | |
| Modificada | Crítica (9.8) | 2.3% | — | Cylan Clever DOG Smart Camera Panorama Dog-2w FirmwareCylan Clever DOG Smart Camera Plus Dog-2w-v4 Firmware | 20/6/2019 | 17/6/2026 | On Shenzhen Cylan Clever Dog Smart Camera DOG-2W and DOG-2W-V4 devices, an attacker on the network can login remotely to the camera and gain root access. The device ships with a hardcoded 12345678 password for the root account, accessible from a TELNET login prompt. | |
| Modificada | Media (5.5) | 0.35% | — | Cylan Clever DOG Smart Camera Panorama Dog-2w FirmwareCylan Clever DOG Smart Camera Plus Dog-2w-v4 Firmware | 20/6/2019 | 17/6/2026 | On Shenzhen Cylan Clever Dog Smart Camera DOG-2W and DOG-2W-V4 devices, an attacker on the local network has unauthenticated access to the internal SD card via the HTTP service on port 8000. The HTTP web server on the camera allows anyone to view or download the video archive recorded and saved on the external memory… | |
| Modificada | Crítica (9.8) | 2.7% | — | Clever Saml2-js | 17/4/2019 | 17/6/2026 | Clever saml2-js 2.0 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may be able to manipulate the SAML data without invalidating the cryptographic signature, allowing the attack to potentially bypass authentication to SAML service providers. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Clever Copy | 30/6/2008 | 16/6/2026 | SQL injection vulnerability in results.php in Clever Copy 3.0 allows remote attackers to execute arbitrary SQL commands via the searchtype parameter. | |
| Modificada | Alta (7.5) | 1.1% | — | Clever Copy | 1/4/2008 | 16/6/2026 | SQL injection vulnerability in postview.php in Clever Copy 3.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter, a different vector than CVE-2008-0363 and CVE-2006-0583. | |
| Modificada | Media (4.3) | 1.1% | — | Clever Copy | 18/1/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in gallery.php in Clever Copy 3.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the album parameter. | |
| Modificada | Alta (7.5) | 1.1% | — | Clever Copy | 18/1/2008 | 16/6/2026 | Multiple SQL injection vulnerabilities in Clever Copy 3.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) ID parameter to postcomment.php and the (2) album parameter to gallery.php. | |
| Modificada | Alta (9.3) | 7.0% | 💥 Exploit | Clever Components Internet Activex Suite | 30/7/2007 | 16/6/2026 | Absolute path traversal vulnerability in the clInetSuiteX6.clWebDav ActiveX control in CLINETSUITEX6.OCX in Clever Internet ActiveX Suite 6.2 allows remote attackers to create or overwrite arbitrary files via a full pathname in the second argument to the GetToFile method. NOTE: some of these details are obtained from… | |
| Modificada | Alta (9.3) | 24% | — | Broadcom Advantage Data TransportBroadcom Brightstor PortalBroadcom Brightstor SAN ManagerBroadcom Cleverpath Aion+20 | 26/7/2007 | 16/6/2026 | Stack-based buffer overflow in the Message Queuing Server (Cam.exe) in CA (formerly Computer Associates) Message Queuing (CAM / CAFT) software before 1.11 Build 54_4 on Windows and NetWare, as used in CA Advantage Data Transport, eTrust Admin, certain BrightStor products, certain CleverPath products, and certain… | |
| Modificada | Alta (9.3) | 7.0% | 💥 Exploit | Clever Components Clever Database Comparer | 14/5/2007 | 16/6/2026 | Stack-based buffer overflow in the Clever Database Comparer 2.2 ActiveX control (comparerax.ocx) allows remote attackers to execute arbitrary code via a long argument to the ConnectToDatabase function. | |
| Modificada | Media (6.5) | 2.0% | — | Broadcom Cleverpath Portal | 25/4/2007 | 16/6/2026 | SQL injection vulnerability in CA Clever Path Portal allows remote authenticated users to execute limited SQL commands and retrieve arbitrary database contents via (1) the ofinterest parameter in a light search query, (2) description parameter in the advanced search query, and possibly other vectors. | |
| Modificada | Alta (7.5) | 2.6% | — | Arcserve BrightstorBroadcom Cleverpath PortalCleverpath Aion BPMCleverpath Portal+7 | 20/12/2006 | 16/6/2026 | Unspecified vulnerability in CA CleverPath Portal before maintenance version 4.71.001_179_060830, as used in multiple products including BrightStor Portal r11.1, CleverPath Aion BPM r10 through r10.2, eTrust Security Command Center r1 and r8, and Unicenter, does not properly handle when multiple Portal servers are… | |
| Modificada | Media (5) | 7.6% | 💥 Exploit | Clever Copy | 11/4/2006 | 16/6/2026 | Magus Perde Clever Copy 3.0 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to view the database username and password via a direct request for connect.inc. | |
| Modificada | Media (4.3) | 1.2% | — | Clever Copy | 19/2/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in default.php in Clever Copy 3.0 allows remote attackers to inject arbitrary web script or HTML via the Subject field when sending private messages (privatemessages.php). NOTE: the provenance of this information is unknown; the details are obtained solely from third party… | |
| Modificada | Media (4.3) | 1.4% | — | Clever Copy | 9/2/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Clever Copy 2.0, 2.0a, and 3.0 allows remote attackers to inject arbitrary web script or HTML via the (1) Referer or (2) X-Forwarded-For headers in an HTTP request, which are not properly handled when the administrator accesses Site Stats. | |
| Modificada | Alta (7.5) | 2.6% | 💥 Exploit | Clever Copy | 8/2/2006 | 16/6/2026 | SQL injection vulnerability in mailarticle.php in Clever Copy 3.0 and earlier allows remote attackers to execute arbitrary SQL commands via the ID parameter. | |
| Modificada | Media (4.3) | 2.4% | — | Broadcom Cleverpath Portal | 10/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the portal login page in Computer Associates CleverPath 4.7 allows remote attackers to execute Javascript via unknown vectors. | |
| Modificada | Media (5) | 3.1% | — | Broadcom Advantage Data TransportBroadcom AdviseitBroadcom Brightstor PortalBroadcom Brightstor SAN Manager+20 | 23/8/2005 | 16/6/2026 | Unknown vulnerability in Computer Associates (CA) Message Queuing (CAM / CAFT) 1.05, 1.07 before Build 220_13, and 1.11 before Build 29_13 allows attackers to cause a denial of service via unknown vectors, aka the "CAM TCP port vulnerability." | |
| Modificada | Alta (10) | 75% | 💥 Exploit | Broadcom Advantage Data TransportBroadcom AdviseitBroadcom Brightstor PortalBroadcom Brightstor SAN Manager+24 | 23/8/2005 | 16/6/2026 | Multiple buffer overflows in Computer Associates (CA) Message Queuing (CAM / CAFT) 1.05, 1.07 before Build 220_13, and 1.11 before Build 29_13 allow remote attackers to execute arbitrary code via unknown vectors. | |
| Modificada | Alta (10) | 7.3% | — | Broadcom Advantage Data TransportBroadcom AdviseitBroadcom Brightstor PortalBroadcom Brightstor SAN Manager+24 | 23/8/2005 | 16/6/2026 | Computer Associates (CA) Message Queuing (CAM / CAFT) 1.05, 1.07 before Build 220_13, and 1.11 before Build 29_13 allows remote attackers to execute arbitrary commands via spoofed CAFT packets. |