Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
224 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.95% | — | Git-shallow-cloneAI | 1/10/2024 | 17/6/2026 | All versions of the package git-shallow-clone are vulnerable to Command injection due to missing sanitization or mitigation flags in the process variable of the gitShallowClone function. | |
| Aplazada | Media (5.3) | 0.37% | — | XclonerAI | 16/7/2024 | 17/6/2026 | The Backup, Restore and Migrate WordPress Sites With the XCloner Plugin plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 4.7.3. This is due the plugin utilizing sabre without preventing direct access to the files. This makes it possible for unauthenticated attackers to… | |
| Modificada | Media (5.4) | 0.31% | — | Carlosfazenda Page AND Post Clone | 29/6/2024 | 17/6/2026 | The Page and Post Clone plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.0 via the 'content_clone' function due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Author-level access and above, to clone… | |
| Aplazada | Alta (7.5) | 0.59% | — | Cyclonedx Core JavaAI | 28/6/2024 | 17/6/2026 | The CycloneDX core module provides a model representation of the SBOM along with utilities to assist in creating, validating, and parsing SBOMs. Before deserializing CycloneDX Bill of Materials in XML format, _cyclonedx-core-java_ leverages XPath expressions to determine the schema version of the BOM. The… | |
| Modificada | Media (4.3) | 0.31% | — | Afzalmultani WP Clone Menu | 12/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Afzal Multani WP Clone Menu.This issue affects WP Clone Menu: from n/a through 1.0.1. | |
| Aplazada | Media (6.5) | 0.25% | — | Cyclonetheme Elegant BlocksAI | 3/6/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in cyclonetheme Elegant Blocks allows Stored XSS.This issue affects Elegant Blocks: from n/a through 1.7. | |
| Aplazada | Alta (8.1) | 0.92% | — | Owasp CyclonedxAICyclonedx JavascriptAI | 14/5/2024 | 17/6/2026 | The CycloneDX JavaScript library contains the core functionality of OWASP CycloneDX for JavaScript. In 6.7.0, XML External entity injections were possible, when running the provided XML Validator on arbitrary input. This issue was fixed in version 6.7.1. | |
| Aplazada | Media (5.4) | 0.30% | — | Mahesh Vora WP Page Post Widget CloneAI | 29/4/2024 | 17/6/2026 | Missing Authorization vulnerability in Mahesh Vora WP Page Post Widget Clone.This issue affects WP Page Post Widget Clone: from n/a through 1.0.1. | |
| Modificada | Alta (7.5) | 1.9% | 💥 Exploit | Backupbliss Clone | 8/1/2024 | 17/6/2026 | The Clone WordPress plugin before 2.4.3 uses buffer files to store in-progress backup informations, which is stored at a publicly accessible, statically defined file path. | |
| Modificada | Media (5.9) | 94% | 💥 Exploit | Openbsd OpensshPuttyFilezilla-project Filezilla ClientPanic Transmit 5+64 | 18/12/2023 | 17/6/2026 | The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension negotiation message), and a client and server may consequently end up with a connection for which some… | |
| Modificada | Crítica (9.8) | 1.1% | — | Oryx-embedded Cyclonetcp | 10/10/2023 | 17/6/2026 | In Oryx CycloneTCP 1.9.6, TCP ISNs are improperly random. | |
| Modificada | Media (4.3) | 0.61% | — | Backupbliss Backup MigrationBackupbliss CloneCopy-delete-posts Duplicate PostInisev Enhanced Text Widget+6 | 28/7/2023 | 17/6/2026 | Several plugins for WordPress by Inisev are vulnerable to Cross-Site Request Forgery to unauthorized installation of plugins due to a missing nonce check on the handle_installation function that is called via the inisev_installation AJAX aciton in various versions. This makes it possible for unauthenticated attackers… | |
| Modificada | Media (6.5) | 0.69% | — | Backupbliss Backup MigrationBackupbliss CloneCopy-delete-posts Duplicate PostInisev Enhanced Text Widget+7 | 28/7/2023 | 17/6/2026 | Several plugins for WordPress by Inisev are vulnerable to unauthorized installation of plugins due to a missing capability check on the handle_installation function that is called via the inisev_installation AJAX aciton in various versions. This makes it possible for authenticated attackers with minimal permissions,… | |
| Modificada | Media (6.5) | 0.60% | — | Jenkins View-cloner | 26/1/2023 | 17/6/2026 | Jenkins view-cloner Plugin 1.1 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Extended Read permission, or access to the Jenkins controller file system. | |
| Modificada | Crítica (9.8) | 3.5% | — | Git-clone Project Git-clone | 1/7/2022 | 17/6/2026 | All versions of package git-clone are vulnerable to Command Injection due to insecure usage of the --upload-pack feature of git. | |
| Modificada | Media (4.3) | 0.29% | — | Watchful Xcloner | 27/6/2022 | 17/6/2026 | The Backup, Restore and Migrate WordPress Sites With the XCloner Plugin WordPress plugin before 4.3.6 does not have authorisation and CSRF checks when resetting its settings, allowing unauthenticated attackers to reset them, including generating a new backup encryption key. | |
| Modificada | Crítica (9.8) | 2.1% | — | Eclipse Cyclonedds | 5/5/2022 | 17/6/2026 | Eclipse CycloneDDS versions prior to 0.8.0 improperly handle invalid structures, which may allow an attacker to write arbitrary values in the XML parser. | |
| Modificada | Crítica (9.8) | 2.1% | — | Eclipse Cyclonedds | 5/5/2022 | 17/6/2026 | Eclipse CycloneDDS versions prior to 0.8.0 are vulnerable to a write-what-where condition, which may allow an attacker to write arbitrary values in the XML parser. | |
| Modificada | Crítica (9.8) | 3.7% | — | Git-pull-or-clone Project Git-pull-or-clone | 1/5/2022 | 17/6/2026 | The package git-pull-or-clone before 2.0.2 are vulnerable to Command Injection due to the use of the --upload-pack feature of git which is also supported for git clone. The source includes the use of the secure child process API spawn(). However, the outpath parameter passed to it may be a command-line argument to the… | |
| Modificada | Alta (8.1) | 1.5% | — | Cyclonedx Bill OF Materials Repository Server | 22/3/2022 | 17/6/2026 | CycloneDX BOM Repository Server is a bill of materials (BOM) repository server for distributing CycloneDX BOMs. CycloneDX BOM Repository Server before version 2.0.1 has an improper input validation vulnerability leading to path traversal. A malicious user may potentially exploit this vulnerability to create arbitrary… | |
| Modificada | Alta (7.5) | 2.5% | — | 1byte Copy91byte Exactspy1byte Fonetracker1byte Guestspy+5 | 24/2/2022 | 17/6/2026 | The backend infrastructure shared by multiple mobile device monitoring services does not adequately authenticate or authorize API requests, creating an IDOR (Insecure Direct Object Reference) vulnerability. | |
| Modificada | Media (4.3) | 0.78% | — | WP Post Page Clone Project WP Post Page Clone | 24/1/2022 | 17/6/2026 | The WP Post Page Clone WordPress plugin before 1.2 allows users with a role as low as Contributor to clone and view other users' draft and password-protected posts which they cannot view normally. | |
| Modificada | Alta (7.5) | 1.9% | — | Eclipse Cyclone Data Distribution Service | 23/8/2021 | 17/6/2026 | A heap buffer overflow in /src/dds_stream.c of Eclipse IOT Cyclone DDS Project v0.1.0 causes the DDS subscriber server to crash. | |
| Modificada | Alta (7.5) | 1.9% | — | Eclipse Cyclone Data Distribution Service | 23/8/2021 | 17/6/2026 | A stack buffer overflow in /ddsi/q_bitset.h of Eclipse IOT Cyclone DDS Project v0.1.0 causes the DDS subscriber server to crash. | |
| Modificada | Alta (7.5) | 1.2% | — | Oryx-embedded Cyclonetcp | 8/3/2021 | 17/6/2026 | Oryx Embedded CycloneTCP 1.7.6 to 2.0.0, fixed in 2.0.2, is affected by incorrect input validation, which may cause a denial of service (DoS). To exploit the vulnerability, an attacker needs to have TCP connectivity to the target system. Receiving a maliciously crafted TCP packet from an unauthenticated endpoint is… |