Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 572 respecto a la semana anterior
Críticas / altas1301▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
298 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.24% | — | Wp-buy WP Content Copy Protection & NO Right Click | 20/10/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in wp-buy WP Content Copy Protection & No Right Click wp-content-copy-protector allows Cross Site Request Forgery.This issue affects WP Content Copy Protection & No Right Click: from n/a through <= 3.5.9. | |
| Modificada | Media (5.4) | 0.33% | — | Ninjateam Click TO Chat | 18/10/2024 | 17/6/2026 | The Click to Chat – WP Support All-in-One Floating Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpsaio_snapchat shortcode in all versions up to, and including, 2.3.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it… | |
| Modificada | Media (5.4) | 0.55% | — | Ninjateam Click TO Chat | 17/10/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Ninja Team Click to Chat – WP Support All-in-One Floating Widget support-chat allows Stored XSS.This issue affects Click to Chat – WP Support All-in-One Floating Widget: from n/a through <= 2.3.3. | |
| Analizada | Media (5.4) | 0.42% | — | 4pace Cadclick | 4/10/2024 | 17/6/2026 | A Reflected cross-site scripting (XSS) vulnerability in "ccHandler.aspx" CADClick <= 1.11.0 allows remote attackers to inject arbitrary web script or HTML via the "bomid" parameter. | |
| Analizada | Media (5.4) | 0.42% | — | 4pace Cadclick | 4/10/2024 | 17/6/2026 | A reflected cross-site scripting (XSS) vulnerability in "ccHandlerResource.ashx" in CADClick <= 1.11.0 allows remote attackers to inject arbitrary web script or HTML via the "res_url" parameter. | |
| Analizada | Media (5.4) | 0.42% | — | 4pace Cadclick | 4/10/2024 | 17/6/2026 | A reflected cross-site scripting (XSS) vulnerability in "PrevPgGroup.aspx" in CADClick v1.11.0 and before allows remote attackers to inject arbitrary web script or HTML via the "wer" parameter. | |
| Analizada | Media (5.4) | 0.42% | — | 4pace Cadclick | 4/10/2024 | 17/6/2026 | A reflected cross-site scripting (XSS) vulnerability in "Artikel.aspx" in CADClick v1.11.0 and before allows remote attackers to inject arbitrary web script or HTML via the "searchindex" parameter. | |
| Analizada | Alta (8.8) | 0.67% | — | 4pace Cadclick | 4/10/2024 | 17/6/2026 | A SQL Injection vulnerability in "ccHandler.aspx" in all versions of CADClick v.1.11.0 and before allows remote attackers to execute arbitrary SQL commands via the "bomid" parameter. | |
| Analizada | Baja (3.9) | 0.92% | — | 4pace Cadclick | 4/10/2024 | 17/6/2026 | A Path Traversal (Local File Inclusion) vulnerability in "BinaryFileRedirector.ashx" in CADClick v1.11.0 and before allows remote attackers to retrieve arbitrary local files via the "path" parameter. | |
| Analizada | Alta (7.5) | 0.56% | — | Clickhouse | 3/9/2024 | 17/6/2026 | ClickHouse v24.3.3.102 was discovered to contain a buffer overflow via the component DB::evaluateConstantExpressionImpl. | |
| Analizada | Alta (7.5) | 0.39% | — | Olivethemes Olive ONE Click Demo Import | 13/8/2024 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Olive Themes Olive One Click Demo Import allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Olive One Click Demo Import: from n/a through 1.1.2. | |
| Aplazada | Alta (8.1) | 0.72% | — | ClickhouseAI | 1/8/2024 | 17/6/2026 | It is possible to crash or redirect the execution flow of the ClickHouse server process from an unauthenticated vector by sending a specially crafted request to the ClickHouse server native interface. This redirection is limited to what is available within a 256-byte range of memory at the time of execution, and no… | |
| Aplazada | Media (5.3) | 0.45% | — | ONE Click Close CommentsAI | 27/7/2024 | 17/6/2026 | The One Click Close Comments plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.7.1. This is due to the plugin utilizing bootstrap and leaving test files with display_errors on. This makes it possible for unauthenticated attackers to retrieve the full path of the web… | |
| Aplazada | Media (6.5) | 0.25% | — | Clicklabs Download Button FOR ElementorAI | 20/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in clicklabs® Medienagentur Download Button for Elementor allows Stored XSS.This issue affects Download Button for Elementor: from n/a through 1.2.1. | |
| Modificada | Media (5.4) | 0.30% | — | Cedcommerce ONE Click Order Re-order | 4/7/2024 | 17/6/2026 | The One Click Order Re-Order plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ced_ocor_save_general_setting' function in all versions up to, and including, 1.1.9. This makes it possible for authenticated attackers, with Subscriber-level access and above,… | |
| Aplazada | Media (6.5) | 0.31% | — | Clickstudios PasswordstateAI | 24/6/2024 | 17/6/2026 | Click Studios Passwordstate Core before 9.8 build 9858 allows Authentication Bypass. | |
| Aplazada | Media (5.3) | 1.3% | 💥 PoC | 2clickportalAI | 14/6/2024 | 17/6/2026 | Improper neutralization of input during web page generation vulnerability in 2ClickPortal software allows reflected cross-site scripting (XSS). An attacker might trick somebody into using a crafted URL, which will cause a script to be run in user's browser. This issue affects 2ClickPortal software versions from 7.2.31… | |
| Modificada | Alta (7.5) | 0.29% | — | Olivethemes Olive ONE Click Demo Import | 9/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Olive Themes Olive One Click Demo Import.This issue affects Olive One Click Demo Import: from n/a through 1.1.1. | |
| Modificada | Alta (7.2) | 0.50% | — | Ocdi ONE Click Demo Import | 14/5/2024 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in OCDI One Click Demo Import.This issue affects One Click Demo Import: from n/a through 3.2.0. | |
| Aplazada | Media (4.3) | 0.37% | — | Clickcease Click Fraud ProtectionAI | 7/5/2024 | 17/6/2026 | The ClickCease Click Fraud Protection plugin for WordPress is vulnerable to unauthorized access of data due to an improper capability check on the get_settings function in all versions up to, and including, 3.2.4. This makes it possible for authenticated attackers, with author access and above, to retrieve the… | |
| Aplazada | Alta (8.8) | 1.7% | — | Holithemes Click TO ChatAI | 2/5/2024 | 17/6/2026 | The Click to Chat – HoliThemes plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.35. This makes it possible for authenticated attackers, with contributor access or above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in… | |
| Aplazada | Media (4.3) | 0.20% | — | Clickcease Click Fraud ProtectionAI | 26/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in eranfl ClickCease Click Fraud Protection clickcease-click-fraud-protection.This issue affects ClickCease Click Fraud Protection: from n/a through <= 3.2.7. | |
| Aplazada | Media (6.5) | 0.36% | — | Walterpinem Oneclick Chat TO OrderAI | 27/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Walter Pinem OneClick Chat to Order allows Stored XSS.This issue affects OneClick Chat to Order: from n/a through 1.0.5. | |
| Analizada | Alta (8.8) | 1.1% | — | Clickup | 23/3/2024 | 17/6/2026 | ClickUp Desktop before 3.3.77 on macOS and Windows allows code injection because of specific Electron Fuses. There is inadequate protection against code injection through settings such as RunAsNode. | |
| Modificada | Crítica (9.8) | 0.58% | — | Olivethemes Olive ONE Click Demo Import | 20/3/2024 | 17/6/2026 | Missing Authorization vulnerability in Olive Themes Olive One Click Demo Import allows importing settings and data, ultimately leading to XSS.This issue affects Olive One Click Demo Import: from n/a through 1.1.1. |