Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2730▼ 572 respecto a la semana anterior
Críticas / altas1301▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
–

298 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)0.24%—Wp-buy WP Content Copy Protection & NO Right Click20/10/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in wp-buy WP Content Copy Protection & No Right Click wp-content-copy-protector allows Cross Site Request Forgery.This issue affects WP Content Copy Protection & No Right Click: from n/a through <= 3.5.9.
ModificadaMedia (5.4)0.33%—Ninjateam Click TO Chat18/10/202417/6/2026
The Click to Chat – WP Support All-in-One Floating Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpsaio_snapchat shortcode in all versions up to, and including, 2.3.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it…
ModificadaMedia (5.4)0.55%—Ninjateam Click TO Chat17/10/202417/6/2026
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Ninja Team Click to Chat – WP Support All-in-One Floating Widget support-chat allows Stored XSS.This issue affects Click to Chat – WP Support All-in-One Floating Widget: from n/a through <= 2.3.3.
AnalizadaMedia (5.4)0.42%—4pace Cadclick4/10/202417/6/2026
A Reflected cross-site scripting (XSS) vulnerability in "ccHandler.aspx" CADClick <= 1.11.0 allows remote attackers to inject arbitrary web script or HTML via the "bomid" parameter.
AnalizadaMedia (5.4)0.42%—4pace Cadclick4/10/202417/6/2026
A reflected cross-site scripting (XSS) vulnerability in "ccHandlerResource.ashx" in CADClick <= 1.11.0 allows remote attackers to inject arbitrary web script or HTML via the "res_url" parameter.
AnalizadaMedia (5.4)0.42%—4pace Cadclick4/10/202417/6/2026
A reflected cross-site scripting (XSS) vulnerability in "PrevPgGroup.aspx" in CADClick v1.11.0 and before allows remote attackers to inject arbitrary web script or HTML via the "wer" parameter.
AnalizadaMedia (5.4)0.42%—4pace Cadclick4/10/202417/6/2026
A reflected cross-site scripting (XSS) vulnerability in "Artikel.aspx" in CADClick v1.11.0 and before allows remote attackers to inject arbitrary web script or HTML via the "searchindex" parameter.
AnalizadaAlta (8.8)0.67%—4pace Cadclick4/10/202417/6/2026
A SQL Injection vulnerability in "ccHandler.aspx" in all versions of CADClick v.1.11.0 and before allows remote attackers to execute arbitrary SQL commands via the "bomid" parameter.
AnalizadaBaja (3.9)0.92%—4pace Cadclick4/10/202417/6/2026
A Path Traversal (Local File Inclusion) vulnerability in "BinaryFileRedirector.ashx" in CADClick v1.11.0 and before allows remote attackers to retrieve arbitrary local files via the "path" parameter.
AnalizadaAlta (7.5)0.56%—Clickhouse3/9/202417/6/2026
ClickHouse v24.3.3.102 was discovered to contain a buffer overflow via the component DB::evaluateConstantExpressionImpl.
AnalizadaAlta (7.5)0.39%—Olivethemes Olive ONE Click Demo Import13/8/202417/6/2026
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Olive Themes Olive One Click Demo Import allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Olive One Click Demo Import: from n/a through 1.1.2.
AplazadaAlta (8.1)0.72%—ClickhouseAI1/8/202417/6/2026
It is possible to crash or redirect the execution flow of the ClickHouse server process from an unauthenticated vector by sending a specially crafted request to the ClickHouse server native interface. This redirection is limited to what is available within a 256-byte range of memory at the time of execution, and no…
AplazadaMedia (5.3)0.45%—ONE Click Close CommentsAI27/7/202417/6/2026
The One Click Close Comments plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.7.1. This is due to the plugin utilizing bootstrap and leaving test files with display_errors on. This makes it possible for unauthenticated attackers to retrieve the full path of the web…
AplazadaMedia (6.5)0.25%—Clicklabs Download Button FOR ElementorAI20/7/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in clicklabs® Medienagentur Download Button for Elementor allows Stored XSS.This issue affects Download Button for Elementor: from n/a through 1.2.1.
ModificadaMedia (5.4)0.30%—Cedcommerce ONE Click Order Re-order4/7/202417/6/2026
The One Click Order Re-Order plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ced_ocor_save_general_setting' function in all versions up to, and including, 1.1.9. This makes it possible for authenticated attackers, with Subscriber-level access and above,…
AplazadaMedia (6.5)0.31%—Clickstudios PasswordstateAI24/6/202417/6/2026
Click Studios Passwordstate Core before 9.8 build 9858 allows Authentication Bypass.
AplazadaMedia (5.3)1.3%💥 PoC2clickportalAI14/6/202417/6/2026
Improper neutralization of input during web page generation vulnerability in 2ClickPortal software allows reflected cross-site scripting (XSS). An attacker might trick somebody into using a crafted URL, which will cause a script to be run in user's browser. This issue affects 2ClickPortal software versions from 7.2.31…
ModificadaAlta (7.5)0.29%—Olivethemes Olive ONE Click Demo Import9/6/202417/6/2026
Missing Authorization vulnerability in Olive Themes Olive One Click Demo Import.This issue affects Olive One Click Demo Import: from n/a through 1.1.1.
ModificadaAlta (7.2)0.50%—Ocdi ONE Click Demo Import14/5/202417/6/2026
Deserialization of Untrusted Data vulnerability in OCDI One Click Demo Import.This issue affects One Click Demo Import: from n/a through 3.2.0.
AplazadaMedia (4.3)0.37%—Clickcease Click Fraud ProtectionAI7/5/202417/6/2026
The ClickCease Click Fraud Protection plugin for WordPress is vulnerable to unauthorized access of data due to an improper capability check on the get_settings function in all versions up to, and including, 3.2.4. This makes it possible for authenticated attackers, with author access and above, to retrieve the…
AplazadaAlta (8.8)1.7%—Holithemes Click TO ChatAI2/5/202417/6/2026
The Click to Chat – HoliThemes plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.35. This makes it possible for authenticated attackers, with contributor access or above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in…
AplazadaMedia (4.3)0.20%—Clickcease Click Fraud ProtectionAI26/4/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in eranfl ClickCease Click Fraud Protection clickcease-click-fraud-protection.This issue affects ClickCease Click Fraud Protection: from n/a through <= 3.2.7.
AplazadaMedia (6.5)0.36%—Walterpinem Oneclick Chat TO OrderAI27/3/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Walter Pinem OneClick Chat to Order allows Stored XSS.This issue affects OneClick Chat to Order: from n/a through 1.0.5.
AnalizadaAlta (8.8)1.1%—Clickup23/3/202417/6/2026
ClickUp Desktop before 3.3.77 on macOS and Windows allows code injection because of specific Electron Fuses. There is inadequate protection against code injection through settings such as RunAsNode.
ModificadaCrítica (9.8)0.58%—Olivethemes Olive ONE Click Demo Import20/3/202417/6/2026
Missing Authorization vulnerability in Olive Themes Olive One Click Demo Import allows importing settings and data, ultimately leading to XSS.This issue affects Olive One Click Demo Import: from n/a through 1.1.1.
Orbitaley — Vulnerabilidades