Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
224 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.94% | — | Xcloner | 1/1/2021 | 17/6/2026 | An issue was discovered in the XCloner Backup and Restore plugin before 4.2.153 for WordPress. It allows CSRF (via almost any endpoint). | |
| Modificada | Alta (8.8) | 25% | 💥 Exploit | Xcloner | 1/1/2021 | 17/6/2026 | An issue was discovered in the XCloner Backup and Restore plugin before 4.2.13 for WordPress. It gave authenticated attackers the ability to modify arbitrary files, including PHP files. Doing so would allow an attacker to achieve remote code execution. The xcloner_restore.php write_file_action could overwrite… | |
| Modificada | Alta (7.5) | 1.4% | — | RcloneFedoraproject Fedora | 19/11/2020 | 17/6/2026 | An issue was discovered in Rclone before 1.53.3. Due to the use of a weak random number generator, the password generator has been producing weak passwords with much less entropy than advertised. The suggested passwords depend deterministically on the time the second rclone was started. This limits the entropy of the… | |
| Modificada | Media (6.5) | 1.7% | 💥 PoC | Xcloner | 23/5/2020 | 17/6/2026 | The XCloner component before 3.5.4 for Joomla! allows Authenticated Local File Disclosure. | |
| Modificada | Media (5.5) | 0.44% | — | Deepin Clone | 4/7/2019 | 17/6/2026 | deepin-clone before 1.1.3 uses a fixed path /tmp/partclone.log in the Helper::getPartitionSizeInfo() function to write a log file as root, and follows symlinks there. An unprivileged user can prepare a symlink attack there to create or overwrite files in arbitrary file system locations. The content is not attacker… | |
| Modificada | Media (4.7) | 0.39% | — | Deepin-clone | 4/7/2019 | 17/6/2026 | deepin-clone before 1.1.3 uses a fixed path /tmp/repo.iso in the BootDoctor::fix() function to download an ISO file, and follows symlinks there. An unprivileged user can prepare a symlink attack there to create or overwrite files in arbitrary file system locations. The content is not attacker controlled. By winning a… | |
| Modificada | Media (5.5) | 0.44% | — | Deepin-clone | 4/7/2019 | 17/6/2026 | In GUI mode, deepin-clone before 1.1.3 creates a log file at the fixed path /tmp/.deepin-clone.log as root, and follows symlinks there. An unprivileged user can prepare a symlink attack there to create or overwrite files in arbitrary file system locations. The content is not attacker controlled. | |
| Modificada | Alta (7) | 0.28% | — | Deepin-cloneFedoraproject Fedora | 4/7/2019 | 17/6/2026 | deepin-clone before 1.1.3 uses a predictable path /tmp/.deepin-clone/mount/<block-dev-basename> in the Helper::temporaryMountDevice() function to temporarily mount a file system as root. An unprivileged user can prepare a symlink at this location to have the file system mounted in an arbitrary location. By winning a… | |
| Modificada | Crítica (9.8) | 2.3% | — | Flippa Marketplace Clone Project Flippa Marketplace Clone | 19/6/2019 | 17/6/2026 | SQL injection exists in Scriptzee Flippa Marketplace Clone 1.0 via the site-search sortBy or sortDir parameter. | |
| Modificada | Media (6.1) | 0.66% | — | Citysearch / Hotfrog / Gelbeseiten Clone Script Project Citysearch / Hotfrog / Gelbeseiten Clone Script | 13/1/2019 | 17/6/2026 | PHP Scripts Mall Citysearch / Hotfrog / Gelbeseiten Clone Script 2.0.1 has Reflected XSS via the srch parameter, as demonstrated by restaurants-details.php. | |
| Modificada | Media (6.1) | 0.68% | — | Phpscriptsmall OLX Clone | 4/10/2018 | 17/6/2026 | PHP Scripts Mall Olx Clone 3.4.2 has XSS. | |
| Modificada | Media (6.5) | 0.94% | — | Naukri Clone Script Project Naukri Clone Script | 10/8/2018 | 17/6/2026 | PHP Scripts Mall Naukri / Shine / Jobsite Clone Script 3.0.4 allows remote attackers to cause a denial of service (page update outage) via crafted PHP and JavaScript code in the "Current Position" field. | |
| Modificada | Media (5.4) | 0.55% | — | Naukri Clone Script Project Naukri Clone Script | 9/8/2018 | 17/6/2026 | PHP Scripts Mall Naukri / Shine / Jobsite Clone Script 3.0.4 has Stored XSS via the USERNAME field, a related issue to CVE-2018-6795. | |
| Modificada | Media (6.1) | 0.69% | — | Myperfectresume / Jobhero / Resume Clone Script Project Myperfectresume / Jobhero / Resume Clone Script | 9/8/2018 | 17/6/2026 | PHP Scripts Mall Myperfectresume / JobHero / Resume Clone Script 2.0.6 has Stored XSS via the Full Name and Title fields. | |
| Modificada | Media (6.1) | 2.3% | 💥 Exploit | Instagram-clone Project Instagram-clone | 10/7/2018 | 17/6/2026 | edit_requests.php in yTakkar Instagram-clone through 2018-04-23 has XSS via an onmouseover payload because of an inadequate XSS protection mechanism based on preg_replace. | |
| Modificada | Alta (7.5) | 1.3% | — | Rclone | 27/6/2018 | 17/6/2026 | In Rclone 1.42, use of "rclone sync" to migrate data between two Google Cloud Storage buckets might allow attackers to trigger the transmission of any URL's content to Google, because there is no validation of a URL field received from the Google Cloud Storage API server, aka a "RESTLESS" issue. | |
| Modificada | Alta (8.8) | 1.1% | — | Naukri Clone Script Project Naukri Clone Script | 28/5/2018 | 17/6/2026 | PHP Scripts Mall Naukri Clone Script through 3.0.3 allows Unrestricted Upload of a File with a Dangerous Type in edit_resume_det.php, as demonstrated by changing .docx to .php. | |
| Modificada | Crítica (9.8) | 2.6% | — | Partclone Project Partclone | 2/5/2018 | 17/6/2026 | partclone.fat in Partclone before 0.2.88 is prone to a heap-based buffer overflow vulnerability due to insufficient validation of the FAT superblock, related to the mark_reserved_sectors function. An attacker may be able to execute arbitrary code in the context of the user running the affected application. | |
| Modificada | Crítica (9.8) | 2.1% | — | Partclone | 2/5/2018 | 17/6/2026 | partclone.restore in Partclone 0.2.87 is prone to a heap-based buffer overflow vulnerability due to insufficient validation of the partclone image header. An attacker may be able to execute arbitrary code in the context of the user running the affected application. | |
| Modificada | Alta (8.8) | 1.0% | — | HOT Scripts Clone Project HOT Scripts Clone | 12/4/2018 | 17/6/2026 | PHP Scripts Mall Hot Scripts Clone Script Classified v3.1 uses the client side to enforce validation of an e-mail address, which allows remote attackers to modify a registered e-mail address by removing the validation code. | |
| Modificada | Media (6.1) | 2.2% | 💥 Exploit | Match Clone Script Project Match Clone Script | 9/4/2018 | 17/6/2026 | PHP Scripts Mall Match Clone Script 1.0.4 has XSS via the search field to searchbyid.php (aka the "View Search By Id" screen). | |
| Modificada | Media (6.1) | 0.67% | — | Redbus Clone Script Project Redbus Clone Script | 5/4/2018 | 17/6/2026 | PHP Scripts Mall Redbus Clone Script 3.0.6 has XSS via the ter_from or tag parameter to results.php. | |
| Modificada | Media (4.8) | 0.53% | — | HOT Scripts Clone Project HOT Scripts Clone | 6/3/2018 | 17/6/2026 | PHP Scripts Mall Hot Scripts Clone:Script Classified Version 3.1 Application is vulnerable to stored XSS within the "Add New" function for a Management User. Within the "Add New" section, the application does not sanitize user supplied input to the name parameter, and renders injected JavaScript code to the user's… | |
| Modificada | Media (5.4) | 0.54% | — | Groupon Clone Script Project Groupon Clone Script | 23/2/2018 | 17/6/2026 | Cross Site Scripting (XSS) exists in PHP Scripts Mall Slickdeals / DealNews / Groupon Clone Script 3.0.2 via a User Profile Field parameter. | |
| Modificada | Media (5.4) | 0.66% | — | Alibaba Clone Script Project Alibaba Clone Script | 23/2/2018 | 17/6/2026 | Cross Site Scripting (XSS) exists in PHP Scripts Mall Alibaba Clone Script 1.0.2 via a profile parameter. |