Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

224 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)0.94%—Xcloner1/1/202117/6/2026
An issue was discovered in the XCloner Backup and Restore plugin before 4.2.153 for WordPress. It allows CSRF (via almost any endpoint).
ModificadaAlta (8.8)25%💥 ExploitXcloner1/1/202117/6/2026
An issue was discovered in the XCloner Backup and Restore plugin before 4.2.13 for WordPress. It gave authenticated attackers the ability to modify arbitrary files, including PHP files. Doing so would allow an attacker to achieve remote code execution. The xcloner_restore.php write_file_action could overwrite…
ModificadaAlta (7.5)1.4%—RcloneFedoraproject Fedora19/11/202017/6/2026
An issue was discovered in Rclone before 1.53.3. Due to the use of a weak random number generator, the password generator has been producing weak passwords with much less entropy than advertised. The suggested passwords depend deterministically on the time the second rclone was started. This limits the entropy of the…
ModificadaMedia (6.5)1.7%💥 PoCXcloner23/5/202017/6/2026
The XCloner component before 3.5.4 for Joomla! allows Authenticated Local File Disclosure.
ModificadaMedia (5.5)0.44%—Deepin Clone4/7/201917/6/2026
deepin-clone before 1.1.3 uses a fixed path /tmp/partclone.log in the Helper::getPartitionSizeInfo() function to write a log file as root, and follows symlinks there. An unprivileged user can prepare a symlink attack there to create or overwrite files in arbitrary file system locations. The content is not attacker…
ModificadaMedia (4.7)0.39%—Deepin-clone4/7/201917/6/2026
deepin-clone before 1.1.3 uses a fixed path /tmp/repo.iso in the BootDoctor::fix() function to download an ISO file, and follows symlinks there. An unprivileged user can prepare a symlink attack there to create or overwrite files in arbitrary file system locations. The content is not attacker controlled. By winning a…
ModificadaMedia (5.5)0.44%—Deepin-clone4/7/201917/6/2026
In GUI mode, deepin-clone before 1.1.3 creates a log file at the fixed path /tmp/.deepin-clone.log as root, and follows symlinks there. An unprivileged user can prepare a symlink attack there to create or overwrite files in arbitrary file system locations. The content is not attacker controlled.
ModificadaAlta (7)0.28%—Deepin-cloneFedoraproject Fedora4/7/201917/6/2026
deepin-clone before 1.1.3 uses a predictable path /tmp/.deepin-clone/mount/<block-dev-basename> in the Helper::temporaryMountDevice() function to temporarily mount a file system as root. An unprivileged user can prepare a symlink at this location to have the file system mounted in an arbitrary location. By winning a…
ModificadaCrítica (9.8)2.3%—Flippa Marketplace Clone Project Flippa Marketplace Clone19/6/201917/6/2026
SQL injection exists in Scriptzee Flippa Marketplace Clone 1.0 via the site-search sortBy or sortDir parameter.
ModificadaMedia (6.1)0.66%—Citysearch / Hotfrog / Gelbeseiten Clone Script Project Citysearch / Hotfrog / Gelbeseiten Clone Script13/1/201917/6/2026
PHP Scripts Mall Citysearch / Hotfrog / Gelbeseiten Clone Script 2.0.1 has Reflected XSS via the srch parameter, as demonstrated by restaurants-details.php.
ModificadaMedia (6.1)0.68%—Phpscriptsmall OLX Clone4/10/201817/6/2026
PHP Scripts Mall Olx Clone 3.4.2 has XSS.
ModificadaMedia (6.5)0.94%—Naukri Clone Script Project Naukri Clone Script10/8/201817/6/2026
PHP Scripts Mall Naukri / Shine / Jobsite Clone Script 3.0.4 allows remote attackers to cause a denial of service (page update outage) via crafted PHP and JavaScript code in the "Current Position" field.
ModificadaMedia (5.4)0.55%—Naukri Clone Script Project Naukri Clone Script9/8/201817/6/2026
PHP Scripts Mall Naukri / Shine / Jobsite Clone Script 3.0.4 has Stored XSS via the USERNAME field, a related issue to CVE-2018-6795.
ModificadaMedia (6.1)0.69%—Myperfectresume / Jobhero / Resume Clone Script Project Myperfectresume / Jobhero / Resume Clone Script9/8/201817/6/2026
PHP Scripts Mall Myperfectresume / JobHero / Resume Clone Script 2.0.6 has Stored XSS via the Full Name and Title fields.
ModificadaMedia (6.1)2.3%💥 ExploitInstagram-clone Project Instagram-clone10/7/201817/6/2026
edit_requests.php in yTakkar Instagram-clone through 2018-04-23 has XSS via an onmouseover payload because of an inadequate XSS protection mechanism based on preg_replace.
ModificadaAlta (7.5)1.3%—Rclone27/6/201817/6/2026
In Rclone 1.42, use of "rclone sync" to migrate data between two Google Cloud Storage buckets might allow attackers to trigger the transmission of any URL's content to Google, because there is no validation of a URL field received from the Google Cloud Storage API server, aka a "RESTLESS" issue.
ModificadaAlta (8.8)1.1%—Naukri Clone Script Project Naukri Clone Script28/5/201817/6/2026
PHP Scripts Mall Naukri Clone Script through 3.0.3 allows Unrestricted Upload of a File with a Dangerous Type in edit_resume_det.php, as demonstrated by changing .docx to .php.
ModificadaCrítica (9.8)2.6%—Partclone Project Partclone2/5/201817/6/2026
partclone.fat in Partclone before 0.2.88 is prone to a heap-based buffer overflow vulnerability due to insufficient validation of the FAT superblock, related to the mark_reserved_sectors function. An attacker may be able to execute arbitrary code in the context of the user running the affected application.
ModificadaCrítica (9.8)2.1%—Partclone2/5/201817/6/2026
partclone.restore in Partclone 0.2.87 is prone to a heap-based buffer overflow vulnerability due to insufficient validation of the partclone image header. An attacker may be able to execute arbitrary code in the context of the user running the affected application.
ModificadaAlta (8.8)1.0%—HOT Scripts Clone Project HOT Scripts Clone12/4/201817/6/2026
PHP Scripts Mall Hot Scripts Clone Script Classified v3.1 uses the client side to enforce validation of an e-mail address, which allows remote attackers to modify a registered e-mail address by removing the validation code.
ModificadaMedia (6.1)2.2%💥 ExploitMatch Clone Script Project Match Clone Script9/4/201817/6/2026
PHP Scripts Mall Match Clone Script 1.0.4 has XSS via the search field to searchbyid.php (aka the "View Search By Id" screen).
ModificadaMedia (6.1)0.67%—Redbus Clone Script Project Redbus Clone Script5/4/201817/6/2026
PHP Scripts Mall Redbus Clone Script 3.0.6 has XSS via the ter_from or tag parameter to results.php.
ModificadaMedia (4.8)0.53%—HOT Scripts Clone Project HOT Scripts Clone6/3/201817/6/2026
PHP Scripts Mall Hot Scripts Clone:Script Classified Version 3.1 Application is vulnerable to stored XSS within the "Add New" function for a Management User. Within the "Add New" section, the application does not sanitize user supplied input to the name parameter, and renders injected JavaScript code to the user's…
ModificadaMedia (5.4)0.54%—Groupon Clone Script Project Groupon Clone Script23/2/201817/6/2026
Cross Site Scripting (XSS) exists in PHP Scripts Mall Slickdeals / DealNews / Groupon Clone Script 3.0.2 via a User Profile Field parameter.
ModificadaMedia (5.4)0.66%—Alibaba Clone Script Project Alibaba Clone Script23/2/201817/6/2026
Cross Site Scripting (XSS) exists in PHP Scripts Mall Alibaba Clone Script 1.0.2 via a profile parameter.
Orbitaley — Vulnerabilidades