Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

224 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)3.0%💥 ExploitMakemytrip Clone Project Makemytrip Clone13/12/201717/6/2026
FS Makemytrip Clone 1.0 has SQL Injection via the show-flight-result.php fl_orig or fl_dest parameter.
ModificadaCrítica (9.8)3.0%💥 ExploitShutterstock Clone Project Shutterstock Clone13/12/201717/6/2026
FS Shutterstock Clone 1.0 has SQL Injection via the /Category keywords parameter.
ModificadaCrítica (9.8)3.0%💥 ExploitGrubhub Clone Project Grubhub Clone13/12/201717/6/2026
FS Grubhub Clone 1.0 has SQL Injection via the /food keywords parameter.
ModificadaCrítica (9.8)3.0%💥 ExploitQuibids Clone Project Quibids Clone13/12/201717/6/2026
FS Quibids Clone 1.0 has SQL Injection via the itechd.php productid parameter.
ModificadaCrítica (9.8)3.0%💥 ExploitLinkedin Clone Project Linkedin Clone13/12/201717/6/2026
FS Linkedin Clone 1.0 has SQL Injection via the group.php grid parameter, profile.php fid parameter, or company_details.php id parameter.
ModificadaCrítica (9.8)3.0%💥 ExploitFreelancer Clone Project Freelancer Clone13/12/201717/6/2026
FS Freelancer Clone 1.0 has SQL Injection via the profile.php u parameter.
ModificadaCrítica (9.8)3.0%💥 ExploitTrademe Clone Project Trademe Clone13/12/201717/6/2026
FS Trademe Clone 1.0 has SQL Injection via the search_item.php search parameter or the general_item_details.php id parameter.
ModificadaCrítica (9.8)3.0%💥 ExploitGroupon Clone Project Groupon Clone13/12/201717/6/2026
FS Groupon Clone 1.0 has SQL Injection via the item_details.php id parameter or the vendor_details.php id parameter.
ModificadaCrítica (9.8)3.0%💥 ExploitCare Clone Project Care Clone13/12/201717/6/2026
FS Care Clone 1.0 has SQL Injection via the searchJob.php jobType or jobFrequency parameter.
ModificadaCrítica (9.8)3.0%💥 ExploitFortunescripts Ebay Clone13/12/201717/6/2026
FS Ebay Clone 1.0 has SQL Injection via the product.php id parameter, or the search.php category_id or sub_category_id parameter.
ModificadaCrítica (9.8)3.0%💥 ExploitAmazon Clone Project Amazon Clone13/12/201717/6/2026
FS Amazon Clone 1.0 has SQL Injection via the PATH_INFO to /VerAyari.
ModificadaCrítica (9.8)3.0%💥 ExploitFoodpanda Clone Project Foodpanda Clone13/12/201717/6/2026
FS Foodpanda Clone 1.0 has SQL Injection via the /food keywords parameter.
ModificadaCrítica (9.8)3.0%💥 ExploitExpedia Clone Project Expedia Clone13/12/201717/6/2026
FS Expedia Clone 1.0 has SQL Injection via the pages.php or content.php id parameter, or the show-flight-result.php fl_orig or fl_dest parameter.
ModificadaCrítica (9.8)2.7%💥 ExploitZomato Clone Script Project Zomato Clone Script31/10/201717/6/2026
Zomato Clone Script allows SQL Injection via the restaurant-menu.php resid parameter.
ModificadaAlta (8.8)8.5%💥 ExploitClaydip Airbnb Clone26/9/201717/6/2026
Multiple unrestricted file upload vulnerabilities in the (1) imageSubmit and (2) proof_submit functions in Claydip Laravel Airbnb Clone 1.0 allow remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in images/profile.
ModificadaMedia (5.5)0.79%—Partclone Project Partclone10/3/201717/6/2026
partclone.chkimg in partclone 0.2.89 is prone to a heap-based buffer overflow vulnerability due to insufficient validation of the partclone image header. An attacker may be able to launch a 'Denial of Service attack' in the context of the user running the affected application.
ModificadaCrítica (9.8)4.8%—Squareup Git-fastclone3/11/201617/6/2026
git-fastclone before 1.0.5 passes user modifiable strings directly to a shell command. An attacker can execute malicious commands by modifying the strings that are passed as arguments to "cd " and "git clone " commands in the library.
ModificadaAlta (8.8)5.2%—Squareup Git-fastclone3/11/201617/6/2026
git-fastclone before 1.0.1 permits arbitrary shell command execution from .gitmodules. If an attacker can instruct a user to run a recursive clone from a repository they control, they can get a client to run an arbitrary shell command. Alternately, if an attacker can MITM an unencrypted git clone, they could exploit…
ModificadaAlta (7.5)1.3%💥 ExploitMilw0rm Project Milw0rm Clone Script18/6/201517/6/2026
Multiple SQL injection vulnerabilities in admin/login.php in Milw0rm Clone Script 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) usr or (2) pwd parameter.
ModificadaMedia (6.5)2.3%—Xcloner17/6/201517/6/2026
Static code injection vulnerability in the XCloner plugin 3.1.2 for WordPress allows remote authenticated users to inject arbitrary PHP code into the language files via a Translation LM_FRONT_* field for a language, as demonstrated by language/italian.php.
ModificadaBaja (3.5)1.6%—Xcloner17/6/201517/6/2026
Cross-site scripting (XSS) vulnerability in the XCloner plugin 3.1.2 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the excl_manual parameter in the xcloner_show page to wpadmin/plugins.php.
ModificadaMedia (6.5)2.6%—Xcloner17/6/201517/6/2026
cloner.functions.php in the XCloner plugin 3.1.2 for WordPress allows remote authenticated users to execute arbitrary commands via a file containing filenames with shell metacharacters, as demonstrated by using the backup comments feature to create the file.
ModificadaBaja (2.1)0.86%💥 ExploitXcloner10/6/201517/6/2026
The XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! provides the MySQL username and password on the command line, which allows local users to obtain sensitive information via the ps command.
ModificadaMedia (4)6.0%💥 ExploitXcloner10/6/201517/6/2026
Directory traversal vulnerability in the XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! allows remote administrators to read arbitrary files via a .. (dot dot) in the file parameter in a json_return action in the xcloner_show page to wp-admin/admin-ajax.php.
ModificadaMedia (5)6.9%💥 ExploitXcloner10/6/201517/6/2026
The XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! stores database backup files with predictable names under the web root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request to a backup file in administrators/backups/.
Orbitaley — Vulnerabilidades