Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
224 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 3.0% | 💥 Exploit | Makemytrip Clone Project Makemytrip Clone | 13/12/2017 | 17/6/2026 | FS Makemytrip Clone 1.0 has SQL Injection via the show-flight-result.php fl_orig or fl_dest parameter. | |
| Modificada | Crítica (9.8) | 3.0% | 💥 Exploit | Shutterstock Clone Project Shutterstock Clone | 13/12/2017 | 17/6/2026 | FS Shutterstock Clone 1.0 has SQL Injection via the /Category keywords parameter. | |
| Modificada | Crítica (9.8) | 3.0% | 💥 Exploit | Grubhub Clone Project Grubhub Clone | 13/12/2017 | 17/6/2026 | FS Grubhub Clone 1.0 has SQL Injection via the /food keywords parameter. | |
| Modificada | Crítica (9.8) | 3.0% | 💥 Exploit | Quibids Clone Project Quibids Clone | 13/12/2017 | 17/6/2026 | FS Quibids Clone 1.0 has SQL Injection via the itechd.php productid parameter. | |
| Modificada | Crítica (9.8) | 3.0% | 💥 Exploit | Linkedin Clone Project Linkedin Clone | 13/12/2017 | 17/6/2026 | FS Linkedin Clone 1.0 has SQL Injection via the group.php grid parameter, profile.php fid parameter, or company_details.php id parameter. | |
| Modificada | Crítica (9.8) | 3.0% | 💥 Exploit | Freelancer Clone Project Freelancer Clone | 13/12/2017 | 17/6/2026 | FS Freelancer Clone 1.0 has SQL Injection via the profile.php u parameter. | |
| Modificada | Crítica (9.8) | 3.0% | 💥 Exploit | Trademe Clone Project Trademe Clone | 13/12/2017 | 17/6/2026 | FS Trademe Clone 1.0 has SQL Injection via the search_item.php search parameter or the general_item_details.php id parameter. | |
| Modificada | Crítica (9.8) | 3.0% | 💥 Exploit | Groupon Clone Project Groupon Clone | 13/12/2017 | 17/6/2026 | FS Groupon Clone 1.0 has SQL Injection via the item_details.php id parameter or the vendor_details.php id parameter. | |
| Modificada | Crítica (9.8) | 3.0% | 💥 Exploit | Care Clone Project Care Clone | 13/12/2017 | 17/6/2026 | FS Care Clone 1.0 has SQL Injection via the searchJob.php jobType or jobFrequency parameter. | |
| Modificada | Crítica (9.8) | 3.0% | 💥 Exploit | Fortunescripts Ebay Clone | 13/12/2017 | 17/6/2026 | FS Ebay Clone 1.0 has SQL Injection via the product.php id parameter, or the search.php category_id or sub_category_id parameter. | |
| Modificada | Crítica (9.8) | 3.0% | 💥 Exploit | Amazon Clone Project Amazon Clone | 13/12/2017 | 17/6/2026 | FS Amazon Clone 1.0 has SQL Injection via the PATH_INFO to /VerAyari. | |
| Modificada | Crítica (9.8) | 3.0% | 💥 Exploit | Foodpanda Clone Project Foodpanda Clone | 13/12/2017 | 17/6/2026 | FS Foodpanda Clone 1.0 has SQL Injection via the /food keywords parameter. | |
| Modificada | Crítica (9.8) | 3.0% | 💥 Exploit | Expedia Clone Project Expedia Clone | 13/12/2017 | 17/6/2026 | FS Expedia Clone 1.0 has SQL Injection via the pages.php or content.php id parameter, or the show-flight-result.php fl_orig or fl_dest parameter. | |
| Modificada | Crítica (9.8) | 2.7% | 💥 Exploit | Zomato Clone Script Project Zomato Clone Script | 31/10/2017 | 17/6/2026 | Zomato Clone Script allows SQL Injection via the restaurant-menu.php resid parameter. | |
| Modificada | Alta (8.8) | 8.5% | 💥 Exploit | Claydip Airbnb Clone | 26/9/2017 | 17/6/2026 | Multiple unrestricted file upload vulnerabilities in the (1) imageSubmit and (2) proof_submit functions in Claydip Laravel Airbnb Clone 1.0 allow remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in images/profile. | |
| Modificada | Media (5.5) | 0.79% | — | Partclone Project Partclone | 10/3/2017 | 17/6/2026 | partclone.chkimg in partclone 0.2.89 is prone to a heap-based buffer overflow vulnerability due to insufficient validation of the partclone image header. An attacker may be able to launch a 'Denial of Service attack' in the context of the user running the affected application. | |
| Modificada | Crítica (9.8) | 4.8% | — | Squareup Git-fastclone | 3/11/2016 | 17/6/2026 | git-fastclone before 1.0.5 passes user modifiable strings directly to a shell command. An attacker can execute malicious commands by modifying the strings that are passed as arguments to "cd " and "git clone " commands in the library. | |
| Modificada | Alta (8.8) | 5.2% | — | Squareup Git-fastclone | 3/11/2016 | 17/6/2026 | git-fastclone before 1.0.1 permits arbitrary shell command execution from .gitmodules. If an attacker can instruct a user to run a recursive clone from a repository they control, they can get a client to run an arbitrary shell command. Alternately, if an attacker can MITM an unencrypted git clone, they could exploit… | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Milw0rm Project Milw0rm Clone Script | 18/6/2015 | 17/6/2026 | Multiple SQL injection vulnerabilities in admin/login.php in Milw0rm Clone Script 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) usr or (2) pwd parameter. | |
| Modificada | Media (6.5) | 2.3% | — | Xcloner | 17/6/2015 | 17/6/2026 | Static code injection vulnerability in the XCloner plugin 3.1.2 for WordPress allows remote authenticated users to inject arbitrary PHP code into the language files via a Translation LM_FRONT_* field for a language, as demonstrated by language/italian.php. | |
| Modificada | Baja (3.5) | 1.6% | — | Xcloner | 17/6/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the XCloner plugin 3.1.2 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the excl_manual parameter in the xcloner_show page to wpadmin/plugins.php. | |
| Modificada | Media (6.5) | 2.6% | — | Xcloner | 17/6/2015 | 17/6/2026 | cloner.functions.php in the XCloner plugin 3.1.2 for WordPress allows remote authenticated users to execute arbitrary commands via a file containing filenames with shell metacharacters, as demonstrated by using the backup comments feature to create the file. | |
| Modificada | Baja (2.1) | 0.86% | 💥 Exploit | Xcloner | 10/6/2015 | 17/6/2026 | The XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! provides the MySQL username and password on the command line, which allows local users to obtain sensitive information via the ps command. | |
| Modificada | Media (4) | 6.0% | 💥 Exploit | Xcloner | 10/6/2015 | 17/6/2026 | Directory traversal vulnerability in the XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! allows remote administrators to read arbitrary files via a .. (dot dot) in the file parameter in a json_return action in the xcloner_show page to wp-admin/admin-ajax.php. | |
| Modificada | Media (5) | 6.9% | 💥 Exploit | Xcloner | 10/6/2015 | 17/6/2026 | The XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! stores database backup files with predictable names under the web root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request to a backup file in administrators/backups/. |