Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2778▼ 418 respecto a la semana anterior
Críticas / altas1332▼ 108 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
298 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.86% | — | Backclick | 16/11/2022 | 17/6/2026 | An issue was discovered in BACKCLICK Professional 5.9.63. Due to an unsafe implementation of session tracking, it is possible for an attacker to trick users into opening an authenticated user session for a session identifier known to the attacker, aka Session Fixation. | |
| Modificada | Crítica (9.8) | 1.0% | — | Backclick | 16/11/2022 | 17/6/2026 | An issue was discovered in BACKCLICK Professional 5.9.63. Due to exposed CORBA management services, arbitrary system commands can be executed on the server. | |
| Modificada | Alta (8.8) | 0.68% | — | Summitmediaconcepts Ucontext FOR Clickbank | 6/9/2022 | 17/6/2026 | The uContext for Clickbank plugin for WordPress is vulnerable to Cross-Site Request Forgery to Cross-Site Scripting in versions up to, and including 3.9.1. This is due to missing nonce validation in the ~/app/sites/ajax/actions/keyword_save.php file that is called via the doAjax() function. This makes it possible for… | |
| Modificada | Alta (8.8) | 0.98% | — | Wp-kama Kama Click Counter | 27/6/2022 | 17/6/2026 | A vulnerability classified as critical has been found in Kama Click Counter Plugin up to 3.4.8. This affects an unknown part of the file wp-admin/admin.php. The manipulation of the argument order_by/order with the input ASC%2c(select*from(select(sleep(2)))a) leads to sql injection (Blind). It is possible to initiate… | |
| Modificada | Alta (8.1) | 0.52% | — | ONE Click Plugin Updater Project ONE Click Plugin Updater | 13/6/2022 | 17/6/2026 | The One Click Plugin Updater WordPress plugin through 2.4.14 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and disable / hide the badge of the available updates and the related check. | |
| Modificada | Alta (8.8) | 0.41% | — | Disable Right Click FOR WP Wordpress Disable Right Click FOR WP | 20/5/2022 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Aftab Muni's Disable Right Click For WP plugin <= 1.1.6 at WordPress. | |
| Modificada | Media (6.5) | 0.58% | — | Acnam AD Invalid Click Protector | 2/5/2022 | 17/6/2026 | The Ad Invalid Click Protector (AICP) WordPress plugin before 1.2.7 does not have CSRF check deleting banned users, which could allow attackers to make a logged in admin remove arbitrary bans | |
| Modificada | Alta (8.8) | 0.58% | — | Rarathemes Rara ONE Click Demo Import | 29/4/2022 | 17/6/2026 | Cross-Site Request Forgery (CSRF) leading to Arbitrary File Upload vulnerability in Rara One Click Demo Import plugin <= 1.2.9 on WordPress allows attackers to trick logged-in admin users into uploading dangerous files into /wp-content/uploads/ directory. | |
| Modificada | Alta (7.2) | 1.7% | — | Ocdi ONE Click Demo Import | 11/4/2022 | 17/6/2026 | The One Click Demo Import WordPress plugin before 3.1.0 does not validate the imported file, allowing high privilege users such as admin to upload arbitrary files (such as PHP) even when FILE_MODS and FILE_EDIT are disallowed | |
| Modificada | Media (6.5) | 0.82% | — | Clickstudios Passwordstate | 21/3/2022 | 17/6/2026 | In Click Studios (SA) Pty Ltd Passwordstate 9435, users with access to a passwordlist can gain access to additional password lists without permissions. Specifically, an authenticated user who has write permissions to a password list in one folder (with the default permission model) can extend his permissions to all… | |
| Modificada | Alta (8.8) | 1.7% | — | ClickhouseDebian Linux | 14/3/2022 | 17/6/2026 | Heap buffer overflow in Clickhouse's LZ4 compression codec when parsing a malicious query. There is no verification that the copy operations in the LZ4::decompressImpl loop and especially the arbitrary copy operation wildCopy<copy_amount>(op, ip, copy_end), don’t exceed the destination buffer’s limits. This issue is… | |
| Modificada | Alta (8.8) | 1.7% | — | ClickhouseDebian Linux | 14/3/2022 | 17/6/2026 | Heap buffer overflow in Clickhouse's LZ4 compression codec when parsing a malicious query. There is no verification that the copy operations in the LZ4::decompressImpl loop and especially the arbitrary copy operation wildCopy<copy_amount>(op, ip, copy_end), don’t exceed the destination buffer’s limits. | |
| Modificada | Media (6.5) | 1.4% | — | Clickhouse | 14/3/2022 | 17/6/2026 | Divide-by-zero in Clickhouse's Gorilla compression codec when parsing a malicious query. The first byte of the compressed buffer is used in a modulo operation without being checked for 0. | |
| Modificada | Media (6.5) | 1.3% | — | Clickhouse | 14/3/2022 | 17/6/2026 | Divide-by-zero in Clickhouse's DeltaDouble compression codec when parsing a malicious query. The first byte of the compressed buffer is used in a modulo operation without being checked for 0. | |
| Modificada | Media (6.5) | 1.3% | — | Clickhouse | 14/3/2022 | 17/6/2026 | Divide-by-zero in Clickhouse's Delta compression codec when parsing a malicious query. The first byte of the compressed buffer is used in a modulo operation without being checked for 0. | |
| Modificada | Alta (8.1) | 1.6% | — | ClickhouseDebian Linux | 14/3/2022 | 17/6/2026 | Heap out-of-bounds read in Clickhouse's LZ4 compression codec when parsing a malicious query. As part of the LZ4::decompressImpl() loop, a 16-bit unsigned user-supplied value ('offset') is read from the compressed data. The offset is later used in the length of a copy operation, without checking the lower bounds of… | |
| Modificada | Alta (8.1) | 1.6% | — | ClickhouseDebian Linux | 14/3/2022 | 17/6/2026 | Heap out-of-bounds read in Clickhouse's LZ4 compression codec when parsing a malicious query. As part of the LZ4::decompressImpl() loop, a 16-bit unsigned user-supplied value ('offset') is read from the compressed data. The offset is later used in the length of a copy operation, without checking the upper bounds of… | |
| Modificada | Alta (8.8) | 0.42% | — | Wp-buy WP Content Copy Protection & NO Right Click | 21/2/2022 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability leading to plugin Settings Update discovered in WP Content Copy Protection & No Right Click WordPress plugin (versions <= 3.4.4). | |
| Modificada | Alta (8.8) | 1.3% | — | Acnam AD Invalid Click Protector | 14/2/2022 | 17/6/2026 | The Ad Invalid Click Protector (AICP) WordPress plugin before 1.2.6 is affected by a SQL Injection in the id parameter of the delete action. | |
| Modificada | Media (4.8) | 0.70% | — | Cbads Clickbank Affiliate ADS | 2/12/2021 | 17/6/2026 | The ClickBank Affiliate Ads WordPress plugin through 1.20 does not escape its settings, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed. | |
| Modificada | Crítica (9.6) | 0.98% | — | Cbads Clickbank Affiliate ADS | 2/12/2021 | 17/6/2026 | The ClickBank Affiliate Ads WordPress plugin through 1.20 does not have CSRF check when saving its settings, allowing attacker to make logged in admin change them via a CSRF attack. Furthermore, due to the lack of escaping when they are outputting, it could also lead to Stored Cross-Site Scripting issues | |
| Modificada | Media (5.4) | 0.66% | — | Connekthq Instant Images - ONE Click Unsplash Uploads | 1/6/2021 | 17/6/2026 | The Instant Images – One Click Unsplash Uploads WordPress plugin before 4.4.0.1 did not properly validate and sanitise its unsplash_download_w and unsplash_download_h parameter settings (/wp-admin/upload.php?page=instant-images), only validating them client side before saving them, leading to a Stored Cross-Site… | |
| Modificada | Alta (8.8) | 1.3% | — | Wp-buy WP Content Copy Protection & NO Right Click | 14/5/2021 | 17/6/2026 | Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the WP Content Copy Protection & No Right Click WordPress plugin before 3.1.5, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which helps… | |
| Modificada | Media (5.4) | 0.53% | — | Media2click Project Media2click | 28/4/2021 | 17/6/2026 | The media2click (aka 2 Clicks for External Media) extension 1.x before 1.3.3 for TYPO3 allows XSS by a backend user account. | |
| Modificada | Media (6.1) | 0.76% | — | Click-ranker Click Ranker | 7/4/2021 | 17/6/2026 | Cross-site scripting vulnerability in Click Ranker Ver.3.5 allows remote attackers to inject an arbitrary script via unspecified vectors. |