Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
224 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 6.9% | 💥 Exploit | Xcloner | 10/6/2015 | 17/6/2026 | The XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! returns the MySQL password in cleartext to a text box in the configuration panel, which allows remote attackers to obtain sensitive information via unspecified vectors. | |
| Modificada | Media (6.5) | 6.2% | 💥 Exploit | Xcloner | 10/6/2015 | 17/6/2026 | cloner.functions.php in the XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! allows remote administrators to execute arbitrary code via shell metacharacters in the (1) file name when creating a backup or vectors related to the (2) $_CONFIG[tarpath], (3) $exclude, (4) $_CONFIG['tarcompress'], (5)… | |
| Modificada | Alta (7.5) | 2.5% | 💥 Exploit | Milw0rm Project Milw0rm Clone Script | 29/5/2015 | 17/6/2026 | SQL injection vulnerability in related.php in Milw0rm Clone Script 1.0 allows remote attackers to execute arbitrary SQL commands via the program parameter. | |
| Modificada | Alta (7.1) | 9.9% | 💥 Exploit | Xcloner | 25/4/2014 | 17/6/2026 | XCloner Standalone 3.5 and earlier, when enable_db_backup and sql_mem are enabled, allows remote authenticated administrators to execute arbitrary commands via shell metacharacters in the dbbackup_comp parameter in a generate action to index2.php. NOTE: it is not clear whether this issue crosses privilege boundaries,… | |
| Modificada | Alta (7.6) | 6.0% | 💥 Exploit | Xcloner | 25/4/2014 | 17/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in XCloner Standalone 3.5 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) change the administrator password via the config task to index2.php or (2) when the enable_db_backup and sql_mem options are… | |
| Modificada | Media (6.8) | 2.8% | 💥 Exploit | Xcloner | 3/4/2014 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in the XCloner plugin before 3.1.1 for WordPress allows remote attackers to hijack the authentication of administrators for requests that create website backups via a request to wp-admin/plugins.php. | |
| Modificada | Media (4.3) | 1.6% | 💥 Exploit | Cloneforest Graphicsclone Script | 9/10/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in search/ in GraphicsClone Script, possibly 1.11, allows remote attackers to inject arbitrary web script or HTML via the term parameter. | |
| Modificada | Media (4.3) | 1.2% | — | Clonemonster Social Book Facebook Clone Monster | 20/9/2012 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Social Book Facebook Clone 2010 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO parameter to (1) signup.php, (2) lostpass.php, (3) login.php, (4) index.php, (5) help_tos.php, (6) help_contact.php, or (7) help.php. | |
| Modificada | Alta (7.5) | 0.91% | 💥 Exploit | Olykit Swoopo Clone 2010 | 2/11/2011 | 16/6/2026 | SQL injection vulnerability in index.php in OlyKit Swoopo Clone 2010 allows remote attackers to execute arbitrary SQL commands via the id parameter in a product action. | |
| Modificada | Alta (7.5) | 0.91% | 💥 Exploit | Alibabaclone Alibaba Clone B2B | 27/9/2011 | 16/6/2026 | SQL injection vulnerability in countrydetails.php in Alibaba Clone B2B 3.4 allows remote attackers to execute arbitrary SQL commands via the es_id parameter. | |
| Modificada | Media (4.3) | 3.4% | 💥 Exploit | Zeeways Ebay Clone Auction Script | 3/6/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in signinform.php in Zeeways eBay Clone Auction Script allows remote attackers to inject arbitrary web script or HTML via the msg parameter. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (4.3) | 1.3% | 💥 Exploit | Turnkeyforms Yahoo-answers-clone | 11/5/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in questiondetail.php in Yahoo Answers Clone allows remote attackers to inject arbitrary web script or HTML via the questionid parameter. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Alibabaclone B2B Gold Script | 6/5/2010 | 16/6/2026 | SQL injection vulnerability in product.html in B2B Gold Script allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Alta (7.5) | 0.99% | 💥 Exploit | Alibabaclone Ec21 Clone | 6/5/2010 | 16/6/2026 | SQL injection vulnerability in offers_buy.php in EC21 Clone 3.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Alta (7.5) | 0.99% | 💥 Exploit | Alibabaclone Alibaba Clone Platinum | 6/5/2010 | 16/6/2026 | SQL injection vulnerability in offers_buy.php in Alibaba Clone Platinum allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Imagoscripts Deviant ART Clone | 23/3/2010 | 16/6/2026 | SQL injection vulnerability in index.php in ImagoScripts Deviant Art Clone allows remote attackers to execute arbitrary SQL commands via the seid parameter in a forums viewcat action. | |
| Modificada | Alta (7.5) | 1.00% | 💥 Exploit | Ebayclonescript Ebay Clone | 16/10/2009 | 16/6/2026 | Multiple SQL injection vulnerabilities in Ebay Clone 2009 allow remote attackers to execute arbitrary SQL commands via the (1) user_id parameter to feedback.php; and the item_id parameter to (2) view_full_size.php, (3) classifide_ad.php, and (4) crosspromoteitems.php. | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Alibabaclone Alibaba Clone | 30/9/2009 | 16/6/2026 | SQL injection vulnerability in offers_buy.php in Alibaba Clone 3.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Media (6.5) | 1.1% | 💥 Exploit | Fmyclone | 23/9/2009 | 16/6/2026 | Multiple SQL injection vulnerabilities in FMyClone 2.3 allow remote attackers to execute arbitrary SQL commands via the comp parameter to (1) index.php and (2) editComments.php, and (3) allow remote authenticated administrators to execute arbitrary SQL commands via the id parameter in a comment action to edit.php. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Revou Micro Blogging Twitter Clone | 25/8/2009 | 16/6/2026 | Multiple SQL injection vulnerabilities in ReVou Micro Blogging Twitter clone allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password fields. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Clone2009 Ebay Clone | 20/8/2009 | 16/6/2026 | Multiple SQL injection vulnerabilities in Ebay Clone 2009 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to product_desc.php, and the cid parameter to (2) showcategory.php and (3) gallery.php. | |
| Modificada | Alta (7.5) | 7.4% | 💥 Exploit | Zeeways Shaadiclone | 7/8/2009 | 16/6/2026 | Zeeways SHAADICLONE 2.0 allows remote attackers to bypass authentication and gain administrative privileges via a direct request to admin/home.php. | |
| Modificada | Media (4.3) | 2.2% | 💥 Exploit | Resalecode Hotscripts Type PHP Clone Script | 24/7/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Hotscripts Type PHP Clone Script allow remote attackers to inject arbitrary web script or HTML via the msg parameter to (1) feedback.php, (2) index.php, and (3) lostpassword.php. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | WEB Development House Alibaba Clone | 13/7/2009 | 16/6/2026 | Multiple SQL injection vulnerabilities in Web Development House Alibaba Clone allow remote attackers to execute arbitrary SQL commands via the (1) IndustryID parameter to category.php and the (2) SellerID parameter to supplier/view_contact_details.php. NOTE: this is a product that was developed by a third party; it is… | |
| Modificada | Media (4.3) | 1.2% | 💥 Exploit | Clone2009 Ebay Clone | 10/7/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in search.php in Ebay Clone 2009 allows remote attackers to inject arbitrary web script or HTML via the mode parameter. |