Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

224 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.1%💥 ExploitEbayclonescript Ebay Clone10/7/200916/6/2026
SQL injection vulnerability in category.php in Ebay Clone 2009 allows remote attackers to execute arbitrary SQL commands via the cate_id parameter in a list action.
ModificadaMedia (5)2.1%💥 Exploit2daybiz Template Monster Clone22/5/200916/6/2026
admin/edituser.php in 2daybiz Template Monster Clone does not require administrative authentication, which allows remote attackers to modify arbitrary accounts via the (1) loginname, (2) password, (3) email, (4) firstname, or (5) lastname parameter.
ModificadaMedia (6.8)3.6%💥 ExploitRevou Tclone24/4/200916/6/2026
Unrestricted file upload vulnerability in index.php in the Twitter Clone (TClone) plugin for ReVou Micro Blogging allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in settings/my_photo.
ModificadaMedia (4.9)0.73%💥 ExploitSlysoft AnydvdSlysoft ClonecdSlysoft ClonedvdSlysoft Virtualclonedrive14/3/200916/6/2026
Elaborate Bytes ElbyCDIO.sys 6.0.2.0 and earlier, as distributed in SlySoft AnyDVD before 6.5.2.6, Virtual CloneDrive 5.4.2.3 and earlier, CloneDVD 2.9.2.0 and earlier, and CloneCD 5.3.1.3 and earlier, uses the METHOD_NEITHER communication method for IOCTLs and does not properly validate a buffer associated with the…
ModificadaAlta (7.5)0.97%💥 ExploitGreatclone Hotscripts Clone6/3/200916/6/2026
SQL injection vulnerability in showcategory.php in Hotscripts Clone allows remote attackers to execute arbitrary SQL commands via the cid parameter.
ModificadaAlta (7.5)2.6%💥 ExploitBux.to Clone Script20/2/200916/6/2026
Bux.to Clone script allows remote attackers to bypass authentication and gain administrative access by setting the loggedin cookie to 1 and the usNick cookie to admin.
ModificadaMedia (4.3)1.4%💥 ExploitI-netsolution Orkut Clone27/1/200916/6/2026
Cross-site scripting (XSS) vulnerability in profile_social.php in i-Net Solution Orkut Clone allows remote authenticated users to inject arbitrary web script or HTML via the id parameter.
ModificadaMedia (6.5)0.85%💥 ExploitI-netsolution Orkut Clone27/1/200916/6/2026
SQL injection vulnerability in profile_social.php in i-Net Solution Orkut Clone allows remote authenticated users to execute arbitrary SQL commands via the id parameter.
ModificadaMedia (6)0.85%—Drupal Node Clone21/10/200816/6/2026
SQL injection vulnerability in Node Vote 5.x before 5.x-1.1 and 6.x before 6.x-1.0, a module for Drupal, when "Allow user to vote again" is enabled, allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors related to a "previously cast vote."
ModificadaAlta (7.5)1.0%💥 ExploitGreatclone Youtuber Clone31/7/200816/6/2026
SQL injection vulnerability in ugroups.php in Youtuber Clone allows remote attackers to execute arbitrary SQL commands via the UID parameter.
ModificadaAlta (7.5)1.2%💥 ExploitGreatclone Auction Platinum31/7/200816/6/2026
SQL injection vulnerability in category.php in Greatclone GC Auction Platinum allows remote attackers to execute arbitrary SQL commands via the cate_id parameter.
ModificadaAlta (7.5)1.00%💥 ExploitGreatclone Getacoder Clone30/7/200816/6/2026
SQL injection vulnerability in search_form.php in Getacoder Clone allows remote attackers to execute arbitrary SQL commands via the sb_protype parameter.
ModificadaAlta (7.5)1.1%💥 ExploitBuyscripts Vshare Youtube Clone14/5/200816/6/2026
SQL injection vulnerability in group_posts.php in vShare YouTube Clone 2.6 allows remote attackers to execute arbitrary SQL commands via the tid parameter.
ModificadaAlta (7.5)1.4%—Youtube Clone Script12/2/200816/6/2026
Cross-site scripting (XSS) vulnerability in siteadmin/editor_files/includes/load_message.php in the Youtube Clone Script allows remote attackers to inject arbitrary web script or HTML via the lang[please_wait] parameter.
ModificadaMedia (5)2.9%💥 ExploitHotscripts HOT OR NOT Clone31/12/200716/6/2026
Hot or Not Clone has insufficient access control for producing and reading database backups, which allows remote attackers to obtain the administrator username and password via a direct request to control/backup/backup.php, which generates a backup/dump/backup.sql file that can be downloaded via a direct request to…
ModificadaAlta (7.5)1.0%💥 ExploitHotscripts Clone Script22/11/200716/6/2026
SQL injection vulnerability in software-description.php in HotScripts Clone Script allows remote attackers to execute arbitrary SQL commands via the id parameter.
ModificadaAlta (9.3)1.8%—Generic Youtube Clone Script15/7/200716/6/2026
Cross-site request forgery (CSRF) vulnerability in the Email-Template module in Generic YouTube Clone Script allows remote attackers to upload files with arbitrary file types to templates/emails/ as administrators.
ModificadaAlta (7.5)1.7%—Freedomain.co.nr Clone5/7/200716/6/2026
SQL injection vulnerability in includes/functions in FreeDomain.co.nr Clone allows remote attackers to execute arbitrary SQL commands via the logindomain parameter to members.php.
ModificadaAlta (7.5)1.2%💥 ExploitHispah Youtube Clone Script3/7/200716/6/2026
SQL injection vulnerability in msg.php in HispaH YouTube Clone Script (youtubeclone) allows remote attackers to execute arbitrary SQL commands via the id parameter.
ModificadaAlta (7.5)3.1%💥 ExploitBbclone26/1/200716/6/2026
PHP remote file inclusion vulnerability in lib/selectlang.php in BBClone 0.31 allows remote attackers to execute arbitrary PHP code via a URL in the BBC_LANGUAGE_PATH parameter.
ModificadaMedia (5)9.2%💥 ExploitBomberclone7/8/200616/6/2026
The do_gameinfo function in BomberClone 0.11.6 and earlier, and possibly other functions, does not reset the packet data size, which causes the send_pkg function (packets.c) to use this data size when sending a reply, and allows remote attackers to read portions of server memory.
ModificadaMedia (5)3.7%—Bomberclone7/8/200616/6/2026
BomberClone 0.11.6 and earlier allows remote attackers to cause a denial of service (daemon crash) via (1) a certain malformed PKGF_ackreq packet, which triggers a crash in the rscache_add() function in pkgcache.c; and (2) an error packet, which is intended to be received by clients and force client shutdown, but also…
ModificadaAlta (7.5)68%💥 ExploitBomberclone17/2/200616/6/2026
Multiple buffer overflows in BomberClone before 0.11.6.2 allow remote attackers to execute arbitrary code via long error messages.
ModificadaBaja (3.6)0.37%—Fdclone27/8/200316/6/2026
FDclone 2.00a, and other versions before 2.02a, creates temporary directories with predictable names and uses them if they already exist, which allows local users to read or modify files of other fdclone users by creating the directory ahead of time.
Orbitaley — Vulnerabilidades