Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
224 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Ebayclonescript Ebay Clone | 10/7/2009 | 16/6/2026 | SQL injection vulnerability in category.php in Ebay Clone 2009 allows remote attackers to execute arbitrary SQL commands via the cate_id parameter in a list action. | |
| Modificada | Media (5) | 2.1% | 💥 Exploit | 2daybiz Template Monster Clone | 22/5/2009 | 16/6/2026 | admin/edituser.php in 2daybiz Template Monster Clone does not require administrative authentication, which allows remote attackers to modify arbitrary accounts via the (1) loginname, (2) password, (3) email, (4) firstname, or (5) lastname parameter. | |
| Modificada | Media (6.8) | 3.6% | 💥 Exploit | Revou Tclone | 24/4/2009 | 16/6/2026 | Unrestricted file upload vulnerability in index.php in the Twitter Clone (TClone) plugin for ReVou Micro Blogging allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in settings/my_photo. | |
| Modificada | Media (4.9) | 0.73% | 💥 Exploit | Slysoft AnydvdSlysoft ClonecdSlysoft ClonedvdSlysoft Virtualclonedrive | 14/3/2009 | 16/6/2026 | Elaborate Bytes ElbyCDIO.sys 6.0.2.0 and earlier, as distributed in SlySoft AnyDVD before 6.5.2.6, Virtual CloneDrive 5.4.2.3 and earlier, CloneDVD 2.9.2.0 and earlier, and CloneCD 5.3.1.3 and earlier, uses the METHOD_NEITHER communication method for IOCTLs and does not properly validate a buffer associated with the… | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Greatclone Hotscripts Clone | 6/3/2009 | 16/6/2026 | SQL injection vulnerability in showcategory.php in Hotscripts Clone allows remote attackers to execute arbitrary SQL commands via the cid parameter. | |
| Modificada | Alta (7.5) | 2.6% | 💥 Exploit | Bux.to Clone Script | 20/2/2009 | 16/6/2026 | Bux.to Clone script allows remote attackers to bypass authentication and gain administrative access by setting the loggedin cookie to 1 and the usNick cookie to admin. | |
| Modificada | Media (4.3) | 1.4% | 💥 Exploit | I-netsolution Orkut Clone | 27/1/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in profile_social.php in i-Net Solution Orkut Clone allows remote authenticated users to inject arbitrary web script or HTML via the id parameter. | |
| Modificada | Media (6.5) | 0.85% | 💥 Exploit | I-netsolution Orkut Clone | 27/1/2009 | 16/6/2026 | SQL injection vulnerability in profile_social.php in i-Net Solution Orkut Clone allows remote authenticated users to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Media (6) | 0.85% | — | Drupal Node Clone | 21/10/2008 | 16/6/2026 | SQL injection vulnerability in Node Vote 5.x before 5.x-1.1 and 6.x before 6.x-1.0, a module for Drupal, when "Allow user to vote again" is enabled, allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors related to a "previously cast vote." | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Greatclone Youtuber Clone | 31/7/2008 | 16/6/2026 | SQL injection vulnerability in ugroups.php in Youtuber Clone allows remote attackers to execute arbitrary SQL commands via the UID parameter. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Greatclone Auction Platinum | 31/7/2008 | 16/6/2026 | SQL injection vulnerability in category.php in Greatclone GC Auction Platinum allows remote attackers to execute arbitrary SQL commands via the cate_id parameter. | |
| Modificada | Alta (7.5) | 1.00% | 💥 Exploit | Greatclone Getacoder Clone | 30/7/2008 | 16/6/2026 | SQL injection vulnerability in search_form.php in Getacoder Clone allows remote attackers to execute arbitrary SQL commands via the sb_protype parameter. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Buyscripts Vshare Youtube Clone | 14/5/2008 | 16/6/2026 | SQL injection vulnerability in group_posts.php in vShare YouTube Clone 2.6 allows remote attackers to execute arbitrary SQL commands via the tid parameter. | |
| Modificada | Alta (7.5) | 1.4% | — | Youtube Clone Script | 12/2/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in siteadmin/editor_files/includes/load_message.php in the Youtube Clone Script allows remote attackers to inject arbitrary web script or HTML via the lang[please_wait] parameter. | |
| Modificada | Media (5) | 2.9% | 💥 Exploit | Hotscripts HOT OR NOT Clone | 31/12/2007 | 16/6/2026 | Hot or Not Clone has insufficient access control for producing and reading database backups, which allows remote attackers to obtain the administrator username and password via a direct request to control/backup/backup.php, which generates a backup/dump/backup.sql file that can be downloaded via a direct request to… | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Hotscripts Clone Script | 22/11/2007 | 16/6/2026 | SQL injection vulnerability in software-description.php in HotScripts Clone Script allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Alta (9.3) | 1.8% | — | Generic Youtube Clone Script | 15/7/2007 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in the Email-Template module in Generic YouTube Clone Script allows remote attackers to upload files with arbitrary file types to templates/emails/ as administrators. | |
| Modificada | Alta (7.5) | 1.7% | — | Freedomain.co.nr Clone | 5/7/2007 | 16/6/2026 | SQL injection vulnerability in includes/functions in FreeDomain.co.nr Clone allows remote attackers to execute arbitrary SQL commands via the logindomain parameter to members.php. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Hispah Youtube Clone Script | 3/7/2007 | 16/6/2026 | SQL injection vulnerability in msg.php in HispaH YouTube Clone Script (youtubeclone) allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Alta (7.5) | 3.1% | 💥 Exploit | Bbclone | 26/1/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in lib/selectlang.php in BBClone 0.31 allows remote attackers to execute arbitrary PHP code via a URL in the BBC_LANGUAGE_PATH parameter. | |
| Modificada | Media (5) | 9.2% | 💥 Exploit | Bomberclone | 7/8/2006 | 16/6/2026 | The do_gameinfo function in BomberClone 0.11.6 and earlier, and possibly other functions, does not reset the packet data size, which causes the send_pkg function (packets.c) to use this data size when sending a reply, and allows remote attackers to read portions of server memory. | |
| Modificada | Media (5) | 3.7% | — | Bomberclone | 7/8/2006 | 16/6/2026 | BomberClone 0.11.6 and earlier allows remote attackers to cause a denial of service (daemon crash) via (1) a certain malformed PKGF_ackreq packet, which triggers a crash in the rscache_add() function in pkgcache.c; and (2) an error packet, which is intended to be received by clients and force client shutdown, but also… | |
| Modificada | Alta (7.5) | 68% | 💥 Exploit | Bomberclone | 17/2/2006 | 16/6/2026 | Multiple buffer overflows in BomberClone before 0.11.6.2 allow remote attackers to execute arbitrary code via long error messages. | |
| Modificada | Baja (3.6) | 0.37% | — | Fdclone | 27/8/2003 | 16/6/2026 | FDclone 2.00a, and other versions before 2.02a, creates temporary directories with predictable names and uses them if they already exist, which allows local users to read or modify files of other fdclone users by creating the directory ahead of time. |