Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2751▲ 29 respecto a la semana anterior
Críticas / altas1468▲ 334 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
298 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | — | — | Chiranjit Hazarika Smart ONE Click SetupAI | 2/10/2026 | 2/10/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Chiranjit Hazarika Smart One Click Setup – Complete Demo Import & Export smart-one-click-setup allows Retrieve Embedded Sensitive Data.This issue affects Smart One Click Setup – Complete Demo Import & Export: from n/a through 1.4.3. | |
| Aplazada | Media (5.7) | 0.33% | — | Barco Clickshare Cx-20 Gen2AI | 28/9/2026 | 28/9/2026 | A vulnerability was determined in Barco ClickShare CX-20 Gen2 up to 02.26.00.0007. Affected by this issue is some unknown functionality of the file /wallpaper of the component Wallpaper Upload. This manipulation of the argument wallpaper causes improper validation of syntactic correctness of input. The attack can be… | |
| Aplazada | Alta (7.9) | 0.46% | — | ClickhouseAIDepomo ChartbrewAI | 21/9/2026 | 28/9/2026 | Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to 5.2.3, Chartbrew's ClickHouse protocol in server/sources/plugins/clickhouse/clickhouse.protocol.js calls applySqlVariables() from server/sources/shared/sql/sql.variables.js without… | |
| Aplazada | Media (5.3) | 0.33% | — | OpenpanelAIClickhouseAI | 19/9/2026 | 2/10/2026 | OpenPanel through 2.3.0 fails to escape property keys in ClickHouse SQL queries, allowing authenticated users to inject boolean SQL terms. Attackers can supply crafted filter names to bypass project isolation and access metrics from other projects. | |
| Pendiente de análisis | Alta (8.9) | 0.51% | — | OpenmeterAIClickhouseAI | 16/9/2026 | 18/9/2026 | SQL injection in ClickHouse-backed meter definitions in OpenMeter OpenMeter before v1.0.0-beta.228 on all platforms allows a remote unauthenticated attacker to access or modify metering event data, and potentially cause denial of service, via crafted user-controlled JSONPath values submitted to meters API. | |
| Aplazada | Alta (8.7) | 0.58% | — | Bizwell XclickAI | 15/9/2026 | 18/9/2026 | Insufficient session expiration vulnerability in bizwell xClick allows Authentication Bypass. This issue affects xClick: R2, R3, and R3.1. | |
| Aplazada | Media (5.1) | 0.38% | — | Bizwell XclickAI | 15/9/2026 | 18/9/2026 | Improper input validation vulnerability in bizwell xClick allows Stored XSS. This issue affects xClick: R2, R3, and R3.1. | |
| Pendiente de análisis | Alta (8.6) | 0.82% | — | Rarathemes Rara ONE Click Demo ImportAI | 9/9/2026 | 10/9/2026 | Rara One Click Demo Import plugin for WordPress before 1.3.5 contains an arbitrary file upload vulnerability that allows authenticated attackers with Administrator privileges to upload arbitrary PHP files by passing a false value to wp_handle_upload() that disables WordPress core's file type validation checks across… | |
| Aplazada | Alta (8.6) | 0.19% | — | Siemens Desigo CC Clickonce ClientAISiemens Desigo CC Flex ClientAISiemens Desigo CC Installed ClientAISiemens Desigo CCAI | 8/9/2026 | 14/9/2026 | A vulnerability has been identified in Desigo CC ClickOnce Client V6 (All versions), Desigo CC ClickOnce Client V7 (All versions), Desigo CC family V8 (All versions), Desigo CC family V9 (All versions), Desigo CC Flex Client V6 (All versions), Desigo CC Flex Client V7 (All versions), Desigo CC Installed Client V6 (All… | |
| Aplazada | Media (6.4) | 0.20% | — | Social Chat Click TO Chat APP ButtonAI | 5/9/2026 | 8/9/2026 | The Social Chat – Click To Chat App Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'consent_message' JSON Attribute in .qlwapp data-box in all versions up to, and including, 8.6.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| Pendiente de análisis | Media (6.1) | 0.05% | — | ClickhouseAI | 27/8/2026 | 31/8/2026 | When the ClickHouse plugin uses Native protocol (the default) with PDC or secure SOCKS, it asks for TLS but the connection library ignores that and talks to ClickHouse in the clear. Username, password, queries, and results can be read on the hop after the proxy. The server certificate is never checked, and a… | |
| Rechazada | Sin puntuar | — | — | ClickhouseAIPostgresqlAI | 29/7/2026 | 6/8/2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. ClickHouse's PostgreSQL integration intentionally allows users with valid PostgreSQL credentials to execute queries against a remote PostgreSQL server. No vulnerability in ClickHouse is exploited; code execution occurs on the… | |
| Aplazada | Crítica (9.8) | 0.82% | — | HypequeryAIClickhouseAI | 28/7/2026 | 4/8/2026 | Hypequery is a TypeScript semantic layer for ClickHouse. Prior to 2.5.1, escapeValue() in packages/clickhouse/src/core/utils.ts did not escape backslashes before single quotes during parameter substitution, allowing attacker controlled query parameters with a trailing backslash to escape the closing quote and inject… | |
| Aplazada | Media (6.5) | 0.33% | — | Acnam AD Invalid Click ProtectorAI | 27/7/2026 | 28/7/2026 | Unauthenticated Broken Access Control in Ad Invalid Click Protector (AICP) <= 1.3.0 versions. | |
| Aplazada | Alta (7.1) | 0.40% | — | AptabaseAIClickhouseAI | 21/7/2026 | 23/7/2026 | Aptabase through commit 5a89368 contains a SQL injection vulnerability in the ClickHouse query backend that allows authenticated attackers to read event data across all tenants by injecting unsanitized filter parameters into Liquid SQL templates. Attackers can supply malicious values through EventName, CountryCode,… | |
| Aplazada | Baja (3.3) | 0.31% | — | Docker ComposeAIRedisAIKeydbAIDragonflyAI+4 | 7/7/2026 | 7/7/2026 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, database credential fields (redis_password, keydb_password, dragonfly_password, clickhouse_admin_user, clickhouse_admin_password, postgres_user, mysql_user) are validated only as 'string' at the… | |
| Aplazada | Media (6.4) | 0.49% | — | Click TO Chat WA WidgetAI | 6/6/2026 | 23/7/2026 | The Click to Chat – WA Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the [chat] shortcode 'num' parameter in all versions up to, and including, 4.38. This is due to insufficient escaping when embedding user-supplied shortcode attribute values inside JavaScript string literals that are… | |
| Aplazada | Alta (8.7) | 0.32% | — | AgnoAIClickhouseAI | 29/5/2026 | 21/7/2026 | agno 2.6.5 contains a SQL injection vulnerability in the ClickHouse vector database backend that allows attackers to inject arbitrary SQL expressions by supplying malicious metadata keys and values to the delete_by_metadata() method. Attackers can exploit the unsafe f-string interpolation in clickhousedb.py to delete… | |
| Aplazada | Media (6.1) | 0.38% | — | Zingaya Click TO CallAI | 5/5/2026 | 17/6/2026 | The Zingaya Click-to-Call plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'email', 'first_name', 'last_name', and 'phone' parameters on the plugin's sign-up admin page in all versions up to, and including, 1.0. This is due to insufficient input sanitization and output escaping. This makes… | |
| Modificada | Alta (7.2) | 0.92% | — | Palletsprojects Click | 30/4/2026 | 18/8/2026 | This CVE record was assigned not following CNA/CVE rules and is not considered a valid vulnerability by the Pallets Click project. The original CVE record description is preserved below: Pallets Click, versions 8.3.2 and below, contain a command injection vulnerability in the click.edit() function, allowing attackers… | |
| Aplazada | Media (5.1) | 0.44% | — | ClickeduAI | 27/3/2026 | 17/6/2026 | A reflected Cross-Site Scripting (XSS) vulnerability has been discovered in Clickedu. This vulnerability allows an attacker to execute JavaScript code in the victim’s browser by sending them a malicious URL using the endpoint “/user.php/”. This vulnerability can be exploited to steal sensitive user data, such as… | |
| Analizada | Alta (8.8) | 0.42% | — | Nextclickventures Realtyscript | 16/3/2026 | 17/6/2026 | Next Click Ventures RealtyScript 4.0.2 contains SQL injection vulnerabilities that allow unauthenticated attackers to manipulate database queries by injecting arbitrary SQL code through the GET parameter 'u_id' in /admin/users.php and the POST parameter 'agent[]' in /admin/mailer.php. Attackers can exploit time-based… | |
| Analizada | Alta (8.8) | 0.42% | — | Nextclickventures Realtyscript | 16/3/2026 | 17/6/2026 | Next Click Ventures RealtyScript 4.0.2 contains multiple time-based blind SQL injection vulnerabilities that allow unauthenticated attackers to extract database information by injecting SQL code into application parameters. Attackers can craft requests with time-delay payloads to infer database contents character by… | |
| Analizada | Media (5.1) | 0.21% | — | Nextclickventures Realtyscript | 16/3/2026 | 17/6/2026 | Next Click Ventures RealtyScript 4.0.2 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious HTML and iframe elements through the text parameter in the pages.php admin interface. Attackers can submit POST requests to the add page action with crafted iframe… | |
| Analizada | Media (5.1) | 0.32% | — | Nextclickventures Realtyscript | 16/3/2026 | 17/6/2026 | Next Click Ventures RealtyScript 4.0.2 contains a stored cross-site scripting vulnerability in the location_name parameter of the admin locations interface. Attackers can submit POST requests to the locations.php endpoint with JavaScript payloads in the location_name field to execute arbitrary code in administrator… |