Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3029▼ 65 respecto a la semana anterior
Críticas / altas1425▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
27 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.2) | 0.29% | — | ABB Freelance Controller DCPAIABB Freelance Controller Ac700AIABB Freelance Controller Ac800AIABB Freelance Controller Ac900AI | 18/9/2026 | 18/9/2026 | Improper handling of length parameter inconsistency vulnerability in ABB Freelance Controller DCP, ABB Freelance Controller AC700, ABB Freelance Controller AC800, and ABB Freelance Controller AC900. This issue affects Freelance Controller DCP: through 2013, 2013 SP1, 2016, 2016 SP1, 2019, and 2019 SP1; Freelance… | |
| Aplazada | Media (5.6) | 0.12% | — | ABB FreelanceAI | 11/6/2026 | 30/9/2026 | Authentication bypass by primary weakness vulnerability in ABB Freelance. This issue affects Freelance: through 2013, 2013 SP1, 2016, 2016 SP1, 2019, 2019 SP1, 2019 SP1 FP1, 2024. | |
| Analizada | Media (5) | 0.22% | — | Freelance-it-consultant EU Cookie Compliance | 13/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal EU Cookie Compliance (GDPR Compliance) allows Cross-Site Scripting (XSS).This issue affects EU Cookie Compliance (GDPR Compliance): from 0.0.0 before 1.26.0. | |
| Aplazada | Alta (7.1) | 0.27% | — | Upeksha Wisidagama UW FreelancerAI | 9/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Upeksha Wisidagama UW Freelancer uw-freelancer allows Reflected XSS.This issue affects UW Freelancer: from n/a through <= 0.1. | |
| Analizada | Alta (7.2) | 1.4% | — | Freelancer-coder Wordpress Simple Html Sitemap | 25/9/2024 | 17/6/2026 | The WordPress Simple HTML Sitemap plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and including, 3.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated… | |
| Modificada | Media (6.1) | 0.41% | — | Freelancer-coder Wordpress Simple Html Sitemap | 8/11/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Ashish Ajani WordPress Simple HTML Sitemap plugin <= 2.1 versions. | |
| Modificada | Media (5.4) | 0.31% | — | Freelancer-coder Wordpress Simple Html Sitemap | 18/10/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Ashish Ajani WordPress Simple HTML Sitemap plugin <= 2.1 versions. | |
| Modificada | Alta (7.5) | 0.48% | — | ABB Ac700f FirmwareABB Freelance 2013ABB Freelance 2016ABB Freelance 2019 | 7/8/2023 | 17/6/2026 | ABB is aware of vulnerabilities in the product versions listed below. An update is available that resolves the reported vulnerabilities in the product versions under maintenance. An attacker who successfully exploited one or more of these vulnerabilities could cause the product to stop or make the product… | |
| Modificada | Alta (7.5) | 0.47% | — | ABB Ac700f FirmwareABB Freelance 2013ABB Freelance 2016ABB Freelance 2019 | 7/8/2023 | 17/6/2026 | ABB is aware of vulnerabilities in the product versions listed below. An update is available that resolves the reported vulnerabilities in the product versions under maintenance. An attacker who successfully exploited one or more of these vulnerabilities could cause the product to stop or make the product… | |
| Modificada | Crítica (9.8) | 0.89% | — | Itechscripts Freelancer Script | 16/7/2022 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in Itech Freelancer Script 5.13. Affected by this issue is some unknown functionality of the file /category.php. The manipulation of the argument sk leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the… | |
| Modificada | Alta (7.2) | 6.5% | — | Freelancetoindia Paytm-pay | 23/8/2021 | 17/6/2026 | The Paytm – Donation Plugin WordPress plugin through 1.3.2 does not sanitise, validate or escape the id GET parameter before using it in a SQL statement when deleting donations, leading to an authenticated SQL injection issue | |
| Modificada | Crítica (9.8) | 3.6% | — | Ambittechnologies Itech B2B ScriptAmbittechnologies Itech Business Networking ScriptAmbittechnologies Itech Caregiver ScriptAmbittechnologies Itech Classifieds Script+8 | 9/5/2019 | 17/6/2026 | Certain Ambit Technologies Pvt. Ltd products are affected by: SQL Injection. This affects iTech B2B Script 4.42i and Tech Business Networking Script 8.26i and Tech Caregiver Script 2.71i and Tech Classifieds Script 7.41i and Tech Dating Script 3.40i and Tech Freelancer Script 5.27i and Tech Image Sharing Script 4.13i… | |
| Modificada | Media (5.4) | 0.66% | — | Freelancewebdesignerchennai JOB Portal | 18/7/2018 | 17/6/2026 | PHP Scripts Mall JOB SITE (aka Job Portal) 3.0.1 has Cross-site Scripting (XSS) via the search bar. | |
| Modificada | Crítica (9.8) | 3.0% | — | Freelance Website Script Project Freelance Website Script | 13/12/2017 | 17/6/2026 | Freelance Website Script 2.0.6 has SQL Injection via the jobdetails.php pr_id parameter or the searchbycat_list.php catid parameter. | |
| Modificada | Crítica (9.8) | 3.0% | — | Freelancer Clone Project Freelancer Clone | 13/12/2017 | 17/6/2026 | FS Freelancer Clone 1.0 has SQL Injection via the profile.php u parameter. | |
| Modificada | Baja (2.1) | 0.94% | — | Freelance-it-consultant EU Cookie Compliance | 29/4/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the EU Cookie Compliance module 7.x-1.x before 7.x-1.12 for Drupal allows remote authenticated administrators with the "Administer EU Cookie Compliance popup" permission to inject arbitrary web script or HTML via unspecified configuration values. | |
| Modificada | Alta (7.5) | 1.1% | — | Vastal Freelance Zone | 31/1/2013 | 16/6/2026 | SQL injection vulnerability in show_code.php in Vastal I-Tech Freelance Zone allows remote attackers to execute arbitrary SQL commands via the code_id parameter. | |
| Modificada | Alta (7.5) | 2.0% | — | John GEO Freelancer Calendar | 23/8/2012 | 16/6/2026 | Multiple SQL injection vulnerabilities in Freelancer calendar 1.01 and earlier allow remote attackers to inject arbitrary web script or HTML via the SearchField parameter in a search action to (1) category_list.php, (2) Copy_of_calendar_list.php, (3) customer_statistics_list.php, (4) customer_list.php, and (5)… | |
| Modificada | Media (4.3) | 1.1% | — | Freelancerkit | 21/2/2012 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in freelancerKit 2.35 allow remote attackers to inject arbitrary web script or HTML via the (1) ticket parameter to tickets.php, (2) title parameter to notes.php, or (3) task parameter to todo.php. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (7.5) | 1.1% | — | Freelancerkit | 21/2/2012 | 16/6/2026 | Multiple SQL injection vulnerabilities in freelancerKit 2.35 allow remote attackers to execute arbitrary SQL commands via unspecified vectors to the (1) notes and (2) tickets components. | |
| Modificada | Media (4.3) | 1.5% | — | Freewebscriptz Freelancers | 8/10/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Freelancers 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to placebid.php and (2) jobid parameter to post_resume.php. | |
| Modificada | Alta (7.5) | 1.0% | — | Vastal I-tech Freelance Zone | 7/10/2008 | 16/6/2026 | SQL injection vulnerability in view_cresume.php in Vastal I-Tech Freelance Zone allows remote attackers to execute arbitrary SQL commands via the coder_id parameter. | |
| Modificada | Media (5) | 2.3% | — | Freelance Auction Script | 16/5/2008 | 16/6/2026 | Freelance Auction Script 1.0 stores user passwords in plaintext in the tbl_users table, which allows attackers to gain privileges by reading the table. | |
| Modificada | Alta (7.5) | 1.0% | — | Freelanceauction Freelance Auction Script | 16/5/2008 | 16/6/2026 | SQL injection vulnerability in browseproject.php in Freelance Auction Script 1.0 allows remote attackers to execute arbitrary SQL commands via the pid parameter in a pdetails action. | |
| Modificada | Alta (7.5) | 1.0% | — | Prozilla Freelancers | 17/4/2008 | 16/6/2026 | SQL injection vulnerability in project.php in Prozilla Freelancers allows remote attackers to execute arbitrary SQL commands via the project parameter. |