Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2541▼ 407 respecto a la semana anterior
Críticas / altas1311▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)59▼ 467 respecto a la semana anterior
11 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.5) | 0.52% | — | Klik SocialmediawebsiteAI | 25/5/2026 | 23/7/2026 | A vulnerability was identified in KLiK SocialMediaWebsite 1.0. This issue affects some unknown processing of the component HTTP POST Request Parameter Handler. Such manipulation leads to injection. The attack can be launched remotely. The exploit is publicly available and might be used. | |
| Aplazada | Media (5.5) | 0.50% | — | Klik SocialmediawebsiteAI | 25/5/2026 | 23/7/2026 | A vulnerability was determined in KLiK SocialMediaWebsite 1.0. This vulnerability affects the function uniqid of the file upload.inc.php of the component File Handler. This manipulation causes unrestricted upload. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. | |
| Aplazada | Baja (2.1) | 0.42% | — | Klik SocialmediawebsiteAI | 25/5/2026 | 23/7/2026 | A vulnerability was found in KLiK SocialMediaWebsite 1.0. This affects an unknown part of the component HTTP GET Request Parameter Handler. The manipulation results in injection. It is possible to launch the attack remotely. The exploit has been made public and could be used. | |
| Aplazada | Media (6.9) | 0.40% | — | Klik SocialmediawebsiteAI | 25/4/2026 | 17/6/2026 | A vulnerability was determined in KLiK SocialMediaWebsite up to 1.0.1. This vulnerability affects unknown code of the file /includes/get_message_ajax.php of the component Private Message Handler. Executing a manipulation of the argument c_id can lead to sql injection. It is possible to launch the attack remotely. | |
| Modificada | Alta (8.8) | 0.34% | — | NLB Mklik Makedonija | 30/12/2025 | 24/9/2026 | NLB mKlik Macedonia 3.3.12 contains a SQL injection vulnerability in international transfer parameters that allows attackers to manipulate database queries. Attackers can inject arbitrary SQL code through unsanitized input to potentially disclose sensitive information from the mobile banking application. | |
| Analizada | Media (6.1) | 0.45% | — | Msaad1999 Klik Socialmediawebsite | 29/2/2024 | 17/6/2026 | A reflected cross-site scripting (XSS) vulnerability in SocialMediaWebsite v1.0.1 allows attackers to inject malicious JavaScript into the web browser of a victim via the poll parameter in poll.php. | |
| Analizada | Media (6.1) | 0.55% | — | Msaad1999 Klik Socialmediawebsite | 29/2/2024 | 17/6/2026 | KLiK SocialMediaWebsite version 1.0.1 from msaad1999 has a reflected cross-site scripting (XSS) vulnerability which may allow remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the 'selector' or 'validator' parameters of 'create-new-pwd.php'. | |
| Analizada | Media (5.4) | 0.46% | — | Msaad1999 Klik Socialmediawebsite | 29/2/2024 | 17/6/2026 | A reflected cross-site scripting (XSS) vulnerability in zhimengzhe iBarn v1.5 allows attackers to inject malicious JavaScript into the web browser of a victim via the search parameter in offer.php. | |
| Modificada | Media (5.4) | 0.51% | — | Klik Project Klik | 29/11/2022 | 17/6/2026 | KLiK SocialMediaWebsite Version 1.0.1 has XSS vulnerabilities that allow attackers to store XSS via location input reply-form. | |
| Modificada | Media (5.4) | 0.51% | — | Klik Project Klik | 29/11/2022 | 17/6/2026 | KLiK SocialMediaWebsite Version 1.0.1 has XSS vulnerabilities that allow attackers to store XSS via location Forum Subject input. | |
| Modificada | Alta (8.8) | 1.4% | — | Klik-socialmediawebsite Project Klik-socialmediawebsite | 22/11/2022 | 17/6/2026 | KLiK SocialMediaWebsite version v1.0.1 is vulnerable to SQL Injection via the profile.php. |