Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
621 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 1.7% | — | Linksys E7350 Firmware | 10/1/2025 | 17/6/2026 | Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_do_enr_pin_wps function. | |
| Analizada | Crítica (9.8) | 1.7% | — | Linksys E7350 Firmware | 10/1/2025 | 17/6/2026 | Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_wps_gen_pincode function. | |
| Analizada | Media (6.3) | 0.81% | — | Linksys E7350 Firmware | 10/1/2025 | 17/6/2026 | Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_cancel_wps function. | |
| Modificada | Alta (8.8) | 0.36% | — | Wpdeveloper Betterlinks | 2/1/2025 | 17/6/2026 | Missing Authorization vulnerability in WPDeveloper BetterLinks betterlinks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects BetterLinks: from n/a through <= 1.6.0. | |
| Aplazada | Alta (7.1) | 0.26% | — | Linksoftwarellc Html FormsAI | 2/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Link Software LLC HTML Forms html-forms allows Reflected XSS.This issue affects HTML Forms: from n/a through <= 1.4.1. | |
| Aplazada | Media (6.5) | 0.66% | — | Flamescorpion Auto Affiliate LinksAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Lucian Apostol Auto Affiliate Links allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Auto Affiliate Links: from n/a through 6.2.1.5. | |
| Analizada | Media (4.8) | 0.32% | — | Linkstack | 29/11/2024 | 17/6/2026 | LinkStack 2.7.9 through 4.7.7 allows resources\views\components\favicon.blade.php link SSRF. | |
| Analizada | Alta (8) | 13% | — | Linksys E3000 Firmware | 21/11/2024 | 17/6/2026 | Linksys E3000 1.0.06.002_US is vulnerable to command injection via the diag_ping_start function. | |
| Aplazada | Crítica (9.1) | 0.56% | — | Kasda Linksmart Router Kw5515AI | 20/11/2024 | 17/6/2026 | An issue in Kasda LinkSmart Router KW5515 v1.7 and before allows an authenticated remote attacker to execute arbitrary OS commands via cgi parameters. | |
| Aplazada | Crítica (9.1) | 1.0% | — | Kasda Linksmart Router Kw6512AI | 20/11/2024 | 17/6/2026 | Multiple OS Command Injection vulnerabilities affecting Kasda LinkSmart Router KW6512 <= v1.3 enable an authenticated remote attacker to execute arbitrary OS commands via various cgi parameters. | |
| Aplazada | Media (6.5) | 0.29% | — | Philspectrum Icon Widget With LinksAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in philspectrum Icon Widget icon-widget-with-links allows DOM-Based XSS.This issue affects Icon Widget: from n/a through <= 1.1.0. | |
| Aplazada | Media (6.5) | 0.24% | — | Santhosh Veer Stylish Internal LinksAI | 18/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Santhosh veer Stylish Internal Links stylish-internal-links allows DOM-Based XSS.This issue affects Stylish Internal Links: from n/a through <= 1.9. | |
| Analizada | Media (5.3) | 0.55% | — | Avovkdesign Hide Links | 13/11/2024 | 17/6/2026 | The Hide Links plugin for WordPress is vulnerable to unauthorized shortcode execution due to do_shortcode being hooked through the comment_text filter in all versions up to and including 1.4.2. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes available on the target site. | |
| Modificada | Alta (7.2) | 0.46% | — | Wpdeveloper Betterlinks | 4/11/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPDeveloper BetterLinks betterlinks allows SQL Injection.This issue affects BetterLinks: from n/a through <= 2.1.7. | |
| Aplazada | Media (6.4) | 0.36% | — | WP Simple Anchors LinksAI | 31/10/2024 | 17/6/2026 | The WP Simple Anchors Links plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpanchor shortcode in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Modificada | Alta (8.8) | 0.44% | — | Jordanlyall Mytweetlinks | 20/10/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Jordan Lyall MyTweetLinks mytweetlinks allows Blind SQL Injection.This issue affects MyTweetLinks: from n/a through <= 1.1.1. | |
| Aplazada | Media (5.9) | 0.27% | — | Walterpinem WP MylinksAI | 5/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Walter Pinem WP MyLinks wp-mylinks allows Stored XSS.This issue affects WP MyLinks: from n/a through <= 1.0.6. | |
| Analizada | Media (6.1) | 0.43% | — | Michaeluno Auto Amazon Links | 4/10/2024 | 17/6/2026 | The Auto Amazon Links – Amazon Associates Affiliate Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 5.4.2. This makes it possible for unauthenticated attackers to inject arbitrary… | |
| Analizada | Media (6.5) | 0.22% | — | Rubayathasan Infolinks AD Wrap | 17/9/2024 | 17/6/2026 | The infolinks Ad Wrap WordPress plugin through 1.0.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack | |
| Analizada | Media (5.3) | 0.75% | — | Linksys Wrt54g Firmware | 4/9/2024 | 17/6/2026 | A vulnerability was found in Linksys WRT54G 4.21.5. It has been rated as critical. Affected by this issue is the function validate_services_port of the file /apply.cgi of the component POST Parameter Handler. The manipulation of the argument services_array leads to stack-based buffer overflow. The attack may be… | |
| Analizada | Media (5.4) | 0.32% | — | Samiahmedsiddiqui Custom Permalinks | 24/8/2024 | 17/6/2026 | The Custom Permalinks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.6.0 due to insufficient input sanitization and output escaping on tag names. This allows authenticated users, with editor-level permissions or greater to inject arbitrary web scripts in pages… | |
| Aplazada | Crítica (9.6) | 0.54% | — | Hamed Naderfar Compute LinksAIPHPAI | 19/8/2024 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Hamed Naderfar Compute Links allows PHP Remote File Inclusion.This issue affects Compute Links: from n/a through 1.2.1. | |
| Analizada | Alta (8.8) | 2.1% | — | Linksys E1500 Firmware | 19/8/2024 | 17/6/2026 | A Command Injection vulnerability exists in the do_upgrade_post function of the httpd binary in Linksys E1500 v1.0.06.001. As a result, an authenticated attacker can execute OS commands with root privileges. | |
| Analizada | Media (6.5) | 0.27% | — | Linksoftwarellc Html Forms | 31/7/2024 | 17/6/2026 | The HTML Forms WordPress plugin before 1.3.34 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks | |
| Modificada | Alta (8) | 0.76% | — | Linksys E2500 Firmware | 24/7/2024 | 9/7/2026 | A vulnerability was discovered in Linksys Router E2500 with firmware 2.0.00, allows authenticated attackers to execute arbitrary code via the hnd_parentalctrl_unblock function. |