Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

621 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.8)1.7%—Linksys E7350 Firmware10/1/202517/6/2026
Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_do_enr_pin_wps function.
AnalizadaCrítica (9.8)1.7%—Linksys E7350 Firmware10/1/202517/6/2026
Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_wps_gen_pincode function.
AnalizadaMedia (6.3)0.81%—Linksys E7350 Firmware10/1/202517/6/2026
Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_cancel_wps function.
ModificadaAlta (8.8)0.36%—Wpdeveloper Betterlinks2/1/202517/6/2026
Missing Authorization vulnerability in WPDeveloper BetterLinks betterlinks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects BetterLinks: from n/a through <= 1.6.0.
AplazadaAlta (7.1)0.26%—Linksoftwarellc Html FormsAI2/1/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Link Software LLC HTML Forms html-forms allows Reflected XSS.This issue affects HTML Forms: from n/a through <= 1.4.1.
AplazadaMedia (6.5)0.66%—Flamescorpion Auto Affiliate LinksAI13/12/202417/6/2026
Missing Authorization vulnerability in Lucian Apostol Auto Affiliate Links allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Auto Affiliate Links: from n/a through 6.2.1.5.
AnalizadaMedia (4.8)0.32%—Linkstack29/11/202417/6/2026
LinkStack 2.7.9 through 4.7.7 allows resources\views\components\favicon.blade.php link SSRF.
AnalizadaAlta (8)13%—Linksys E3000 Firmware21/11/202417/6/2026
Linksys E3000 1.0.06.002_US is vulnerable to command injection via the diag_ping_start function.
AplazadaCrítica (9.1)0.56%—Kasda Linksmart Router Kw5515AI20/11/202417/6/2026
An issue in Kasda LinkSmart Router KW5515 v1.7 and before allows an authenticated remote attacker to execute arbitrary OS commands via cgi parameters.
AplazadaCrítica (9.1)1.0%—Kasda Linksmart Router Kw6512AI20/11/202417/6/2026
Multiple OS Command Injection vulnerabilities affecting Kasda LinkSmart Router KW6512 <= v1.3 enable an authenticated remote attacker to execute arbitrary OS commands via various cgi parameters.
AplazadaMedia (6.5)0.29%—Philspectrum Icon Widget With LinksAI19/11/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in philspectrum Icon Widget icon-widget-with-links allows DOM-Based XSS.This issue affects Icon Widget: from n/a through <= 1.1.0.
AplazadaMedia (6.5)0.24%—Santhosh Veer Stylish Internal LinksAI18/11/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Santhosh veer Stylish Internal Links stylish-internal-links allows DOM-Based XSS.This issue affects Stylish Internal Links: from n/a through <= 1.9.
AnalizadaMedia (5.3)0.55%—Avovkdesign Hide Links13/11/202417/6/2026
The Hide Links plugin for WordPress is vulnerable to unauthorized shortcode execution due to do_shortcode being hooked through the comment_text filter in all versions up to and including 1.4.2. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes available on the target site.
ModificadaAlta (7.2)0.46%—Wpdeveloper Betterlinks4/11/202417/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPDeveloper BetterLinks betterlinks allows SQL Injection.This issue affects BetterLinks: from n/a through <= 2.1.7.
AplazadaMedia (6.4)0.36%—WP Simple Anchors LinksAI31/10/202417/6/2026
The WP Simple Anchors Links plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpanchor shortcode in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with…
ModificadaAlta (8.8)0.44%—Jordanlyall Mytweetlinks20/10/202417/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Jordan Lyall MyTweetLinks mytweetlinks allows Blind SQL Injection.This issue affects MyTweetLinks: from n/a through <= 1.1.1.
AplazadaMedia (5.9)0.27%—Walterpinem WP MylinksAI5/10/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Walter Pinem WP MyLinks wp-mylinks allows Stored XSS.This issue affects WP MyLinks: from n/a through <= 1.0.6.
AnalizadaMedia (6.1)0.43%—Michaeluno Auto Amazon Links4/10/202417/6/2026
The Auto Amazon Links – Amazon Associates Affiliate Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 5.4.2. This makes it possible for unauthenticated attackers to inject arbitrary…
AnalizadaMedia (6.5)0.22%—Rubayathasan Infolinks AD Wrap17/9/202417/6/2026
The infolinks Ad Wrap WordPress plugin through 1.0.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
AnalizadaMedia (5.3)0.75%—Linksys Wrt54g Firmware4/9/202417/6/2026
A vulnerability was found in Linksys WRT54G 4.21.5. It has been rated as critical. Affected by this issue is the function validate_services_port of the file /apply.cgi of the component POST Parameter Handler. The manipulation of the argument services_array leads to stack-based buffer overflow. The attack may be…
AnalizadaMedia (5.4)0.32%—Samiahmedsiddiqui Custom Permalinks24/8/202417/6/2026
The Custom Permalinks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.6.0 due to insufficient input sanitization and output escaping on tag names. This allows authenticated users, with editor-level permissions or greater to inject arbitrary web scripts in pages…
AplazadaCrítica (9.6)0.54%—Hamed Naderfar Compute LinksAIPHPAI19/8/202417/6/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Hamed Naderfar Compute Links allows PHP Remote File Inclusion.This issue affects Compute Links: from n/a through 1.2.1.
AnalizadaAlta (8.8)2.1%—Linksys E1500 Firmware19/8/202417/6/2026
A Command Injection vulnerability exists in the do_upgrade_post function of the httpd binary in Linksys E1500 v1.0.06.001. As a result, an authenticated attacker can execute OS commands with root privileges.
AnalizadaMedia (6.5)0.27%—Linksoftwarellc Html Forms31/7/202417/6/2026
The HTML Forms WordPress plugin before 1.3.34 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks
ModificadaAlta (8)0.76%—Linksys E2500 Firmware24/7/20249/7/2026
A vulnerability was discovered in Linksys Router E2500 with firmware 2.0.00, allows authenticated attackers to execute arbitrary code via the hnd_parentalctrl_unblock function.
Orbitaley — Vulnerabilidades