Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

621 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (4.8)0.35%—Linksoftwarellc Html Forms22/7/202417/6/2026
The HTML Forms WordPress plugin before 1.3.33 does not sanitize and escape the form message inputs, allowing high-privilege users, such as administrators, to perform Stored Cross-Site Scripting (XSS) attacks even when the unfiltered_html capability is disabled.
ModificadaMedia (5.4)0.27%—Celloexpressions Floating Social Media Links21/7/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Nick Halsey Floating Social Media Links allows Stored XSS.This issue affects Floating Social Media Links: from n/a through 1.5.2.
AnalizadaAlta (8.8)0.32%—Linksys Wrt54g Firmware19/7/202417/6/2026
Linksys WRT54G v4.21.5 has a stack overflow vulnerability in get_merge_mac function.
AplazadaAlta (7.3)0.19%—Elinksmart Hidden Smart Cabinet LockAI15/7/202417/6/2026
eLinkSmart Hidden Smart Cabinet Lock 2024-05-22 has Incorrect Access Control and fails to perform an authorization check which can lead to card duplication and other attacks.
AplazadaMedia (4.3)0.39%—Wplinkspage WP Links PageAI13/7/202417/6/2026
The WP Links Page plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wplf_ajax_update_screenshots' function in all versions up to, and including, 4.9.5. This makes it possible for authenticated attackers, with Subscriber-level access and above, to…
AnalizadaMedia (5.3)0.10%—Linksys Mx6200 FirmwareLinksys Mbe7000 Firmware9/7/202417/6/2026
Linksys Velop Pro 6E 1.0.8 MX6200_1.0.8.215731 and 7 1.0.10.215314 devices send cleartext Wi-Fi passwords over the public Internet during app-based installation.
AplazadaMedia (4.3)0.40%—Bootstrapped Easy Affiliate LinksAI28/6/202417/6/2026
The Easy Affiliate Links plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the eafl_reset_settings AJAX action in all versions up to, and including, 3.7.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to reset the…
ModificadaCrítica (9.8)0.41%—Prestashop PK Customlinks19/6/202417/6/2026
In the module "Custom links" (pk_customlinks) <= 2.3 from Promokit.eu for PrestaShop, a guest can perform SQL injection. The script ajax.php have a sensitive SQL call that can be executed with a trivial http call and exploited to forge a SQL injection.
ModificadaMedia (6.8)2.9%💥 PoCLinksys Velop Whw0101 Firmware11/6/202417/6/2026
Insecure permissions in Linksys Velop WiFi 5 (WHW01v1) 1.1.13.202617 allows attackers to escalate privileges from Guest to root.
AnalizadaAlta (7.5)0.42%—Linksys E5600 Firmware28/5/202417/6/2026
An issue discovered in Linksys E5600 routers allows attackers to hijack TCP sessions which could lead to a denial of service.
AplazadaMedia (6.5)0.41%—Bootstrapped Easy Affiliate LinksAI14/5/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bootstrapped Ventures Easy Affiliate Links allows Stored XSS.This issue affects Easy Affiliate Links: from n/a through 3.7.2.
AnalizadaCrítica (9.8)1.6%💥 PoCLinksys Ea7500 Firmware7/5/202417/6/2026
Buffer Overflow vulnerability LINKSYS EA7500 3.0.1.207964 allows a remote attacker to execute arbitrary code via an HTTP request to the IGD UPnP.
AplazadaAlta (7.6)0.52%—Flamescorpion Auto Affiliate LinksAI6/5/202417/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Lucian Apostol Auto Affiliate Links.This issue affects Auto Affiliate Links: from n/a through 6.4.3.1.
AnalizadaAlta (8)1.9%—Linksys E5600 Firmware6/5/202417/6/2026
Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability via the PinCode parameter at /API/info form endpoint.
AnalizadaCrítica (9.8)2.4%—Linksys E5600 Firmware3/5/202417/6/2026
Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability via the ipurl parameter at /API/info form endpoint.
AnalizadaAlta (8.8)17%💥 ExploitLinksys Re7000 Firmware11/4/202417/6/2026
Linksys RE7000 v2.0.9, v2.0.11, and v2.0.15 have a command execution vulnerability in the "AccessControlList" parameter of the access control function point. An attacker can use the vulnerability to obtain device administrator rights.
AplazadaAlta (7.5)0.74%—Woocommerce Cloak Affiliate LinksAI9/4/202417/6/2026
The WooCommerce Cloak Affiliate Links plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'permalink_settings_save' function in all versions up to, and including, 1.0.33. This makes it possible for unauthenticated attackers to modify the affiliate permalink…
AplazadaAlta (8.1)0.75%—Mainwp Links Manager ExtensionAI28/3/202417/6/2026
Deserialization of Untrusted Data vulnerability in MainWP MainWP Links Manager Extension.This issue affects MainWP Links Manager Extension: from n/a through 2.1.
AplazadaAlta (7.1)0.42%—Prettylinks ShortlinksAI27/3/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pretty Links Shortlinks by Pretty Links allows Reflected XSS.This issue affects Shortlinks by Pretty Links: from n/a through 3.6.2.
ModificadaMedia (4.3)0.21%—Caseproof Prettylinks23/3/202417/6/2026
The Pretty Links – Affiliate Links, Link Branding, Link Tracking & Marketing Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.6.3. This is due to missing or incorrect nonce validation when saving plugin settings. This makes it possible for unauthenticated…
AnalizadaMedia (6.7)0.46%—Linksys E1000 Firmware19/3/202417/6/2026
There is stack-based buffer overflow vulnerability in pc_change_act function in Linksys E1000 router firmware version v.2.1.03 and before, leading to remote code execution.
ModificadaMedia (4.3)0.53%—Flamescorpion Auto Affiliate Links13/3/202417/6/2026
The Auto Affiliate Links plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the aalAddLink function in all versions up to, and including, 6.4.3. This makes it possible for authenticated attackers, with subscriber access or higher, to add arbitrary links to…
ModificadaAlta (7.5)0.50%💥 PoCElinksmart Esmartcam5/3/202417/6/2026
The Elink Smart eSmartCam (com.cn.dq.ipc) application 2.1.5 for Android contains hardcoded AES encryption keys that can be extracted from a binary file. Thus, encryption can be defeated by an attacker who can observe packet data (e.g., over Wi-Fi).
AnalizadaAlta (8.8)27%💥 ExploitLinksys E2000 Firmware1/3/202417/6/2026
Linksys E2000 Ver.1.0.06 build 1 is vulnerable to authentication bypass via the position.js file.
AnalizadaAlta (8)9.3%—Linksys E1700 Firmware27/2/202417/6/2026
An issue was discovered in Linksys Router E1700 version 1.0.04 (build 3), allows authenticated attackers to execute arbitrary code via the setDateTime function.
Orbitaley — Vulnerabilidades