Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
621 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.8) | 0.35% | — | Linksoftwarellc Html Forms | 22/7/2024 | 17/6/2026 | The HTML Forms WordPress plugin before 1.3.33 does not sanitize and escape the form message inputs, allowing high-privilege users, such as administrators, to perform Stored Cross-Site Scripting (XSS) attacks even when the unfiltered_html capability is disabled. | |
| Modificada | Media (5.4) | 0.27% | — | Celloexpressions Floating Social Media Links | 21/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Nick Halsey Floating Social Media Links allows Stored XSS.This issue affects Floating Social Media Links: from n/a through 1.5.2. | |
| Analizada | Alta (8.8) | 0.32% | — | Linksys Wrt54g Firmware | 19/7/2024 | 17/6/2026 | Linksys WRT54G v4.21.5 has a stack overflow vulnerability in get_merge_mac function. | |
| Aplazada | Alta (7.3) | 0.19% | — | Elinksmart Hidden Smart Cabinet LockAI | 15/7/2024 | 17/6/2026 | eLinkSmart Hidden Smart Cabinet Lock 2024-05-22 has Incorrect Access Control and fails to perform an authorization check which can lead to card duplication and other attacks. | |
| Aplazada | Media (4.3) | 0.39% | — | Wplinkspage WP Links PageAI | 13/7/2024 | 17/6/2026 | The WP Links Page plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wplf_ajax_update_screenshots' function in all versions up to, and including, 4.9.5. This makes it possible for authenticated attackers, with Subscriber-level access and above, to… | |
| Analizada | Media (5.3) | 0.10% | — | Linksys Mx6200 FirmwareLinksys Mbe7000 Firmware | 9/7/2024 | 17/6/2026 | Linksys Velop Pro 6E 1.0.8 MX6200_1.0.8.215731 and 7 1.0.10.215314 devices send cleartext Wi-Fi passwords over the public Internet during app-based installation. | |
| Aplazada | Media (4.3) | 0.40% | — | Bootstrapped Easy Affiliate LinksAI | 28/6/2024 | 17/6/2026 | The Easy Affiliate Links plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the eafl_reset_settings AJAX action in all versions up to, and including, 3.7.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to reset the… | |
| Modificada | Crítica (9.8) | 0.41% | — | Prestashop PK Customlinks | 19/6/2024 | 17/6/2026 | In the module "Custom links" (pk_customlinks) <= 2.3 from Promokit.eu for PrestaShop, a guest can perform SQL injection. The script ajax.php have a sensitive SQL call that can be executed with a trivial http call and exploited to forge a SQL injection. | |
| Modificada | Media (6.8) | 2.9% | 💥 PoC | Linksys Velop Whw0101 Firmware | 11/6/2024 | 17/6/2026 | Insecure permissions in Linksys Velop WiFi 5 (WHW01v1) 1.1.13.202617 allows attackers to escalate privileges from Guest to root. | |
| Analizada | Alta (7.5) | 0.42% | — | Linksys E5600 Firmware | 28/5/2024 | 17/6/2026 | An issue discovered in Linksys E5600 routers allows attackers to hijack TCP sessions which could lead to a denial of service. | |
| Aplazada | Media (6.5) | 0.41% | — | Bootstrapped Easy Affiliate LinksAI | 14/5/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bootstrapped Ventures Easy Affiliate Links allows Stored XSS.This issue affects Easy Affiliate Links: from n/a through 3.7.2. | |
| Analizada | Crítica (9.8) | 1.6% | 💥 PoC | Linksys Ea7500 Firmware | 7/5/2024 | 17/6/2026 | Buffer Overflow vulnerability LINKSYS EA7500 3.0.1.207964 allows a remote attacker to execute arbitrary code via an HTTP request to the IGD UPnP. | |
| Aplazada | Alta (7.6) | 0.52% | — | Flamescorpion Auto Affiliate LinksAI | 6/5/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Lucian Apostol Auto Affiliate Links.This issue affects Auto Affiliate Links: from n/a through 6.4.3.1. | |
| Analizada | Alta (8) | 1.9% | — | Linksys E5600 Firmware | 6/5/2024 | 17/6/2026 | Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability via the PinCode parameter at /API/info form endpoint. | |
| Analizada | Crítica (9.8) | 2.4% | — | Linksys E5600 Firmware | 3/5/2024 | 17/6/2026 | Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability via the ipurl parameter at /API/info form endpoint. | |
| Analizada | Alta (8.8) | 17% | 💥 Exploit | Linksys Re7000 Firmware | 11/4/2024 | 17/6/2026 | Linksys RE7000 v2.0.9, v2.0.11, and v2.0.15 have a command execution vulnerability in the "AccessControlList" parameter of the access control function point. An attacker can use the vulnerability to obtain device administrator rights. | |
| Aplazada | Alta (7.5) | 0.74% | — | Woocommerce Cloak Affiliate LinksAI | 9/4/2024 | 17/6/2026 | The WooCommerce Cloak Affiliate Links plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'permalink_settings_save' function in all versions up to, and including, 1.0.33. This makes it possible for unauthenticated attackers to modify the affiliate permalink… | |
| Aplazada | Alta (8.1) | 0.75% | — | Mainwp Links Manager ExtensionAI | 28/3/2024 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in MainWP MainWP Links Manager Extension.This issue affects MainWP Links Manager Extension: from n/a through 2.1. | |
| Aplazada | Alta (7.1) | 0.42% | — | Prettylinks ShortlinksAI | 27/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pretty Links Shortlinks by Pretty Links allows Reflected XSS.This issue affects Shortlinks by Pretty Links: from n/a through 3.6.2. | |
| Modificada | Media (4.3) | 0.21% | — | Caseproof Prettylinks | 23/3/2024 | 17/6/2026 | The Pretty Links – Affiliate Links, Link Branding, Link Tracking & Marketing Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.6.3. This is due to missing or incorrect nonce validation when saving plugin settings. This makes it possible for unauthenticated… | |
| Analizada | Media (6.7) | 0.46% | — | Linksys E1000 Firmware | 19/3/2024 | 17/6/2026 | There is stack-based buffer overflow vulnerability in pc_change_act function in Linksys E1000 router firmware version v.2.1.03 and before, leading to remote code execution. | |
| Modificada | Media (4.3) | 0.53% | — | Flamescorpion Auto Affiliate Links | 13/3/2024 | 17/6/2026 | The Auto Affiliate Links plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the aalAddLink function in all versions up to, and including, 6.4.3. This makes it possible for authenticated attackers, with subscriber access or higher, to add arbitrary links to… | |
| Modificada | Alta (7.5) | 0.50% | 💥 PoC | Elinksmart Esmartcam | 5/3/2024 | 17/6/2026 | The Elink Smart eSmartCam (com.cn.dq.ipc) application 2.1.5 for Android contains hardcoded AES encryption keys that can be extracted from a binary file. Thus, encryption can be defeated by an attacker who can observe packet data (e.g., over Wi-Fi). | |
| Analizada | Alta (8.8) | 27% | 💥 Exploit | Linksys E2000 Firmware | 1/3/2024 | 17/6/2026 | Linksys E2000 Ver.1.0.06 build 1 is vulnerable to authentication bypass via the position.js file. | |
| Analizada | Alta (8) | 9.3% | — | Linksys E1700 Firmware | 27/2/2024 | 17/6/2026 | An issue was discovered in Linksys Router E1700 version 1.0.04 (build 3), allows authenticated attackers to execute arbitrary code via the setDateTime function. |