Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
621 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.1) | 1.2% | — | Linksys E1700 Firmware | 27/2/2024 | 17/6/2026 | An issue was discovered in Linksys Router E1700 1.0.04 (build 3), allows authenticated attackers to escalate privileges via a crafted GET request to the /goform/* URI or via the ExportSettings function. | |
| Modificada | Media (4.3) | 0.48% | — | Linksys Wrt54gl Firmware | 10/2/2024 | 17/6/2026 | A vulnerability was found in Linksys WRT54GL 4.30.18. It has been declared as problematic. This vulnerability affects unknown code of the file /SysInfo1.htm of the component Web Management Interface. The manipulation leads to information disclosure. The exploit has been disclosed to the public and may be used.… | |
| Modificada | Media (4.3) | 0.36% | — | Linksys Wrt54gl Firmware | 10/2/2024 | 17/6/2026 | A vulnerability was found in Linksys WRT54GL 4.30.18. It has been classified as problematic. This affects an unknown part of the file /wlaninfo.htm of the component Web Management Interface. The manipulation leads to information disclosure. The exploit has been disclosed to the public and may be used. The identifier… | |
| Modificada | Alta (7.5) | 0.77% | — | Linksys Wrt54gl Firmware | 9/2/2024 | 17/6/2026 | A vulnerability was found in Linksys WRT54GL 4.30.18 and classified as problematic. Affected by this issue is some unknown functionality of the file /SysInfo.htm of the component Web Management Interface. The manipulation leads to information disclosure. The exploit has been disclosed to the public and may be used.… | |
| Modificada | Media (5.4) | 0.34% | — | Michaeluno Auto Amazon Links | 1/2/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michael Uno (miunosoft) Auto Amazon Links – Amazon Associates Affiliate Plugin allows Stored XSS.This issue affects Auto Amazon Links – Amazon Associates Affiliate Plugin: from n/a through 5.1.1. | |
| Modificada | Media (6.1) | 0.18% | — | Ludek Better Anchor Links | 31/1/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Luděk Melichar Better Anchor Links allows Cross-Site Scripting (XSS).This issue affects Better Anchor Links: from n/a through 1.7.5. | |
| Modificada | Alta (8.8) | 0.22% | — | Linksoftwarellc White Label | 5/1/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WhiteWP White Label – WordPress Custom Admin, Custom Login Page, and Custom Dashboard.This issue affects White Label – WordPress Custom Admin, Custom Login Page, and Custom Dashboard: from n/a through 2.9.0. | |
| Modificada | Media (4.8) | 0.34% | — | Linksoftwarellc Html Forms | 28/12/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ibericode HTML Forms allows Stored XSS.This issue affects HTML Forms: from n/a through 1.3.28. | |
| Modificada | Alta (7.5) | 0.27% | — | Blinksocks | 21/12/2023 | 17/6/2026 | An issue was discovered in blinksocks version 3.3.8, allows remote attackers to obtain sensitive information via weak encryption algorithms in the component /presets/ssr-auth-chain.js. | |
| Modificada | Alta (7.5) | 0.96% | — | Openlinksw Virtuoso | 29/11/2023 | 17/6/2026 | An issue in the box_deserialize_reusing function in openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) after running a SELECT statement. | |
| Modificada | Alta (7.5) | 0.79% | — | Openlinksw Virtuoso | 29/11/2023 | 17/6/2026 | An issue in the box_equal function in openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) after running a SELECT statement. | |
| Modificada | Alta (7.5) | 0.90% | — | Openlinksw Virtuoso | 29/11/2023 | 17/6/2026 | An issue in the box_col_len function in openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) after running a SELECT statement. | |
| Modificada | Alta (7.5) | 0.83% | — | Openlinksw Virtuoso | 29/11/2023 | 17/6/2026 | An issue in the box_add function in openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) after running a SELECT statement. | |
| Modificada | Alta (7.5) | 0.87% | — | Openlinksw Virtuoso | 29/11/2023 | 17/6/2026 | An issue in the box_div function in openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) after running a SELECT statement. | |
| Modificada | Alta (7.5) | 0.85% | — | Openlinksw Virtuoso | 29/11/2023 | 17/6/2026 | An issue in the cha_cmp function of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) after running a SELECT statement. | |
| Modificada | Alta (7.5) | 0.89% | — | Openlinksw Virtuoso | 29/11/2023 | 17/6/2026 | An issue in the box_mpy function of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) after running a SELECT statement. | |
| Modificada | Alta (7.5) | 0.89% | — | Openlinksw Virtuoso | 29/11/2023 | 17/6/2026 | A stack overflow in openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements. | |
| Modificada | Media (6.1) | 0.41% | — | Yasglobal Permalinks Customizer | 22/11/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in YAS Global Team Permalinks Customizer plugin <= 2.8.2 versions. | |
| Modificada | Alta (8.8) | 0.29% | — | Wplinkspage WP Links Page | 18/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Robert Macchi WP Links Page.This issue affects WP Links Page: from n/a through 4.9.4. | |
| Modificada | Media (6.1) | 0.21% | — | Flamescorpion Auto Affiliate Links | 13/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Lucian Apostol Auto Affiliate Links allows Stored XSS.This issue affects Auto Affiliate Links: from n/a through 6.4.2.4. | |
| Modificada | Alta (8.8) | 0.26% | — | Daext Autolinks Manager | 13/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in DAEXT Autolinks Manager plugin <= 1.10.04 versions. | |
| Modificada | Alta (7.2) | 0.80% | — | Avirtum Imagelinks | 6/11/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Avirtum ImageLinks Interactive Image Builder for WordPress allows SQL Injection.This issue affects ImageLinks Interactive Image Builder for WordPress: from n/a through 1.5.4. | |
| Modificada | Alta (8.8) | 0.67% | — | Linkstack | 29/10/2023 | 17/6/2026 | Weak Password Recovery Mechanism for Forgotten Password in GitHub repository linkstackorg/linkstack prior to v4.2.9. | |
| Modificada | Crítica (9.8) | 0.50% | — | Linkstack | 29/10/2023 | 17/6/2026 | Insufficient Session Expiration in GitHub repository linkstackorg/linkstack prior to v4.2.9. | |
| Modificada | Alta (8.8) | 0.21% | — | Chetangole Smooth Scroll Links | 22/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Chetan Gole Smooth Scroll Links [SSL] plugin <= 1.1.0 versions. |