Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

621 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.1)1.2%—Linksys E1700 Firmware27/2/202417/6/2026
An issue was discovered in Linksys Router E1700 1.0.04 (build 3), allows authenticated attackers to escalate privileges via a crafted GET request to the /goform/* URI or via the ExportSettings function.
ModificadaMedia (4.3)0.48%—Linksys Wrt54gl Firmware10/2/202417/6/2026
A vulnerability was found in Linksys WRT54GL 4.30.18. It has been declared as problematic. This vulnerability affects unknown code of the file /SysInfo1.htm of the component Web Management Interface. The manipulation leads to information disclosure. The exploit has been disclosed to the public and may be used.…
ModificadaMedia (4.3)0.36%—Linksys Wrt54gl Firmware10/2/202417/6/2026
A vulnerability was found in Linksys WRT54GL 4.30.18. It has been classified as problematic. This affects an unknown part of the file /wlaninfo.htm of the component Web Management Interface. The manipulation leads to information disclosure. The exploit has been disclosed to the public and may be used. The identifier…
ModificadaAlta (7.5)0.77%—Linksys Wrt54gl Firmware9/2/202417/6/2026
A vulnerability was found in Linksys WRT54GL 4.30.18 and classified as problematic. Affected by this issue is some unknown functionality of the file /SysInfo.htm of the component Web Management Interface. The manipulation leads to information disclosure. The exploit has been disclosed to the public and may be used.…
ModificadaMedia (5.4)0.34%—Michaeluno Auto Amazon Links1/2/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michael Uno (miunosoft) Auto Amazon Links – Amazon Associates Affiliate Plugin allows Stored XSS.This issue affects Auto Amazon Links – Amazon Associates Affiliate Plugin: from n/a through 5.1.1.
ModificadaMedia (6.1)0.18%—Ludek Better Anchor Links31/1/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Luděk Melichar Better Anchor Links allows Cross-Site Scripting (XSS).This issue affects Better Anchor Links: from n/a through 1.7.5.
ModificadaAlta (8.8)0.22%—Linksoftwarellc White Label5/1/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in WhiteWP White Label – WordPress Custom Admin, Custom Login Page, and Custom Dashboard.This issue affects White Label – WordPress Custom Admin, Custom Login Page, and Custom Dashboard: from n/a through 2.9.0.
ModificadaMedia (4.8)0.34%—Linksoftwarellc Html Forms28/12/202317/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ibericode HTML Forms allows Stored XSS.This issue affects HTML Forms: from n/a through 1.3.28.
ModificadaAlta (7.5)0.27%—Blinksocks21/12/202317/6/2026
An issue was discovered in blinksocks version 3.3.8, allows remote attackers to obtain sensitive information via weak encryption algorithms in the component /presets/ssr-auth-chain.js.
ModificadaAlta (7.5)0.96%—Openlinksw Virtuoso29/11/202317/6/2026
An issue in the box_deserialize_reusing function in openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) after running a SELECT statement.
ModificadaAlta (7.5)0.79%—Openlinksw Virtuoso29/11/202317/6/2026
An issue in the box_equal function in openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) after running a SELECT statement.
ModificadaAlta (7.5)0.90%—Openlinksw Virtuoso29/11/202317/6/2026
An issue in the box_col_len function in openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) after running a SELECT statement.
ModificadaAlta (7.5)0.83%—Openlinksw Virtuoso29/11/202317/6/2026
An issue in the box_add function in openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) after running a SELECT statement.
ModificadaAlta (7.5)0.87%—Openlinksw Virtuoso29/11/202317/6/2026
An issue in the box_div function in openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) after running a SELECT statement.
ModificadaAlta (7.5)0.85%—Openlinksw Virtuoso29/11/202317/6/2026
An issue in the cha_cmp function of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) after running a SELECT statement.
ModificadaAlta (7.5)0.89%—Openlinksw Virtuoso29/11/202317/6/2026
An issue in the box_mpy function of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) after running a SELECT statement.
ModificadaAlta (7.5)0.89%—Openlinksw Virtuoso29/11/202317/6/2026
A stack overflow in openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
ModificadaMedia (6.1)0.41%—Yasglobal Permalinks Customizer22/11/202317/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in YAS Global Team Permalinks Customizer plugin <= 2.8.2 versions.
ModificadaAlta (8.8)0.29%—Wplinkspage WP Links Page18/11/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Robert Macchi WP Links Page.This issue affects WP Links Page: from n/a through 4.9.4.
ModificadaMedia (6.1)0.21%—Flamescorpion Auto Affiliate Links13/11/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Lucian Apostol Auto Affiliate Links allows Stored XSS.This issue affects Auto Affiliate Links: from n/a through 6.4.2.4.
ModificadaAlta (8.8)0.26%—Daext Autolinks Manager13/11/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in DAEXT Autolinks Manager plugin <= 1.10.04 versions.
ModificadaAlta (7.2)0.80%—Avirtum Imagelinks6/11/202317/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Avirtum ImageLinks Interactive Image Builder for WordPress allows SQL Injection.This issue affects ImageLinks Interactive Image Builder for WordPress: from n/a through 1.5.4.
ModificadaAlta (8.8)0.67%—Linkstack29/10/202317/6/2026
Weak Password Recovery Mechanism for Forgotten Password in GitHub repository linkstackorg/linkstack prior to v4.2.9.
ModificadaCrítica (9.8)0.50%—Linkstack29/10/202317/6/2026
Insufficient Session Expiration in GitHub repository linkstackorg/linkstack prior to v4.2.9.
ModificadaAlta (8.8)0.21%—Chetangole Smooth Scroll Links22/10/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Chetan Gole Smooth Scroll Links [SSL] plugin <= 1.1.0 versions.
Orbitaley — Vulnerabilidades