Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
–

621 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)0.91%—Openlinksw Virtuoso15/5/202317/6/2026
An issue in the dk_set_delete component of openlink virtuoso-opensource v7.2.9 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
ModificadaAlta (7.5)0.91%—Openlinksw Virtuoso15/5/202317/6/2026
An issue in the bif_mod component of openlink virtuoso-opensource v7.2.9 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
ModificadaAlta (7.5)0.91%—Openlinksw Virtuoso15/5/202317/6/2026
An issue in the chash_array component of openlink virtuoso-opensource v7.2.9 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
ModificadaAlta (7.5)0.91%—Openlinksw Virtuoso15/5/202317/6/2026
An issue in the mp_box_deserialize_string function in openlink virtuoso-opensource v7.2.9 allows attackers to cause a Denial of Service (DoS) after running a SELECT statement.
ModificadaAlta (7.5)0.91%—Openlinksw Virtuoso15/5/202317/6/2026
An issue in the __nss_database_lookup component of openlink virtuoso-opensource v7.2.9 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
ModificadaAlta (7.5)0.91%—Openlinksw Virtuoso15/5/202317/6/2026
An issue in the dfe_qexp_list component of openlink virtuoso-opensource v7.2.9 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
ModificadaAlta (7.5)0.91%—Openlinksw Virtuoso15/5/202317/6/2026
An issue in the __libc_longjmp component of openlink virtuoso-opensource v7.2.9 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
ModificadaAlta (7.5)0.91%—Openlinksw Virtuoso15/5/202317/6/2026
An issue in the _IO_default_xsputn component of openlink virtuoso-opensource v7.2.9 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
ModificadaAlta (7.5)0.91%—Openlinksw Virtuoso15/5/202317/6/2026
An issue in the dfe_unit_col_loci component of openlink virtuoso-opensource v7.2.9 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
ModificadaAlta (7.5)0.91%—Openlinksw Virtuoso15/5/202317/6/2026
An issue in the artm_div_int component of openlink virtuoso-opensource v7.2.9 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
ModificadaAlta (7.5)0.91%—Openlinksw Virtuoso15/5/202317/6/2026
An issue in the __libc_malloc component of openlink virtuoso-opensource v7.2.9 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
ModificadaMedia (5.4)0.37%—WP Links Page Project WP Links Page11/5/202317/6/2026
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Robert Macchi WP Links Page plugin <= 4.9.3 versions.
ModificadaMedia (5.4)0.36%—Custom4web Affiliate Links Lite10/5/202317/6/2026
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Custom4Web Affiliate Links Lite plugin <= 2.5 versions.
ModificadaAlta (8.8)11%💥 ExploitLinksys E8450 Firmware16/4/202317/6/2026
Linksys AX3200 1.1.00 is vulnerable to OS command injection by authenticated users via shell metacharacters to the diagnostics traceroute page.
ModificadaMedia (4.8)0.39%—Linksoftwarellc WP Terms Popup6/4/202317/6/2026
Auth. (admin+) Cross-Site Scripting (XSS) vulnerability in Link Software LLC WP Terms Popup plugin <= 2.6.0 versions.
ModificadaMedia (5.4)0.38%—Galaxyweblinks Gallery With Thumbnail Slider21/3/202317/6/2026
Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in Galaxy Weblinks Gallery with thumbnail slider plugin <= 6.0 versions.
ModificadaAlta (8.8)0.25%—Flamescorpion Auto Affiliate Links13/3/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Lucian Apostol Auto Affiliate Links plugin <= 6.3.0.2 versions.
ModificadaMedia (5.4)0.70%—Bootstrapped Easy Affiliate Links21/2/202317/6/2026
The Easy Affiliate Links WordPress plugin before 3.7.1 does not validate and escape some of its block options before outputting them back in a page/post where the block is embedded, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
ModificadaMedia (5.4)0.47%—Linksalpha Social Sharing Toolkit30/1/202317/6/2026
The Social Sharing Toolkit WordPress plugin through 2.6 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such…
ModificadaMedia (5.4)0.47%—Avirtum Imagelinks9/1/202317/6/2026
The ImageLinks Interactive Image Builder for WordPress plugin through 1.5.3 does not sanitise and escape some of its settings, which could allow users such as contributor+ to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
ModificadaAlta (7.2)1.9%💥 PoCLinksys Wrt54gl Firmware9/1/202317/6/2026
An arbitrary code execution vulnerability exisits in Linksys WRT54GL Wireless-G Broadband Router with firmware <= 4.30.18.006. The Check_TSSI function within the httpd binary uses unvalidated user input in the construction of a system command. An authenticated attacker with administrator privileges can leverage this…
ModificadaAlta (7.5)1.3%—Linksys Wrt54gl Firmware9/1/202317/6/2026
A null pointer dereference vulnerability exists in Linksys WRT54GL Wireless-G Broadband Router with firmware <= 4.30.18.006. A null pointer dereference in the soap_action function within the upnp binary can be triggered by an unauthenticated attacker via a malicious POST request invoking the AddPortMapping action.
ModificadaAlta (7.2)1.7%—Linksys Wumc710 Firmware9/1/202317/6/2026
An arbitrary code exection vulnerability exists in Linksys WUMC710 Wireless-AC Universal Media Connector with firmware <= 1.0.02 (build3). The do_setNTP function within the httpd binary uses unvalidated user input in the construction of a system command. An authenticated attacker with administrator privileges can…
ModificadaAlta (7.2)19%—Linksys Wrt54gl Firmware9/1/202317/6/2026
A buffer overflow vulnerability exists in Linksys WRT54GL Wireless-G Broadband Router with firmware <= 4.30.18.006. A stack-based buffer overflow in the Start_EPI function within the httpd binary allows an authenticated attacker with administrator privileges to execute arbitrary commands on the underlying Linux…
AnalizadaAlta (7.2)1.9%💥 PoCLinksoftwarellc Html Forms28/11/202217/6/2026
The HTML Forms WordPress plugin before 1.3.25 does not properly properly escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users
Orbitaley — Vulnerabilidades