Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
621 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.91% | — | Openlinksw Virtuoso | 15/5/2023 | 17/6/2026 | An issue in the dk_set_delete component of openlink virtuoso-opensource v7.2.9 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements. | |
| Modificada | Alta (7.5) | 0.91% | — | Openlinksw Virtuoso | 15/5/2023 | 17/6/2026 | An issue in the bif_mod component of openlink virtuoso-opensource v7.2.9 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements. | |
| Modificada | Alta (7.5) | 0.91% | — | Openlinksw Virtuoso | 15/5/2023 | 17/6/2026 | An issue in the chash_array component of openlink virtuoso-opensource v7.2.9 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements. | |
| Modificada | Alta (7.5) | 0.91% | — | Openlinksw Virtuoso | 15/5/2023 | 17/6/2026 | An issue in the mp_box_deserialize_string function in openlink virtuoso-opensource v7.2.9 allows attackers to cause a Denial of Service (DoS) after running a SELECT statement. | |
| Modificada | Alta (7.5) | 0.91% | — | Openlinksw Virtuoso | 15/5/2023 | 17/6/2026 | An issue in the __nss_database_lookup component of openlink virtuoso-opensource v7.2.9 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements. | |
| Modificada | Alta (7.5) | 0.91% | — | Openlinksw Virtuoso | 15/5/2023 | 17/6/2026 | An issue in the dfe_qexp_list component of openlink virtuoso-opensource v7.2.9 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements. | |
| Modificada | Alta (7.5) | 0.91% | — | Openlinksw Virtuoso | 15/5/2023 | 17/6/2026 | An issue in the __libc_longjmp component of openlink virtuoso-opensource v7.2.9 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements. | |
| Modificada | Alta (7.5) | 0.91% | — | Openlinksw Virtuoso | 15/5/2023 | 17/6/2026 | An issue in the _IO_default_xsputn component of openlink virtuoso-opensource v7.2.9 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements. | |
| Modificada | Alta (7.5) | 0.91% | — | Openlinksw Virtuoso | 15/5/2023 | 17/6/2026 | An issue in the dfe_unit_col_loci component of openlink virtuoso-opensource v7.2.9 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements. | |
| Modificada | Alta (7.5) | 0.91% | — | Openlinksw Virtuoso | 15/5/2023 | 17/6/2026 | An issue in the artm_div_int component of openlink virtuoso-opensource v7.2.9 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements. | |
| Modificada | Alta (7.5) | 0.91% | — | Openlinksw Virtuoso | 15/5/2023 | 17/6/2026 | An issue in the __libc_malloc component of openlink virtuoso-opensource v7.2.9 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements. | |
| Modificada | Media (5.4) | 0.37% | — | WP Links Page Project WP Links Page | 11/5/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Robert Macchi WP Links Page plugin <= 4.9.3 versions. | |
| Modificada | Media (5.4) | 0.36% | — | Custom4web Affiliate Links Lite | 10/5/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Custom4Web Affiliate Links Lite plugin <= 2.5 versions. | |
| Modificada | Alta (8.8) | 11% | 💥 Exploit | Linksys E8450 Firmware | 16/4/2023 | 17/6/2026 | Linksys AX3200 1.1.00 is vulnerable to OS command injection by authenticated users via shell metacharacters to the diagnostics traceroute page. | |
| Modificada | Media (4.8) | 0.39% | — | Linksoftwarellc WP Terms Popup | 6/4/2023 | 17/6/2026 | Auth. (admin+) Cross-Site Scripting (XSS) vulnerability in Link Software LLC WP Terms Popup plugin <= 2.6.0 versions. | |
| Modificada | Media (5.4) | 0.38% | — | Galaxyweblinks Gallery With Thumbnail Slider | 21/3/2023 | 17/6/2026 | Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in Galaxy Weblinks Gallery with thumbnail slider plugin <= 6.0 versions. | |
| Modificada | Alta (8.8) | 0.25% | — | Flamescorpion Auto Affiliate Links | 13/3/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Lucian Apostol Auto Affiliate Links plugin <= 6.3.0.2 versions. | |
| Modificada | Media (5.4) | 0.70% | — | Bootstrapped Easy Affiliate Links | 21/2/2023 | 17/6/2026 | The Easy Affiliate Links WordPress plugin before 3.7.1 does not validate and escape some of its block options before outputting them back in a page/post where the block is embedded, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Modificada | Media (5.4) | 0.47% | — | Linksalpha Social Sharing Toolkit | 30/1/2023 | 17/6/2026 | The Social Sharing Toolkit WordPress plugin through 2.6 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such… | |
| Modificada | Media (5.4) | 0.47% | — | Avirtum Imagelinks | 9/1/2023 | 17/6/2026 | The ImageLinks Interactive Image Builder for WordPress plugin through 1.5.3 does not sanitise and escape some of its settings, which could allow users such as contributor+ to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. | |
| Modificada | Alta (7.2) | 1.9% | 💥 PoC | Linksys Wrt54gl Firmware | 9/1/2023 | 17/6/2026 | An arbitrary code execution vulnerability exisits in Linksys WRT54GL Wireless-G Broadband Router with firmware <= 4.30.18.006. The Check_TSSI function within the httpd binary uses unvalidated user input in the construction of a system command. An authenticated attacker with administrator privileges can leverage this… | |
| Modificada | Alta (7.5) | 1.3% | — | Linksys Wrt54gl Firmware | 9/1/2023 | 17/6/2026 | A null pointer dereference vulnerability exists in Linksys WRT54GL Wireless-G Broadband Router with firmware <= 4.30.18.006. A null pointer dereference in the soap_action function within the upnp binary can be triggered by an unauthenticated attacker via a malicious POST request invoking the AddPortMapping action. | |
| Modificada | Alta (7.2) | 1.7% | — | Linksys Wumc710 Firmware | 9/1/2023 | 17/6/2026 | An arbitrary code exection vulnerability exists in Linksys WUMC710 Wireless-AC Universal Media Connector with firmware <= 1.0.02 (build3). The do_setNTP function within the httpd binary uses unvalidated user input in the construction of a system command. An authenticated attacker with administrator privileges can… | |
| Modificada | Alta (7.2) | 19% | — | Linksys Wrt54gl Firmware | 9/1/2023 | 17/6/2026 | A buffer overflow vulnerability exists in Linksys WRT54GL Wireless-G Broadband Router with firmware <= 4.30.18.006. A stack-based buffer overflow in the Start_EPI function within the httpd binary allows an authenticated attacker with administrator privileges to execute arbitrary commands on the underlying Linux… | |
| Analizada | Alta (7.2) | 1.9% | 💥 PoC | Linksoftwarellc Html Forms | 28/11/2022 | 17/6/2026 | The HTML Forms WordPress plugin before 1.3.25 does not properly properly escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users |