Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
621 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.8) | 0.66% | — | SEO Smart Links Project SEO Smart Links | 26/9/2022 | 17/6/2026 | The SEO Smart Links WordPress plugin through 3.0.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Alta (7.5) | 0.88% | — | Linksys E5350 Firmware | 12/9/2022 | 17/6/2026 | On Linksys E5350 WiFi Router with firmware version 1.0.00.037 and lower, (and potentially other vendors/devices due to code reuse), the /SysInfo.htm URI does not require a session ID. This web page calls a show_sysinfo function which retrieves WPA passwords, SSIDs, MAC Addresses, serial numbers, WPS Pins, and… | |
| Modificada | Crítica (9.8) | 9.8% | — | Linksys E1200 Firmware | 28/8/2022 | 9/7/2026 | Linksys E1200 v1.0.04 is vulnerable to Buffer Overflow via ej_get_web_page_name. | |
| Modificada | Alta (8.8) | 0.58% | — | Linksys Mr8300 Firmware | 24/8/2022 | 17/6/2026 | Command injection vulnerability in Linksys MR8300 router while Registration to DDNS Service. By specifying username and password, an attacker connected to the router's web interface can execute arbitrary OS commands. The username and password fields are not sanitized correctly and are used as URL construction… | |
| Modificada | Media (4.8) | 0.59% | — | Mihdan\ NO External Links Project | 27/6/2022 | 17/6/2026 | The Mihdan: No External Links WordPress plugin before 5.0.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Media (6.5) | 0.41% | — | Amazon Einzeltitellinks Project Amazon Einzeltitellinks | 20/6/2022 | 17/6/2026 | The Amazon Einzeltitellinks WordPress plugin through 1.3.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and lead to Stored Cross-Site Scripting due to the lack of sanitisation and escaping | |
| Modificada | Media (5.4) | 0.30% | — | RB Internal Links Project RB Internal Links | 13/6/2022 | 17/6/2026 | The RB Internal Links WordPress plugin through 2.0.16 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack, as well as perform Stored Cross-Site Scripting attacks due to the lack of sanitisation and escaping | |
| Modificada | Media (6.5) | 1.3% | — | Webfactoryltd External Links IN NEW Window / NEW TAB | 30/5/2022 | 17/6/2026 | The External Links in New Window / New Tab WordPress plugin before 1.43 does not ensure window.opener is set to "null" when links to external sites are clicked, which may enable tabnabbing attacks to occur. | |
| Modificada | Media (6.1) | 0.79% | — | Webfactoryltd External Links IN NEW Window / NEW TAB | 30/5/2022 | 17/6/2026 | The External Links in New Window / New Tab WordPress plugin before 1.43 does not properly escape URLs it concatenates to onclick event handlers, which makes Stored Cross-Site Scripting attacks possible. | |
| Modificada | Media (4.6) | 0.47% | — | Linksys Mr9600 Firmware | 27/4/2022 | 17/6/2026 | Linksys MR9600 devices before 2.0.5 allow attackers to read arbitrary files via a symbolic link to the root directory of a NAS SMB share. | |
| Modificada | Media (5.4) | 0.31% | — | Autolinks Project Autolinks | 18/4/2022 | 17/6/2026 | The Autolinks WordPress plugin through 1.0.1 does not have CSRF check in place when updating its settings, and does not sanitise as well as escape them, which could allow attackers to perform Stored Cross-Site scripting against a logged in admin via a CSRF attack | |
| Modificada | Media (4.8) | 0.60% | — | Pootlepress Easy Smooth Scroll Links | 11/4/2022 | 17/6/2026 | The Easy Smooth Scroll Links WordPress plugin before 2.23.1 does not sanitise and escape its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed | |
| Modificada | Crítica (9.1) | 37% | 💥 Exploit | Iclinks Scadaflex II FirmwareIclinks Weblib | 26/2/2022 | 17/6/2026 | On ICL ScadaFlex II SCADA Controller SC-1 and SC-2 1.03.07 devices, unauthenticated remote attackers can overwrite, delete, or create files. | |
| Modificada | Media (5.4) | 0.62% | — | Wpdeveloper Betterlinks | 23/11/2021 | 17/6/2026 | The BetterLinks WordPress plugin before 1.2.6 does not sanitise and escape some of imported link fields, which could lead to Stored Cross-Site Scripting issues when an admin import a malicious CSV. | |
| Modificada | Alta (8.8) | 0.68% | — | SEO Backlinks Project SEO Backlinks | 2/8/2021 | 17/6/2026 | The SEO Backlinks WordPress plugin is vulnerable to Cross-Site Request Forgery via the loc_config function found in the ~/seo-backlinks.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 4.0.1. | |
| Modificada | Alta (8.8) | 4.6% | — | Belkin Linksys Wrt160nl Firmware | 2/2/2021 | 17/6/2026 | The administration web interface on Belkin Linksys WRT160NL 1.0.04.002_US_20130619 devices allows remote authenticated attackers to execute system commands with root privileges via shell metacharacters in the ui_language POST parameter to the apply.cgi form endpoint. This occurs in do_upgrade_post in mini_httpd. NOTE:… | |
| Modificada | Alta (7.5) | 4.0% | — | Linksys Re6500 Firmware | 26/12/2020 | 17/6/2026 | Belkin LINKSYS RE6500 devices before 1.0.012.001 allow remote attackers to cause a persistent denial of service (segmentation fault) via a long /goform/langSwitch langSelectionOnly parameter. | |
| Modificada | Alta (8.8) | 3.7% | — | Linksys Re6500 Firmware | 26/12/2020 | 17/6/2026 | Belkin LINKSYS RE6500 devices before 1.0.012.001 allow remote authenticated users to execute arbitrary commands via shell metacharacters in a filename to the upload_settings.cgi page. | |
| Modificada | Alta (8.8) | 2.7% | — | Linksys Re6500 Firmware | 26/12/2020 | 17/6/2026 | Belkin LINKSYS RE6500 devices before 1.0.11.001 allow remote authenticated users to execute arbitrary commands via goform/systemCommand?command= in conjunction with the goform/pingstart program. | |
| Modificada | Crítica (9.8) | 33% | 💥 Exploit | Linksys Re6500 Firmware | 26/12/2020 | 17/6/2026 | Belkin LINKSYS RE6500 devices before 1.0.012.001 allow remote attackers to execute arbitrary commands or set a new password via shell metacharacters to the goform/setSysAdm page. | |
| Modificada | Alta (8.8) | 12% | — | Belkin Linksys WRT 160nl Firmware | 23/10/2020 | 17/6/2026 | Belkin LINKSYS WRT160NL 1.0.04.002_US_20130619 devices have a stack-based buffer overflow vulnerability because of sprintf in create_dir in mini_httpd. Successful exploitation leads to arbitrary code execution. NOTE: This vulnerability only affects products that are no longer supported by the maintainer | |
| Modificada | Media (4.3) | 0.75% | — | Atlassian Navigator Links | 3/6/2020 | 17/6/2026 | The CustomAppsRestResource list resource in Atlassian Navigator Links before version 3.3.23, from version 4.0.0 before version 4.3.7, from version 5.0.0 before 5.0.1, and from version 5.1.0 before 5.1.1 allows remote attackers to enumerate all linked applications, including those that are restricted or otherwise… | |
| Modificada | Media (4.9) | 1.5% | — | Atlassian Application Links | 17/3/2020 | 17/6/2026 | The EditApplinkServlet resource in the Atlassian Application Links plugin before version 5.4.20, from version 6.0.0 before version 6.0.12, from version 6.1.0 before version 6.1.2, from version 7.0.0 before version 7.0.1, and from version 7.1.0 before version 7.1.3 allows remote attackers who have obtained access to… | |
| Modificada | Media (6.1) | 20% | 💥 Exploit | Belkin Linksys E4200 Firmware | 18/2/2020 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Cisco Linksys E4200 router with firmware 1.0.05 build 7 allow remote attackers to inject arbitrary web script or HTML via the (1) log_type, (2) ping_ip, (3) ping_size, (4) submit_type, or (5) traceroute_ip parameter to apply.cgi or (6) new_workgroup or (7)… | |
| Modificada | Alta (8.8) | 1.4% | — | Linksys Spa2102 Firmware | 12/2/2020 | 16/6/2026 | The SIP implementation on the Linksys SPA2102 phone adapter provides hashed credentials in a response to an invalid authentication challenge, which makes it easier for remote attackers to obtain access via a brute-force attack, related to a "SIP Digest Leak" issue. |