Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

621 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.8)0.66%—SEO Smart Links Project SEO Smart Links26/9/202217/6/2026
The SEO Smart Links WordPress plugin through 3.0.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
ModificadaAlta (7.5)0.88%—Linksys E5350 Firmware12/9/202217/6/2026
On Linksys E5350 WiFi Router with firmware version 1.0.00.037 and lower, (and potentially other vendors/devices due to code reuse), the /SysInfo.htm URI does not require a session ID. This web page calls a show_sysinfo function which retrieves WPA passwords, SSIDs, MAC Addresses, serial numbers, WPS Pins, and…
ModificadaCrítica (9.8)9.8%—Linksys E1200 Firmware28/8/20229/7/2026
Linksys E1200 v1.0.04 is vulnerable to Buffer Overflow via ej_get_web_page_name.
ModificadaAlta (8.8)0.58%—Linksys Mr8300 Firmware24/8/202217/6/2026
Command injection vulnerability in Linksys MR8300 router while Registration to DDNS Service. By specifying username and password, an attacker connected to the router's web interface can execute arbitrary OS commands. The username and password fields are not sanitized correctly and are used as URL construction…
ModificadaMedia (4.8)0.59%—Mihdan\ NO External Links Project27/6/202217/6/2026
The Mihdan: No External Links WordPress plugin before 5.0.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
ModificadaMedia (6.5)0.41%—Amazon Einzeltitellinks Project Amazon Einzeltitellinks20/6/202217/6/2026
The Amazon Einzeltitellinks WordPress plugin through 1.3.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and lead to Stored Cross-Site Scripting due to the lack of sanitisation and escaping
ModificadaMedia (5.4)0.30%—RB Internal Links Project RB Internal Links13/6/202217/6/2026
The RB Internal Links WordPress plugin through 2.0.16 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack, as well as perform Stored Cross-Site Scripting attacks due to the lack of sanitisation and escaping
ModificadaMedia (6.5)1.3%—Webfactoryltd External Links IN NEW Window / NEW TAB30/5/202217/6/2026
The External Links in New Window / New Tab WordPress plugin before 1.43 does not ensure window.opener is set to "null" when links to external sites are clicked, which may enable tabnabbing attacks to occur.
ModificadaMedia (6.1)0.79%—Webfactoryltd External Links IN NEW Window / NEW TAB30/5/202217/6/2026
The External Links in New Window / New Tab WordPress plugin before 1.43 does not properly escape URLs it concatenates to onclick event handlers, which makes Stored Cross-Site Scripting attacks possible.
ModificadaMedia (4.6)0.47%—Linksys Mr9600 Firmware27/4/202217/6/2026
Linksys MR9600 devices before 2.0.5 allow attackers to read arbitrary files via a symbolic link to the root directory of a NAS SMB share.
ModificadaMedia (5.4)0.31%—Autolinks Project Autolinks18/4/202217/6/2026
The Autolinks WordPress plugin through 1.0.1 does not have CSRF check in place when updating its settings, and does not sanitise as well as escape them, which could allow attackers to perform Stored Cross-Site scripting against a logged in admin via a CSRF attack
ModificadaMedia (4.8)0.60%—Pootlepress Easy Smooth Scroll Links11/4/202217/6/2026
The Easy Smooth Scroll Links WordPress plugin before 2.23.1 does not sanitise and escape its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
ModificadaCrítica (9.1)37%💥 ExploitIclinks Scadaflex II FirmwareIclinks Weblib26/2/202217/6/2026
On ICL ScadaFlex II SCADA Controller SC-1 and SC-2 1.03.07 devices, unauthenticated remote attackers can overwrite, delete, or create files.
ModificadaMedia (5.4)0.62%—Wpdeveloper Betterlinks23/11/202117/6/2026
The BetterLinks WordPress plugin before 1.2.6 does not sanitise and escape some of imported link fields, which could lead to Stored Cross-Site Scripting issues when an admin import a malicious CSV.
ModificadaAlta (8.8)0.68%—SEO Backlinks Project SEO Backlinks2/8/202117/6/2026
The SEO Backlinks WordPress plugin is vulnerable to Cross-Site Request Forgery via the loc_config function found in the ~/seo-backlinks.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 4.0.1.
ModificadaAlta (8.8)4.6%—Belkin Linksys Wrt160nl Firmware2/2/202117/6/2026
The administration web interface on Belkin Linksys WRT160NL 1.0.04.002_US_20130619 devices allows remote authenticated attackers to execute system commands with root privileges via shell metacharacters in the ui_language POST parameter to the apply.cgi form endpoint. This occurs in do_upgrade_post in mini_httpd. NOTE:…
ModificadaAlta (7.5)4.0%—Linksys Re6500 Firmware26/12/202017/6/2026
Belkin LINKSYS RE6500 devices before 1.0.012.001 allow remote attackers to cause a persistent denial of service (segmentation fault) via a long /goform/langSwitch langSelectionOnly parameter.
ModificadaAlta (8.8)3.7%—Linksys Re6500 Firmware26/12/202017/6/2026
Belkin LINKSYS RE6500 devices before 1.0.012.001 allow remote authenticated users to execute arbitrary commands via shell metacharacters in a filename to the upload_settings.cgi page.
ModificadaAlta (8.8)2.7%—Linksys Re6500 Firmware26/12/202017/6/2026
Belkin LINKSYS RE6500 devices before 1.0.11.001 allow remote authenticated users to execute arbitrary commands via goform/systemCommand?command= in conjunction with the goform/pingstart program.
ModificadaCrítica (9.8)33%💥 ExploitLinksys Re6500 Firmware26/12/202017/6/2026
Belkin LINKSYS RE6500 devices before 1.0.012.001 allow remote attackers to execute arbitrary commands or set a new password via shell metacharacters to the goform/setSysAdm page.
ModificadaAlta (8.8)12%—Belkin Linksys WRT 160nl Firmware23/10/202017/6/2026
Belkin LINKSYS WRT160NL 1.0.04.002_US_20130619 devices have a stack-based buffer overflow vulnerability because of sprintf in create_dir in mini_httpd. Successful exploitation leads to arbitrary code execution. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
ModificadaMedia (4.3)0.75%—Atlassian Navigator Links3/6/202017/6/2026
The CustomAppsRestResource list resource in Atlassian Navigator Links before version 3.3.23, from version 4.0.0 before version 4.3.7, from version 5.0.0 before 5.0.1, and from version 5.1.0 before 5.1.1 allows remote attackers to enumerate all linked applications, including those that are restricted or otherwise…
ModificadaMedia (4.9)1.5%—Atlassian Application Links17/3/202017/6/2026
The EditApplinkServlet resource in the Atlassian Application Links plugin before version 5.4.20, from version 6.0.0 before version 6.0.12, from version 6.1.0 before version 6.1.2, from version 7.0.0 before version 7.0.1, and from version 7.1.0 before version 7.1.3 allows remote attackers who have obtained access to…
ModificadaMedia (6.1)20%💥 ExploitBelkin Linksys E4200 Firmware18/2/202016/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Cisco Linksys E4200 router with firmware 1.0.05 build 7 allow remote attackers to inject arbitrary web script or HTML via the (1) log_type, (2) ping_ip, (3) ping_size, (4) submit_type, or (5) traceroute_ip parameter to apply.cgi or (6) new_workgroup or (7)…
ModificadaAlta (8.8)1.4%—Linksys Spa2102 Firmware12/2/202016/6/2026
The SIP implementation on the Linksys SPA2102 phone adapter provides hashed credentials in a response to an invalid authentication challenge, which makes it easier for remote attackers to obtain access via a brute-force attack, related to a "SIP Digest Leak" issue.