Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
621 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.76% | — | Linksys Wrt310n Firmware | 7/2/2020 | 16/6/2026 | Linksys WRT310Nv2 2.0.0.1 is vulnerable to XSS. | |
| Modificada | Alta (8.8) | 25% | 💥 Exploit | Cisco Linksys Wrt110 Firmware | 6/2/2020 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in Cisco Linksys WRT110 allows remote attackers to hijack the authentication of users for requests that have unspecified impact via unknown vectors. | |
| Modificada | Media (6.1) | 3.7% | 💥 Exploit | Cisco Linksys E4200 Firmware | 6/2/2020 | 16/6/2026 | Cross-site Scripting (XSS) in Cisco Linksys E4200 1.0.05 Build 7 devices allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (5.3) | 13% | 💥 Exploit | Cisco Linksys E4200 Firmware | 6/2/2020 | 16/6/2026 | Cisco Linksys E4200 1.0.05 Build 7 devices contain an Information Disclosure Vulnerability which allows remote attackers to obtain private IP addresses and other sensitive information. | |
| Modificada | Media (4.3) | 6.3% | 💥 Exploit | Cisco Linksys E4200 Firmware | 5/2/2020 | 16/6/2026 | Cisco Linksys E4200 1.0.05 Build 7 devices contain a Clickjacking Vulnerability which allows remote attackers to obtain sensitive information. | |
| Modificada | Crítica (9.8) | 10% | 💥 Exploit | Cisco Linksys E4200 Firmware | 5/2/2020 | 16/6/2026 | Cisco Linksys E4200 1.0.05 Build 7 devices contain a Security Bypass Vulnerability which could allow remote attackers to gain unauthorized access. | |
| Modificada | Alta (7.5) | 8.7% | 💥 Exploit | Cisco Linksys E4200 Firmware | 5/2/2020 | 16/6/2026 | Cisco Linksys E4200 1.0.05 Build 7 devices store passwords in cleartext allowing remote attackers to obtain sensitive information. | |
| Modificada | Alta (8.1) | 17% | 💥 Exploit | Cisco Linksys E4200 Firmware | 4/2/2020 | 16/6/2026 | Cisco Linksys E4200 1.0.05 Build 7 routers contain a Local File Include Vulnerability which could allow remote attackers to obtain sensitive information or execute arbitrary code by sending a crafted URL request to the apply.cgi script using the submit_type parameter. | |
| Modificada | Media (6.1) | 2.4% | 💥 Exploit | Caseproof Prettylinks | 10/1/2020 | 16/6/2026 | Pretty-Link WordPress plugin 1.5.2 has XSS | |
| Modificada | Crítica (9.8) | 3.7% | — | Cisco Linksys Ea2700 FirmwareCisco Linksys Ea3500 FirmwareCisco Linksys E4200 FirmwareCisco Linksys Ea4500 Firmware | 7/1/2020 | 16/6/2026 | Cisco Linksys Routers EA2700, EA3500, E4200, EA4500: A bug can cause an unsafe TCP port to open which leads to unauthenticated access | |
| Modificada | Media (4.3) | 0.92% | — | Atlassian Application Links | 17/12/2019 | 17/6/2026 | The ListEntityLinksServlet resource in Application Links before version 5.0.12, from version 5.1.0 before version 5.2.11, from version 5.3.0 before version 5.3.7, from version 5.4.0 before 5.4.13, and from version 6.0.0 before 6.0.5 disclosed application link information to non-admin users via a missing permissions… | |
| Modificada | Crítica (9.8) | 19% | — | Linksys Velop Whw0303 FirmwareLinksys Velop Whw0302 FirmwareLinksys Velop Whw0301 Firmware | 21/11/2019 | 17/6/2026 | Belkin Linksys Velop 1.1.8.192419 devices allows remote attackers to discover the recovery key via a direct request for the /sysinfo_json.cgi URI. | |
| Modificada | Crítica (9.8) | 9.3% | — | Linksys Ea6500 Firmware | 25/10/2019 | 16/6/2026 | Linksys EA6500 has SMB Symlink Traversal allowing symbolic links to be created to locations outside of the Samba share. | |
| Modificada | Media (6.1) | 1.0% | — | Syndication Links Project Syndication Links | 22/10/2019 | 17/6/2026 | The syndication-links plugin before 1.0.3 for WordPress has XSS via the genericons/example.html anchor identifier. | |
| Modificada | Media (6.1) | 1.3% | — | Monitorbacklinks Incoming Links | 10/10/2019 | 17/6/2026 | The incoming-links plugin before 0.9.10b for WordPress has referrers.php XSS via the Referer HTTP header. | |
| Modificada | Alta (7.2) | 1.9% | — | Caseproof Prettylinks | 10/10/2019 | 17/6/2026 | The pretty-link plugin before 1.6.8 for WordPress has PrliLinksController::list_links SQL injection via the group parameter. | |
| Modificada | Alta (8.8) | 0.70% | — | WP Better Permalinks Project WP Better Permalinks | 30/8/2019 | 17/6/2026 | The wp-better-permalinks plugin before 3.0.5 for WordPress has CSRF. | |
| Modificada | Crítica (9.8) | 5.1% | — | Linksys Re6400 FirmwareLinksys Re6300 Firmware | 17/7/2019 | 17/6/2026 | Unsanitized user input in the web interface for Linksys WiFi extender products (RE6400 and RE6300 through 1.2.04.022) allows for remote command execution. An attacker can access system OS configurations and commands that are not intended for use beyond the web UI. | |
| Modificada | Alta (7.5) | 1.8% | — | Linksys Wrt1900acs Firmware | 17/6/2019 | 17/6/2026 | An issue was discovered on Linksys WRT1900ACS 1.0.3.187766 devices. An ability exists for an unauthenticated user to browse a confidential ui/1.0.99.187766/dynamic/js/setup.js.localized file on the router's webserver, allowing for an attacker to identify possible passwords that the system uses to set the default guest… | |
| Modificada | Alta (8.8) | 5.8% | — | Linksys Wag54g2 Firmware | 11/6/2019 | 16/6/2026 | On Linksys WAG54G2 1.00.10 devices, there is authenticated command injection via shell metacharacters in the setup.cgi c4_ping_ipaddr variable. | |
| Modificada | Alta (7.8) | 0.18% | — | Linksys Wrt1900acs Firmware | 6/6/2019 | 17/6/2026 | An issue was discovered on Linksys WRT1900ACS 1.0.3.187766 devices. A lack of encryption in how the user login cookie (admin-auth) is stored on a victim's computer results in the admin password being discoverable by a local attacker, and usable to gain administrative access to the victim's router. The admin password… | |
| Modificada | Media (5.4) | 3.3% | — | Atlassian Application LinksAtlassian Confluence Data CenterAtlassian Confluence ServerAtlassian Crowd+4 | 30/4/2019 | 17/6/2026 | Application Links before version 5.0.11, from version 5.1.0 before 5.2.10, from version 5.3.0 before 5.3.6, from version 5.4.0 before 5.4.12, and from version 6.0.0 before 6.0.4 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the applinkStartingUrl… | |
| Modificada | Alta (8.7) | 1.6% | — | Atlassian Application Links | 29/3/2019 | 17/6/2026 | The OAuthHelper in Atlassian Application Links before version 5.0.10, from version 5.1.0 before version 5.1.3, and from version 5.2.0 before version 5.2.6 used an XML document builder that was vulnerable to XXE when consuming a client OAuth request. This allowed malicious oauth application linked applications to probe… | |
| Modificada | Alta (7.2) | 4.8% | — | Linksys E1200 FirmwareLinksys E2500 Firmware | 17/10/2018 | 17/6/2026 | An exploitable operating system command injection exists in the Linksys ESeries line of routers (Linksys E1200 Firmware Version 2.0.09 and Linksys E2500 Firmware Version 3.0.04). Specially crafted entries to network configuration information can cause execution of arbitrary system commands, resulting in full control… | |
| Modificada | Alta (7.2) | 3.4% | — | Linksys E1200 FirmwareLinksys E2500 Firmware | 17/10/2018 | 17/6/2026 | Devices in the Linksys ESeries line of routers (Linksys E1200 Firmware Version 2.0.09 and Linksys E2500 Firmware Version 3.0.04) are susceptible to OS command injection vulnerabilities due to improper filtering of data passed to and retrieved from NVRAMData entered into the 'Router Name' input field through the web… |