Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

621 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)0.76%—Linksys Wrt310n Firmware7/2/202016/6/2026
Linksys WRT310Nv2 2.0.0.1 is vulnerable to XSS.
ModificadaAlta (8.8)25%💥 ExploitCisco Linksys Wrt110 Firmware6/2/202016/6/2026
Cross-site request forgery (CSRF) vulnerability in Cisco Linksys WRT110 allows remote attackers to hijack the authentication of users for requests that have unspecified impact via unknown vectors.
ModificadaMedia (6.1)3.7%💥 ExploitCisco Linksys E4200 Firmware6/2/202016/6/2026
Cross-site Scripting (XSS) in Cisco Linksys E4200 1.0.05 Build 7 devices allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (5.3)13%💥 ExploitCisco Linksys E4200 Firmware6/2/202016/6/2026
Cisco Linksys E4200 1.0.05 Build 7 devices contain an Information Disclosure Vulnerability which allows remote attackers to obtain private IP addresses and other sensitive information.
ModificadaMedia (4.3)6.3%💥 ExploitCisco Linksys E4200 Firmware5/2/202016/6/2026
Cisco Linksys E4200 1.0.05 Build 7 devices contain a Clickjacking Vulnerability which allows remote attackers to obtain sensitive information.
ModificadaCrítica (9.8)10%💥 ExploitCisco Linksys E4200 Firmware5/2/202016/6/2026
Cisco Linksys E4200 1.0.05 Build 7 devices contain a Security Bypass Vulnerability which could allow remote attackers to gain unauthorized access.
ModificadaAlta (7.5)8.7%💥 ExploitCisco Linksys E4200 Firmware5/2/202016/6/2026
Cisco Linksys E4200 1.0.05 Build 7 devices store passwords in cleartext allowing remote attackers to obtain sensitive information.
ModificadaAlta (8.1)17%💥 ExploitCisco Linksys E4200 Firmware4/2/202016/6/2026
Cisco Linksys E4200 1.0.05 Build 7 routers contain a Local File Include Vulnerability which could allow remote attackers to obtain sensitive information or execute arbitrary code by sending a crafted URL request to the apply.cgi script using the submit_type parameter.
ModificadaMedia (6.1)2.4%💥 ExploitCaseproof Prettylinks10/1/202016/6/2026
Pretty-Link WordPress plugin 1.5.2 has XSS
ModificadaCrítica (9.8)3.7%—Cisco Linksys Ea2700 FirmwareCisco Linksys Ea3500 FirmwareCisco Linksys E4200 FirmwareCisco Linksys Ea4500 Firmware7/1/202016/6/2026
Cisco Linksys Routers EA2700, EA3500, E4200, EA4500: A bug can cause an unsafe TCP port to open which leads to unauthenticated access
ModificadaMedia (4.3)0.92%—Atlassian Application Links17/12/201917/6/2026
The ListEntityLinksServlet resource in Application Links before version 5.0.12, from version 5.1.0 before version 5.2.11, from version 5.3.0 before version 5.3.7, from version 5.4.0 before 5.4.13, and from version 6.0.0 before 6.0.5 disclosed application link information to non-admin users via a missing permissions…
ModificadaCrítica (9.8)19%—Linksys Velop Whw0303 FirmwareLinksys Velop Whw0302 FirmwareLinksys Velop Whw0301 Firmware21/11/201917/6/2026
Belkin Linksys Velop 1.1.8.192419 devices allows remote attackers to discover the recovery key via a direct request for the /sysinfo_json.cgi URI.
ModificadaCrítica (9.8)9.3%—Linksys Ea6500 Firmware25/10/201916/6/2026
Linksys EA6500 has SMB Symlink Traversal allowing symbolic links to be created to locations outside of the Samba share.
ModificadaMedia (6.1)1.0%—Syndication Links Project Syndication Links22/10/201917/6/2026
The syndication-links plugin before 1.0.3 for WordPress has XSS via the genericons/example.html anchor identifier.
ModificadaMedia (6.1)1.3%—Monitorbacklinks Incoming Links10/10/201917/6/2026
The incoming-links plugin before 0.9.10b for WordPress has referrers.php XSS via the Referer HTTP header.
ModificadaAlta (7.2)1.9%—Caseproof Prettylinks10/10/201917/6/2026
The pretty-link plugin before 1.6.8 for WordPress has PrliLinksController::list_links SQL injection via the group parameter.
ModificadaAlta (8.8)0.70%—WP Better Permalinks Project WP Better Permalinks30/8/201917/6/2026
The wp-better-permalinks plugin before 3.0.5 for WordPress has CSRF.
ModificadaCrítica (9.8)5.1%—Linksys Re6400 FirmwareLinksys Re6300 Firmware17/7/201917/6/2026
Unsanitized user input in the web interface for Linksys WiFi extender products (RE6400 and RE6300 through 1.2.04.022) allows for remote command execution. An attacker can access system OS configurations and commands that are not intended for use beyond the web UI.
ModificadaAlta (7.5)1.8%—Linksys Wrt1900acs Firmware17/6/201917/6/2026
An issue was discovered on Linksys WRT1900ACS 1.0.3.187766 devices. An ability exists for an unauthenticated user to browse a confidential ui/1.0.99.187766/dynamic/js/setup.js.localized file on the router's webserver, allowing for an attacker to identify possible passwords that the system uses to set the default guest…
ModificadaAlta (8.8)5.8%—Linksys Wag54g2 Firmware11/6/201916/6/2026
On Linksys WAG54G2 1.00.10 devices, there is authenticated command injection via shell metacharacters in the setup.cgi c4_ping_ipaddr variable.
ModificadaAlta (7.8)0.18%—Linksys Wrt1900acs Firmware6/6/201917/6/2026
An issue was discovered on Linksys WRT1900ACS 1.0.3.187766 devices. A lack of encryption in how the user login cookie (admin-auth) is stored on a victim's computer results in the admin password being discoverable by a local attacker, and usable to gain administrative access to the victim's router. The admin password…
ModificadaMedia (5.4)3.3%—Atlassian Application LinksAtlassian Confluence Data CenterAtlassian Confluence ServerAtlassian Crowd+430/4/201917/6/2026
Application Links before version 5.0.11, from version 5.1.0 before 5.2.10, from version 5.3.0 before 5.3.6, from version 5.4.0 before 5.4.12, and from version 6.0.0 before 6.0.4 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the applinkStartingUrl…
ModificadaAlta (8.7)1.6%—Atlassian Application Links29/3/201917/6/2026
The OAuthHelper in Atlassian Application Links before version 5.0.10, from version 5.1.0 before version 5.1.3, and from version 5.2.0 before version 5.2.6 used an XML document builder that was vulnerable to XXE when consuming a client OAuth request. This allowed malicious oauth application linked applications to probe…
ModificadaAlta (7.2)4.8%—Linksys E1200 FirmwareLinksys E2500 Firmware17/10/201817/6/2026
An exploitable operating system command injection exists in the Linksys ESeries line of routers (Linksys E1200 Firmware Version 2.0.09 and Linksys E2500 Firmware Version 3.0.04). Specially crafted entries to network configuration information can cause execution of arbitrary system commands, resulting in full control…
ModificadaAlta (7.2)3.4%—Linksys E1200 FirmwareLinksys E2500 Firmware17/10/201817/6/2026
Devices in the Linksys ESeries line of routers (Linksys E1200 Firmware Version 2.0.09 and Linksys E2500 Firmware Version 3.0.04) are susceptible to OS command injection vulnerabilities due to improper filtering of data passed to and retrieved from NVRAMData entered into the 'Router Name' input field through the web…