Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
621 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.2) | 14% | 💥 Exploit | Linksys E1200 FirmwareLinksys E2500 Firmware | 17/10/2018 | 17/6/2026 | Devices in the Linksys ESeries line of routers (Linksys E1200 Firmware Version 2.0.09 and Linksys E2500 Firmware Version 3.0.04) are susceptible to OS command injection vulnerabilities due to improper filtering of data passed to and retrieved from NVRAM. Data entered into the 'Router Name' input field through the web… | |
| Modificada | Alta (8.8) | 2.5% | — | Linksys Velop Firmware | 19/9/2018 | 17/6/2026 | Linksys Velop 1.1.2.187020 devices allow unauthenticated command injection, providing an attacker with full root access, via cgi-bin/zbtest.cgi or cgi-bin/zbtest2.cgi (scripts that can be discovered with binwalk on the firmware, but are not visible in the web interface). This occurs because shell metacharacters in the… | |
| Modificada | Media (6.1) | 0.89% | — | Atlassian Application Links | 14/5/2018 | 17/6/2026 | The invalidRedirectUrl template in Atlassian Application Links before version 5.2.7, from version 5.3.0 before version 5.3.4 and from version 5.4.0 before version 5.4.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the redirectUrl parameter link in the… | |
| Modificada | Media (4.8) | 0.60% | — | Atlassian Application Links | 10/4/2018 | 17/6/2026 | Various administrative application link resources in Atlassian Application Links before version 5.4.4 allow remote attackers with administration rights to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the display url of a configured application link. | |
| Modificada | Alta (7.2) | 1.2% | — | Atlassian Application Links | 4/4/2018 | 17/6/2026 | The OAuth status rest resource in Atlassian Application Links before version 5.2.7, from 5.3.0 before 5.3.4 and from 5.4.0 before 5.4.3 allows remote attackers with administrative rights to access the content of internal network resources via a Server Side Request Forgery (SSRF) by creating an OAuth application link… | |
| Modificada | Media (5.9) | 0.66% | — | ElinksTwibright Links | 23/2/2018 | 16/6/2026 | ELinks 0.12 and Twibright Links 2.3 have Missing SSL Certificate Validation. | |
| Modificada | Crítica (9.8) | 88% | 💥 Exploit | Linksys Wvbr0 Firmware | 21/12/2017 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Linksys WVBR0. Authentication is not required to exploit this vulnerability. The specific flaw exists within the web management portal. The issue lies in the lack of proper validation of user data before executing a… | |
| Modificada | Alta (8.8) | 2.0% | — | Inlinks Project Inlinks | 27/11/2017 | 17/6/2026 | SQL injection vulnerability in the InLinks plugin through 1.1 for WordPress allows authenticated users to execute arbitrary SQL commands via the "keyword" parameter to /wp-admin/options-general.php?page=inlinks/inlinks.php. | |
| Modificada | Crítica (9.8) | 2.7% | 💥 Exploit | Protectedlinks Expiring Download Links | 31/10/2017 | 17/6/2026 | Protected Links - Expiring Download Links 1.0 allows SQL Injection via the username parameter. | |
| Modificada | Media (6.1) | 0.95% | — | WP NO External Links Project WP NO External Links | 24/10/2017 | 17/6/2026 | Cross Site Scripting (XSS) exists in the wp-noexternallinks plugin before 3.5.19 for WordPress via the date1 or date2 parameter to wp-admin/options-general.php. | |
| Modificada | Alta (8.8) | 3.5% | 💥 Exploit | Teamworktec JOB Links | 28/9/2017 | 17/6/2026 | TeamWork Job Links allows Arbitrary File Upload in profileChange and coverChange. | |
| Modificada | Alta (8.8) | 0.48% | — | Linksys Ea4500 Firmware | 6/8/2017 | 17/6/2026 | Cross-Site Request Forgery (CSRF) exists on Linksys EA4500 devices with Firmware Version before 2.1.41.164606, as demonstrated by a request to apply.cgi to disable SIP. | |
| Modificada | Media (5.5) | 0.89% | — | Twibright Links | 31/7/2017 | 17/6/2026 | The put_chars function in html_r.c in Twibright Links 2.14 allows remote attackers to cause a denial of service (buffer over-read) via a crafted HTML file. | |
| Modificada | Media (6.1) | 1.8% | — | Nofollow Links Project Nofollow Links | 3/8/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Nofollow Links plugin before 1.0.11 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Baja (3.5) | 0.97% | — | WEB Links Project WEB Links | 18/8/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Web Links module 6.x-2.x before 6.x-2.6 and 7.x-1.x before 7.x-1.0 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Baja (2.6) | 1.2% | — | Current Search Links Project Current Search Links | 15/6/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Current Search Links module 7.x-1.x before 7.x-1.1 for Drupal, when the "Append the keywords passed by the user to the list" option is disabled, allows remote attackers to inject arbitrary web script or HTML via a crafted search query. | |
| Modificada | Media (4.3) | 1.1% | — | Inlinks Project Inlinks | 15/6/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the inLinks Integration module for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified path arguments. | |
| Modificada | Media (4.3) | 1.9% | — | Allomani Weblinks | 4/11/2014 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Allomani Weblinks 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) default URI to admin.php or the (2) id parameter to admin.php or (3) go.php. | |
| Modificada | Alta (7.5) | 4.0% | 💥 PoC | Linksys Ea3500 FirmwareLinksys Ea3500Linksys Ea6700 FirmwareLinksys Ea6700+16 | 1/11/2014 | 17/6/2026 | Linksys SMART WiFi firmware on EA2700 and EA3500 devices; before 2.1.41 build 162351 on E4200v2 and EA4500 devices; before 1.1.41 build 162599 on EA6200 devices; before 1.1.40 build 160989 on EA6300, EA6400, EA6500, and EA6700 devices; and before 1.1.42 build 161129 on EA6900 devices allows remote attackers to obtain… | |
| Modificada | Baja (3.3) | 1.2% | — | Linksys Ea4500 FirmwareLinksys Ea4500Linksys Ea6500 FirmwareLinksys Ea6500+16 | 1/11/2014 | 17/6/2026 | Linksys SMART WiFi firmware on EA2700 and EA3500 devices; before 2.1.41 build 162351 on E4200v2 and EA4500 devices; before 1.1.41 build 162599 on EA6200 devices; before 1.1.40 build 160989 on EA6300, EA6400, EA6500, and EA6700 devices; and before 1.1.42 build 161129 on EA6900 devices allows remote attackers to obtain… | |
| Modificada | Alta (7.5) | 2.1% | — | Allomani Weblinks | 14/10/2014 | 17/6/2026 | Multiple SQL injection vulnerabilities in Allomani Weblinks 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) cat parameter in a browse action to index.php or (2) unspecified parameters to admin.php. | |
| Modificada | Media (4.3) | 0.94% | — | External Links Click Statistics Project External Links Click Statistics | 3/10/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the External links click statistics (outstats) extension 0.0.3 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (6.8) | 0.61% | — | Cisco Linksys Wrt310n Router FirmwareCisco Linksys Wrt350n | 29/9/2014 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in apply.cgi in Linksys WRT310Nv2 2.0.0.1 allows remote attackers to hijack the authentication of administrators for requests that change passwords and modify remote management ports. | |
| Modificada | Alta (7.1) | 2.1% | — | Linksys Ea6500 FirmwareLinksys Ea6500 | 29/9/2014 | 16/6/2026 | Linksys EA6500 with firmware 1.1.28.147876 does not properly restrict access, which allows remote attackers to obtain sensitive information (clients and router configuration) via a request to /JNAP/. | |
| Modificada | Baja (3.5) | 0.78% | — | Linksys Ea6500 FirmwareLinksys Ea6500 | 29/9/2014 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Parental Controls section in Linksys EA6500 with firmware 1.1.28.147876 allows remote authenticated users to inject arbitrary web script or HTML via vectors related to the Blocked Specific Sites section. |