Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

621 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.2)14%💥 ExploitLinksys E1200 FirmwareLinksys E2500 Firmware17/10/201817/6/2026
Devices in the Linksys ESeries line of routers (Linksys E1200 Firmware Version 2.0.09 and Linksys E2500 Firmware Version 3.0.04) are susceptible to OS command injection vulnerabilities due to improper filtering of data passed to and retrieved from NVRAM. Data entered into the 'Router Name' input field through the web…
ModificadaAlta (8.8)2.5%—Linksys Velop Firmware19/9/201817/6/2026
Linksys Velop 1.1.2.187020 devices allow unauthenticated command injection, providing an attacker with full root access, via cgi-bin/zbtest.cgi or cgi-bin/zbtest2.cgi (scripts that can be discovered with binwalk on the firmware, but are not visible in the web interface). This occurs because shell metacharacters in the…
ModificadaMedia (6.1)0.89%—Atlassian Application Links14/5/201817/6/2026
The invalidRedirectUrl template in Atlassian Application Links before version 5.2.7, from version 5.3.0 before version 5.3.4 and from version 5.4.0 before version 5.4.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the redirectUrl parameter link in the…
ModificadaMedia (4.8)0.60%—Atlassian Application Links10/4/201817/6/2026
Various administrative application link resources in Atlassian Application Links before version 5.4.4 allow remote attackers with administration rights to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the display url of a configured application link.
ModificadaAlta (7.2)1.2%—Atlassian Application Links4/4/201817/6/2026
The OAuth status rest resource in Atlassian Application Links before version 5.2.7, from 5.3.0 before 5.3.4 and from 5.4.0 before 5.4.3 allows remote attackers with administrative rights to access the content of internal network resources via a Server Side Request Forgery (SSRF) by creating an OAuth application link…
ModificadaMedia (5.9)0.66%—ElinksTwibright Links23/2/201816/6/2026
ELinks 0.12 and Twibright Links 2.3 have Missing SSL Certificate Validation.
ModificadaCrítica (9.8)88%💥 ExploitLinksys Wvbr0 Firmware21/12/201717/6/2026
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Linksys WVBR0. Authentication is not required to exploit this vulnerability. The specific flaw exists within the web management portal. The issue lies in the lack of proper validation of user data before executing a…
ModificadaAlta (8.8)2.0%—Inlinks Project Inlinks27/11/201717/6/2026
SQL injection vulnerability in the InLinks plugin through 1.1 for WordPress allows authenticated users to execute arbitrary SQL commands via the "keyword" parameter to /wp-admin/options-general.php?page=inlinks/inlinks.php.
ModificadaCrítica (9.8)2.7%💥 ExploitProtectedlinks Expiring Download Links31/10/201717/6/2026
Protected Links - Expiring Download Links 1.0 allows SQL Injection via the username parameter.
ModificadaMedia (6.1)0.95%—WP NO External Links Project WP NO External Links24/10/201717/6/2026
Cross Site Scripting (XSS) exists in the wp-noexternallinks plugin before 3.5.19 for WordPress via the date1 or date2 parameter to wp-admin/options-general.php.
ModificadaAlta (8.8)3.5%💥 ExploitTeamworktec JOB Links28/9/201717/6/2026
TeamWork Job Links allows Arbitrary File Upload in profileChange and coverChange.
ModificadaAlta (8.8)0.48%—Linksys Ea4500 Firmware6/8/201717/6/2026
Cross-Site Request Forgery (CSRF) exists on Linksys EA4500 devices with Firmware Version before 2.1.41.164606, as demonstrated by a request to apply.cgi to disable SIP.
ModificadaMedia (5.5)0.89%—Twibright Links31/7/201717/6/2026
The put_chars function in html_r.c in Twibright Links 2.14 allows remote attackers to cause a denial of service (buffer over-read) via a crafted HTML file.
ModificadaMedia (6.1)1.8%—Nofollow Links Project Nofollow Links3/8/201617/6/2026
Cross-site scripting (XSS) vulnerability in the Nofollow Links plugin before 1.0.11 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaBaja (3.5)0.97%—WEB Links Project WEB Links18/8/201517/6/2026
Cross-site scripting (XSS) vulnerability in the Web Links module 6.x-2.x before 6.x-2.6 and 7.x-1.x before 7.x-1.0 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via unspecified vectors.
ModificadaBaja (2.6)1.2%—Current Search Links Project Current Search Links15/6/201517/6/2026
Cross-site scripting (XSS) vulnerability in the Current Search Links module 7.x-1.x before 7.x-1.1 for Drupal, when the "Append the keywords passed by the user to the list" option is disabled, allows remote attackers to inject arbitrary web script or HTML via a crafted search query.
ModificadaMedia (4.3)1.1%—Inlinks Project Inlinks15/6/201517/6/2026
Cross-site scripting (XSS) vulnerability in the inLinks Integration module for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified path arguments.
ModificadaMedia (4.3)1.9%—Allomani Weblinks4/11/201417/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Allomani Weblinks 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) default URI to admin.php or the (2) id parameter to admin.php or (3) go.php.
ModificadaAlta (7.5)4.0%💥 PoCLinksys Ea3500 FirmwareLinksys Ea3500Linksys Ea6700 FirmwareLinksys Ea6700+161/11/201417/6/2026
Linksys SMART WiFi firmware on EA2700 and EA3500 devices; before 2.1.41 build 162351 on E4200v2 and EA4500 devices; before 1.1.41 build 162599 on EA6200 devices; before 1.1.40 build 160989 on EA6300, EA6400, EA6500, and EA6700 devices; and before 1.1.42 build 161129 on EA6900 devices allows remote attackers to obtain…
ModificadaBaja (3.3)1.2%—Linksys Ea4500 FirmwareLinksys Ea4500Linksys Ea6500 FirmwareLinksys Ea6500+161/11/201417/6/2026
Linksys SMART WiFi firmware on EA2700 and EA3500 devices; before 2.1.41 build 162351 on E4200v2 and EA4500 devices; before 1.1.41 build 162599 on EA6200 devices; before 1.1.40 build 160989 on EA6300, EA6400, EA6500, and EA6700 devices; and before 1.1.42 build 161129 on EA6900 devices allows remote attackers to obtain…
ModificadaAlta (7.5)2.1%—Allomani Weblinks14/10/201417/6/2026
Multiple SQL injection vulnerabilities in Allomani Weblinks 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) cat parameter in a browse action to index.php or (2) unspecified parameters to admin.php.
ModificadaMedia (4.3)0.94%—External Links Click Statistics Project External Links Click Statistics3/10/201417/6/2026
Cross-site scripting (XSS) vulnerability in the External links click statistics (outstats) extension 0.0.3 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (6.8)0.61%—Cisco Linksys Wrt310n Router FirmwareCisco Linksys Wrt350n29/9/201416/6/2026
Cross-site request forgery (CSRF) vulnerability in apply.cgi in Linksys WRT310Nv2 2.0.0.1 allows remote attackers to hijack the authentication of administrators for requests that change passwords and modify remote management ports.
ModificadaAlta (7.1)2.1%—Linksys Ea6500 FirmwareLinksys Ea650029/9/201416/6/2026
Linksys EA6500 with firmware 1.1.28.147876 does not properly restrict access, which allows remote attackers to obtain sensitive information (clients and router configuration) via a request to /JNAP/.
ModificadaBaja (3.5)0.78%—Linksys Ea6500 FirmwareLinksys Ea650029/9/201416/6/2026
Cross-site scripting (XSS) vulnerability in the Parental Controls section in Linksys EA6500 with firmware 1.1.28.147876 allows remote authenticated users to inject arbitrary web script or HTML via vectors related to the Blocked Specific Sites section.
Orbitaley — Vulnerabilidades