Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

621 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.8)1.3%—Linksys Ea6500 FirmwareLinksys Ea650029/9/201416/6/2026
Open redirect vulnerability in ui/dynamic/unsecured.html in Linksys EA6500 with firmware 1.1.28.147876 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the target parameter.
ModificadaMedia (4.3)1.2%—Php365 365 LinksPhp365 365 Links+Php365 365 Links 2+Php365 365 Links218/9/201417/6/2026
Cross-site scripting (XSS) vulnerability in php365.com 365 Links 3.11 and earlier, 365 Links2 3.11 and earlier, 365 Links+ 2.10 and earlier, and 365 Links2+ 2.10 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (4.3)1.6%—Keyword Strategy Internal Links Project Keyword Strategy Internal Links2/7/201417/6/2026
Cross-site scripting (XSS) vulnerability in inpage.tpl.php in the Keyword Strategy Internal Links plugin 2.0 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the (1) sort, (2) search, or (3) dir parameter.
ModificadaAlta (7.5)1.3%💥 ExploitCacti Superlinks25/6/201417/6/2026
SQL injection vulnerability in superlinks.php in the superlinks plugin 1.4-2 for Cacti allows remote attackers to execute arbitrary SQL commands via the id parameter.
ModificadaMedia (4.3)6.3%💥 ExploitCaseproof PrettylinksJoobi COM JnewsCivicrm12/3/201416/6/2026
Cross-site scripting (XSS) vulnerability in open-flash-chart.swf in Open Flash Chart (aka Open-Flash Chart), as used in the Pretty Link Lite plugin before 1.6.3 for WordPress, JNews (com_jnews) component 8.0.1 for Joomla!, and CiviCRM 3.1.0 through 4.2.9 and 4.3.0 through 4.3.3, allows remote attackers to inject…
ModificadaMedia (4.3)1.2%—Twibright Links7/12/201316/6/2026
Integer overflow in Links before 2.8 allows remote attackers to cause a denial of service (crash) via crafted HTML tables.
ModificadaMedia (6.8)0.97%—Linksalpha Social Sharing Toolkit Plugin1/11/201316/6/2026
Cross-site request forgery (CSRF) vulnerability in the Social Sharing Toolkit plugin 2.1.1 for WordPress allows remote attackers to hijack the authentication of administrators for requests that manipulate plugin settings via unknown vectors.
ModificadaMedia (4.3)1.6%—Linksalpha Social Sharing Toolkit Plugin25/10/201317/6/2026
Cross-site scripting (XSS) vulnerability in Social Sharing Toolkit plugin before 2.1.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (5.1)1.9%—Elinks3/1/201316/6/2026
The http_negotiate_create_context function in protocol/http/http_negotiate.c in ELinks 0.12 before 0.12pre6, when using HTTP Negotiate or GSS-Negotiate authentication, delegates user credentials through GSSAPI, which allows remote servers to authenticate as the client via the delegated credentials.
ModificadaAlta (7.5)1.1%💥 ExploitJ Waite Php-x-links23/9/201216/6/2026
Multiple SQL injection vulnerabilities in Php-X-Links, possibly 1.0, allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to rate.php, (2) cid parameter to view.php, or (3) t parameter to pop.php.
ModificadaAlta (7.5)1.1%💥 ExploitJoomla COM Weblinks6/9/201216/6/2026
SQL injection vulnerability in the Weblinks (com_weblinks) component for Joomla! and Mambo 1.0.9 and earlier allows remote attackers to execute arbitrary SQL commands via the title parameter.
ModificadaBaja (3.5)0.94%—Wearepropeople Glossify Internal Links Auto SEO25/7/201216/6/2026
Cross-site scripting (XSS) vulnerability in the Glossify Internal Links Auto SEO module for Drupal 6.x-2.5 and earlier allows remote authenticated users with certain roles to inject arbitrary web script or HTML via unspecified vectors.
ModificadaAlta (9.3)36%💥 ExploitCisco Linksys Playerpt Activex Control19/7/201216/6/2026
Stack-based buffer overflow in the SetSource method in the Cisco Linksys PlayerPT ActiveX control 1.0.0.15 in PlayerPT.ocx on the Cisco WVC200 Wireless-G PTZ Internet video camera allows remote attackers to execute arbitrary code via a long URL in the first argument (aka the sURL argument).
ModificadaAlta (7.5)1.0%💥 ExploitPhpnuke Php-nukePhpnuke WEB Links Module14/2/201216/6/2026
SQL injection vulnerability in the Web_Links module for PHP-Nuke 8.0 allows remote attackers to execute arbitrary SQL commands via the url parameter in an Add action to modules.php.
ModificadaAlta (7.5)1.3%—Cisco Linksys Wrt54gx Router FirmwareLinksys Wrt54gx22/11/201116/6/2026
The UPnP IGD implementation on the Cisco Linksys WRT54GX with firmware 2.00.05, when UPnP is enabled, configures the SOAP server to listen on the WAN port, which allows remote attackers to administer the firewall via SOAP requests.
ModificadaAlta (7.5)1.3%—Cisco Linksys Wrt54g Router FirmwareLinksys Wrt54gCisco Linksys Wrt54gs Router FirmwareLinksys Wrt54gs22/11/201116/6/2026
The UPnP IGD implementation in the Broadcom UPnP stack on the Cisco Linksys WRT54G with firmware before 4.30.5, WRT54GS v1 through v3 with firmware before 4.71.1, and WRT54GS v4 with firmware before 1.06.1 allows remote attackers to establish arbitrary port mappings by sending a UPnP AddPortMapping action in a SOAP…
ModificadaAlta (7.5)0.90%💥 ExploitJoomla COM Weblinks9/10/201116/6/2026
SQL injection vulnerability in the Weblinks (com_weblinks) component in Joomla! allows remote attackers to execute arbitrary SQL commands via the Itemid parameter in a categories action to index.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
ModificadaMedia (4.3)1.1%—Axscripts Axslinks27/9/201116/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in addlink.php in AXScripts AxsLinks 0.3 allow remote attackers to inject arbitrary web script or HTML via the (1) url or (2) title parameter.
ModificadaAlta (7.5)0.99%💥 ExploitVlinks12/9/201116/6/2026
SQL injection vulnerability in page.php in Vlinks 1.0.3 and 1.1.6 allows remote attackers to execute arbitrary SQL commands via the id parameter.
ModificadaAlta (7.8)2.2%—Cisco Linksys Wrt54gc RouterCisco Linksys Wrt54gc Router Firmware24/1/201116/6/2026
Buffer overflow in the web-based management interface on the Cisco Linksys WRT54GC router with firmware before 1.06.1 allows remote attackers to cause a denial of service (device crash) via a long string in a POST request.
ModificadaAlta (7.5)1.1%💥 ExploitWSN LinksWSN LinksWsnlinks WSN Links3/11/201016/6/2026
Multiple SQL injection vulnerabilities in search.php in WSN Links 5.0.x before 5.0.81, 5.1.x before 5.1.51, and 6.0.x before 6.0.1 allow remote attackers to execute arbitrary SQL commands via the (1) namecondition or (2) namesearch parameter.
ModificadaAlta (7.5)2.8%💥 ExploitSilvercover Mylinksdump Plugin30/7/201016/6/2026
SQL injection vulnerability in myLDlinker.php in the myLinksDump Plugin 1.2 for WordPress allows remote attackers to execute arbitrary SQL commands via the url parameter. NOTE: some of these details are obtained from third party information.
ModificadaAlta (7.5)0.97%💥 ExploitJoomla COM WeblinksJoomla!8/7/201016/6/2026
SQL injection vulnerability in the Weblinks (com_weblinks) component in Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a view action to index.php.
ModificadaAlta (7.5)13%💥 ExploitMiyabi-seo CGI Tools SEO Links2/7/201016/6/2026
index.pl in Miyabi CGI Tools SEO Links 1.02 allows remote attackers to execute arbitrary commands via shell metacharacters in the fn command. NOTE: some of these details are obtained from third party information.
ModificadaBaja (2.9)0.66%—Cisco Linksys FirmwareCisco Linksys Wap54g28/6/201016/6/2026
Cross-site scripting (XSS) vulnerability in debug.cgi in Linksys WAP54Gv3 firmware 3.05.03 and 3.04.03 allows remote attackers to inject arbitrary web script or HTML via the data1 parameter.
Orbitaley — Vulnerabilidades