Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
621 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.8) | 1.3% | — | Linksys Ea6500 FirmwareLinksys Ea6500 | 29/9/2014 | 16/6/2026 | Open redirect vulnerability in ui/dynamic/unsecured.html in Linksys EA6500 with firmware 1.1.28.147876 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the target parameter. | |
| Modificada | Media (4.3) | 1.2% | — | Php365 365 LinksPhp365 365 Links+Php365 365 Links 2+Php365 365 Links2 | 18/9/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in php365.com 365 Links 3.11 and earlier, 365 Links2 3.11 and earlier, 365 Links+ 2.10 and earlier, and 365 Links2+ 2.10 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (4.3) | 1.6% | — | Keyword Strategy Internal Links Project Keyword Strategy Internal Links | 2/7/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in inpage.tpl.php in the Keyword Strategy Internal Links plugin 2.0 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the (1) sort, (2) search, or (3) dir parameter. | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Cacti Superlinks | 25/6/2014 | 17/6/2026 | SQL injection vulnerability in superlinks.php in the superlinks plugin 1.4-2 for Cacti allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Media (4.3) | 6.3% | 💥 Exploit | Caseproof PrettylinksJoobi COM JnewsCivicrm | 12/3/2014 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in open-flash-chart.swf in Open Flash Chart (aka Open-Flash Chart), as used in the Pretty Link Lite plugin before 1.6.3 for WordPress, JNews (com_jnews) component 8.0.1 for Joomla!, and CiviCRM 3.1.0 through 4.2.9 and 4.3.0 through 4.3.3, allows remote attackers to inject… | |
| Modificada | Media (4.3) | 1.2% | — | Twibright Links | 7/12/2013 | 16/6/2026 | Integer overflow in Links before 2.8 allows remote attackers to cause a denial of service (crash) via crafted HTML tables. | |
| Modificada | Media (6.8) | 0.97% | — | Linksalpha Social Sharing Toolkit Plugin | 1/11/2013 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in the Social Sharing Toolkit plugin 2.1.1 for WordPress allows remote attackers to hijack the authentication of administrators for requests that manipulate plugin settings via unknown vectors. | |
| Modificada | Media (4.3) | 1.6% | — | Linksalpha Social Sharing Toolkit Plugin | 25/10/2013 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Social Sharing Toolkit plugin before 2.1.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (5.1) | 1.9% | — | Elinks | 3/1/2013 | 16/6/2026 | The http_negotiate_create_context function in protocol/http/http_negotiate.c in ELinks 0.12 before 0.12pre6, when using HTTP Negotiate or GSS-Negotiate authentication, delegates user credentials through GSSAPI, which allows remote servers to authenticate as the client via the delegated credentials. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | J Waite Php-x-links | 23/9/2012 | 16/6/2026 | Multiple SQL injection vulnerabilities in Php-X-Links, possibly 1.0, allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to rate.php, (2) cid parameter to view.php, or (3) t parameter to pop.php. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Joomla COM Weblinks | 6/9/2012 | 16/6/2026 | SQL injection vulnerability in the Weblinks (com_weblinks) component for Joomla! and Mambo 1.0.9 and earlier allows remote attackers to execute arbitrary SQL commands via the title parameter. | |
| Modificada | Baja (3.5) | 0.94% | — | Wearepropeople Glossify Internal Links Auto SEO | 25/7/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Glossify Internal Links Auto SEO module for Drupal 6.x-2.5 and earlier allows remote authenticated users with certain roles to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (9.3) | 36% | 💥 Exploit | Cisco Linksys Playerpt Activex Control | 19/7/2012 | 16/6/2026 | Stack-based buffer overflow in the SetSource method in the Cisco Linksys PlayerPT ActiveX control 1.0.0.15 in PlayerPT.ocx on the Cisco WVC200 Wireless-G PTZ Internet video camera allows remote attackers to execute arbitrary code via a long URL in the first argument (aka the sURL argument). | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Phpnuke Php-nukePhpnuke WEB Links Module | 14/2/2012 | 16/6/2026 | SQL injection vulnerability in the Web_Links module for PHP-Nuke 8.0 allows remote attackers to execute arbitrary SQL commands via the url parameter in an Add action to modules.php. | |
| Modificada | Alta (7.5) | 1.3% | — | Cisco Linksys Wrt54gx Router FirmwareLinksys Wrt54gx | 22/11/2011 | 16/6/2026 | The UPnP IGD implementation on the Cisco Linksys WRT54GX with firmware 2.00.05, when UPnP is enabled, configures the SOAP server to listen on the WAN port, which allows remote attackers to administer the firewall via SOAP requests. | |
| Modificada | Alta (7.5) | 1.3% | — | Cisco Linksys Wrt54g Router FirmwareLinksys Wrt54gCisco Linksys Wrt54gs Router FirmwareLinksys Wrt54gs | 22/11/2011 | 16/6/2026 | The UPnP IGD implementation in the Broadcom UPnP stack on the Cisco Linksys WRT54G with firmware before 4.30.5, WRT54GS v1 through v3 with firmware before 4.71.1, and WRT54GS v4 with firmware before 1.06.1 allows remote attackers to establish arbitrary port mappings by sending a UPnP AddPortMapping action in a SOAP… | |
| Modificada | Alta (7.5) | 0.90% | 💥 Exploit | Joomla COM Weblinks | 9/10/2011 | 16/6/2026 | SQL injection vulnerability in the Weblinks (com_weblinks) component in Joomla! allows remote attackers to execute arbitrary SQL commands via the Itemid parameter in a categories action to index.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Media (4.3) | 1.1% | — | Axscripts Axslinks | 27/9/2011 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in addlink.php in AXScripts AxsLinks 0.3 allow remote attackers to inject arbitrary web script or HTML via the (1) url or (2) title parameter. | |
| Modificada | Alta (7.5) | 0.99% | 💥 Exploit | Vlinks | 12/9/2011 | 16/6/2026 | SQL injection vulnerability in page.php in Vlinks 1.0.3 and 1.1.6 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Alta (7.8) | 2.2% | — | Cisco Linksys Wrt54gc RouterCisco Linksys Wrt54gc Router Firmware | 24/1/2011 | 16/6/2026 | Buffer overflow in the web-based management interface on the Cisco Linksys WRT54GC router with firmware before 1.06.1 allows remote attackers to cause a denial of service (device crash) via a long string in a POST request. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | WSN LinksWSN LinksWsnlinks WSN Links | 3/11/2010 | 16/6/2026 | Multiple SQL injection vulnerabilities in search.php in WSN Links 5.0.x before 5.0.81, 5.1.x before 5.1.51, and 6.0.x before 6.0.1 allow remote attackers to execute arbitrary SQL commands via the (1) namecondition or (2) namesearch parameter. | |
| Modificada | Alta (7.5) | 2.8% | 💥 Exploit | Silvercover Mylinksdump Plugin | 30/7/2010 | 16/6/2026 | SQL injection vulnerability in myLDlinker.php in the myLinksDump Plugin 1.2 for WordPress allows remote attackers to execute arbitrary SQL commands via the url parameter. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Joomla COM WeblinksJoomla! | 8/7/2010 | 16/6/2026 | SQL injection vulnerability in the Weblinks (com_weblinks) component in Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a view action to index.php. | |
| Modificada | Alta (7.5) | 13% | 💥 Exploit | Miyabi-seo CGI Tools SEO Links | 2/7/2010 | 16/6/2026 | index.pl in Miyabi CGI Tools SEO Links 1.02 allows remote attackers to execute arbitrary commands via shell metacharacters in the fn command. NOTE: some of these details are obtained from third party information. | |
| Modificada | Baja (2.9) | 0.66% | — | Cisco Linksys FirmwareCisco Linksys Wap54g | 28/6/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in debug.cgi in Linksys WAP54Gv3 firmware 3.05.03 and 3.04.03 allows remote attackers to inject arbitrary web script or HTML via the data1 parameter. |