Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
–

621 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (10)2.6%—Linksys Wap54gv310/6/201016/6/2026
Linksys WAP54Gv3 firmware 3.04.03 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) data2 and (2) data3 parameters to (a) Debug_command_page.asp and (b) debug.cgi.
ModificadaCrítica (9.8)21%—Linksys Wap54g Firmware10/6/201016/6/2026
Linksys WAP54Gv3 firmware 3.04.03 and earlier uses a hard-coded username (Gemtek) and password (gemtekswd) for a debug interface for certain web pages, which allows remote attackers to execute arbitrary commands via the (1) data1, (2) data2, or (3) data3 parameters to (a) Debug_command_page.asp and (b) debug.cgi.
ModificadaAlta (7.5)1.2%—Files2links F2L 3000 Appliance2/2/201016/6/2026
SQL injection vulnerability in Files2Links F2L 3000 appliance 4.0.0, and possibly other versions and models, allows remote attackers to execute arbitrary SQL commands via unspecified parameters to the login page.
ModificadaAlta (7.5)1.0%—Typo3 Vm19 Userlinks15/1/201016/6/2026
SQL injection vulnerability in the User Links (vm19_userlinks) extension 0.1.1 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
ModificadaAlta (7.5)1.6%—Dbmasters DB Masters Multimedia Links Directory6/1/201016/6/2026
admin.php in dB Masters Multimedia Links Directory 3.1.3 allows remote attackers to bypass authentication and gain administrative access via a certain value of the admin_log cookie.
ModificadaAlta (7.5)1.00%💥 ExploitCmsnx Million Dollar Text Links4/12/200916/6/2026
SQL injection vulnerability in admin.link.modify.php in Million Dollar Text Links 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
ModificadaMedia (6.8)1.9%—Marvell 88w8361p-bem ChipsetLinksys Wap4400n12/11/200916/6/2026
Multiple buffer overflows in the Marvell wireless driver, as used in Linksys WAP4400N Wi-Fi access point with firmware 1.2.17 on the Marvell 88W8361P-BEM1 chipset, and other products, allow remote 802.11-authenticated users to cause a denial of service (wireless access point crash) and possibly execute arbitrary code…
ModificadaBaja (3.5)1.4%—Apsivam Service Links9/10/200916/6/2026
Cross-site scripting (XSS) vulnerability in Service Links 6.x-1.0, a module for Drupal, allows remote authenticated users, with 'administer content types' permissions, to inject arbitrary web script or HTML via unspecified vectors when displaying content type names.
ModificadaAlta (7.5)0.95%💥 ExploitDataspheric Linkspheric1/10/200916/6/2026
SQL injection vulnerability in viewListing.php in linkSpheric 0.74 Beta 6 allows remote attackers to execute arbitrary SQL commands via the listID parameter.
ModificadaAlta (10)4.6%—Linksys Wrt54gl24/9/200916/6/2026
Buffer overflow on the Linksys WRT54GL wireless router allows remote attackers to execute arbitrary code via unspecified vectors, as demonstrated by a certain module in VulnDisco Pack Professional 8.10 through 8.11. NOTE: as of 20090917, this disclosure has no actionable information. However, because the VulnDisco…
ModificadaAlta (7.8)2.8%—Elinks14/9/200916/6/2026
Buffer overflow in entity_cache in ELinks before 0.11.4rc0 allows remote attackers to cause a denial of service (crash) via a crafted link.
ModificadaMedia (4.3)0.90%—Mrcgiguy HOT Links Sql-php28/8/200916/6/2026
Cross-site scripting (XSS) vulnerability in Mr. CGI Guy Hot Links SQL-PHP 3 and earlier allows remote attackers to inject arbitrary web script or HTML via the search bar.
ModificadaAlta (7.5)1.1%💥 ExploitMrcgiguy HOT Links Sql-php28/8/200916/6/2026
SQL injection vulnerability in Mr. CGI Guy Hot Links SQL-PHP 3 and earlier allows remote attackers to execute arbitrary SQL commands via the news.php parameter.
ModificadaAlta (10)3.7%💥 ExploitSkalinks Exchange Script19/8/200916/6/2026
Skalfa Software SkaLinks Exchange Script 1.5 allows remote attackers to add new administrators and gain privileges via a direct request to admin/register.php.
ModificadaBaja (3.5)1.00%—Scott Courtney Links Package27/7/200916/6/2026
Cross-site scripting (XSS) vulnerability in the Links Related module in the Links Package 5.x before 5.x-1.13 and 6.x before 6.x-1.2, a module for Drupal, allows remote authenticated users to inject arbitrary web script or HTML via the title field.
ModificadaAlta (7.5)2.4%💥 ExploitCmsnx Million Dollar Text Links1/6/200916/6/2026
Million Dollar Text Links 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the userid cookie to 1.
ModificadaMedia (5)2.9%💥 ExploitDew-code Dew-newphplinks12/5/200916/6/2026
Directory traversal vulnerability in index.php in Dew-NewPHPLinks 2.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the show parameter.
ModificadaMedia (4.3)1.4%💥 ExploitDew-code Dew-newphplinks12/5/200916/6/2026
Cross-site scripting (XSS) vulnerability in index.php in Dew-NewPHPLinks 2.0 allows remote attackers to inject arbitrary web script or HTML via the PID parameter.
ModificadaAlta (7.5)2.8%💥 ExploitKalptarudemos Million Dollar Text Links7/5/200916/6/2026
Million Dollar Text Links 1.0 does not properly restrict administrator access to admin.home.php, which allows remote attackers to bypass intended restrictions and gain privileges via a direct request to admin.home.php after visiting admin.php.
ModificadaAlta (7.5)0.97%💥 ExploitDeltascripts PHP Links13/4/200916/6/2026
SQL injection vulnerability in admin/adm_login.php in DeltaScripts PHP Links 1.3 and earlier allows remote attackers to execute arbitrary SQL commands via the admin_username parameter (aka the admin field).
ModificadaAlta (9.3)9.1%💥 ExploitImera Teamlinks5/3/200916/6/2026
Insecure method vulnerability in the ImeraIEPlugin ActiveX control (ImeraIEPlugin.dll 1.0.2.54) in Imera TeamLinks Client allows remote attackers to force the download and execution of arbitrary URLs via modified DownloadProtocol, DownloadHost, DownloadPort, and DownloadURI parameters.
ModificadaAlta (7.5)0.91%💥 ExploitHispah Text Links ADS16/2/200916/6/2026
SQL injection vulnerability in index.php in Hispah Text Links Ads 1.1 allows remote attackers to execute arbitrary SQL commands via the idtl parameter in a buy action. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
ModificadaAlta (7.5)0.97%💥 ExploitHispah Text Links ADS16/2/200916/6/2026
SQL injection vulnerability in index.php in Hispah Text Links Ads 1.1 allows remote attackers to execute arbitrary SQL commands via the idcat parameter.
ModificadaMedia (6.8)2.3%💥 ExploitGroonesworld Glinks10/2/200916/6/2026
PHP remote file inclusion vulnerability in includes/header.php in Groone GLinks 2.1 allows remote attackers to execute arbitrary PHP code via a URL in the abspath parameter.
ModificadaAlta (7.5)0.95%💥 ExploitSkalinks10/2/200916/6/2026
SQL injection vulnerability in Skalfa SkaLinks 1.5 allows remote attackers to execute arbitrary SQL commands via the Admin name field to the default URI under admin/.
Orbitaley — Vulnerabilidades