Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
621 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (10) | 2.6% | — | Linksys Wap54gv3 | 10/6/2010 | 16/6/2026 | Linksys WAP54Gv3 firmware 3.04.03 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) data2 and (2) data3 parameters to (a) Debug_command_page.asp and (b) debug.cgi. | |
| Modificada | Crítica (9.8) | 21% | — | Linksys Wap54g Firmware | 10/6/2010 | 16/6/2026 | Linksys WAP54Gv3 firmware 3.04.03 and earlier uses a hard-coded username (Gemtek) and password (gemtekswd) for a debug interface for certain web pages, which allows remote attackers to execute arbitrary commands via the (1) data1, (2) data2, or (3) data3 parameters to (a) Debug_command_page.asp and (b) debug.cgi. | |
| Modificada | Alta (7.5) | 1.2% | — | Files2links F2L 3000 Appliance | 2/2/2010 | 16/6/2026 | SQL injection vulnerability in Files2Links F2L 3000 appliance 4.0.0, and possibly other versions and models, allows remote attackers to execute arbitrary SQL commands via unspecified parameters to the login page. | |
| Modificada | Alta (7.5) | 1.0% | — | Typo3 Vm19 Userlinks | 15/1/2010 | 16/6/2026 | SQL injection vulnerability in the User Links (vm19_userlinks) extension 0.1.1 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Alta (7.5) | 1.6% | — | Dbmasters DB Masters Multimedia Links Directory | 6/1/2010 | 16/6/2026 | admin.php in dB Masters Multimedia Links Directory 3.1.3 allows remote attackers to bypass authentication and gain administrative access via a certain value of the admin_log cookie. | |
| Modificada | Alta (7.5) | 1.00% | 💥 Exploit | Cmsnx Million Dollar Text Links | 4/12/2009 | 16/6/2026 | SQL injection vulnerability in admin.link.modify.php in Million Dollar Text Links 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Media (6.8) | 1.9% | — | Marvell 88w8361p-bem ChipsetLinksys Wap4400n | 12/11/2009 | 16/6/2026 | Multiple buffer overflows in the Marvell wireless driver, as used in Linksys WAP4400N Wi-Fi access point with firmware 1.2.17 on the Marvell 88W8361P-BEM1 chipset, and other products, allow remote 802.11-authenticated users to cause a denial of service (wireless access point crash) and possibly execute arbitrary code… | |
| Modificada | Baja (3.5) | 1.4% | — | Apsivam Service Links | 9/10/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Service Links 6.x-1.0, a module for Drupal, allows remote authenticated users, with 'administer content types' permissions, to inject arbitrary web script or HTML via unspecified vectors when displaying content type names. | |
| Modificada | Alta (7.5) | 0.95% | 💥 Exploit | Dataspheric Linkspheric | 1/10/2009 | 16/6/2026 | SQL injection vulnerability in viewListing.php in linkSpheric 0.74 Beta 6 allows remote attackers to execute arbitrary SQL commands via the listID parameter. | |
| Modificada | Alta (10) | 4.6% | — | Linksys Wrt54gl | 24/9/2009 | 16/6/2026 | Buffer overflow on the Linksys WRT54GL wireless router allows remote attackers to execute arbitrary code via unspecified vectors, as demonstrated by a certain module in VulnDisco Pack Professional 8.10 through 8.11. NOTE: as of 20090917, this disclosure has no actionable information. However, because the VulnDisco… | |
| Modificada | Alta (7.8) | 2.8% | — | Elinks | 14/9/2009 | 16/6/2026 | Buffer overflow in entity_cache in ELinks before 0.11.4rc0 allows remote attackers to cause a denial of service (crash) via a crafted link. | |
| Modificada | Media (4.3) | 0.90% | — | Mrcgiguy HOT Links Sql-php | 28/8/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Mr. CGI Guy Hot Links SQL-PHP 3 and earlier allows remote attackers to inject arbitrary web script or HTML via the search bar. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Mrcgiguy HOT Links Sql-php | 28/8/2009 | 16/6/2026 | SQL injection vulnerability in Mr. CGI Guy Hot Links SQL-PHP 3 and earlier allows remote attackers to execute arbitrary SQL commands via the news.php parameter. | |
| Modificada | Alta (10) | 3.7% | 💥 Exploit | Skalinks Exchange Script | 19/8/2009 | 16/6/2026 | Skalfa Software SkaLinks Exchange Script 1.5 allows remote attackers to add new administrators and gain privileges via a direct request to admin/register.php. | |
| Modificada | Baja (3.5) | 1.00% | — | Scott Courtney Links Package | 27/7/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Links Related module in the Links Package 5.x before 5.x-1.13 and 6.x before 6.x-1.2, a module for Drupal, allows remote authenticated users to inject arbitrary web script or HTML via the title field. | |
| Modificada | Alta (7.5) | 2.4% | 💥 Exploit | Cmsnx Million Dollar Text Links | 1/6/2009 | 16/6/2026 | Million Dollar Text Links 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the userid cookie to 1. | |
| Modificada | Media (5) | 2.9% | 💥 Exploit | Dew-code Dew-newphplinks | 12/5/2009 | 16/6/2026 | Directory traversal vulnerability in index.php in Dew-NewPHPLinks 2.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the show parameter. | |
| Modificada | Media (4.3) | 1.4% | 💥 Exploit | Dew-code Dew-newphplinks | 12/5/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in Dew-NewPHPLinks 2.0 allows remote attackers to inject arbitrary web script or HTML via the PID parameter. | |
| Modificada | Alta (7.5) | 2.8% | 💥 Exploit | Kalptarudemos Million Dollar Text Links | 7/5/2009 | 16/6/2026 | Million Dollar Text Links 1.0 does not properly restrict administrator access to admin.home.php, which allows remote attackers to bypass intended restrictions and gain privileges via a direct request to admin.home.php after visiting admin.php. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Deltascripts PHP Links | 13/4/2009 | 16/6/2026 | SQL injection vulnerability in admin/adm_login.php in DeltaScripts PHP Links 1.3 and earlier allows remote attackers to execute arbitrary SQL commands via the admin_username parameter (aka the admin field). | |
| Modificada | Alta (9.3) | 9.1% | 💥 Exploit | Imera Teamlinks | 5/3/2009 | 16/6/2026 | Insecure method vulnerability in the ImeraIEPlugin ActiveX control (ImeraIEPlugin.dll 1.0.2.54) in Imera TeamLinks Client allows remote attackers to force the download and execution of arbitrary URLs via modified DownloadProtocol, DownloadHost, DownloadPort, and DownloadURI parameters. | |
| Modificada | Alta (7.5) | 0.91% | 💥 Exploit | Hispah Text Links ADS | 16/2/2009 | 16/6/2026 | SQL injection vulnerability in index.php in Hispah Text Links Ads 1.1 allows remote attackers to execute arbitrary SQL commands via the idtl parameter in a buy action. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Hispah Text Links ADS | 16/2/2009 | 16/6/2026 | SQL injection vulnerability in index.php in Hispah Text Links Ads 1.1 allows remote attackers to execute arbitrary SQL commands via the idcat parameter. | |
| Modificada | Media (6.8) | 2.3% | 💥 Exploit | Groonesworld Glinks | 10/2/2009 | 16/6/2026 | PHP remote file inclusion vulnerability in includes/header.php in Groone GLinks 2.1 allows remote attackers to execute arbitrary PHP code via a URL in the abspath parameter. | |
| Modificada | Alta (7.5) | 0.95% | 💥 Exploit | Skalinks | 10/2/2009 | 16/6/2026 | SQL injection vulnerability in Skalfa SkaLinks 1.5 allows remote attackers to execute arbitrary SQL commands via the Admin name field to the default URI under admin/. |