Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
621 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.4) | 0.26% | — | Altumcode 66biolinks | 12/1/2026 | 17/6/2026 | Cross Site Scripting vulnerability in 66biolinks by AltumCode v.61.0.1 allows an attacker to execute arbitrary code via a crafted favicon file | |
| Analizada | Crítica (9.8) | 1.3% | — | Linksys E5600 Firmware | 23/12/2025 | 17/6/2026 | linksys E5600 V1.1.0.26 is vulnerable to command injection in the function ddnsStatus. | |
| Analizada | Crítica (9.8) | 1.3% | — | Linksys E5600 Firmware | 23/12/2025 | 17/6/2026 | Linksys E5600 V1.1.0.26 is vulnerable to command injection in the runtime.macClone function via the mc.ip parameter. | |
| Aplazada | Media (6.1) | 0.26% | — | Overstock Affiliate LinksAI | 20/12/2025 | 17/6/2026 | The Overstock Affiliate Links plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']` parameter in all versions up to, and including, 1.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Analizada | Alta (8.8) | 6.4% | — | Linksys E9450-sg Firmware | 19/12/2025 | 30/9/2026 | Successful exploitation of the vulnerability could allow an attacker with local network access to send a specially crafted URL to access certain administration functions without login credentials. | |
| Analizada | Media (6.1) | 0.19% | — | Linksys E5600 Firmware | 16/12/2025 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in the page_save component of Linksys E5600 V1.1.0.26 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the hostname and domainName parameters. | |
| Analizada | Alta (7.4) | 1.1% | — | Linksys Re6500 FirmwareLinksys Re6250 FirmwareLinksys Re6300 FirmwareLinksys Re6350 Firmware+2 | 6/12/2025 | 25/9/2026 | A security flaw has been discovered in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. This vulnerability affects the function RE2000v2Repeater_get_wired_clientlist_setClientsName of the file mod_form.so. The manipulation of the argument clientsname_0… | |
| Analizada | Alta (7.4) | 0.87% | — | Linksys Re6500 FirmwareLinksys Re6250 FirmwareLinksys Re6300 FirmwareLinksys Re6350 Firmware+2 | 6/12/2025 | 17/6/2026 | A vulnerability was determined in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. Affected by this issue is the function RE2000v2Repeater_get_wireless_clientlist_setClientsName of the file mod_form.so. Executing manipulation of the argument… | |
| Analizada | Alta (7.4) | 0.87% | — | Linksys Re6500 FirmwareLinksys Re6250 FirmwareLinksys Re6300 FirmwareLinksys Re6350 Firmware+2 | 6/12/2025 | 25/9/2026 | A vulnerability was identified in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. This affects the function AP_get_wired_clientlist_setClientsName of the file mod_form.so. The manipulation of the argument clientsname_0 leads to stack-based buffer… | |
| Analizada | Alta (7.4) | 0.87% | — | Linksys Re6500 FirmwareLinksys Re6250 FirmwareLinksys Re6300 FirmwareLinksys Re6350 Firmware+2 | 6/12/2025 | 25/9/2026 | A vulnerability was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. Affected by this vulnerability is the function AP_get_wireless_clientlist_setClientsName of the file mod_form.so. Performing manipulation of the argument clientsname_0 results… | |
| Aplazada | Media (6.4) | 0.24% | — | Easy Jump Links MenusAI | 5/12/2025 | 17/6/2026 | The Easy Jump Links Menus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `h_tags` parameter in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to… | |
| Aplazada | Media (4.3) | 0.22% | — | Permalinks CascadeAI | 18/11/2025 | 17/6/2026 | The Permalinks Cascade plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.2. This is due to the plugin not properly verifying that a user is authorized to perform an action in the handleTPCAdminAjaxRequest function. This makes it possible for authenticated attackers,… | |
| Modificada | Media (6.5) | 0.77% | — | Linksys E1200 Firmware | 13/11/2025 | 5/7/2026 | A stack-based buffer overflow exists in the get_merge_mac function of the httpd binary on Linksys E1200 v2 routers (Firmware E1200_v2.0.11.001_us.tar.gz). The function concatenates up to six user-supplied CGI parameters matching <parameter>_0~5 into a fixed-size buffer (a2) without proper bounds checking, appending… | |
| Modificada | Alta (8.4) | 0.23% | — | Linksys Re7000 Firmware | 13/11/2025 | 5/7/2026 | A stack-based buffer overflow vulnerability exists in the makeRequest.cgi binary of Linksys RE7000 routers (Firmware FW_v2.0.15_211230_1012). The arplookup function parses lines from /proc/net/arp using sscanf("%16s ... %18s ..."), storing results into buffers v6 (12 bytes) and v7 (20 bytes). Since the format… | |
| Modificada | Media (5.9) | 0.21% | — | Linksys E7350 Firmware | 13/11/2025 | 5/7/2026 | A stack-based buffer overflow vulnerability exists in the mtk_dut binary of Linksys E7350 routers (Firmware 1.1.00.032). The function sub_4045A8 reads up to 256 bytes from /sys/class/net/%s/address into a local buffer and then copies it into caller-provided buffer a1 using strcpy without boundary checks. Since a1 is… | |
| Modificada | Alta (7.5) | 1.1% | — | Linksys E1200 Firmware | 13/11/2025 | 5/7/2026 | A stack-based buffer overflow exists in the validate_static_route function of the httpd binary on Linksys E1200 v2 routers (Firmware E1200_v2.0.11.001_us.tar.gz). The function improperly concatenates user-supplied CGI parameters (route_ipaddr_0~3, route_netmask_0~3, route_gateway_0~3) into fixed-size buffers (v6, v10,… | |
| Modificada | Alta (8.4) | 0.23% | — | Linksys E1200 Firmware | 13/11/2025 | 5/7/2026 | A stack-based buffer overflow vulnerability exists in the libshared.so library of Cisco Linksys E1200 v2 routers (Firmware E1200_v2.0.11.001_us.tar.gz). The functions get_mac_from_ip and get_ip_from_mac use sscanf with overly permissive "%100s" format specifiers to parse entries from /proc/net/arp into fixed-size… | |
| Modificada | Alta (8.8) | 0.71% | — | Linksys E1200 Firmware | 13/11/2025 | 5/7/2026 | A stack-based buffer overflow exists in the httpd binary of Linksys E1200 v2 routers (Firmware E1200_v2.0.11.001_us.tar.gz). The apply_cgi and block_cgi functions copy user-supplied input from the "url" CGI parameter into stack buffers (v36, v29) using sprintf without bounds checking. Because these buffers are… | |
| Modificada | Alta (8.8) | 3.9% | — | Linksys E1200 Firmware | 13/11/2025 | 5/7/2026 | A stack-based buffer overflow exists in the get_merge_ipaddr function of the httpd binary on Linksys E1200 v2 routers (Firmware E1200_v2.0.11.001_us.tar.gz). The function concatenates up to four user-supplied CGI parameters matching <parameter>_0~3 into a fixed-size buffer (a2) without bounds checking. Remote… | |
| Modificada | Media (5.4) | 18% | — | Linksys E1200 Firmware | 13/11/2025 | 22/7/2026 | An unauthenticated command injection vulnerability exists in the Start_EPI function of the httpd binary on Linksys E1200 v2 routers (Firmware E1200_v2.0.11.001_us.tar.gz). The vulnerability occurs because user-supplied CGI parameters (wl_ant, wl_ssid, wl_rate, ttcp_num, ttcp_ip, ttcp_size) are concatenated into system… | |
| Aplazada | Alta (7.5) | 0.46% | — | Michaeluno Auto Amazon LinksAI | 11/11/2025 | 17/6/2026 | The Auto Amazon Links – Amazon Associates Affiliate Plugin plugin for WordPress is vulnerable to arbitrary files reads in all versions up to, and including, 5.4.3 via the '/wp-json/wp/v2/aal_ajax_unit_loading' RST API endpoint. This makes it possible for unauthenticated attackers to read the contents of arbitrary… | |
| Aplazada | Media (4.3) | 0.13% | — | WPM Navigation Links FOR Sections AND HeadingsAI | 4/11/2025 | 17/6/2026 | The Posts Navigation Links for Sections and Headings – Free by WP Masters plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.1. This is due to missing or incorrect nonce validation on the 'wpm_navigation_links_settings' page. This makes it possible for… | |
| Aplazada | Media (6.5) | 0.21% | — | Maarten Links Shortcode Links-shortcodeAI | 27/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Maarten Links shortcode links-shortcode allows Stored XSS.This issue affects Links shortcode: from n/a through <= 1.8.3. | |
| Aplazada | Media (6.5) | 0.39% | — | Wplinkspage WP Links PageAI | 11/10/2025 | 17/6/2026 | The WP Links Page plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and including, 4.9.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (4.3) | 0.14% | — | Galaxyweblinks Post Featured VideoAI | 26/9/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Galaxy Weblinks Post Featured Video post-featured-video allows Cross Site Request Forgery.This issue affects Post Featured Video: from n/a through <= 1.7. |