Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2702▼ 361 respecto a la semana anterior
Críticas / altas1278▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)216▼ 113 respecto a la semana anterior
–

621 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.2%—Drupal Easylinks Module27/8/200616/6/2026
Vulnerabilidad de inyección SQL en Drupal Easylinks Module (easylinks.module) 4.7 anterior a 1.5.2.1 19/08/2006 12:02:27 permite a atacantes remotos ejecutar comandos SQL de su elección mediante vectores no especificados.
ModificadaMedia (6.8)1.6%—Cloudnine Interactive Links Manager24/8/200616/6/2026
Múltiples vulnerabilidades de secuencias de comandos en sitios cruzados (XSS) en add_url.php de CloudNine Interactive Links Manager 2006-06-12 permiten a atacantes remotos inyectar secuencias de comandos web o HTML de su elección a través de los parámetros (1) title, (2) description, o (2) keywords.
ModificadaMedia (5.1)1.3%—Cloudnine Interactive Links Manager24/8/200616/6/2026
Vulnerabilidad de inyección SQL en admin.php de CloudNine Interactive Links Manager 2006-06-12, cuando magic_quites_gpc está desactivado, permite a atacantes remotos ejecutar comandos SQL a través del parámetro nick.
ModificadaMedia (6.8)4.5%💥 ExploitMambo Artlinks Component1/8/200616/6/2026
Vulnerabilidad PHP de inclusión remota de archivo en artlinks.dispnew.php en el componente Artlinks (com_artlinks) para Mambo permite a atacantes remotos ejecutar código PHP de su elección a través de una URL en el parámetro mosConfig_absolute_path.
ModificadaMedia (5.1)1.1%—Gonafish Linkscaffe31/7/200616/6/2026
Vulnerabilidad de inyección SQL en links.php en Gonafish LinksCaffe 3.0 permite a atacantes remotos ejecutar comandos SQL de su elección a través del parámetro cat. NOTA: la procedencia de esta información es desconocida; los detalles han sido obtenidos a partir de la información de terceros.
ModificadaAlta (7.5)3.9%💥 ExploitGonafish Linkscaffe27/7/200616/6/2026
Múltiples vulnerabilidades de inyección SQL en links.php de Gonafish LinksCaffe 3.0 permiten a atacantes remotos ejecutar comandos SQL de su elección a través de los parámetros (1) offset y (2)limit, el parámetro (3) newdays en una acción nueva, y el parámetro (4) link_id en una acción deadlink (enlace roto). NOTA:…
ModificadaMedia (4.3)4.8%💥 ExploitGonafish Linkscaffe27/7/200616/6/2026
Múltiples vulnerabilidades de secuencias de comandos en sitios cruzados (XSS) en Gonafish LinksCaffe 3.0 permiten a atacantes remotos inyectar secuencias de comandos web o HTML de su elección a través del parámetro (1) tablewidth en (a) counter.php; el parámetro (2) newdays en (b) links.php; y los parámetros (3)…
ModificadaMedia (4.3)1.9%—Okscripts Quicklinks13/6/200616/6/2026
Cross-site scripting (XSS) vulnerability in search.php in OkScripts QuickLinks 1.1 allows remote attackers to inject arbitrary web script or HTML via the q parameter.
ModificadaMedia (5)1.4%—Particle Soft Particle Links8/6/200616/6/2026
Partial Links 1.2.2 allows remote attackers to obtain sensitive information via a direct request to (1) page_footer.php and (2) page_header.php, which displays the path in an error message.
ModificadaBaja (2.6)1.8%—Particle Soft Particle Links8/6/200616/6/2026
Cross-site scripting (XSS) vulnerability in admin.php in Particle Links 1.2.2 allows remote attackers to inject arbitrary web script or HTML via the username parameter.
ModificadaMedia (5)1.5%—Particle Soft Particle Links8/6/200616/6/2026
Directory traversal vulnerability in Particle Links 1.2.2 might allow remote attackers to access arbitrary files via ".." sequences in an HTTP request. NOTE: it is not clear whether this issue is legitimate, as the original researcher seems unsure.
ModificadaAlta (7.5)1.2%—Particle Soft Particle Links8/6/200616/6/2026
SQL injection vulnerability in index.php in Partial Links 1.2.2 allows remote attackers to execute arbitrary SQL commands via the topic parameter.
ModificadaMedia (5)1.8%💥 ExploitFull Revolution Aspweblinks6/6/200616/6/2026
links.asp in aspWebLinks 2.0 allows remote attackers to change the administrative password, possibly via a direct request with a modified txtAdministrativePassword field.
ModificadaAlta (7.5)1.3%💥 ExploitFull Revolution Aspweblinks6/6/200616/6/2026
SQL injection vulnerability in links.asp in aspWebLinks 2.0 allows remote attackers to execute arbitrary SQL commands via the linkID parameter.
ModificadaMedia (6.4)1.1%—Greg Donald Destiney Links Script25/5/200616/6/2026
SQL injection vulnerability in Destiney Links Script 2.1.2 allows remote attackers to execute arbitrary SQL commands via the ID parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
ModificadaAlta (7.5)1.7%—Linksys Wrt54gLinksys Wrt54g V524/5/200616/6/2026
Linksys WRT54G Wireless-G Broadband Router allows remote attackers to bypass access restrictions and conduct unauthorized operations via a UPnP request with a modified InternalClient parameter, which is not validated, as demonstrated by using AddPortMapping to forward arbitrary traffic.
ModificadaMedia (5.8)1.3%—Greg Donald Destiney Links Script22/5/200616/6/2026
Cross-site scripting (XSS) vulnerability in Destiney Links Script 2.1.2 allows remote attackers to inject arbitrary web script or HTML via the (1) "Search" (term parameter in index.php) and (2) "Add a Site" (add.php) fields.
ModificadaMedia (5)1.3%—Greg Donald Destiney Links Script22/5/200616/6/2026
Destiney Links Script 2.1.2 does not protect library and other support files, which allows remote attackers to obtain the installation path via a direct URL to files in the (1) include and (2) themes/original directories.
ModificadaMedia (5)1.8%—Greg Donald Destiney Links Script22/5/200616/6/2026
index.php in Destiney Links Script 2.1.2 allows remote attackers to obtain the installation path via an invalid show parameter referencing a non-existent file, which reveals the path in the resulting error message. NOTE: this issue might be resultant from a more serious issue such as directory traversal.
ModificadaMedia (5)2.3%—Linksys Rt31p221/4/200616/6/2026
Multiple unspecified vulnerabilities in Linksys RT31P2 VoIP router allow remote attackers to cause a denial of service via malformed Session Initiation Protocol (SIP) messages.
ModificadaMedia (6.8)1.8%💥 ExploitPhplinks18/4/200616/6/2026
Cross-site scripting (XSS) vulnerability in index.php in phpLinks 2.1.3.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the term parameter.
ModificadaMedia (5)1.8%—Linksys Wrt54g V57/3/200616/6/2026
Linksys WRT54G routers version 5 (running VXWorks) allow remote attackers to cause a denial of service by sending a malformed DCC SEND string to an IRC channel, which causes an IRC connection reset, possibly related to the masquerading code for NAT environments, and as demonstrated via (1) a DCC SEND with a single…
ModificadaMedia (4)1.5%—Linksys Befvp4119/1/200616/6/2026
Linksys BEFVP41 VPN Router 2.0 with firmware 1.01.04 allows remote attackers on the local network, to cause a denial of service via IP packets with a null IP option length.
ModificadaAlta (7.5)1.2%—Vego Links Builder3/1/200616/6/2026
SQL injection vulnerability in login.php in VEGO Links Builder 2.00 and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter.
ModificadaAlta (7.8)1.4%—Linksys Befw11s4Linksys Befw11s4 V3Linksys Befw11s4 V4Linksys Wrt54gs15/12/200516/6/2026
Linksys WRT54GS y BEFW11S4 permiten a atacantes remotos causar una denegación de servicio (caída de dispositivo) mediante un paquete IP con los mismos IPs y puertos de origen y destino, y con la bandera SYN establecida (tcc LAND). NOTA: La proveniencia de esta cuestión es desconocida, los detalles son obtenidos…