Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2702▼ 361 respecto a la semana anterior
Críticas / altas1278▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)216▼ 113 respecto a la semana anterior
621 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.2% | — | Drupal Easylinks Module | 27/8/2006 | 16/6/2026 | Vulnerabilidad de inyección SQL en Drupal Easylinks Module (easylinks.module) 4.7 anterior a 1.5.2.1 19/08/2006 12:02:27 permite a atacantes remotos ejecutar comandos SQL de su elección mediante vectores no especificados. | |
| Modificada | Media (6.8) | 1.6% | — | Cloudnine Interactive Links Manager | 24/8/2006 | 16/6/2026 | Múltiples vulnerabilidades de secuencias de comandos en sitios cruzados (XSS) en add_url.php de CloudNine Interactive Links Manager 2006-06-12 permiten a atacantes remotos inyectar secuencias de comandos web o HTML de su elección a través de los parámetros (1) title, (2) description, o (2) keywords. | |
| Modificada | Media (5.1) | 1.3% | — | Cloudnine Interactive Links Manager | 24/8/2006 | 16/6/2026 | Vulnerabilidad de inyección SQL en admin.php de CloudNine Interactive Links Manager 2006-06-12, cuando magic_quites_gpc está desactivado, permite a atacantes remotos ejecutar comandos SQL a través del parámetro nick. | |
| Modificada | Media (6.8) | 4.5% | 💥 Exploit | Mambo Artlinks Component | 1/8/2006 | 16/6/2026 | Vulnerabilidad PHP de inclusión remota de archivo en artlinks.dispnew.php en el componente Artlinks (com_artlinks) para Mambo permite a atacantes remotos ejecutar código PHP de su elección a través de una URL en el parámetro mosConfig_absolute_path. | |
| Modificada | Media (5.1) | 1.1% | — | Gonafish Linkscaffe | 31/7/2006 | 16/6/2026 | Vulnerabilidad de inyección SQL en links.php en Gonafish LinksCaffe 3.0 permite a atacantes remotos ejecutar comandos SQL de su elección a través del parámetro cat. NOTA: la procedencia de esta información es desconocida; los detalles han sido obtenidos a partir de la información de terceros. | |
| Modificada | Alta (7.5) | 3.9% | 💥 Exploit | Gonafish Linkscaffe | 27/7/2006 | 16/6/2026 | Múltiples vulnerabilidades de inyección SQL en links.php de Gonafish LinksCaffe 3.0 permiten a atacantes remotos ejecutar comandos SQL de su elección a través de los parámetros (1) offset y (2)limit, el parámetro (3) newdays en una acción nueva, y el parámetro (4) link_id en una acción deadlink (enlace roto). NOTA:… | |
| Modificada | Media (4.3) | 4.8% | 💥 Exploit | Gonafish Linkscaffe | 27/7/2006 | 16/6/2026 | Múltiples vulnerabilidades de secuencias de comandos en sitios cruzados (XSS) en Gonafish LinksCaffe 3.0 permiten a atacantes remotos inyectar secuencias de comandos web o HTML de su elección a través del parámetro (1) tablewidth en (a) counter.php; el parámetro (2) newdays en (b) links.php; y los parámetros (3)… | |
| Modificada | Media (4.3) | 1.9% | — | Okscripts Quicklinks | 13/6/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in search.php in OkScripts QuickLinks 1.1 allows remote attackers to inject arbitrary web script or HTML via the q parameter. | |
| Modificada | Media (5) | 1.4% | — | Particle Soft Particle Links | 8/6/2006 | 16/6/2026 | Partial Links 1.2.2 allows remote attackers to obtain sensitive information via a direct request to (1) page_footer.php and (2) page_header.php, which displays the path in an error message. | |
| Modificada | Baja (2.6) | 1.8% | — | Particle Soft Particle Links | 8/6/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in admin.php in Particle Links 1.2.2 allows remote attackers to inject arbitrary web script or HTML via the username parameter. | |
| Modificada | Media (5) | 1.5% | — | Particle Soft Particle Links | 8/6/2006 | 16/6/2026 | Directory traversal vulnerability in Particle Links 1.2.2 might allow remote attackers to access arbitrary files via ".." sequences in an HTTP request. NOTE: it is not clear whether this issue is legitimate, as the original researcher seems unsure. | |
| Modificada | Alta (7.5) | 1.2% | — | Particle Soft Particle Links | 8/6/2006 | 16/6/2026 | SQL injection vulnerability in index.php in Partial Links 1.2.2 allows remote attackers to execute arbitrary SQL commands via the topic parameter. | |
| Modificada | Media (5) | 1.8% | 💥 Exploit | Full Revolution Aspweblinks | 6/6/2006 | 16/6/2026 | links.asp in aspWebLinks 2.0 allows remote attackers to change the administrative password, possibly via a direct request with a modified txtAdministrativePassword field. | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Full Revolution Aspweblinks | 6/6/2006 | 16/6/2026 | SQL injection vulnerability in links.asp in aspWebLinks 2.0 allows remote attackers to execute arbitrary SQL commands via the linkID parameter. | |
| Modificada | Media (6.4) | 1.1% | — | Greg Donald Destiney Links Script | 25/5/2006 | 16/6/2026 | SQL injection vulnerability in Destiney Links Script 2.1.2 allows remote attackers to execute arbitrary SQL commands via the ID parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Alta (7.5) | 1.7% | — | Linksys Wrt54gLinksys Wrt54g V5 | 24/5/2006 | 16/6/2026 | Linksys WRT54G Wireless-G Broadband Router allows remote attackers to bypass access restrictions and conduct unauthorized operations via a UPnP request with a modified InternalClient parameter, which is not validated, as demonstrated by using AddPortMapping to forward arbitrary traffic. | |
| Modificada | Media (5.8) | 1.3% | — | Greg Donald Destiney Links Script | 22/5/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Destiney Links Script 2.1.2 allows remote attackers to inject arbitrary web script or HTML via the (1) "Search" (term parameter in index.php) and (2) "Add a Site" (add.php) fields. | |
| Modificada | Media (5) | 1.3% | — | Greg Donald Destiney Links Script | 22/5/2006 | 16/6/2026 | Destiney Links Script 2.1.2 does not protect library and other support files, which allows remote attackers to obtain the installation path via a direct URL to files in the (1) include and (2) themes/original directories. | |
| Modificada | Media (5) | 1.8% | — | Greg Donald Destiney Links Script | 22/5/2006 | 16/6/2026 | index.php in Destiney Links Script 2.1.2 allows remote attackers to obtain the installation path via an invalid show parameter referencing a non-existent file, which reveals the path in the resulting error message. NOTE: this issue might be resultant from a more serious issue such as directory traversal. | |
| Modificada | Media (5) | 2.3% | — | Linksys Rt31p2 | 21/4/2006 | 16/6/2026 | Multiple unspecified vulnerabilities in Linksys RT31P2 VoIP router allow remote attackers to cause a denial of service via malformed Session Initiation Protocol (SIP) messages. | |
| Modificada | Media (6.8) | 1.8% | 💥 Exploit | Phplinks | 18/4/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in phpLinks 2.1.3.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the term parameter. | |
| Modificada | Media (5) | 1.8% | — | Linksys Wrt54g V5 | 7/3/2006 | 16/6/2026 | Linksys WRT54G routers version 5 (running VXWorks) allow remote attackers to cause a denial of service by sending a malformed DCC SEND string to an IRC channel, which causes an IRC connection reset, possibly related to the masquerading code for NAT environments, and as demonstrated via (1) a DCC SEND with a single… | |
| Modificada | Media (4) | 1.5% | — | Linksys Befvp41 | 19/1/2006 | 16/6/2026 | Linksys BEFVP41 VPN Router 2.0 with firmware 1.01.04 allows remote attackers on the local network, to cause a denial of service via IP packets with a null IP option length. | |
| Modificada | Alta (7.5) | 1.2% | — | Vego Links Builder | 3/1/2006 | 16/6/2026 | SQL injection vulnerability in login.php in VEGO Links Builder 2.00 and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter. | |
| Modificada | Alta (7.8) | 1.4% | — | Linksys Befw11s4Linksys Befw11s4 V3Linksys Befw11s4 V4Linksys Wrt54gs | 15/12/2005 | 16/6/2026 | Linksys WRT54GS y BEFW11S4 permiten a atacantes remotos causar una denegación de servicio (caída de dispositivo) mediante un paquete IP con los mismos IPs y puertos de origen y destino, y con la bandera SYN establecida (tcc LAND). NOTA: La proveniencia de esta cuestión es desconocida, los detalles son obtenidos… |