Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2723▼ 319 respecto a la semana anterior
Críticas / altas1277▼ 191 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)210▼ 117 respecto a la semana anterior
621 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 1.2% | — | MR. CGI GUY Warm Links | 6/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Warm Links 1.0.0 and earlier allows remote attackers to inject arbitrary web script or HTML via a parameter to search.cgi. | |
| Modificada | Media (4.3) | 1.3% | — | MR. CGI GUY HOT Links PROMR. CGI GUY HOT Links SQL | 6/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in search.cgi in MR CGI Guy Hot Links SQL 3.1.x and Hot Links Pro 3.1.x allows remote attackers to inject arbitrary web script or HTML via the query string. | |
| Modificada | Alta (7.5) | 1.4% | — | Uresk Links | 21/11/2005 | 16/6/2026 | Unspecified vulnerability in the administration interface in Uresk Links 2.0 Lite allows remote attackers to bypass authentication via unspecified vectors in index.php. | |
| Modificada | Alta (7.5) | 71% | 💥 Exploit | Linksys Wrt54g | 15/9/2005 | 16/6/2026 | Buffer overflow in apply.cgi in Linksys WRT54G 3.01.03, 3.03.6, and possibly other versions before 4.20.7, allows remote attackers to execute arbitrary code via a long HTTP POST request. | |
| Modificada | Alta (7.5) | 1.4% | — | Linksys Wrt54g | 14/9/2005 | 16/6/2026 | ezconfig.asp in Linksys WRT54G router 3.01.03, 3.03.6, non-default configurations of 2.04.4, and possibly other versions, does not use an authentication initialization function, which allows remote attackers to obtain encrypted configuration information and, if the key is known, modify the configuration. | |
| Modificada | Media (5) | 1.1% | — | Linksys Wrt54g | 14/9/2005 | 16/6/2026 | Linksys WRT54G 3.01.03, 3.03.6, 4.00.7, and possibly other versions before 4.20.7, does not verify user authentication until after an HTTP POST request has been processed, which allows remote attackers to (1) modify configuration using restore.cgi or (2) upload new firmware using upgrade.cgi. | |
| Modificada | Media (5) | 1.2% | — | Linksys Wrt54g | 14/9/2005 | 16/6/2026 | Linksys WRT54G router allows remote attackers to cause a denial of service (CPU consumption and server hang) via an HTTP POST request with a negative Content-Length value. | |
| Modificada | Media (5) | 0.61% | — | Linksys Wrt54g | 14/9/2005 | 16/6/2026 | ezconfig.asp in Linksys WRT54G router 3.01.03, 3.03.6, non-default configurations of 2.04.4, and possibly other versions, uses weak encryption (XOR encoding with a fixed byte mask) for configuration information, which could allow attackers to decrypt the information and possibly re-encrypt it in conjunction with… | |
| Modificada | Alta (7.5) | 2.7% | 💥 Exploit | Autolinks | 2/9/2005 | 16/6/2026 | PHP remote file inclusion vulnerability in al_initialize.php for AutoLinks Pro 2.1 allows remote attackers to execute arbitrary PHP code via an "ftp://" URL in the alpath parameter, which bypasses the incomplete blacklist that only checks for "http" and "https" URLs. | |
| Modificada | Alta (7.5) | 1.2% | — | Linksys Wrt54gs | 17/8/2005 | 16/6/2026 | Unknown vulnerability in Linksys WRT54GS wireless router with firmware 4.50.6, with WPA Personal/TKIP authentication enabled, allows remote clients to bypass authentication by connecting without using encryption. | |
| Modificada | Media (5) | 0.85% | — | Linksys Wrt54g | 3/8/2005 | 16/6/2026 | El rúter de Linksys WRT54G usa la misma clave privada en todos los rúter, lo que permite que atacantes remotos puedan escuchar conexiones SSL y obtener así información confidencial. | |
| Modificada | Media (4.3) | 0.94% | — | Metalinks Metacart E-shop | 16/5/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in productsByCategory.asp in MetaCart e-Shop allows remote attackers to inject arbitrary web script or HTML via the strCatalog_NAME parameter. | |
| Modificada | Media (4.3) | 4.4% | 💥 Exploit | Gossamer Threads LinksGossamer Threads Links-sql | 11/5/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in user.cgi in Gossamer Threads Links SQL 2.x and 3.0 allows remote attackers to inject arbitrary web script or HTML via the url parameter. | |
| Modificada | Alta (7.5) | 1.5% | — | Metalinks Metabid Auctions | 2/5/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in MetaBid Auctions allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password fields in logIn.asp, or (3) intAuctionID parameter to item.asp. | |
| Modificada | Media (5) | 1.2% | — | IRC Services Nickserv Listlinks | 2/5/2005 | 16/6/2026 | Unknown vulnerability in IRC Services NickServ LISTLINKS before 5.0.50 allows remote attackers to obtain the links of a nick. | |
| Modificada | Alta (7.5) | 1.5% | — | Metalinks Metacart2 | 2/5/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in MetaCart 2.0 for PayFlow allow remote attackers to execute arbitrary commands via (1) intCatalogID, (2) strSubCatalogID, or (3) strSubCatalog_NAME parameter to productsByCategory.asp, (4) curCatalogID, (5) strSubCatalog_NAME, (6) intCatalogID, or (7) page parameter to… | |
| Modificada | Baja (2.1) | 3.2% | 💥 Exploit | Linksys Wet11 | 2/5/2005 | 16/6/2026 | Linksys WET11 1.5.4 allows remote attackers to change the password without providing the original password via the data parameter to changepw.html. | |
| Modificada | Media (5) | 1.7% | — | Linksys Psus4 Printserver | 2/5/2005 | 16/6/2026 | Linksys PSUS4 running firmware 6032 allows remote attackers to cause a denial of service (device crash) via an HTTP POST request containing an unknown parameter without a value. | |
| Modificada | Alta (7.5) | 1.2% | — | Metalinks Metacart2 | 2/5/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in MetaCart 2.0 for Paypal allow remote attackers to execute arbitrary SQL commands via the (1) intProdID parameter to product.asp, (2) intCatalogID or (3) strSubCatalogID parameters to productsByCategory.asp, (4) chkText, (5) strText, (6) chkPrice, (7) intPrice, (8) chkCat, or… | |
| Modificada | Alta (7.5) | 1.3% | — | Metalinks Metacart E-shop | 2/5/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in MetaCart e-Shop 8.0 allow remote attackers to execute arbitrary SQL commands via the (1) intProdID parameter in product.asp or (2) strCatalog_NAME parameter to productsByCategory.asp. | |
| Modificada | Media (5) | 7.7% | 💥 Exploit | Linksys Wvc11b | 31/12/2004 | 16/6/2026 | Absolute path traversal vulnerability in main.cgi in Linksys WVC11B Wireless-B Internet Video Camera allows remote attackers to read arbitrary files via an absolute pathname in the next_file parameter. | |
| Modificada | Media (5) | 1.2% | — | Greg Donald Phplinks | 31/12/2004 | 16/6/2026 | index.php in PHP Links allows remote attackers to gain sensitive information via an invalid show parameter, which reveals the full path in an error message. | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | Linksys Wvc11b | 31/12/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in main.cgi in Linksys WVC11B Wireless-B Internet Video Camera allows remote attackers to inject arbitrary web script or HTML via the next_file parameter. | |
| Modificada | Alta (7.5) | 2.6% | — | Linksys Befsr41 V3Linksys Wrt54g | 31/12/2004 | 16/6/2026 | The Web interface in Linksys WRT54G 2.02.7 and BEFSR41 version 3, with the firewall disabled, allows remote attackers to attempt to login to an administration web page, even when the configuration specifies that remote administration is disabled. | |
| Modificada | Alta (7.5) | 1.3% | — | Artmedic Webdesign Artmedic Links | 6/12/2004 | 16/6/2026 | Vulnerabiliad de inyección remota de código PHP en index.php de Artmedic links 5.0 (artmedic_links5) permite a atacantes remotos ejecutar código PHP de su elección modificando el parámetro id para referenciar a una URL en un servidor web remoto que contiene el código. |