Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2723▼ 319 respecto a la semana anterior
Críticas / altas1277▼ 191 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)210▼ 117 respecto a la semana anterior
–

621 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)1.2%—MR. CGI GUY Warm Links6/12/200516/6/2026
Cross-site scripting (XSS) vulnerability in Warm Links 1.0.0 and earlier allows remote attackers to inject arbitrary web script or HTML via a parameter to search.cgi.
ModificadaMedia (4.3)1.3%—MR. CGI GUY HOT Links PROMR. CGI GUY HOT Links SQL6/12/200516/6/2026
Cross-site scripting (XSS) vulnerability in search.cgi in MR CGI Guy Hot Links SQL 3.1.x and Hot Links Pro 3.1.x allows remote attackers to inject arbitrary web script or HTML via the query string.
ModificadaAlta (7.5)1.4%—Uresk Links21/11/200516/6/2026
Unspecified vulnerability in the administration interface in Uresk Links 2.0 Lite allows remote attackers to bypass authentication via unspecified vectors in index.php.
ModificadaAlta (7.5)71%💥 ExploitLinksys Wrt54g15/9/200516/6/2026
Buffer overflow in apply.cgi in Linksys WRT54G 3.01.03, 3.03.6, and possibly other versions before 4.20.7, allows remote attackers to execute arbitrary code via a long HTTP POST request.
ModificadaAlta (7.5)1.4%—Linksys Wrt54g14/9/200516/6/2026
ezconfig.asp in Linksys WRT54G router 3.01.03, 3.03.6, non-default configurations of 2.04.4, and possibly other versions, does not use an authentication initialization function, which allows remote attackers to obtain encrypted configuration information and, if the key is known, modify the configuration.
ModificadaMedia (5)1.1%—Linksys Wrt54g14/9/200516/6/2026
Linksys WRT54G 3.01.03, 3.03.6, 4.00.7, and possibly other versions before 4.20.7, does not verify user authentication until after an HTTP POST request has been processed, which allows remote attackers to (1) modify configuration using restore.cgi or (2) upload new firmware using upgrade.cgi.
ModificadaMedia (5)1.2%—Linksys Wrt54g14/9/200516/6/2026
Linksys WRT54G router allows remote attackers to cause a denial of service (CPU consumption and server hang) via an HTTP POST request with a negative Content-Length value.
ModificadaMedia (5)0.61%—Linksys Wrt54g14/9/200516/6/2026
ezconfig.asp in Linksys WRT54G router 3.01.03, 3.03.6, non-default configurations of 2.04.4, and possibly other versions, uses weak encryption (XOR encoding with a fixed byte mask) for configuration information, which could allow attackers to decrypt the information and possibly re-encrypt it in conjunction with…
ModificadaAlta (7.5)2.7%💥 ExploitAutolinks2/9/200516/6/2026
PHP remote file inclusion vulnerability in al_initialize.php for AutoLinks Pro 2.1 allows remote attackers to execute arbitrary PHP code via an "ftp://" URL in the alpath parameter, which bypasses the incomplete blacklist that only checks for "http" and "https" URLs.
ModificadaAlta (7.5)1.2%—Linksys Wrt54gs17/8/200516/6/2026
Unknown vulnerability in Linksys WRT54GS wireless router with firmware 4.50.6, with WPA Personal/TKIP authentication enabled, allows remote clients to bypass authentication by connecting without using encryption.
ModificadaMedia (5)0.85%—Linksys Wrt54g3/8/200516/6/2026
El rúter de Linksys WRT54G usa la misma clave privada en todos los rúter, lo que permite que atacantes remotos puedan escuchar conexiones SSL y obtener así información confidencial.
ModificadaMedia (4.3)0.94%—Metalinks Metacart E-shop16/5/200516/6/2026
Cross-site scripting (XSS) vulnerability in productsByCategory.asp in MetaCart e-Shop allows remote attackers to inject arbitrary web script or HTML via the strCatalog_NAME parameter.
ModificadaMedia (4.3)4.4%💥 ExploitGossamer Threads LinksGossamer Threads Links-sql11/5/200516/6/2026
Cross-site scripting (XSS) vulnerability in user.cgi in Gossamer Threads Links SQL 2.x and 3.0 allows remote attackers to inject arbitrary web script or HTML via the url parameter.
ModificadaAlta (7.5)1.5%—Metalinks Metabid Auctions2/5/200516/6/2026
Multiple SQL injection vulnerabilities in MetaBid Auctions allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password fields in logIn.asp, or (3) intAuctionID parameter to item.asp.
ModificadaMedia (5)1.2%—IRC Services Nickserv Listlinks2/5/200516/6/2026
Unknown vulnerability in IRC Services NickServ LISTLINKS before 5.0.50 allows remote attackers to obtain the links of a nick.
ModificadaAlta (7.5)1.5%—Metalinks Metacart22/5/200516/6/2026
Multiple SQL injection vulnerabilities in MetaCart 2.0 for PayFlow allow remote attackers to execute arbitrary commands via (1) intCatalogID, (2) strSubCatalogID, or (3) strSubCatalog_NAME parameter to productsByCategory.asp, (4) curCatalogID, (5) strSubCatalog_NAME, (6) intCatalogID, or (7) page parameter to…
ModificadaBaja (2.1)3.2%💥 ExploitLinksys Wet112/5/200516/6/2026
Linksys WET11 1.5.4 allows remote attackers to change the password without providing the original password via the data parameter to changepw.html.
ModificadaMedia (5)1.7%—Linksys Psus4 Printserver2/5/200516/6/2026
Linksys PSUS4 running firmware 6032 allows remote attackers to cause a denial of service (device crash) via an HTTP POST request containing an unknown parameter without a value.
ModificadaAlta (7.5)1.2%—Metalinks Metacart22/5/200516/6/2026
Multiple SQL injection vulnerabilities in MetaCart 2.0 for Paypal allow remote attackers to execute arbitrary SQL commands via the (1) intProdID parameter to product.asp, (2) intCatalogID or (3) strSubCatalogID parameters to productsByCategory.asp, (4) chkText, (5) strText, (6) chkPrice, (7) intPrice, (8) chkCat, or…
ModificadaAlta (7.5)1.3%—Metalinks Metacart E-shop2/5/200516/6/2026
Multiple SQL injection vulnerabilities in MetaCart e-Shop 8.0 allow remote attackers to execute arbitrary SQL commands via the (1) intProdID parameter in product.asp or (2) strCatalog_NAME parameter to productsByCategory.asp.
ModificadaMedia (5)7.7%💥 ExploitLinksys Wvc11b31/12/200416/6/2026
Absolute path traversal vulnerability in main.cgi in Linksys WVC11B Wireless-B Internet Video Camera allows remote attackers to read arbitrary files via an absolute pathname in the next_file parameter.
ModificadaMedia (5)1.2%—Greg Donald Phplinks31/12/200416/6/2026
index.php in PHP Links allows remote attackers to gain sensitive information via an invalid show parameter, which reveals the full path in an error message.
ModificadaMedia (4.3)1.7%💥 ExploitLinksys Wvc11b31/12/200416/6/2026
Cross-site scripting (XSS) vulnerability in main.cgi in Linksys WVC11B Wireless-B Internet Video Camera allows remote attackers to inject arbitrary web script or HTML via the next_file parameter.
ModificadaAlta (7.5)2.6%—Linksys Befsr41 V3Linksys Wrt54g31/12/200416/6/2026
The Web interface in Linksys WRT54G 2.02.7 and BEFSR41 version 3, with the firewall disabled, allows remote attackers to attempt to login to an administration web page, even when the configuration specifies that remote administration is disabled.
ModificadaAlta (7.5)1.3%—Artmedic Webdesign Artmedic Links6/12/200416/6/2026
Vulnerabiliad de inyección remota de código PHP en index.php de Artmedic links 5.0 (artmedic_links5) permite a atacantes remotos ejecutar código PHP de su elección modificando el parámetro id para referenciar a una URL en un servidor web remoto que contiene el código.