Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 321 respecto a la semana anterior
Críticas / altas1271▼ 203 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 108 respecto a la semana anterior
–

621 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)7.8%💥 ExploitAllmyguests Project AllmyguestsAllmylinks Project AllmylinksAllmyvisitors Project Allmyvisitors23/11/200416/6/2026
Vulnerabilidades de inyección remota de código PHP en (1) AllMyVisitors, (2) AllMyLinks, y (3) AllMyGuests permite a atacantes remotos ejecutar código PHP arbitrario modificando el parámetro _AMVconfig[cfg_serverpath] para hacer referencia a una URL en un servidor remoto que contenga template.inc.php
ModificadaMedia (6.4)6.2%💥 ExploitLinksys Wap55ag23/11/200416/6/2026
Linksys WAP55AG 1.07 allows remote attackers with access to an SNMP read only community string to gain access to read/write communtiy strings via a query for OID 1.3.6.1.4.1.3955.2.1.13.1.2.
ModificadaMedia (5)1.9%—Links18/10/200416/6/2026
Links allows remote attackers to cause a denial of service (memory consumption) via a web page or HTML email that contains a table with a td element and a large rowspan value,as demonstrated by mangleme.
ModificadaMedia (5)8.0%💥 ExploitLinksys Befcmu10Linksys Befn2ps4Linksys Befsr11Linksys Befsr41+86/8/200416/6/2026
DHCP en los encaminadores de cable y ADSL Linksys BEFSR11, BEFSR41, BEFSR81 y BEFSRU31, con versión de firmware 1.45.7, no limpia adecuadamente búferes usados anteriormente en un paquete de respueta BOOTP, lo que permite a atacantes remotos obtener información sensible.
ModificadaBaja (2.6)4.6%💥 ExploitPostnukeAIPostnuke Downloads ModuleAIPostnuke WEB Links ModuleAI21/4/200416/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in PostNuke 0.726 allows remote attackers to inject arbitrary web script or HTML via the (1) lid and query parameters to the Downloads module, (2) query parameter to the Web_links module, or (3) hlpfile parameter to openwindow.php.
ModificadaMedia (6.3)1.4%—Linksys Befsx4131/12/200316/6/2026
Buffer overflow in the system log viewer of Linksys BEFSX41 1.44.3 allows remote attackers to cause a denial of service via an HTTP request with a long Log_Page_Num variable.
ModificadaMedia (5)5.0%💥 ExploitElinksLinksUniversity OF Kansas Lynx19/2/200316/6/2026
Vulnerabilidad de inyección de CRLF en Lynx 2.8.4 y anteriores permite a atacantes remotos inyectar cabeceras HTTP falsas en una petición http provista en la linea de comandos, mediante una URL conteniendo un retorno de carro codificado, salto de línea, y otros caractéres espacio en blanco.
ModificadaMedia (5)1.5%—Alloy Gl-2422ap-sD-link Dwl-900ap+Eusso Gl2422 APLinksys Wap11+131/12/200216/6/2026
GlobalSunTech Wireless Access Points (1) WISECOM GL2422AP-0T, and possibly OEM products such as (2) D-Link DWL-900AP+ B1 2.1 and 2.2, (3) ALLOY GL-2422AP-S, (4) EUSSO GL2422-AP, and (5) LINKSYS WAP11-V2.2, allow remote attackers to obtain sensitive information like WEP keys, the administrator password, and the MAC…
ModificadaAlta (7.8)1.8%—Linksys Wet1131/12/200216/6/2026
Linksys WET11 firmware 1.31 and 1.32 allows remote attackers to cause a denial of service (crash) via a packet containing the device's hardware address as the source MAC address in the DLC header.
ModificadaMedia (5)2.9%💥 ExploitD-link Di-804D-link Dl-704Linksys Befw11s4Linksys Wap1131/12/200216/6/2026
Buffer overflow in the Embedded HTTP server, as used in (1) D-Link DI-804 4.68, Dl-704 V2.56b6, and Dl-704 V2.56b5 and (2) Linksys Etherfast BEFW11S4 Wireless AP + Cable/DSL Router 1.37.2 through 1.42.7 and Linksys WAP11 1.3 and 1.4, allows remote attackers to cause a denial of service (crash) via a long header, as…
ModificadaAlta (7.5)0.96%💥 ExploitMyphpsoft Myphplinks31/12/200216/6/2026
SQL injection vulnerability in admin/auth/checksession.php in MyPHPLinks 2.1.9 and 2.2.0 allows remote attackers to execute arbitrary SQL commands via the idsession parameter.
ModificadaAlta (7.5)3.5%—Twibright Labs Links31/12/200216/6/2026
Buffer overflow in Links 2.0 pre4 allows remote attackers to crash client browsers and possibly execute arbitrary code via gamma tables in large 16-bit PNG images.
ModificadaAlta (10)2.4%—Linksys Befsr11Linksys Befsr41Linksys Befsru3131/12/200216/6/2026
Linksys EtherFast Cable/DSL BEFSR11, BEFSR41 and BEFSRU31 with the firmware 1.42.7 upgrade installed opens TCP port 5678 for remote administration even when the "Block WAN" and "Remote Admin" options are disabled, which allows remote attackers to gain access.
ModificadaMedia (5)2.0%—Linksys Befn2ps4Linksys Befsr11Linksys Befsr41Linksys Befsr81+520/11/200216/6/2026
Buffer overflow in the Web management interface in Linksys BEFW11S4 wireless access point router 2 and BEFSR11, BEFSR41, and BEFSRU31 EtherFast Cable/DSL routers with firmware before 1.43.3 with remote management enabled allows remote attackers to cause a denial of service (router crash) via a long password.
ModificadaMedia (5)7.1%💥 ExploitLinksys Befsr4112/11/200216/6/2026
El servidor de adminsitración web remota del router Linksys BEFSR41 EtherFast Cable/DSL con firmware anterior a 1.42.7 permite a atacantes remotos causar una denegación de servicio (caída) mediante una petición HTTP a Gozilla.cgi sin argumentos.
ModificadaMedia (6.4)1.5%—Metalinks Metacart2.sql4/10/200216/6/2026
MetaCart2.sql stores the user database under the web document root without access controls, which allows remote attackers to obtain sensitive information such as passwords and credit card numbers via a direct request for metacart.mdb.
ModificadaAlta (7.5)1.4%—Linksys Befvp4112/8/200216/6/2026
VPN Server module in Linksys EtherFast BEFVP41 Cable/DSL VPN Router before 1.40.1 reduces the key lengths for keys that are supplied via manual key entry, which makes it easier for attackers to crack the keys.
ModificadaMedia (6.4)1.7%—Linksys Befn2ps4Linksys Befsr41Linksys Befsr8125/3/200216/6/2026
Los routers Linksys EtherFast BEFN2PS4, BEFSR41, and BEFSR81, y posiblemente otros productos, permiten a atacantes remotos obterner información sensible y provocar una denegación de servicio mediante una consulta SNMP con la cadena de comunidad por defecto "public," lo que provoca que el router cambie su configuración…
ModificadaMedia (5)2.4%—Atmel FirmwareLinksys Wap11Netgear Me10221/12/200116/6/2026
El Wireless Acces Point (WAP) Atmel Firmware 1.3 permite a atacantes remotos causar una denegación de servicio mediante una petición SNMP con una cadena de comunidad distinta de "public", oun OID (identificador de objeto) desconocido lo que hace que el WAP deniege peticiones SNMP subsiguientes.
ModificadaMedia (5)1.8%—Linksys Befsr4110/8/200116/6/2026
LinkSys EtherFast BEFSR41 Cable/DSL routers running firmware before 1.39.3 Beta allows a remote attacker to view administration and user passwords by connecting to the router and viewing the HTML source for (1) index.htm and (2) Password.htm.
ModificadaAlta (7.5)1.6%—Atmel 802.11b Vnet-b Access PointLinksys Wap11Netgear Me10221/7/200116/6/2026
SNMP service in Atmel 802.11b VNET-B Access Point 1.3 and earlier, as used in Netgear ME102 and Linksys WAP11, accepts arbitrary community strings with requested MIB modifications, which allows remote attackers to obtain sensitive information such as WEP keys, cause a denial of service, or gain access to the network.