Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2989▼ 73 respecto a la semana anterior
Críticas / altas1415▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
621 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.9) | 0.22% | — | Jordymeow Gallery Custom LinksAI | 26/9/2025 | 30/9/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jordy Meow Gallery Custom Links gallery-custom-links allows Stored XSS.This issue affects Gallery Custom Links: from n/a through <= 2.2.5. | |
| Aplazada | Media (5.3) | 0.35% | — | Skimlinks Affiliate Marketing ToolAI | 22/9/2025 | 17/6/2026 | Missing Authorization vulnerability in Skimlinks Skimlinks Affiliate Marketing Tool skimlinks allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Skimlinks Affiliate Marketing Tool: from n/a through <= 1.3. | |
| Aplazada | Media (4.4) | 0.25% | — | Skimlinks Affiliate Marketing ToolAI | 22/9/2025 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in Skimlinks Skimlinks Affiliate Marketing Tool skimlinks allows Server Side Request Forgery.This issue affects Skimlinks Affiliate Marketing Tool: from n/a through <= 1.3.1. | |
| Aplazada | Media (5.9) | 0.30% | — | Onlineoptimisation WP Mailto LinksAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Online Optimisation WP Mailto Links wp-mailto-links allows Stored XSS.This issue affects WP Mailto Links: from n/a through <= 3.1.4. | |
| Aplazada | Media (5.4) | 0.17% | — | Mihdan NO External LinksAI | 22/9/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in mihdan Mihdan: No External Links mihdan-no-external-links allows Cross Site Request Forgery.This issue affects Mihdan: No External Links: from n/a through <= 5.1.6.2. | |
| Aplazada | Media (5.9) | 0.30% | — | Syedbalkhi Affiliatewp External Referral LinksAI | 22/9/2025 | 1/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Syed Balkhi AffiliateWP – External Referral Links affiliatewp-external-referral-links allows Stored XSS.This issue affects AffiliateWP – External Referral Links: from n/a through <= 1.2.0. | |
| Aplazada | Media (4.3) | 0.16% | — | Internal Links ManagerAI | 20/9/2025 | 17/6/2026 | The Internal Links Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0.1. This is due to missing or incorrect nonce validation on the link deletion functionality in the process_bulk_action() function. This makes it possible for unauthenticated attackers to… | |
| Aplazada | Crítica (9) | 0.31% | — | Volkov Labs Business LinksAIGrafanaAI | 8/9/2025 | 17/6/2026 | The Volkov Labs Business Links panel for Grafana provides an interface to navigate using external links, internal dashboards, time pickers, and dropdown menus. Prior to version 2.4.0, a malicious actor with Editor privileges can escalate their privileges to Administrator and perform arbitrary administrative actions.… | |
| Analizada | Baja (2.1) | 6.9% | — | Linksys Re6250 FirmwareLinksys Re6300 FirmwareLinksys Re6350 FirmwareLinksys Re7000 Firmware+2 | 28/8/2025 | 17/6/2026 | A vulnerability was determined in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. This issue affects the function cgiMain of the file /cgi-bin/upload.cgi. Executing manipulation of the argument filename can lead to os command injection. The attack may… | |
| Analizada | Baja (2) | 54% | — | Linksys E1700 Firmware | 27/8/2025 | 17/6/2026 | A vulnerability was determined in Linksys E1700 1.0.0.4.003. This vulnerability affects the function systemCommand of the file /goform/systemCommand. Executing manipulation of the argument command can lead to os command injection. The attack may be launched remotely. The exploit has been publicly disclosed and may be… | |
| Analizada | Alta (7.4) | 1.5% | — | Linksys E1700 Firmware | 27/8/2025 | 17/6/2026 | A vulnerability was found in Linksys E1700 1.0.0.4.003. This affects the function QoSSetup of the file /goform/QoSSetup. Performing manipulation of the argument ack_policy results in stack-based buffer overflow. The attack may be initiated remotely. The exploit has been made public and could be used. The vendor was… | |
| Analizada | Alta (7.4) | 1.4% | — | Linksys E1700 Firmware | 27/8/2025 | 17/6/2026 | A vulnerability has been found in Linksys E1700 1.0.0.4.003. Affected by this issue is the function setSysAdm of the file /goform/setSysAdm. Such manipulation of the argument rm_port leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.… | |
| Analizada | Alta (7.4) | 1.4% | — | Linksys E1700 Firmware | 27/8/2025 | 17/6/2026 | A flaw has been found in Linksys E1700 1.0.0.4.003. Affected by this vulnerability is the function setWan of the file /goform/setWan. This manipulation of the argument DeviceName/lanIp causes stack-based buffer overflow. The attack can be initiated remotely. The exploit has been published and may be used. The vendor… | |
| Analizada | Alta (7.4) | 1.0% | — | Linksys Re6500 FirmwareLinksys Re6250 FirmwareLinksys Re6300 FirmwareLinksys Re6350 Firmware+2 | 26/8/2025 | 17/6/2026 | A flaw has been found in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. Affected is the function singlePortForwardAdd of the file /goform/singlePortForwardAdd. This manipulation of the argument ruleName/schedule/inboundFilter causes stack-based buffer… | |
| Analizada | Alta (7.4) | 9.0% | — | Linksys Re6250 FirmwareLinksys Re6300 FirmwareLinksys Re6350 FirmwareLinksys Re7000 Firmware+2 | 26/8/2025 | 17/6/2026 | A vulnerability was detected in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. This impacts the function portRangeForwardAdd of the file /goform/portRangeForwardAdd. The manipulation of the argument ruleName/schedule/inboundFilter/TCPPorts/UDPPorts… | |
| Analizada | Alta (7.4) | 1.4% | — | Linksys Re6250 FirmwareLinksys Re6300 FirmwareLinksys Re6350 FirmwareLinksys Re7000 Firmware+2 | 26/8/2025 | 17/6/2026 | A security vulnerability has been detected in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. This affects the function setIpv6 of the file /goform/setIpv6. The manipulation of the argument tunrd_Prefix leads to stack-based buffer overflow. Remote… | |
| Analizada | Alta (7.4) | 1.0% | — | Linksys Re6250 FirmwareLinksys Re6300 FirmwareLinksys Re6350 FirmwareLinksys Re7000 Firmware+1 | 24/8/2025 | 17/6/2026 | A vulnerability was detected in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. This vulnerability affects the function addStaProfile of the file /goform/addStaProfile. Performing manipulation of the argument… | |
| Analizada | Alta (7.4) | 4.7% | — | Linksys Re6250 FirmwareLinksys Re6300 FirmwareLinksys Re6350 FirmwareLinksys Re7000 Firmware+2 | 24/8/2025 | 17/6/2026 | A security vulnerability has been detected in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. This affects the function qosClassifier of the file /goform/qosClassifier. Such manipulation of the argument… | |
| Analizada | Alta (7.4) | 4.4% | — | Linksys Re6250 FirmwareLinksys Re6300 FirmwareLinksys Re6350 FirmwareLinksys Re6500 Firmware+2 | 23/8/2025 | 17/6/2026 | A vulnerability has been found in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. This affects the function portTriggerManageRule of the file /goform/portTriggerManageRule. The manipulation of the argument triggerRuleName/schedule leads to stack-based… | |
| Analizada | Media (5.3) | 0.57% | — | Linksys Re6250 FirmwareLinksys Re6300 FirmwareLinksys Re6350 FirmwareLinksys Re6500 Firmware+2 | 23/8/2025 | 17/6/2026 | A flaw has been found in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. The impacted element is the function urlFilterManageRule of the file /goform/urlFilterManageRule. Executing manipulation of the argument urlFilterRuleName/scheduleUrl/addURLFilter… | |
| Analizada | Alta (7.4) | 0.97% | — | Linksys Re6250 FirmwareLinksys Re6300 FirmwareLinksys Re6350 FirmwareLinksys Re6500 Firmware+2 | 23/8/2025 | 17/6/2026 | A vulnerability was detected in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. The affected element is the function ipRangeBlockManageRule of the file /goform/ipRangeBlockManageRule. Performing manipulation of the argument… | |
| Analizada | Alta (7.4) | 1.2% | — | Linksys Re6250 FirmwareLinksys Re6300 FirmwareLinksys Re6350 FirmwareLinksys Re6500 Firmware+2 | 23/8/2025 | 17/6/2026 | A security vulnerability has been detected in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. Impacted is the function accessControlAdd of the file /goform/accessControlAdd. Such manipulation of the argument ruleName/schedule leads to stack-based… | |
| Analizada | Alta (7.4) | 1.0% | — | Linksys Re6500 FirmwareLinksys Re6250 FirmwareLinksys Re6300 FirmwareLinksys Re6350 Firmware+2 | 23/8/2025 | 17/6/2026 | A weakness has been identified in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. This issue affects the function RP_checkCredentialsByBBS of the file /goform/RP_checkCredentialsByBBS. This manipulation of the argument ssidhex/pwd causes stack-based… | |
| Analizada | Alta (7.4) | 1.0% | — | Linksys Re6250 FirmwareLinksys Re6300 FirmwareLinksys Re6350 FirmwareLinksys Re7000 Firmware+2 | 23/8/2025 | 17/6/2026 | A security flaw has been discovered in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. This vulnerability affects the function setSysAdm of the file /goform/setSysAdm. The manipulation of the argument admpasshint results in stack-based buffer overflow.… | |
| Analizada | Alta (7.4) | 1.0% | — | Linksys Re6250 FirmwareLinksys Re6300 FirmwareLinksys Re6350 FirmwareLinksys Re7000 Firmware+2 | 23/8/2025 | 17/6/2026 | A vulnerability was identified in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. This affects the function langSwitchByBBS of the file /goform/langSwitchByBBS. The manipulation of the argument langSelectionOnly leads to stack-based buffer overflow. It… |