Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2766▲ 12 respecto a la semana anterior
Críticas / altas1276▼ 252 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)245▲ 227 respecto a la semana anterior
–

6793 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.4)0.24%—Bootstrapped Visual Link PreviewAI5/11/202517/6/2026
The Visual Link Preview plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's visual-link-preview shortcode in versions up to, and including, 2.2.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,…
AnalizadaAlta (8.7)0.26%—Linkace4/11/202517/6/2026
LinkAce is a self-hosted archive to collect website links. In versions 2.3.1 and below, the social media sharing functionality contains a Stored Cross-Site Scripting (XSS) vulnerability that allows any authenticated user to inject arbitrary JavaScript by creating a link with malicious HTML in the title field. When a…
AnalizadaAlta (7.1)0.39%—Linkace4/11/202517/6/2026
LinkAce is a self-hosted archive to collect website links. In versions 2.3.1 and below, authenticated RSS feed endpoints in the FeedController class fail to implement proper authorization checks, allowing any authenticated user to access all links, lists, and tags from all users in the system, regardless of their…
AnalizadaAlta (7.1)0.40%—Linkace4/11/202517/6/2026
LinkAce is a self-hosted archive to collect website links. Versions 2.3.1 and below allow any authenticated user to export the entire database of links from all users in the system, including private links that should only be accessible to their owners. The HTML and CSV export functions in the ExportController class…
AnalizadaBaja (2.3)0.33%—Linkace4/11/202517/6/2026
LinkAce is a self-hosted archive to collect website links. In versions 2.3.0 and below, the htmlKeywordsFromUrl function in the FetchController class accepts user-provided URLs and makes HTTP requests to them without validating that the destination is not an internal or private network resource. This Server-Side…
AplazadaMedia (6.1)0.16%—Linkedin ResumeAI4/11/202517/6/2026
The LinkedIn Resume plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.00. This is due to missing or incorrect nonce validation on the linkedinresume_printAdminPage() function. This makes it possible for unauthenticated attackers to update settings and inject…
AplazadaMedia (4.3)0.13%—WPM Navigation Links FOR Sections AND HeadingsAI4/11/202517/6/2026
The Posts Navigation Links for Sections and Headings – Free by WP Masters plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.1. This is due to missing or incorrect nonce validation on the 'wpm_navigation_links_settings' page. This makes it possible for…
AnalizadaAlta (7.5)0.41%—Totolink A7000r Firmware31/10/202517/6/2026
Totolink A7000R v9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the ssid5g parameter in the sub_421CF0 function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
AnalizadaAlta (7.5)0.41%—Totolink Lr350 Firmware31/10/202517/6/2026
Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the ssid parameter in the sub_422880 function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
AnalizadaAlta (7.5)0.41%—Totolink Lr350 Firmware31/10/202517/6/2026
Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the ssid parameter in the sub_42396C function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
AnalizadaAlta (7.5)0.41%—Totolink Lr350 Firmware31/10/202517/6/2026
Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the wifiOff parameter in the sub_4232EC function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
AnalizadaAlta (7.5)0.41%—Totolink A7000r Firmware31/10/202517/6/2026
Totolink A7000R v9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the wifiOff parameter in the sub_421A04 function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
AnalizadaAlta (7.5)0.41%—Totolink A7000r Firmware31/10/202517/6/2026
Totolink A7000R v9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the ssid5g parameter in the urldecode function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
AnalizadaAlta (7.5)0.41%—Totolink A7000r Firmware31/10/202517/6/2026
Totolink A7000R v9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the ssid5g parameter in the sub_4222E0 function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
AnalizadaAlta (7.5)0.41%—Totolink Lr350 Firmware31/10/202517/6/2026
Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the ssid parameter in the sub_421BAC function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
AnalizadaAlta (7.5)0.41%—Totolink Lr350 Firmware31/10/202517/6/2026
Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the http_host parameter in the sub_426EF8 function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
AnalizadaAlta (7.5)0.41%—Totolink Lr350 Firmware31/10/202517/6/2026
Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the ssid parameter in the sub_425400 function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
AnalizadaAlta (7.5)0.41%—Totolink Lr350 Firmware31/10/202517/6/2026
Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the password parameter in the sub_426EF8 function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
AnalizadaCrítica (9.3)9.8%—Dlink Dns-343 Firmware29/10/202517/6/2026
D-Link DNS-343 ShareCenter devices running firmware versions up to and including 1.05 contain a command injection vulnerability in the Mail Test functionality. The web maintenance script posts to the internal goForm endpoint '/goform/Mail_Test' and uses several form parameters directly in a call to a system email…
AplazadaAlta (7.5)0.32%—Reolink Video Doorbell Wi-fiAI28/10/202517/6/2026
Reolink Video Doorbell Wi-Fi DB_566128M5MP_W almacena y transmite credenciales DDNS en texto plano dentro de sus scripts de configuración y actualización, permitiendo a los atacantes interceptar o extraer información sensible.
AplazadaCrítica (9.1)0.72%—Wavlink Quantum D3GAIWavlink Wl-wn530hg3AI28/10/202517/6/2026
Una vulnerabilidad de desbordamiento de búfer basado en pila en el firmware M30HG3_V240730 de WAVLINK QUANTUM D3G/WL-WN530HG3, y posiblemente otros modelos de Wavlink, permite a los atacantes ejecutar código arbitrario a través de un valor de referencia manipulado enviado por POST a login.cgi.
AplazadaAlta (7.2)0.23%—Softing Industrial Automation Gmbh Smartlink Hw-pnAISofting Smartlink Hw-dpAI28/10/202517/6/2026
Improper locking vulnerability in Softing Industrial Automation GmbH gateways allows infected memory and/or resource leak exposure.This issue affects smartLink HW-PN: from 1.02 through 1.03 smartLink HW-DP: 1.31
AplazadaAlta (8.7)0.26%—Softing Industrial Automation Gmbh Smartlink Hw-pnAISofting Smartlink Hw-dpAI28/10/202517/6/2026
Webserver crash caused by scanning on TCP port 80 in Softing Industrial Automation GmbH gateways and switch.This issue affects smartLink HW-PN: from 1.02 through 1.03 smartLink HW-DP: 1.31
AnalizadaBaja (2.1)4.0%—Dlink Di-7001mini-8g Firmware27/10/20258/10/2026
Se ha encontrado una vulnerabilidad en D-Link DI-7001 MINI 19.09.19A1/24.04.18B1. El elemento afectado es una función desconocida del archivo /msp_info.htm. Dicha manipulación del argumento cmd conduce a inyección de comandos. El ataque puede lanzarse remotamente. El exploit ha sido divulgado al público y puede usarse.
AnalizadaBaja (2)7.0%—Dlink Dap-2695 Firmware27/10/20258/10/2026
Una vulnerabilidad de seguridad ha sido detectada en D-Link DAP-2695 2.00RC13. El elemento afectado es la función sub_4174B0 del componente Gestor de Actualización de Firmware. La manipulación conduce a inyección de comandos del sistema operativo. El ataque puede ser iniciado remotamente. El exploit ha sido divulgado…