Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2761▲ 61 respecto a la semana anterior
Críticas / altas1285▼ 211 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 215 respecto a la semana anterior
–

6793 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.3)13%—Totolink X6000r Firmware24/9/202517/6/2026
La vulnerabilidad de Neutralización Inadecuada de Elementos Especiales utilizados en un Comando de SO ('Inyección de Comandos de SO') en TOTOLINK X6000R permite la inyección de comandos de SO. Este problema afecta a X6000R: hasta V9.4.0cu.1360_B20241207.
AnalizadaMedia (6.5)1.1%—Dlink Di-7100g Firmware23/9/202517/6/2026
OS Command injection vulnerability in D-Link C1 2020-02-21. The sub_47F028 function in jhttpd contains a command injection vulnerability via the HTTP parameter "time".
AnalizadaAlta (7.5)0.65%—Dlink Di-7100g Firmware23/9/202517/6/2026
Buffer overflow vulnerability in D-Link DI-7100G 2020-02-21 in the sub_451754 function of the jhttpd service in the viav4 parameter allowing attackers to cause a denial of service or execute arbitrary code.
AnalizadaAlta (7)8.1%—Totolink X6000r Firmware23/9/202517/6/2026
Improper Input Validation vulnerability in TOTOLINK X6000R allows Flooding.This issue affects X6000R: through V9.4.0cu.1360_B20241207.
AnalizadaBaja (2.1)6.1%—Dlink Dir-823x Firmware22/9/202517/6/2026
A vulnerability was determined in D-Link DIR-823X 240126/240802/250416. Affected by this vulnerability is an unknown functionality of the file /usr/sbin/goahead. This manipulation of the argument port causes command injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be…
AplazadaMedia (5.9)0.33%—Tmatsuur Slightly Troublesome PermalinkAI22/9/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tmatsuur Slightly troublesome permalink slightly-troublesome-permalink allows Stored XSS.This issue affects Slightly troublesome permalink: from n/a through <= 1.2.0.
AplazadaMedia (5.3)0.35%—Skimlinks Affiliate Marketing ToolAI22/9/202517/6/2026
Missing Authorization vulnerability in Skimlinks Skimlinks Affiliate Marketing Tool skimlinks allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Skimlinks Affiliate Marketing Tool: from n/a through <= 1.3.
AplazadaMedia (4.4)0.25%—Skimlinks Affiliate Marketing ToolAI22/9/202517/6/2026
Server-Side Request Forgery (SSRF) vulnerability in Skimlinks Skimlinks Affiliate Marketing Tool skimlinks allows Server Side Request Forgery.This issue affects Skimlinks Affiliate Marketing Tool: from n/a through <= 1.3.1.
AplazadaMedia (5.9)0.30%—Jonathanmh Append Link ON CopyAI22/9/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in JonathanMH Append Link on Copy append-link-on-copy allows Stored XSS.This issue affects Append Link on Copy: from n/a through <= 0.2.
AplazadaAlta (7.1)0.14%—Era404 LinkedincludeAI22/9/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in ERA404 LinkedInclude linkedinclude allows Stored XSS.This issue affects LinkedInclude: from n/a through <= 3.0.4.
AplazadaAlta (8.8)1.2%—Lb-link Bl-ac2100 AZ3AILb-link Bl-wr4000AILb-link Bl-wr9000 AE4AILb-link Bl-ac1900 AZ2AI+222/9/20255/7/2026
The LB-Link routers, including the BL-AC2100_AZ3 V1.0.4, BL-WR4000 v2.5.0, BL-WR9000_AE4 v2.4.9, BL-AC1900_AZ2 v1.0.2, BL-X26_AC8 v1.2.8, and BL-LTE300_DA4 V1.2.3 models, are vulnerable to unauthorized command injection. Attackers can exploit this vulnerability by accessing the /goform/set_serial_cfg interface to gain…
AplazadaAlta (7.2)0.64%—Raoinfotech Gsheets Connector SheetlinkAI22/9/202517/6/2026
Deserialization of Untrusted Data vulnerability in raoinfotech GSheets Connector sheetlink allows Object Injection.This issue affects GSheets Connector: from n/a through <= 1.1.1.
AplazadaMedia (5.9)0.30%—Onlineoptimisation WP Mailto LinksAI22/9/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Online Optimisation WP Mailto Links wp-mailto-links allows Stored XSS.This issue affects WP Mailto Links: from n/a through <= 3.1.4.
AplazadaMedia (4.4)0.28%—Activewebsight SEO Backlink MonitorAI22/9/202517/6/2026
Server-Side Request Forgery (SSRF) vulnerability in activewebsight SEO Backlink Monitor seo-backlink-monitor allows Server Side Request Forgery.This issue affects SEO Backlink Monitor: from n/a through <= 1.8.0.
AplazadaMedia (4.3)0.17%—Activewebsight SEO Backlink MonitorAI22/9/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in activewebsight SEO Backlink Monitor seo-backlink-monitor allows Cross Site Request Forgery.This issue affects SEO Backlink Monitor: from n/a through <= 1.8.0.
AplazadaMedia (5.4)0.17%—Mihdan NO External LinksAI22/9/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in mihdan Mihdan: No External Links mihdan-no-external-links allows Cross Site Request Forgery.This issue affects Mihdan: No External Links: from n/a through <= 5.1.6.2.
AplazadaMedia (5.9)0.30%—Syedbalkhi Affiliatewp External Referral LinksAI22/9/20251/10/2026
Vulnerabilidad de Neutralización Incorrecta de la Entrada Durante la Generación de Páginas Web ('cross-site scripting') en Syed Balkhi AffiliateWP - External Referral Links permite XSS Almacenado. Este problema afecta a AffiliateWP - External Referral Links: desde n/a hasta 1.2.0.
AnalizadaAlta (7.4)3.2%—Dlink Dir-513 Firmware22/9/202517/6/2026
A security vulnerability has been detected in D-Link DIR-513 A1FW110. Affected is an unknown function of the file /goform/formWPS. Such manipulation of the argument webpage leads to buffer overflow. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. This vulnerability…
AnalizadaAlta (7.4)0.89%—Dlink Dcs-935l Firmware22/9/202517/6/2026
A vulnerability was found in D-Link DCS-935L up to 1.13.01. The impacted element is the function sub_402280 of the file /HNAP1/. The manipulation of the argument HNAP_AUTH/SOAPAction results in stack-based buffer overflow. The attack may be launched remotely. The exploit has been made public and could be used. This…
AnalizadaBaja (2)20%—Wavlink Wl-nu516u1 Firmware22/9/202517/6/2026
A security vulnerability has been detected in Wavlink WL-NU516U1 240425. This vulnerability affects the function sub_4012A0 of the file /cgi-bin/login.cgi. Such manipulation of the argument ipaddr leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and…
ModificadaAlta (7.4)4.0%—Lb-link Bl-ac2100 Firmware22/9/202517/6/2026
A security flaw has been discovered in B-Link BL-AC2100 up to 1.0.3. Affected by this issue is the function delshrpath of the file /goform/set_delshrpath_cfg of the component Web Management Interface. The manipulation of the argument Type results in stack-based buffer overflow. The attack may be performed from remote.…
AplazadaMedia (4.3)0.16%—Internal Links ManagerAI20/9/202517/6/2026
The Internal Links Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0.1. This is due to missing or incorrect nonce validation on the link deletion functionality in the process_bulk_action() function. This makes it possible for unauthenticated attackers to…
AplazadaAlta (8.8)0.39%—Doverfuelingsolutions Progauge Maglink LX4AI18/9/202517/6/2026
Dover Fueling Solutions ProGauge MagLink LX4 Devices fail to handle Unix time values beyond a certain point. An attacker can manually change the system time to exploit this limitation, potentially causing errors in authentication and leading to a denial-of-service condition.
AplazadaCrítica (9.3)0.44%—Doverfuelingsolutions Progauge Maglink LX4AI18/9/202517/6/2026
Dover Fueling Solutions ProGauge MagLink LX4 Devices have default root credentials that cannot be changed through standard administrative means. An attacker with network access to the device can gain administrative access to the system.
AnalizadaBaja (2.1)4.6%—Dlink Dir-645 Firmware18/9/202517/6/2026
A vulnerability was identified in D-Link DIR-645 105B01. This issue affects the function soapcgi_main of the file /soap.cgi. Such manipulation of the argument service leads to command injection. The attack can be launched remotely. The exploit is publicly available and might be used. This vulnerability only affects…