Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
621 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.3) | 0.44% | — | Caio WEB DEV CWD Stealth LinksAI | 17/4/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Caio Web Dev CWD – Stealth Links cwd-stealth-links allows SQL Injection.This issue affects CWD – Stealth Links: from n/a through <= 1.3. | |
| Aplazada | Media (6.5) | 0.40% | — | Galaxyweblinks Video Playlist FOR YoutubeAI | 4/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Galaxy Weblinks Video Playlist For YouTube video-playlist-for-youtube allows Stored XSS.This issue affects Video Playlist For YouTube: from n/a through <= 6.7.1. | |
| Aplazada | Alta (7.1) | 0.39% | — | Linksoftwarellc Html FormsAI | 1/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Link Software LLC HTML Forms html-forms allows Stored XSS.This issue affects HTML Forms: from n/a through <= 1.5.1. | |
| Aplazada | Media (5.3) | 0.37% | — | Galaxyweblinks WP Clone ANY Post TypeAI | 1/4/2025 | 17/6/2026 | Missing Authorization vulnerability in Galaxy Weblinks WP Clone any post type wp-clone-any-post-type allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Clone any post type: from n/a through <= 3.6. | |
| Aplazada | Media (4.7) | 0.36% | — | Galaxyweblinks WP Clone ANY Post TypeAI | 1/4/2025 | 17/6/2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Galaxy Weblinks WP Clone any post type wp-clone-any-post-type allows Phishing.This issue affects WP Clone any post type: from n/a through <= 3.6. | |
| Aplazada | Media (6.5) | 0.36% | — | Smartredfox Pretty File LinksAI | 24/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in smartredfox Pretty file links pretty-file-links allows Stored XSS.This issue affects Pretty file links: from n/a through <= 0.9. | |
| Analizada | Alta (8.6) | 0.78% | — | Linksys E5600 Firmware | 21/3/2025 | 17/6/2026 | Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.emailReg function. The vulnerability can be triggered via the `pt["email"]` parameter. | |
| Analizada | Media (6.3) | 0.66% | — | Linksys E5600 Firmware | 21/3/2025 | 17/6/2026 | In Linksys E5600 V1.1.0.26, the \usr\share\lua\runtime.lua file contains a command injection vulnerability in the runtime.pingTest function via the pt["pkgsize"] parameter. | |
| Analizada | Media (6.3) | 0.66% | — | Linksys E5600 Firmware | 21/3/2025 | 17/6/2026 | In Linksys E5600 V1.1.0.26, the \usr\share\lua\runtime.lua file contains a command injection vulnerability in the runtime.pingTest function via the pt["count"] parameter. | |
| Analizada | Media (6.3) | 0.66% | — | Linksys E5600 Firmware | 21/3/2025 | 17/6/2026 | Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability via the pt parameter in the traceRoute function. | |
| Aplazada | Media (5.8) | 0.21% | — | Winking Affiliate-links-managerAI | 3/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in winking Affiliate Links Manager affiliate-links-manager allows Reflected XSS.This issue affects Affiliate Links Manager: from n/a through <= 1.0. | |
| Aplazada | Media (6.5) | 0.15% | — | Kareemsultan Social LinksAI | 3/3/2025 | 18/8/2026 | Cross-Site Request Forgery (CSRF) vulnerability in kareemsultan Social Links social-links allows Cross Site Request Forgery. This issue affects Social Links: from n/a through 1.0.11. | |
| Aplazada | Alta (7.6) | 0.75% | — | Kareemsultan Social LinksAI | 3/3/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in kareemsultan Social Links social-links allows Command Line Execution through SQL Injection.This issue affects Social Links: from n/a through <= 1.2. | |
| Aplazada | Alta (7.1) | 0.39% | — | Littlejon LJ Custom Menu LinksAI | 3/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in littlejon LJ Custom Menu Links lj-custom-menu-links allows Reflected XSS.This issue affects LJ Custom Menu Links: from n/a through <= 2.5. | |
| Aplazada | Alta (7.1) | 0.37% | — | Mitchell Bundy WP Social LinksAI | 3/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mitchell Bundy WP Social Links wp-social-links allows Reflected XSS.This issue affects WP Social Links: from n/a through <= 0.3.1. | |
| Aplazada | Media (4.3) | 0.16% | — | SEO Roma Auto-tag-linksAI | 24/2/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Free plug in by SEO Roma Auto Tag Links auto-tag-links allows Cross Site Request Forgery.This issue affects Auto Tag Links: from n/a through <= 1.0.13. | |
| Analizada | Crítica (9.8) | 0.59% | — | Wecantrack Affiliate Links | 18/2/2025 | 17/6/2026 | The Affiliate Links: WordPress Plugin for Link Cloaking and Link Management plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.0.1 via deserialization of untrusted input from an file export. This makes it possible for unauthenticated attackers to inject a PHP Object. No… | |
| Aplazada | Alta (7.1) | 0.31% | — | Makong Internal Links GeneratorAI | 14/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in makong Internal Links Generator internal-links-generator allows Reflected XSS.This issue affects Internal Links Generator: from n/a through <= 3.51. | |
| Analizada | Alta (7.3) | 0.16% | — | Linksys Wap610n Firmware | 11/2/2025 | 17/6/2026 | Buffer overflow vulnerability in Linksys WAP610N v1.0.05.002 due to the lack of length verification, which is related to the time setting operation. The attacker can directly control the remote target device by successfully exploiting this vulnerability. | |
| Aplazada | Alta (7.1) | 0.14% | — | Victor Barkalov Custom Links ON Admin Dashboard ToolbarAI | 7/2/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Victor Barkalov Custom Links On Admin Dashboard Toolbar customize-wpadmin allows Stored XSS.This issue affects Custom Links On Admin Dashboard Toolbar: from n/a through <= 3.3. | |
| Aplazada | Media (6.5) | 0.28% | — | Zack Katz Links IN CaptionsAI | 7/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Zack Katz Links in Captions links-in-captions allows Stored XSS.This issue affects Links in Captions: from n/a through <= 1.2. | |
| Aplazada | Media (4.3) | 0.44% | — | Webraketen Internal Links ManagerAI | 24/1/2025 | 17/6/2026 | Missing Authorization vulnerability in webraketen Internal Links Manager seo-automated-link-building allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Internal Links Manager: from n/a through <= 2.5.2. | |
| Aplazada | Media (5.4) | 0.19% | — | Datafeedr Woocommerce Cloak Affiliate LinksAI | 24/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in datafeedr WooCommerce Cloak Affiliate Links woocommerce-cloak-affiliate-links allows Cross Site Request Forgery.This issue affects WooCommerce Cloak Affiliate Links: from n/a through <= 1.0.35. | |
| Aplazada | Alta (7.1) | 0.26% | — | Raminmt Links Problem ReporterAI | 23/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RaminMT Links/Problem Reporter report-broken-links allows Reflected XSS.This issue affects Links/Problem Reporter: from n/a through <= 2.6.0. | |
| Analizada | Media (5.5) | 0.43% | — | Linksys E8450 Firmware | 21/1/2025 | 17/6/2026 | Linksys E8450 v1.2.00.360516 was discovered to contain a buffer overflow vulnerability. The parsed field (hidden_dhcp_num) is copied to the stack without length verification. |