Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2882▼ 181 respecto a la semana anterior
Críticas / altas1279▼ 60 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)487▼ 22 respecto a la semana anterior
13 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 0.76% | — | Laravel MagiclinkAI | 14/9/2026 | 30/9/2026 | Laravel MagicLink creates links for authentication without a password or for accessing private content. From 2.0.0 until 2.25.1, MagicLink stores serialized action objects in the magic_links.action database column and deserializes them through src/MagicLink.php and src/Actions/ResponseAction.php without sufficient… | |
| Aplazada | Alta (7.5) | 0.35% | — | Clink Bitcoin Lightning Payment GatewayAI | 13/8/2026 | 14/8/2026 | Unauthenticated Broken Access Control in Bitcoin Lightning Payment Gateway for WooCommerce (via CLINK) <= 1.0.7 versions. | |
| Analizada | Crítica (10) | 1.5% | — | Beyond Altec Doclink | 24/2/2026 | 17/6/2026 | Altec DocLink (now maintained by Beyond Limits Inc.) version 4.0.336.0 exposes insecure .NET Remoting endpoints over TCP and HTTP/SOAP via Altec.RDCHostService.exe using the ObjectURI "doclinkServer.soap". The service does not require authentication and is vulnerable to unsafe object unmarshalling, allowing remote… | |
| Aplazada | Alta (8.4) | 0.50% | — | NetpclinkerAI | 30/1/2026 | 17/6/2026 | NetPCLinker 1.0.0.0 contains a buffer overflow vulnerability in the Clients Control Panel DNS/IP field that allows attackers to execute arbitrary shellcode. Attackers can craft a malicious payload in the DNS/IP input to overwrite SEH handlers and execute shellcode when adding a new client. | |
| Aplazada | Alta (7.1) | 0.29% | — | Clinked Client PortalAI | 17/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Clinked Clinked Client Portal clinked-client-portal allows Reflected XSS.This issue affects Clinked Client Portal: from n/a through <= 1.10. | |
| Aplazada | Media (6.5) | 0.35% | — | Aryan Themes ClinkAI | 24/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Aryan Themes Clink clink allows DOM-Based XSS.This issue affects Clink: from n/a through <= 1.2.2. | |
| Aplazada | Media (6.4) | 0.30% | — | Clinked Client PortalAI | 30/1/2025 | 17/6/2026 | The Clinked Client Portal plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'clinked-login-button' shortcode in all versions up to, and including, 1.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Modificada | Alta (7.5) | 1.3% | — | Communilink Clink Office | 25/7/2022 | 9/7/2026 | CommuniLink Internet Limited CLink Office v2.0 was discovered to contain multiple SQL injection vulnerabilities via the username and password parameters. | |
| Modificada | Crítica (9.1) | 37% | — | Iclinks Scadaflex II FirmwareIclinks Weblib | 26/2/2022 | 17/6/2026 | On ICL ScadaFlex II SCADA Controller SC-1 and SC-2 1.03.07 devices, unauthenticated remote attackers can overwrite, delete, or create files. | |
| Modificada | Media (6.1) | 0.66% | — | Earclink Espcms-p8 | 28/9/2021 | 17/6/2026 | EARCLINK ESPCMS-P8 contains a cross-site scripting (XSS) vulnerability in espcms_web\espcms_load.php. | |
| Modificada | Media (6.1) | 4.8% | — | Communilink Clink Office | 7/4/2020 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in the index page of the CLink Office 2.0 management console allows remote attackers to inject arbitrary web script or HTML via the lang parameter. | |
| Modificada | Alta (7.5) | 1.2% | — | Earclink Espcms-p8 | 7/1/2019 | 17/6/2026 | EARCLINK ESPCMS-P8 has SQL injection in the install_pack/index.php?ac=Member&at=verifyAccount verify_key parameter. install_pack/espcms_public/espcms_db.php may allow retrieving sensitive information from the ESPCMS database. | |
| Modificada | Alta (7.5) | 2.9% | — | Marc Cagninacci Mclinkscounter | 19/9/2006 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in Marc Cagninacci mcLinksCounter 1.1 allow remote attackers to execute arbitrary PHP code via a URL in the langfile parameter in (1) login.php, (2) stats.php, (3) detail.php, or (4) erase.php. NOTE: CVE and a third party dispute this vulnerability, because the… |