Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2565▼ 302 respecto a la semana anterior
Críticas / altas1351▲ 99 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

621 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.2)0.24%—NO External LinksAI2/10/20263/10/2026
The No External Links plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Log URL via /goto/{base64} Redirect in all versions up to, and including, 5.2.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in…
AplazadaMedia (5.4)0.10%—Razorpay Payment Links FOR WoocommerceAI30/9/202630/9/2026
Unauthenticated Cross Site Request Forgery (CSRF) in Razorpay Payment Links for WooCommerce <= 2.1.5 versions.
AplazadaMedia (4.9)0.35%—LinkstackAI11/9/202622/9/2026
Linkstack v4.8.4 and earlier is vulnerable to Path Traversal, which allows an administrator to read arbitrary files on the server by manipulating file path input. Successful exploitation may lead to unauthorized access to sensitive system or application files.
AplazadaCrítica (9.3)0.37%—Avideo LivelinksAIWwbn AvideoAI10/9/202610/9/2026
AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the LiveLinks plugin where title and description fields are stored without sanitization. A user with canStream permission can inject malicious scripts that execute in the browser of every visitor…
AplazadaAlta (8.6)3.7%—Linksys Re7000AI7/9/202611/9/2026
A vulnerability was detected in Linksys RE7000 2.0.15. This affects the function platform_event_pingTest of the file /cgi-bin/json.cgi?PingTest of the component PingTest Handler. The manipulation of the argument pingTestIp/pingTestPktSize/pingTestTimes results in os command injection. The attack can be launched…
AplazadaCrítica (9.1)0.40%—Jetlinks CommunityAI26/8/20269/9/2026
The device metadata import interface /device/instance/{productId}/property-metadata/import of jetlinks community 2.11 is vulnerable to Server-side request forgery (SSRF).
AplazadaMedia (4.3)0.29%—Wpdeveloper BetterlinksAI25/8/202626/8/2026
The BetterLinks – Link Shortener, Link Cloaking, Redirects, Affiliate Link Manager & MCP plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.1.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for…
AplazadaMedia (4.9)0.44%—Caseproof PrettylinksAI5/8/202612/8/2026
The PrettyLinks – Affiliate Links, Link Branding, Link Tracking, Marketing and Stripe Payments Plugin plugin for WordPress is vulnerable to SQL Injection via the 's' (search) parameter on the Pretty Links listing page in all versions up to, and including, 3.6.20. This is due to insufficient escaping on the user…
AplazadaMedia (6.5)0.33%—Knitpay Razorpay Payment Links FOR WoocommerceAI13/7/202613/7/2026
Missing Authorization vulnerability in knitpay Razorpay Payment Links for WooCommerce rzp-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Razorpay Payment Links for WooCommerce: from n/a through <= 2.1.4.
AplazadaAlta (7.1)0.25%—Internal Links ManagerAI2/7/20262/7/2026
Unauthenticated Cross Site Scripting (XSS) in Internal Links Manager <= 3.0.3 versions.
AplazadaMedia (4.8)0.23%—MylinksdumpAI27/5/202617/6/2026
The myLinksDump plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link_title' parameter in all versions up to, and including, 1.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject…
AplazadaMedia (5.3)0.23%—Flamescorpion Auto Affiliate LinksAI25/5/202624/7/2026
Missing Authorization vulnerability in Lucian Apostol Auto Affiliate Links allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Auto Affiliate Links: from n/a through 6.8.8.3.
AplazadaAlta (7.2)0.51%—Flamescorpion Auto Affiliate LinksAI8/5/202617/6/2026
The Auto Affiliate Links plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.8.8 This is due to insufficient input sanitization on the 'url' POST parameter in the aal_url_stats_save_action() function and a complete absence of output escaping in aal_display_clicks(),…
AplazadaBaja (2.1)0.44%—LinkstackAI30/4/202617/6/2026
A security vulnerability has been detected in LinkStackOrg LinkStack up to 4.8.6. The affected element is the function saveLink of the file app/Http/Controllers/UserController.php of the component Management Endpoint. The manipulation leads to authorization bypass. The attack can be initiated remotely. The exploit has…
AplazadaBaja (2)0.35%—LinkstackAI30/4/202617/6/2026
A weakness has been identified in LinkStackOrg LinkStack up to 4.8.6. Impacted is the function editPage of the file app/Http/Controllers/UserController.php. Executing a manipulation of the argument pageDescription can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has been made…
AnalizadaAlta (7.3)8.0%—Linksys Mr9600 Firmware25/4/202617/6/2026
A vulnerability was identified in Linksys MR9600 2.0.6.206937. This affects the function BTRequestGetSmartConnectStatus of the file /etc/init.d/run_central2.sh of the component JNAP Action Handler. The manipulation of the argument pin leads to os command injection. The attack may be initiated remotely. The exploit is…
AplazadaAlta (7.5)0.39%—Linksoftwarellc WP Terms PopupAI25/3/202617/6/2026
Missing Authorization vulnerability in Link Software LLC WP Terms Popup wp-terms-popup allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Terms Popup: from n/a through <= 2.10.0.
AnalizadaAlta (7.4)7.8%—Linksys Mr9600 Firmware22/3/202617/6/2026
A flaw has been found in Linksys MR9600 2.0.6.206937. Affected is the function smartConnectConfigure of the file SmartConnect.lua. Executing a manipulation of the argument configApSsid/configApPassphrase/srpLogin/srpPassword can lead to os command injection. The attack may be launched remotely. The exploit has been…
AplazadaAlta (8.8)0.44%—Linksy Search AND ReplaceAI21/3/202617/6/2026
The Linksy Search and Replace plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'linksy_search_and_replace_item_details' function in all versions up to, and including, 1.0.4. This makes it possible for authenticated attackers, with subscriber-level access…
AplazadaAlta (7.2)0.35%—MylinksdumpAI21/3/202617/6/2026
The myLinksDump plugin for WordPress is vulnerable to SQL Injection via the 'sort_by' and 'sort_order' parameters in all versions up to, and including, 1.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated…
AnalizadaMedia (6.6)0.30%—Linksys Mr9600 FirmwareLinksys Mx4200 Firmware24/2/202617/6/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Linksys MR9600, Linksys MX4200 allows that contents of a USB drive partition can be mounted in an arbitrary location of the file system. This may result in the execution of shell scripts in the context of a root user.This…
AplazadaAlta (8.4)0.41%—BacklinkspeedAI29/1/202617/6/2026
BacklinkSpeed 2.4 contains a buffer overflow vulnerability that allows attackers to corrupt the Structured Exception Handler (SEH) chain through malicious file import. Attackers can craft a specially designed payload file to overwrite SEH addresses, potentially executing arbitrary code and gaining control of the…
AnalizadaCrítica (9.1)0.40%—Altumcode 66biolinks28/1/202617/6/2026
A session fixation vulnerability exists in 66biolinks v62.0.0 by AltumCode, where the application does not regenerate the session identifier after successful authentication. As a result, the same session cookie value is reused for users logging in from the same browser, allowing an attacker who can set or predict a…
AnalizadaMedia (6.5)0.71%—Altumcode 66biolinks28/1/202617/6/2026
A directory traversal (Zip Slip) vulnerability exists in the “Static Sites” feature of 66biolinks v44.0.0 by AltumCode. Uploaded ZIP archives are automatically extracted without validating or sanitizing file paths. An attacker can include traversal sequences (e.g., ../) in ZIP entries to write files outside the…
AplazadaMedia (6.1)0.26%—SEO Links InterlinkingAI28/1/202617/6/2026
The SEO Links Interlinking plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'google_error' parameter in all versions up to, and including, 1.7.9.9.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…