Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2573▼ 368 respecto a la semana anterior
Críticas / altas1324▲ 44 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)97▼ 430 respecto a la semana anterior
11 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.25% | — | Internal Links ManagerAI | 2/7/2026 | 2/7/2026 | Unauthenticated Cross Site Scripting (XSS) in Internal Links Manager <= 3.0.3 versions. | |
| Aplazada | Media (4.3) | 0.16% | — | Internal Links ManagerAI | 20/9/2025 | 17/6/2026 | The Internal Links Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0.1. This is due to missing or incorrect nonce validation on the link deletion functionality in the process_bulk_action() function. This makes it possible for unauthenticated attackers to… | |
| Aplazada | Media (5.8) | 0.21% | — | Winking Affiliate-links-managerAI | 3/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in winking Affiliate Links Manager affiliate-links-manager allows Reflected XSS.This issue affects Affiliate Links Manager: from n/a through <= 1.0. | |
| Aplazada | Media (4.3) | 0.44% | — | Webraketen Internal Links ManagerAI | 24/1/2025 | 17/6/2026 | Missing Authorization vulnerability in webraketen Internal Links Manager seo-automated-link-building allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Internal Links Manager: from n/a through <= 2.5.2. | |
| Aplazada | Alta (8.1) | 0.75% | — | Mainwp Links Manager ExtensionAI | 28/3/2024 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in MainWP MainWP Links Manager Extension.This issue affects MainWP Links Manager Extension: from n/a through 2.1. | |
| Modificada | Alta (8.8) | 0.26% | — | Daext Autolinks Manager | 13/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in DAEXT Autolinks Manager plugin <= 1.10.04 versions. | |
| Modificada | Alta (7.5) | 1.1% | — | Source Workshop Reciprocal Links Manager | 15/9/2008 | 16/6/2026 | SQL injection vulnerability in index.php in Reciprocal Links Manager 1.1 allows remote attackers to execute arbitrary SQL commands via the site parameter in an open action. | |
| Modificada | Alta (7.5) | 1.3% | — | Jiros Links Manager | 28/11/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in JiRos Links Manager allow remote attackers to execute arbitrary SQL commands via the (1) LinkID parameter to openlink.asp or the (2) CategoryID parameter to viewlinks.asp. | |
| Modificada | Media (6.8) | 1.6% | — | Jiros Links Manager | 28/11/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in submitlink.asp in JiRos Links Manager allow remote attackers to inject arbitrary web script or HTML via the (1) lName, (2) lURL, (3) lImage, and (4) lDescription parameters. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (5.1) | 1.3% | — | Cloudnine Interactive Links Manager | 24/8/2006 | 16/6/2026 | SQL injection vulnerability in admin.php in CloudNine Interactive Links Manager 2006-06-12, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the nick parameter. | |
| Modificada | Media (6.8) | 1.6% | — | Cloudnine Interactive Links Manager | 24/8/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in add_url.php in CloudNine Interactive Links Manager 2006-06-12 allow remote attackers to inject arbitrary web script or HTML via the (1) title, (2) description, or (3) keywords parameters. |