Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2622▼ 226 respecto a la semana anterior
Críticas / altas1383▲ 155 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
62 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.7) | 0.38% | — | Peplink Intcontrol 2 | 26/6/2026 | 2/7/2026 | Peplink InControl 2 through 2.14.2 before 2026-06-03 allows use of a semicolon to bypass access-control rules for certain /rest/o/{orgId} endpoints. | |
| Aplazada | Media (6.5) | 0.39% | — | Wplinkspage WP Links PageAI | 11/10/2025 | 17/6/2026 | The WP Links Page plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and including, 4.9.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (6.4) | 0.30% | — | WP ApplinkAI | 24/7/2025 | 17/6/2026 | The WP Applink plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title’ parameter in all versions up to, and including, 0.4.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject… | |
| Aplazada | Media (4.3) | 0.14% | — | Indgeek CliplinkAI | 20/6/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in indgeek ClipLink cliplink allows Cross Site Request Forgery.This issue affects ClipLink: from n/a through <= 1.1. | |
| Aplazada | Media (6.5) | 0.35% | — | Powieit Powies Plinks PagepeekerAI | 16/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PowieT Powie's pLinks PagePeeker plinks allows DOM-Based XSS.This issue affects Powie's pLinks PagePeeker: from n/a through <= 1.0.2. | |
| Aplazada | Media (4.3) | 0.39% | — | Wplinkspage WP Links PageAI | 13/7/2024 | 17/6/2026 | The WP Links Page plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wplf_ajax_update_screenshots' function in all versions up to, and including, 4.9.5. This makes it possible for authenticated attackers, with Subscriber-level access and above, to… | |
| Modificada | Alta (8.8) | 1.3% | — | Peplink Smart Reader Firmware | 17/4/2024 | 17/6/2026 | A data integrity vulnerability exists in the web interface /cgi-bin/upload_config.cgi functionality of Peplink Smart Reader v1.2.0 (in QEMU). A specially crafted HTTP request can lead to configuration modification. An attacker can make an unauthenticated HTTP request to trigger this vulnerability. | |
| Modificada | Alta (7.5) | 1.4% | — | Peplink Smart Reader Firmware | 17/4/2024 | 17/6/2026 | An information disclosure vulnerability exists in the web interface /cgi-bin/download_config.cgi functionality of Peplink Smart Reader v1.2.0 (in QEMU). A specially crafted HTTP request can lead to a disclosure of sensitive information. An attacker can make an unauthenticated HTTP request to trigger this vulnerability. | |
| Modificada | Alta (7.5) | 1.5% | — | Peplink Smart Reader Firmware | 17/4/2024 | 17/6/2026 | An information disclosure vulnerability exists in the web interface /cgi-bin/debug_dump.cgi functionality of Peplink Smart Reader v1.2.0 (in QEMU). A specially crafted HTTP request can lead to a disclosure of sensitive information. An attacker can make an unauthenticated HTTP request to trigger this vulnerability. | |
| Modificada | Crítica (9.8) | 1.4% | — | Peplink Smart Reader Firmware | 17/4/2024 | 17/6/2026 | A privilege escalation vulnerability exists in the /bin/login functionality of Peplink Smart Reader v1.2.0 (in QEMU). A specially crafted command line argument can lead to a limited-shell escape and elevated capabilities. An attacker can authenticate with hard-coded credentials and execute unblocked default busybox… | |
| Modificada | Alta (7.2) | 38% | — | Peplink Smart Reader Firmware | 17/4/2024 | 17/6/2026 | An OS command injection vulnerability exists in the web interface mac2name functionality of Peplink Smart Reader v1.2.0 (in QEMU). A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability. | |
| Modificada | Alta (8.8) | 2.1% | — | Peplink Balance TWO Firmware | 28/12/2023 | 17/6/2026 | An issue was discovered in Peplink Balance Two before 8.4.0. A missing authorization check in captive portals allows attackers to modify the portals' configurations without prior authentication. | |
| Modificada | Media (4.3) | 0.49% | — | Peplink Balance TWO Firmware | 28/12/2023 | 17/6/2026 | An issue was discovered in Peplink Balance Two before 8.4.0. A missing authorization check in the administration web service allows read-only, unprivileged users to obtain sensitive information about the device configuration. | |
| Modificada | Media (6.4) | 0.47% | — | Peplink Balance TWO Firmware | 28/12/2023 | 17/6/2026 | An issue was discovered in Peplink Balance Two before 8.4.0. Console port authentication uses hard-coded credentials, which allows an attacker with physical access and sufficient knowledge to execute arbitrary commands as root. | |
| Modificada | Alta (7.2) | 3.4% | — | Peplink Balance TWO Firmware | 25/12/2023 | 17/6/2026 | An issue was discovered in Peplink Balance Two before 8.4.0. Command injection in the traceroute feature of the administration console allows users with admin privileges to execute arbitrary commands as root. | |
| Modificada | Alta (8.8) | 0.29% | — | Wplinkspage WP Links Page | 18/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Robert Macchi WP Links Page.This issue affects WP Links Page: from n/a through 4.9.4. | |
| Modificada | Alta (8.8) | 5.6% | — | Peplink Surf Soho Firmware | 11/10/2023 | 17/6/2026 | An OS command injection vulnerability exists in the api.cgi cmd.mvpn.x509.write functionality of peplink Surf SOHO HW1 v6.3.5 (in QEMU). A specially crafted HTTP request can lead to command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.This vulnerability is specifically… | |
| Modificada | Alta (8.8) | 5.6% | — | Peplink Surf Soho Firmware | 11/10/2023 | 17/6/2026 | An OS command injection vulnerability exists in the api.cgi cmd.mvpn.x509.write functionality of peplink Surf SOHO HW1 v6.3.5 (in QEMU). A specially crafted HTTP request can lead to command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.This vulnerability is specifically… | |
| Modificada | Alta (8.8) | 5.5% | — | Peplink Surf Soho Firmware | 11/10/2023 | 17/6/2026 | An OS command injection vulnerability exists in the data.cgi xfer_dns functionality of peplink Surf SOHO HW1 v6.3.5 (in QEMU). A specially crafted HTTP request can lead to command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability. | |
| Modificada | Media (5.4) | 0.81% | — | Peplink Surf Soho Firmware | 11/10/2023 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability exists in the upload_brand.cgi functionality of peplink Surf SOHO HW1 v6.3.5 (in QEMU). A specially crafted HTTP request can lead to execution of arbitrary javascript in another user's browser. An attacker can make an authenticated HTTP request to trigger this… | |
| Modificada | Alta (8.8) | 5.9% | — | Peplink Surf Soho Firmware | 11/10/2023 | 17/6/2026 | An OS command injection vulnerability exists in the admin.cgi MVPN_trial_init functionality of peplink Surf SOHO HW1 v6.3.5 (in QEMU). A specially crafted HTTP request can lead to command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability. | |
| Modificada | Alta (8.8) | 5.7% | — | Peplink Surf Soho Firmware | 11/10/2023 | 17/6/2026 | An OS command injection vulnerability exists in the admin.cgi USSD_send functionality of peplink Surf SOHO HW1 v6.3.5 (in QEMU). A specially crafted HTTP request can lead to command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability. | |
| Modificada | Alta (8.8) | 2.2% | — | Juplink Rx4-1500 Firmware | 22/9/2023 | 17/6/2026 | Command injection in homemng.htm in Juplink RX4-1500 versions V1.0.2, V1.0.3, V1.0.4, and V1.0.5 allows remote authenticated attackers to execute commands via specially crafted requests to the vulnerable endpoint. | |
| Modificada | Alta (8.8) | 2.7% | — | Juplink Rx4-1500 Firmware | 22/9/2023 | 17/6/2026 | Command injection vulnerability in the homemng.htm endpoint in Juplink RX4-1500 Wifi router firmware versions V1.0.2, V1.0.3, V1.0.4, and V1.0.5 allows authenticated remote attackers to execute commands as root via specially crafted HTTP requests to the vulnerable endpoint. | |
| Modificada | Alta (8.8) | 0.89% | — | Juplink Rx4-1500 Firmware | 22/9/2023 | 17/6/2026 | Credential disclosure in the '/webs/userpasswd.htm' endpoint in Juplink RX4-1500 Wifi router firmware versions V1.0.4 and V1.0.5 allows an authenticated attacker to leak the password for the administrative account via requests to the vulnerable endpoint. |