Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2556▼ 352 respecto a la semana anterior
Críticas / altas1335▲ 66 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)93▼ 434 respecto a la semana anterior
–

17 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.9)0.55%—Slinkapp SlinkAI4/9/202623/9/2026
Slink before 1.12.3 fails to properly authorize access to image comment endpoints, allowing unauthenticated attackers to read comment threads via GET /api/image/{imageId}/comments and server-sent-events subscriptions. Attackers who obtain image IDs out of band can retrieve full comment threads on public images and…
AplazadaAlta (7.1)0.19%—Mitsubishielectric Melsec MX Controller Mx-rAIMitsubishielectric Melsec MX Controller Mx-fAIMitsubishielectric Cc-link IE TSN Interface BoardAIMitsubishielectric Motion ModuleAI+2530/7/202618/9/2026
Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability in Mitsubishi Electric MELSEC MX Controller MX-R model, MELSEC MX Controller MX-F model, Master/local module, CC-Link IE TSN interface board, Motion module, MELSEC iQ-L Series Motion Module, Motion Control Board,…
AnalizadaMedia (6.1)0.27%—Slinkapp Slink3/9/202517/6/2026
Slink v1.4.9 allows stored cross-site scripting (XSS) via crafted SVG uploads. When a user views the shared image in a new browser tab, the embedded JavaScript executes. The issue affects both authenticated and unauthenticated users.
ModificadaMedia (6.1)0.45%—Classlink Oneclick23/1/202417/6/2026
A Universal Cross Site Scripting (UXSS) vulnerability in ClassLink OneClick Extension through 10.8 allows remote attackers to inject JavaScript into any webpage. NOTE: this issue exists because of an incomplete fix for CVE-2022-48612.
ModificadaMedia (6.1)0.43%—Classlink Oneclick16/10/202317/6/2026
A Universal Cross Site Scripting (UXSS) vulnerability in ClassLink OneClick Extension through 10.7 allows remote attackers to inject JavaScript into any webpage, because a regular expression (validating whether a URL is controlled by ClassLink) is not present in all applicable places.
ModificadaMedia (5.4)0.55%—Irislink Irisnext6/7/202117/6/2026
Multiple stored XSS vulnerabilities in IrisNext Edition 9.5.16, which allows an authenticated (or compromised) user to inject malicious JavaScript in folder/file name within the application in order to grab other users’ sessions or execute malicious code in their browsers (1-click RCE).
ModificadaAlta (7.5)3.9%—Ovislink Airlive Poe2600hd Firmware11/12/201916/6/2026
AirLive POE-2600HD allows remote attackers to cause a denial of service (device reset) via a long URL.
ModificadaAlta (7.5)0.76%—Systech Syslink Sl-1000 Modular Gateway Firmware25/4/201617/6/2026
SysLINK SL-1000 Machine-to-Machine (M2M) Modular Gateway devices with firmware before 01A.8 use the same hardcoded encryption key across different customers' installations, which allows attackers to defeat cryptographic protection mechanisms by leveraging knowledge of this key from another installation.
ModificadaAlta (8.8)2.8%—Systech Syslink Sl-1000 Modular Gateway Firmware25/4/201617/6/2026
flu.cgi in the web interface on SysLINK SL-1000 Machine-to-Machine (M2M) Modular Gateway devices with firmware before 01A.8 allows remote authenticated users to execute arbitrary commands via the 5066 (aka dnsmasq) parameter.
ModificadaCrítica (9.8)2.5%—Systech Syslink Sl-1000 Modular Gateway Firmware25/4/201617/6/2026
The web interface on SysLINK SL-1000 Machine-to-Machine (M2M) Modular Gateway devices with firmware before 01A.8 has a default password, which makes it easier for remote attackers to obtain access via unspecified vectors.
ModificadaAlta (7.8)2.5%—Ovislink Airlive Od-2025hdOvislink Airlive Od-2060hdOvislink Airlive Poe100hdOvislink Airlive Poe200hd+211/10/201316/6/2026
AirLive POE2600HD, POE250HD, POE200HD, OD-325HD, OD-2025HD, OD-2060HD, POE100HD, and possibly other camera models use cleartext to store sensitive information, which allows attackers to obtain passwords, user names, and other sensitive information by reading an unspecified backup file.
ModificadaAlta (10)28%—Ovislink Airlive Wl2600cam11/10/201316/6/2026
cgi-bin/operator/param in AirLive WL2600CAM and possibly other camera models allows remote attackers to obtain the administrator password via a list action.
ModificadaAlta (7.8)8.9%—Ovislink Airlive Wl2600cam4/10/201316/6/2026
Directory traversal vulnerability in cgi-bin/admin/fileread in AirLive WL2600CAM and possibly other camera models allows remote attackers to read arbitrary files via a .. (dot dot) in the READ.filePath parameter.
ModificadaMedia (6.8)0.97%—Ovislink Airlive Od-2025hdOvislink Airlive Od-2060hdOvislink Airlive Poe100hdOvislink Airlive Poe200hd+24/10/201316/6/2026
Cross-site request forgery (CSRF) vulnerability in cgi-bin/admin/usrgrp.cgi in AirLive POE2600HD, POE250HD, POE200HD, OD-325HD, OD-2025HD, OD-2060HD, POE100HD, and possibly other camera models allows remote attackers to hijack the authentication of administrators for requests that add users.
ModificadaMedia (6.8)8.8%—Ovislink Airlive Wl2600camSony SNC Ch140Sony SNC Ch180Sony SNC Ch240+71/10/201316/6/2026
Cross-site request forgery (CSRF) vulnerability in the command/user.cgi in Sony SNC CH140, SNC CH180, SNC CH240, SNC CH280, SNC DH140, SNC DH140T, SNC DH180, SNC DH240, SNC DH240T, SNC DH280, and possibly other camera models allows remote attackers to hijack the authentication of administrators for requests that add…
ModificadaMedia (4.3)1.1%—Axscripts Axslinks27/9/201116/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in addlink.php in AXScripts AxsLinks 0.3 allow remote attackers to inject arbitrary web script or HTML via the (1) url or (2) title parameter.
ModificadaAlta (7.5)1.4%—Sslinks7/9/200616/6/2026
Multiple SQL injection vulnerabilities in links.php in ssLinks 1.22 allow remote attackers to execute arbitrary SQL commands via the (1) go parameter and (2) id parameter in a rate action.