Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2847▼ 151 respecto a la semana anterior
Críticas / altas1373▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)267▼ 257 respecto a la semana anterior
–

15 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (4.3)0.14%—Galaxyweblinks Post Featured VideoAI26/9/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Galaxy Weblinks Post Featured Video post-featured-video allows Cross Site Request Forgery.This issue affects Post Featured Video: from n/a through <= 1.7.
AplazadaMedia (6.5)0.40%—Galaxyweblinks Video Playlist FOR YoutubeAI4/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Galaxy Weblinks Video Playlist For YouTube video-playlist-for-youtube allows Stored XSS.This issue affects Video Playlist For YouTube: from n/a through <= 6.7.1.
AplazadaMedia (5.3)0.37%—Galaxyweblinks WP Clone ANY Post TypeAI1/4/202517/6/2026
Missing Authorization vulnerability in Galaxy Weblinks WP Clone any post type wp-clone-any-post-type allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Clone any post type: from n/a through <= 3.6.
AplazadaMedia (4.7)0.36%—Galaxyweblinks WP Clone ANY Post TypeAI1/4/202517/6/2026
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Galaxy Weblinks WP Clone any post type wp-clone-any-post-type allows Phishing.This issue affects WP Clone any post type: from n/a through <= 3.6.
ModificadaAlta (8.8)0.21%—Galaxyweblinks Video Playlist FOR Youtube16/10/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Galaxy Weblinks Video Playlist For YouTube plugin <= 6.0 versions.
ModificadaMedia (5.4)0.38%—Galaxyweblinks Gallery With Thumbnail Slider21/3/202317/6/2026
Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in Galaxy Weblinks Gallery with thumbnail slider plugin <= 6.0 versions.
ModificadaCrítica (9.8)0.95%—Hanssak SecuregateHanssak Weblink19/9/202217/6/2026
This vulnerability of SecureGate is SQL-Injection using login without password. A path traversal vulnerability is also identified during file transfer. An attacker can take advantage of these vulnerabilities to perform various attacks such as obtaining privileges and executing remote code, thereby taking over the…
ModificadaMedia (4.3)1.9%—Allomani Weblinks4/11/201417/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Allomani Weblinks 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) default URI to admin.php or the (2) id parameter to admin.php or (3) go.php.
ModificadaAlta (7.5)2.1%—Allomani Weblinks14/10/201417/6/2026
Multiple SQL injection vulnerabilities in Allomani Weblinks 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) cat parameter in a browse action to index.php or (2) unspecified parameters to admin.php.
ModificadaAlta (7.5)1.1%—Joomla COM Weblinks6/9/201216/6/2026
SQL injection vulnerability in the Weblinks (com_weblinks) component for Joomla! and Mambo 1.0.9 and earlier allows remote attackers to execute arbitrary SQL commands via the title parameter.
ModificadaAlta (7.5)0.90%—Joomla COM Weblinks9/10/201116/6/2026
SQL injection vulnerability in the Weblinks (com_weblinks) component in Joomla! allows remote attackers to execute arbitrary SQL commands via the Itemid parameter in a categories action to index.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
ModificadaAlta (7.5)0.97%—Joomla COM WeblinksJoomla!8/7/201016/6/2026
SQL injection vulnerability in the Weblinks (com_weblinks) component in Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a view action to index.php.
ModificadaAlta (7.5)0.97%—Brightcode Weblinks ModuleJoomla COM Brightweblinks9/7/200816/6/2026
SQL injection vulnerability in Brightcode Weblinks (com_brightweblinks) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter.
ModificadaMedia (5)1.8%—Full Revolution Aspweblinks6/6/200616/6/2026
links.asp in aspWebLinks 2.0 allows remote attackers to change the administrative password, possibly via a direct request with a modified txtAdministrativePassword field.
ModificadaAlta (7.5)1.3%—Full Revolution Aspweblinks6/6/200616/6/2026
SQL injection vulnerability in links.asp in aspWebLinks 2.0 allows remote attackers to execute arbitrary SQL commands via the linkID parameter.