Vulnerabilities

Summary — last 7 days

New vulnerabilities2,833▲ 192 vs. last week
Critical / high1,319▼ 117 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)234▲ 220 vs. last week
–

70 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
ModifiedMedium (6.1)1.1%—Visonic Powerlink2 Firmware2/13/20176/17/2026
An issue was discovered in Visonic PowerLink2, all versions prior to October 2016 firmware release. User controlled input is not neutralized prior to being placed in web page output (CROSS-SITE SCRIPTING).
ModifiedHigh (7.5)1.3%💥 ExploitCacti Superlinks6/25/20146/17/2026
SQL injection vulnerability in superlinks.php in the superlinks plugin 1.4-2 for Cacti allows remote attackers to execute arbitrary SQL commands via the id parameter.
ModifiedHigh (10)3.9%—Sierrawireless Raven X Ev-do FirmwareSierrawireless Airlink MP At&tSierrawireless Airlink MP At&t WifiSierrawireless Airlink MP Bell+151/15/20146/16/2026
The Sierra Wireless AirLink Raven X EV-DO gateway 4221_4.0.11.003 and 4228_4.0.11.003 allows remote attackers to reprogram the firmware via a replay attack using UDP ports 17336 and 17388.
ModifiedHigh (9.3)1.9%—Sierrawireless Raven X Ev-do FirmwareSierrawireless Airlink MP At&tSierrawireless Airlink MP At&t WifiSierrawireless Airlink MP Bell+151/15/20146/16/2026
The Sierra Wireless AirLink Raven X EV-DO gateway 4221_4.0.11.003 and 4228_4.0.11.003 allows remote attackers to install Trojan horse firmware by leveraging cleartext credentials in a crafted (1) update or (2) reprogramming action.
ModifiedHigh (9.3)46%💥 ExploitCyberlink Power2go9/15/20126/16/2026
Multiple stack-based buffer overflows in CyberLink Power2Go 7 (build 196) and 8 (build 1031) allow remote attackers to execute arbitrary code via the (1) src and (2) name parameters in a p2g project file.
ModifiedMedium (6.9)0.40%—Cyberlink Power2go9/7/20126/16/2026
Multiple untrusted search path vulnerabilities in Cyberlink Power2Go 7.0.0.0816 allow local users to gain privileges via a Trojan horse (1) dwmapi.dll or (2) MFC71LOC.DLL file in the current working directory, as demonstrated by a directory that contains a .p2g, .iso, .pdl, .pds, or .p2i file. NOTE: some of these…
ModifiedMedium (6.9)0.53%—Cyberlink Powerdirector9/7/20126/16/2026
Untrusted search path vulnerability in CyberLink PowerDirector 8.00.3022 allows local users to gain privileges via a Trojan horse dwmapi.dll file in the current working directory, as demonstrated by a directory that contains a .pdl, .iso, .pds, .p2g, or .p2i file. NOTE: some of these details are obtained from third…
ModifiedMedium (6.9)0.41%—Cyberlink Powerdirector9/7/20126/16/2026
Untrusted search path vulnerability in CyberLink PowerDirector 7 allows local users to gain privileges via a Trojan horse mfc71loc.dll file in the current working directory, as demonstrated by a directory that contains a .pdl, .iso, .pds, .p2g, or .p2i file. NOTE: some of these details are obtained from third party…
ModifiedMedium (6.9)0.41%—Cyberlink Powerproducer9/6/20126/16/2026
Multiple untrusted search path vulnerabilities in CyberLink PowerProducer 5.5.3.2325 allow local users to gain privileges via a Trojan horse (1) mfc71loc.dll or (2) mfc71enu.dll file in the current working directory, as demonstrated by a directory that contains a .ppp or .rdf file. NOTE: the provenance of this…
ModifiedMedium (6.9)0.36%—Cyberlink Streamauthor9/6/20126/16/2026
Multiple untrusted search path vulnerabilities in CyberLink StreamAuthor 4.0 build 3308 allow local users to gain privileges via a Trojan horse (1) mfc71loc.dll or (2) mfc71enu.dll file in the current working directory, as demonstrated by a directory that contains a .sta or .stp file. NOTE: the provenance of this…
ModifiedMedium (6.9)0.36%—Cyberlink Labelprint9/6/20126/16/2026
Multiple untrusted search path vulnerabilities in CyberLink LabelPrint 2.5.3602 allow local users to gain privileges via a Trojan horse (1) mfc71loc.dll or (2) mfc71enu.dll file in the current working directory, as demonstrated by a directory that contains a .lpp file. NOTE: the provenance of this information is…
ModifiedHigh (7.7)1.6%—ABB Interlink ModuleABB QuickteachABB Robotstudio LiteABB Robotstudio S4+34/18/20126/16/2026
Multiple stack-based buffer overflows in (1) COM and (2) ActiveX controls in ABB WebWare Server, WebWare SDK, Interlink Module, S4 OPC Server, QuickTeach, RobotStudio S4, and RobotStudio Lite allow remote attackers to execute arbitrary code via crafted input data.
ModifiedHigh (10)8.2%—ABB Interlink ModuleABB Irc5 OPC ServerABB PC SDKABB Pickmaster 3+63/9/20126/16/2026
Multiple stack-based buffer overflows in RobNetScanHost.exe in ABB Robot Communications Runtime before 5.14.02, as used in ABB Interlink Module, IRC5 OPC Server, PC SDK, PickMaster 3 and 5, RobView 5, RobotStudio, WebWare SDK, and WebWare Server, allow remote attackers to execute arbitrary code via a crafted (1) 0xA…
ModifiedHigh (7.5)1.0%—Typo3 Vm19 Userlinks1/15/20106/16/2026
SQL injection vulnerability in the User Links (vm19_userlinks) extension 0.1.1 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
ModifiedMedium (6.4)16%💥 ExploitCyberlink Powerdvd10/5/20076/16/2026
Directory traversal vulnerability in the CLAVSetting.CLSetting.1 ActiveX control in CLAVSetting.DLL 1.00.1829 in the CLAVSetting module in CyberLink PowerDVD 7.0 allows remote attackers to create or overwrite arbitrary files via a .. (dot dot) in the argument to the CreateNewFile method.
ModifiedHigh (9.3)12%—Microsoft Hyperlink Object Library8/9/20066/16/2026
Unspecified vulnerability in Microsoft Hyperlink Object Library (hlink.dll), possibly a buffer overflow, allows user-assisted attackers to execute arbitrary code via crafted hyperlinks that are not properly handled when hlink.dll "uses a file containing a malformed function," aka "Hyperlink Object Function…
ModifiedHigh (9.3)56%💥 ExploitMicrosoft Hyperlink Object Library6/19/20066/16/2026
Stack-based buffer overflow in the HrShellOpenWithMonikerDisplayName function in Microsoft Hyperlink Object Library (hlink.dll) allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long hyperlink, as demonstrated using an Excel worksheet with a long link in Unicode,…
ModifiedLow (2.6)1.2%—Interlink Advantage6/2/20066/16/2026
Cross-site scripting (XSS) vulnerability in news_information.php in Interlink Advantage allows remote attackers to inject arbitrary web script or HTML via the flag parameter.
ModifiedMedium (4.3)1.2%—Yourboard Rlink2/1/20066/16/2026
Cross-site scripting (XSS) vulnerability in rlink.php in Rlink 1.0.0 module for phpBB allows remote attackers to inject arbitrary web script or HTML via the url parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
ModifiedMedium (6.4)4.9%💥 ExploitTEK Phaserlink6/27/20016/16/2026
Tektronix PhaserLink 850 does not require authentication for access to configuration pages such as _ncl_subjects.shtml and _ncl_items.shtml, which allows remote attackers to modify configuration information and cause a denial of service by accessing the pages.
Orbitaley — Vulnerabilities