Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

6789 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.3)0.81%—Zbtlink L3 V2 8AIZbtlink We826-t2AIZbtlink Zbt-7628AIZbtlink Zbt-zbt7621AI+1127/8/202624/9/2026
Zbtlink L3_V2_8 firmware 3.0.0.4.528, Zbtlink WE826-T2 firmware 19.1101, Zbtlink ZBT-7628 firmware 1.0.0.2.007, Zbtlink ZBT-ZBT7621 firmware 1.0.0.3.001, MoreQuick MQAC-7620, MQAC-7620A, MQAP-7620, MQAP-7620A, and MQAP-7628 firmware 1.0.0.2.000, AP522 firmware 1.0.0.2.014, AP7628 and HC5661A firmware 3.0.0.4.380,…
AplazadaMedia (5.5)0.69%—Danielpopamd Linkedin-ads-mcpAI27/8/202628/8/2026
A security vulnerability has been detected in danielpopamd linkedin-ads-mcp 1.0.0. Affected by this vulnerability is the function fs.readFileSync of the file src/tools/campaign-management.ts of the component Media Upload. Such manipulation of the argument filePath leads to path traversal. The attack may be performed…
AplazadaCrítica (9.1)0.40%—Jetlinks CommunityAI26/8/20269/9/2026
The device metadata import interface /device/instance/{productId}/property-metadata/import of jetlinks community 2.11 is vulnerable to Server-side request forgery (SSRF).
Pendiente de análisisAlta (8.7)0.20%—Tp-link KasaAI26/8/202628/8/2026
Multiple TP-Link Kasa smart home devices contain insufficient cryptographic protections in the local device communication protocol. An adjacent network attacker may intercept, replay or forge locally exchanged control messages, potentially resulting in unauthorized device control. Successful exploitation could allow…
AplazadaMedia (5.5)2.1%—Totolink N600rAI25/8/202626/8/2026
A vulnerability was detected in TOTOLINK N600R 4.3.0cu.7647_B20210106. The impacted element is the function getCurrentTime of the file /cgi-bin/cstecgi.cgi. Performing a manipulation of the argument ntp_server results in command injection. The attack can be initiated remotely. The exploit is now public and may be used.
AplazadaCrítica (9.3)1.1%—Totolink N600rAI25/8/202627/8/2026
A security vulnerability has been detected in TOTOLINK N600R 4.3.0cu.7647_B20210106. The affected element is the function setSystemConfig of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such manipulation of the argument Hostname leads to stack-based buffer overflow. It is possible to launch the attack…
AplazadaMedia (4.3)0.29%—Wpdeveloper BetterlinksAI25/8/202626/8/2026
The BetterLinks – Link Shortener, Link Cloaking, Redirects, Affiliate Link Manager & MCP plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.1.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for…
Pendiente de análisisAlta (8.5)2.3%—Tp-link Archer Be3600AI24/8/202628/8/2026
A stored OS command injection vulnerability exists in the parent-control module of TP-Link Archer BE3600 V1. An authenticated adjacent attacker with administrative access may store a crafted profile name containing shell metacharacters, which is later processed unsafely during daily cloud report generation and may…
Pendiente de análisisAlta (8.7)3.1%💥 PoCTp-link Archer Be800AITp-link Archer Be3600AITp-link Archer Ax75AI24/8/202628/8/2026
An unauthenticated OS command injection vulnerability exists in the parental control functionality of Archer BE800 V1, BE3600 V1, and AX75 V1 due to improper filtering and neutralization of special characters in certain parameters. A LAN-based attacker can inject arbitrary commands and execute them with root…
Pendiente de análisisAlta (8.5)2.0%💥 PoCTp-link Archer Be800AI24/8/202628/8/2026
An authenticated command injection vulnerability in TP-Link Archer BE800 V1 allows an attacker with administrative access to execute arbitrary system commands with root privileges by injecting shell metacharacters via a VPN connection. Successful exploitation may enable persistent backdoors, credential theft, LAN…
Pendiente de análisisAlta (7.7)0.38%💥 PoCTp-link Deco Xe75AITp-link Xe5300AITp-link We10800AI24/8/202628/8/2026
The use of hard-coded cryptographic key vulnerability has been identified in the mesh functionality of Deco XE75 v3, XE5300 v3.6 and WE10800 v3.6. A shared RSA-512 mesh group private key is present in the affected firmware and is used by the mesh protocol for node authentication. An attacker who obtains the firmware…
AplazadaAlta (8.1)0.22%—Dlink Di-8100gAI24/8/202629/9/2026
In D-Link DI-8100G 17.12.20A1, the flag parameter in msp_info can be exploited to execute arbitrary code.
AplazadaAlta (8.1)0.22%—Dlink Di-7001 Mini 5GAI24/8/202629/9/2026
D-Link DI-7001 MINI_5G 19.10.31A1 contains a code execution vulnerability in the flag parameter of msp_info, which can be exploited to run arbitrary commands.
Pendiente de análisisAlta (7.1)0.27%—Tp-link Tl-mr6400AI21/8/202628/8/2026
A stack-based out-of-bounds write vulnerability exists in the login request handling functionality of the administrative web interface of TP-Link TL-MR6400 v7 routers. An unauthenticated adjacent attacker can trigger the vulnerability by sending a specially crafted malformed HTTP request. Successful exploitation may…
Pendiente de análisisAlta (7.1)0.47%—Tp-link TL Mr6400AI21/8/202628/8/2026
A NULL pointer dereference vulnerability exists in the HTTP request parsing functionality of TL-MR6400 v7. An unauthenticated remote attacker can trigger the vulnerability by sending a specially crafted HTTP request containing a malformed session cookie header. Successful exploitation may cause the HTTP service…
Pendiente de análisisAlta (8.5)0.29%—Tp-link Tl-mr6400AI21/8/202628/8/2026
A stack-based buffer overflow vulnerability exists in the firmware update functionality of TL-MR6400 v7 due to unsafe processing of attacker-controlled metadata within a firmware image. Successful exploitation may allow an authenticated attacker to trigger memory corruption and execute arbitrary code on the affected…
AplazadaMedia (6.8)0.39%—Linkwhisper Link Whisper FreeAI21/8/202626/8/2026
The Link Whisper Free WordPress plugin before 0.9.7 does not properly sanitize and escape a parameter before using it in a SQL query, allowing authenticated users with the Editor role or above to perform SQL injection attacks.
AplazadaAlta (7.7)0.44%—PTC Windchill PdmlinkAIPTC FlexplmAI20/8/20269/9/2026
A Server-Side Request Forgery (SSRF) vulnerability has been reported in PTC Windchill PDMLink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data.
AplazadaAlta (7.3)0.37%—LinkaceAI20/8/202618/9/2026
LinkAce is a self-hosted archive to collect website links. Prior to version 2.5.7, the Bulk Link API endpoint (`POST /api/v2/bulk/links`) accepts URLs without any format validation, allowing an authenticated user to store a `javascript:` URI. The stored URI is later rendered verbatim as an `href` in Blade templates,…
AnalizadaMedia (6)0.28%—Tp-link Er7212pc FirmwareTp-link Er605 FirmwareTp-link Er7206 FirmwareTp-link Er7406 Firmware+1420/8/20268/9/2026
An unauthenticated attacker with network access to the captive portal service of an affected device can terminate active captive portal sessions, including forcing logout of specific users or clearing all active sessions. Affected users must re-authenticate to regain access. Successful exploitation may allow…
AnalizadaMedia (6.3)0.25%—Tp-link Er7212pc FirmwareTp-link Er605 FirmwareTp-link Er7206 FirmwareTp-link Er7406 Firmware+1420/8/20268/9/2026
A vulnerability exists in the Dynamic DNS (DDNS) functionality of TP-Link Omada Gateways. During communication with a third-party DDNS service, authentication credentials are transmitted over an unencrypted channel. An attacker who can observe or manipulate traffic between an affected device and the DDNS service may…
AnalizadaCrítica (9.3)5.7%💥 PoCTp-link Er7212pc FirmwareTp-link Er605 FirmwareTp-link Er605w FirmwareTp-link Er7206 Firmware+1420/8/20263/9/2026
A pre-authentication OS command injection vulnerability has been identified in Omada gateways configured to operate as an OpenVPN Server due to insufficient validation of client-supplied data during OpenVPN connection establishment. An unauthenticated remote attacker may provide specially crafted input influencing…
AplazadaAlta (7.5)0.55%—Link Preview JSAI20/8/202618/9/2026
Link Preview JS extracts web links information. Prior to 4.0.4, the resolveDNSHost mitigation in index.ts validates one resolved IP address but fetches the original hostname, allowing an attacker-controlled DNS server to return a public address during validation and a loopback or internal address during the final…
AnalizadaAlta (7.1)0.87%—Tp-link Tl-mr100 FirmwareTp-link Archer Mr600 FirmwareTp-link Tl-mr150 FirmwareTp-link Tl-mr6400 Firmware20/8/20263/9/2026
An unauthenticated denial-of-service vulnerability was identified in TP-Link TL-MR100 v3.2, TL-MR150 v3.2, TL-MR6400 v8.0 and Archer MR600 v2, due to improper handling of exceptional request conditions that may lead to a NULL pointer dereference. A remote attacker on an adjacent network can send a specially crated…
AnalizadaAlta (8.5)2.8%💥 PoCTp-link Archer C20 Firmware19/8/20268/9/2026
An OS command injection vulnerability exists in the web management interface of Archer C20 v6 firmware when processing certain WAN-related configuration operations. An authenticated administrator may exploit insufficient input validation to execute arbitrary system commands, potentially resulting in full device…