Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
1191 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.5) | 0.38% | — | Tp-link Tl-wdr7660 Firmware | 15/10/2024 | 17/6/2026 | In TP-Link TL-WDR7660 1.0, the wlanTimerRuleJsonToBin function handles the parameter string name without checking it, which can lead to stack overflow vulnerabilities. | |
| Analizada | Media (5.5) | 0.24% | — | Tp-link Wr740n Firmware | 7/10/2024 | 17/6/2026 | TP-Link WR740N V6 has a stack overflow vulnerability via the ssid parameter in /userRpm/popupSiteSurveyRpm.htm url. | |
| Analizada | Alta (8) | 0.82% | — | Tp-link Tl-wdr5620 Firmware | 4/10/2024 | 17/6/2026 | TP-LINK TL-WDR5620 v2.3 was discovered to contain a remote code execution (RCE) vulnerability via the httpProcDataSrv function. | |
| Aplazada | Media (4.3) | 0.20% | — | Tp-link Kasa Kp125mAITp-link Tapo P125mAI | 30/9/2024 | 17/6/2026 | An Information Disclosure vulnerability in the Telemetry component in TP-Link Kasa KP125M V1.0.0 and Tapo P125M 1.0.0 Build 220930 Rel.143947 allows attackers to observe device state via observing network traffic. | |
| Aplazada | Alta (7.6) | 0.36% | — | Tp-link Kasa Kp125mAI | 30/9/2024 | 17/6/2026 | An issue in the TP-Link MQTT Broker and API gateway of TP-Link Kasa KP125M v1.0.3 allows attackers to establish connections by impersonating devices owned by other users. | |
| Aplazada | Media (6.3) | 0.16% | — | Tp-link Tapo P125mAITp-link Kasa Kp125mAI | 30/9/2024 | 17/6/2026 | TP-Link Tapo P125M and Kasa KP125M v1.0.3 was discovered to improperly validate certificates, allowing attackers to eavesdrop on communications and access sensitive information via a man-in-the-middle attack. | |
| Analizada | Alta (8) | 2.4% | — | Tp-link Wr941nd Firmware | 30/9/2024 | 17/6/2026 | TP-Link WR941ND V6 has a stack overflow vulnerability in the ssid parameter in /userRpm/popupSiteSurveyRpm.htm. | |
| Analizada | Alta (7.1) | 0.98% | — | Tp-link Tl-wr841nd Firmware | 27/9/2024 | 17/6/2026 | A vulnerability was found in TP-LINK TL-WR841ND up to 20240920. It has been rated as critical. Affected by this issue is some unknown functionality of the file /userRpm/popupSiteSurveyRpm.htm. The manipulation of the argument ssid leads to stack-based buffer overflow. The attack may be launched remotely. The exploit… | |
| Analizada | Crítica (9.8) | 0.81% | — | Tp-link Re365 Firmware | 19/8/2024 | 17/6/2026 | In the TP-Link RE365 V1_180213, there is a buffer overflow vulnerability due to the lack of length verification for the USER_AGENT field in /usr/bin/httpd. Attackers who successfully exploit this vulnerability can cause the remote target device to crash or execute arbitrary commands. | |
| Analizada | Alta (8.7) | 0.48% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+17 | 14/8/2024 | 17/6/2026 | In BIG-IP tenants running on r2000 and r4000 series hardware, or BIG-IP Virtual Edition (VEs) using Intel E810 SR-IOV NIC, undisclosed traffic can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Analizada | Media (5.3) | 0.30% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+17 | 14/8/2024 | 17/6/2026 | Undisclosed requests to BIG-IP iControl REST can lead to information leak of user account names. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Analizada | Alta (8.2) | 0.44% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+19 | 14/8/2024 | 17/6/2026 | When TCP profile with Multipath TCP enabled (MPTCP) is configured on a Virtual Server, undisclosed traffic along with conditions beyond the attackers control can cause TMM to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Analizada | Alta (8.7) | 0.48% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+17 | 14/8/2024 | 17/6/2026 | When a stateless virtual server is configured on BIG-IP system with a High-Speed Bridge (HSB), undisclosed requests can cause TMM to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Aplazada | Media (5.4) | 0.32% | — | Tp-link TL Sg1016deAI | 15/7/2024 | 17/6/2026 | An authenticated stored cross-site scripting (XSS) exists in the TP-Link TL-SG1016DE affecting version TL-SG1016DE(UN) V7.6_1.0.0 Build 20230616, which could allow an adversary to run JavaScript in an administrator's browser. This issue was fixed in TL-SG1016DE(UN) V7_1.0.1 Build 20240628. | |
| Aplazada | Media (4.3) | 0.39% | — | Wplinkspage WP Links PageAI | 13/7/2024 | 17/6/2026 | The WP Links Page plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wplf_ajax_update_screenshots' function in all versions up to, and including, 4.9.5. This makes it possible for authenticated attackers, with Subscriber-level access and above, to… | |
| Aplazada | Media (6.8) | 0.36% | — | Tp-linkAI | 4/7/2024 | 17/6/2026 | Multiple TP-LINK products allow a network-adjacent attacker with an administrative privilege to execute arbitrary OS commands by restoring a crafted backup file. The affected device, with the initial configuration, allows login only from the LAN port or Wi-Fi. | |
| Modificada | Alta (7.2) | 0.88% | — | Tp-link Er7206 Firmware | 25/6/2024 | 17/6/2026 | A leftover debug code vulnerability exists in the cli_server debug functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.4.1 Build 20240117 Rel.57421. A specially crafted series of network requests can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger this vulnerability. | |
| Analizada | Media (6.3) | 0.38% | — | Tp-link Tl-7dr5130 Firmware | 17/6/2024 | 17/6/2026 | TP-LINK TL-7DR5130 v1.0.23 is vulnerable to TCP DoS or hijacking attacks. An attacker in the same WLAN as the victim can disconnect or hijack the traffic between the victim and any remote server by sending out forged TCP RST messages to evict NAT mappings in the router. | |
| Analizada | Media (6.3) | 0.28% | — | Tp-link Tl-7dr5130 Firmware | 17/6/2024 | 17/6/2026 | TP-LINK TL-7DR5130 v1.0.23 is vulnerable to forged ICMP redirect message attacks. An attacker in the same WLAN as the victim can hijack the traffic between the victim and any remote server by sending out forged ICMP redirect messages. | |
| Aplazada | Media (5.4) | 0.31% | — | Martin Gibson WP Linkedin Auto PublishAI | 9/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Martin Gibson WP LinkedIn Auto Publish.This issue affects WP LinkedIn Auto Publish: from n/a through 8.11. | |
| Aplazada | Media (5.3) | 0.36% | — | Tp-link TL R473gp ACAITp-link Xdr6020AITp-link TL R479gp ACAITp-link TL R4239gAI+2 | 28/5/2024 | 17/6/2026 | An issue discovered in TP-LINK TL-R473GP-AC, TP-LINK XDR6020, TP-LINK TL-R479GP-AC, TP-LINK TL-R4239G, TP-LINK TL-WAR1200L, and TP-LINK TL-R476G routers allows attackers to hijack TCP sessions which could lead to a denial of service. | |
| Aplazada | Alta (8.8) | 3.2% | — | Tp-link Archer C4500xAI | 27/5/2024 | 17/6/2026 | The affected device expose a network service called "rftest" that is vulnerable to unauthenticated command injection on ports TCP/8888, TCP/8889, and TCP/8890. By successfully exploiting this flaw, remote unauthenticated attacker can gain arbitrary command execution on the device with elevated privileges.This issue… | |
| Analizada | Media (4.2) | 0.38% | — | Tp-link Omada Er605 Firmware | 23/5/2024 | 17/6/2026 | TP-Link Omada ER605 Reliance on Security Through Obscurity Vulnerability. This vulnerability allows network-adjacent attackers to access or spoof DDNS messages on affected installations of TP-Link Omada ER605 routers. Authentication is not required to exploit this vulnerability. However, devices are vulnerable only if… | |
| Analizada | Alta (7.5) | 0.83% | 💥 PoC | Tp-link Omada Er605 Firmware | 23/5/2024 | 17/6/2026 | TP-Link Omada ER605 Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link Omada ER605 routers. Authentication is not required to exploit this vulnerability. However, devices are vulnerable only if… | |
| Analizada | Alta (7.5) | 0.80% | — | Tp-link Omada Er605 Firmware | 23/5/2024 | 17/6/2026 | TP-Link Omada ER605 Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link Omada ER605 routers. Authentication is not required to exploit this vulnerability. However, devices are vulnerable… |