Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2736▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
6789 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (6.8) | 0.20% | — | Tp-link Archer A6AI | 7/8/2026 | 18/8/2026 | A denial-of-service vulnerability exists in httpd service on Archer A6 v4 where the asynchronous systool instruction handlng path in httpd does not properly synchronize or safely manage concurrent systool operations. By sending crafted systool instructions through the asynchronous request path, successful exploitation… | |
| Aplazada | Alta (7.1) | 0.37% | — | TestlinkAI | 7/8/2026 | 24/9/2026 | TestLink 1.9.20 and prior contains an insecure direct object reference vulnerability that allows any authenticated user, including low-privilege guest accounts, to read arbitrary attachments by supplying an integer attachment ID to the attachmentdownload.php handler without any project or role authorization check.… | |
| Aplazada | Crítica (9.3) | 0.79% | 💥 PoC | Zbtlink Router FirmwareAIOpenwrtAI | 5/8/2026 | 9/9/2026 | Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS, present in every published build across the product line. It is the open-source ycsunjane/rctl tool built in as an OpenWrt package (librctl.so), started at boot and run as root under the process name kworker to blend in with the kernel's… | |
| Aplazada | Media (4.9) | 0.44% | — | Caseproof PrettylinksAI | 5/8/2026 | 12/8/2026 | The PrettyLinks – Affiliate Links, Link Branding, Link Tracking, Marketing and Stripe Payments Plugin plugin for WordPress is vulnerable to SQL Injection via the 's' (search) parameter on the Pretty Links listing page in all versions up to, and including, 3.6.20. This is due to insufficient escaping on the user… | |
| Analizada | Alta (7.1) | 0.76% | — | Tp-link Tapo P110 Firmware | 4/8/2026 | 7/8/2026 | Tapo P110 v1 smart Wi-Fi Plug contains an improper boundary validation vulnerability in the handling of authenticated HTTP request bodies due to insufficient input validation before memory copy operations. This may lead to buffer overflow condition, causing the web service process to crash. Successful exploitation may… | |
| Aplazada | Media (5.1) | 0.49% | — | ShlinkAI | 3/8/2026 | 9/9/2026 | Shlink versions 5.0.0 through 5.1.5 contain a CSV formula injection vulnerability that allows unauthenticated remote attackers to plant spreadsheet formulas into exported visit data by supplying malicious values in User-Agent, Referer, or request path headers beginning with formula-triggering characters such as =, +,… | |
| Aplazada | Alta (7.1) | 0.30% | — | ShlinkAI | 3/8/2026 | 9/9/2026 | Shlink contains a blind SQL injection vulnerability that allows any authenticated API key holder to inject arbitrary SQL fragments by supplying an unvalidated direction value in the orderBy query parameter of the tag statistics endpoint. Attackers can craft a malicious direction string containing SQL subqueries that… | |
| Aplazada | Media (5.3) | 0.30% | — | ShlinkAI | 3/8/2026 | 9/9/2026 | Shlink contains a server-side request forgery vulnerability that allows authenticated API key holders to cause the server to issue arbitrary HTTP GET requests by supplying a crafted long URL during short URL creation with title auto-resolution enabled. Attackers can submit URLs pointing to public hosts that redirect… | |
| Analizada | Media (5.7) | 0.30% | — | Tp-link Omada Fusion 2.5g FirmwareTp-link Omada Er707-m2 FirmwareTp-link Omada Er7206 FirmwareTp-link Omada Er706w Firmware+105 | 3/8/2026 | 29/9/2026 | A cryptographic weakness exists in affected Omada devices where site credentials are protected using a legacy hashing algorithm that does not provide sufficient protection. An attacker who obtains access to stored credential data may be able to recover valid credentials to gain unauthorized access to affected devices… | |
| Analizada | Media (5.8) | 0.31% | — | Tp-link Omada Oc200 V3 FirmwareTp-link Omada Oc300 FirmwareTp-link Omada Oc400 FirmwareTp-link Omada Fusion 2.5g Firmware+108 | 3/8/2026 | 29/9/2026 | A race condition exists in the cloud-based Omada device adoption process when an attacker may be able to interact with the adoption workflow before a legitimate device completes registration, resulting in provisioning information being delivered to an attacker. Successful exploitation may allow disclosure of… | |
| Analizada | Media (6.9) | 0.33% | — | Tp-link Omada Oc200 V3 FirmwareTp-link Omada Oc300 FirmwareTp-link Omada Oc400 FirmwareTp-link Omada Fusion 2.5g Firmware+108 | 3/8/2026 | 29/9/2026 | A cryptographic weakness exists in the Omada adoption protocol where session encryption keys used to protect communications between controllers and managed devices may be predictable due to insufficient entropy in session key generation. An attacker who successfully intercepts adoption-related communications may be… | |
| Analizada | Alta (8.2) | 0.32% | — | Tp-link Omada Oc200 V3 FirmwareTp-link Omada Oc300 FirmwareTp-link Omada Oc400 FirmwareTp-link Omada Fusion 2.5g Firmware+108 | 3/8/2026 | 29/9/2026 | Affected Omada devices rely on embedded certificates that are shared across deployments to establish trust between controllers and managed devices. An attacker who obtains the embedded certificates may be able to impersonate trusted controllers or devices and intercept affected communications. | |
| Analizada | Media (6.9) | 0.68% | — | Tp-link Omada Oc200 V3 FirmwareTp-link Omada Oc300 FirmwareTp-link Omada Oc400 FirmwareTp-link Omada Fusion 2.5g Firmware+108 | 3/8/2026 | 29/9/2026 | A cryptographic weakness exists in the Omada adoption protocol. The protocol relies on hard-coded cryptographic keys to establish trust and protect authentication exchanges between controllers and managed devices during device adoption. An attacker may be able to impersonate trusted controllers or managed devices and… | |
| Analizada | Media (6.9) | 0.34% | — | Tp-link Omada Oc200 V3 FirmwareTp-link Omada Oc300 FirmwareTp-link Omada Oc400 FirmwareTp-link Omada Fusion 2.5g Firmware+109 | 3/8/2026 | 29/9/2026 | A cryptographic weakness exists in the Omada device adoption process. During adoption, authentication credentials associated with site management are transmitted using a weak hashing algorithm that does not provide sufficient protection. An attacker who successfully intercepts adoption-related authentication traffic… | |
| Aplazada | Alta (7.4) | 0.79% | — | Wavlink Wn572AIWavlink Wn570hAIWavlink Wn573AIWavlink Wn529AI+8 | 3/8/2026 | 12/8/2026 | A security vulnerability has been detected in Wavlink WN572, WN570H, WN573, WN529, WN530, WN531, WN535, etc. WN529, WN530, WN531, WN535, WN536, WN551, WN557 and NU516 up to 20260609. Affected by this issue is the function strcpy of the file upload.cgi of the component lighttpd. The manipulation of the argument… | |
| Analizada | Alta (7.7) | 0.22% | — | Tp-link Omada Fusion 2.5g FirmwareTp-link Omada Er707-m2 FirmwareTp-link Omada Er7206 FirmwareTp-link Omada Er706w Firmware+105 | 3/8/2026 | 29/9/2026 | A certification validation weakness exists in communication between affected Omada devices and cloud controllers. Certificate identity verification does not adequately validate that a presented certificate corresponds to the expected cloud controller hostname, which may allow certificate validation protections to be… | |
| Aplazada | Baja (2.1) | 1.8% | — | Wavlink Wl-nu516u1AI | 3/8/2026 | 12/8/2026 | A vulnerability was determined in Wavlink WL-NU516U1 708c073-mt7628. Affected is the function set_sys_adm of the file adm.cgi of the component Admin Password Handler. This manipulation causes os command injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be… | |
| Aplazada | Alta (8.9) | 1.1% | — | Wavlink Wl-nu516u1AI | 3/8/2026 | 12/8/2026 | A vulnerability was found in Wavlink WL-NU516U1 708c073-mt7628. This impacts the function change_password of the file nas.cgi. The manipulation of the argument User1Passwd results in stack-based buffer overflow. The attack can be executed remotely. The exploit has been made public and could be used. The affected… | |
| Aplazada | Crítica (9.3) | 1.1% | — | Wavlink Wl-nu516u1AI | 3/8/2026 | 12/8/2026 | A vulnerability has been found in Wavlink WL-NU516U1 708c073-mt7628. This affects the function fgets of the file nas.cgi. The manipulation of the argument CONTENT_LENGTH leads to stack-based buffer overflow. Remote exploitation of the attack is possible. You should upgrade the affected component. The vendor was… | |
| Aplazada | Media (6.8) | 2.0% | — | Wavlink Wl-nu516u1AI | 3/8/2026 | 12/8/2026 | A flaw has been found in Wavlink WL-NU516U1 708c073-mt7628. The impacted element is an unknown function of the component Config Import. Executing a manipulation of the argument Password can lead to os command injection. The attack may be launched remotely. This attack is characterized by high complexity. The… | |
| Aplazada | Crítica (9.1) | 0.46% | — | Ylefebvre Link LibraryAI | 3/8/2026 | 26/8/2026 | The Link Library WordPress plugin before 7.9.3 does not properly sanitise and escape a user-supplied value before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks. | |
| Analizada | Alta (8.5) | 2.5% | — | Tp-link Archer Axe75 Firmware | 31/7/2026 | 7/8/2026 | An OS command injection vulnerability exists in the VPN module of TP-Link AXE75 V1 routers. This vulnerability allows an adjacent, authenticated attacker to execute arbitrary commands on the device by importing a specially crafted VPN client configuration file. The issue arises from improper filtering of special… | |
| Aplazada | Crítica (9.8) | 2.8% | — | Tp-link Tr1200AITp-link Tr3000AITp-link Wr300AITp-link Wr1200AI+5 | 31/7/2026 | 31/8/2026 | TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, WR1500 v2.3.10, WR3000 v2.4.19, WR3600 v2.3.16, and WR6500 v2.3.15 were discovered to contain a command injection vulnerability in the system.setclock interface. This vulnerability allows attackers to execute arbitrary commands as root via… | |
| Aplazada | Crítica (9.8) | 2.8% | — | Tp-link Tr1200AITp-link Tr3000AITp-link Wr300AITp-link Wr1200AI+5 | 31/7/2026 | 31/8/2026 | TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, WR1500 v2.3.10, WR3000 v2.4.19, WR3600 v2.3.16, and WR6500 v2.3.15 were discovered to contain a command injection vulnerability in the system.upgrade_check interface. This vulnerability allows attackers to execute arbitrary commands as root… | |
| Aplazada | Crítica (9.8) | 2.8% | — | Tp-link Tr1200AITp-link Tr3000AITp-link Wr300AITp-link Wr1200AI+5 | 30/7/2026 | 31/8/2026 | TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, WR1500 v2.3.10, WR3000 v2.4.19, WR3600 v2.3.16, and WR6500 v2.3.15 were discovered to contain a command injection vulnerability in the net.set_wan interface. This vulnerability allows attackers to execute arbitrary commands as root via a… |