Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
6789 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.1) | 0.13% | — | Tp-link Deco M5 Firmware | 14/7/2026 | 6/8/2026 | TP-Link Deco M5 v1 uses a weak password hashing mechanism to store user credentials. An attacker who obtains the password hash through system compromise or privileged access could perform brute-force or dictionary attacks. Successful exploitation may result in disclosure of authentication credentials, enabling… | |
| Aplazada | Alta (8.9) | 1.1% | — | Totolink Nr1800xAILighttpdAI | 14/7/2026 | 15/7/2026 | A weakness has been identified in Totolink NR1800X 9.1.0u.6279_B20210910. Affected by this issue is the function Form_Logout of the file /formLogout.htm of the component lighttpd. This manipulation of the argument Host causes stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit… | |
| Analizada | Media (5.1) | 1.4% | — | Tp-link Archer Vx1800v Firmware | 14/7/2026 | 6/8/2026 | A privilege escalation vulnerability exists in the HTTP authentication component in Archer VX1800v v1. Improper handling of user-controlled input may allow newline characters to be injected into internally constructed configuration data. An authenticated user with sufficient privileges may be able to modify account… | |
| Analizada | Alta (8.5) | 2.1% | — | Tp-link Archer Vx1800v Firmware | 14/7/2026 | 6/8/2026 | An OS command injection vulnerability exists in Archer VX800v v1 due to insufficient input sanitization of the domain name parameter. An adjacent attacker who can access the relevant HTTP interface can modify the parameter to inject shell metacharacters, resulting in arbitrary code execution with root privileges.… | |
| Analizada | Alta (8.6) | 0.84% | — | Tp-link Archer Vx1800v Firmware | 14/7/2026 | 6/8/2026 | An OS command injection vulnerability exists in the TR-069 / CWMP management interface of Archer VX1800v v1 due to insufficient input validation and sanitization of parameters, allowing crafted input to be executed as system-level commands. Exploitation requires specific conditions such as TR-069 being enabled and… | |
| Aplazada | Crítica (9.8) | 0.60% | — | Dlink Dir-1253AI | 13/7/2026 | 15/7/2026 | An issue in D-Link DIR-1253 v.1.0.1.250923.142435 allows an attacker to escalate privileges via the etc/shadow component file | |
| Aplazada | Media (6.5) | 0.33% | — | Knitpay Razorpay Payment Links FOR WoocommerceAI | 13/7/2026 | 13/7/2026 | Missing Authorization vulnerability in knitpay Razorpay Payment Links for WooCommerce rzp-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Razorpay Payment Links for WooCommerce: from n/a through <= 2.1.4. | |
| Aplazada | Baja (2.1) | 1.8% | — | Wavlink Wl-nu516u1AI | 13/7/2026 | 13/7/2026 | A security flaw has been discovered in Wavlink WL-NU516U1 260515. This affects the function wlink_uci_set_value of the file /cgi-bin/adm.cgi. Performing a manipulation of the argument lan_ip results in os command injection. The attack can be initiated remotely. The exploit has been released to the public and may be… | |
| Aplazada | Media (4.3) | 0.37% | — | SurflinkAI | 11/7/2026 | 13/7/2026 | The SurfLink - Ultimate Link Manager plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the ajax_import_410() function in all versions up to 2.6.0. This is due to a missing capability check (current_user_can()) and missing nonce verification (check_ajax_referer())… | |
| Aplazada | Alta (7.7) | 0.71% | — | Totolink A3000ruAITotolink A3100rAITotolink A950rgAITotolink Ac1200t10AI+3 | 9/7/2026 | 3/9/2026 | A security vulnerability has been detected in TOTOLINK A3000RU, A3100R, A950RG, AC1200T10, CP450, CS185R_T10 and EX200 up to 20260906. Affected by this issue is some unknown functionality of the file /etc/boa/boa.conf of the component Web Interface. The manipulation leads to least privilege violation. The attack may… | |
| Analizada | Media (6.8) | 0.85% | — | Dlink Dir-823g Firmware | 9/7/2026 | 3/9/2026 | A weakness has been identified in D-link DIR-823G 1.0.2B05_20181207. Affected by this vulnerability is an unknown functionality of the file /etc/boa/boa.conf of the component Web Interface. Executing a manipulation can lead to least privilege violation. The attack can be launched remotely. The attack requires a high… | |
| Aplazada | Media (5.5) | 0.67% | — | Totolink X5000rAI | 9/7/2026 | 14/7/2026 | A vulnerability was detected in TOTOLINK X5000R 9.1.0cu.2415_B20250515/9.1.0cu.2350_B20230313. Affected by this vulnerability is the function exportOvpn of the file /web/cgi-bin/cstecgi.cgi of the component OpenVPN Export. The manipulation results in path traversal. The attack may be launched remotely. | |
| Analizada | Alta (7.5) | 0.64% | — | Markdown-it Linkify-it | 8/7/2026 | 26/8/2026 | linkify-it is a links recognition library with full Unicode support. Prior to 5.0.2, the mailto: schema validator used by .test() and .match() can be invoked at every mailto: occurrence and scan the remaining input through src_email_name in lib/re.mjs, causing O(n^2) CPU consumption on crafted user text. This issue is… | |
| Aplazada | Alta (7) | 0.28% | — | Tp-link Archer C5AI | 2/7/2026 | 2/7/2026 | A stored Cross-Site Scripting (XSS) vulnerability has been identified in the web-based management interface of Archer C5 v6.8 routers, due to insufficient server-side validation and lack of proper output encoding of user-controlled input in a certain field. An attacker with administrative privileges can inject crafted… | |
| Aplazada | Alta (7.1) | 0.13% | — | Permalink ManagerAI | 2/7/2026 | 2/7/2026 | Unauthenticated Cross Site Request Forgery (CSRF) in Permalink Manager for WooCommerce <= 1.0.8.2 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Quantumcloud Simple Link DirectoryAI | 2/7/2026 | 2/7/2026 | Unauthenticated Cross Site Scripting (XSS) in Simple Link Directory <= 15.0.5 versions. | |
| Aplazada | Media (6.5) | 0.30% | — | Linkwhisper Link Whisper PremiumAI | 2/7/2026 | 2/7/2026 | Subscriber Broken Access Control in Link Whisper Premium <= 2.9.0 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Internal Links ManagerAI | 2/7/2026 | 2/7/2026 | Unauthenticated Cross Site Scripting (XSS) in Internal Links Manager <= 3.0.3 versions. | |
| Aplazada | Alta (7.7) | 0.83% | — | Jaiotlink C492a-w6AI | 1/7/2026 | 2/7/2026 | JAIOTlink C492A-W6 Wi-Fi IP cameras running firmware 4.8.30.57701411 contain a remote code execution vulnerability that allows authenticated attackers to execute arbitrary shell scripts by writing to the writable persistent JFFS2 storage path and triggering execution through the authenticated HTTP endpoint. Attackers… | |
| Aplazada | Crítica (9.3) | 1.9% | — | Jaiotilink C492a-w6AI | 1/7/2026 | 2/7/2026 | JAIOTlink C492A-W6 Wi-Fi IP cameras running firmware 4.8.30.57701411 contain a hard-coded credentials vulnerability that allows network-adjacent attackers to gain unauthorized access by using the default admin username with an empty password accepted by the anyka_ipc HTTP service on port 80. Attackers can authenticate… | |
| Aplazada | Alta (8.7) | 2.7% | — | Jaiotlink C492a-w6AI | 1/7/2026 | 2/7/2026 | JAIOTlink C492A-W6 Wi-Fi IP cameras running firmware 4.8.30.57701411 contain an OS command injection vulnerability that allows authenticated attackers to achieve remote code execution by supplying a malicious Wireless parameter to the HTTP PUT NetSDK/Factory SetMAC endpoint. Attackers can craft a string beginning with… | |
| Aplazada | Media (5.9) | 0.46% | — | Tp-link Archer Ax20 V2AI | 30/6/2026 | 2/7/2026 | An unauthenticated URL redirection vulnerability has been identified in Archer AX20 V2 due to improper validation of user-supplied URL input within the web interface. An unauthenticated attacker can craft URLs containing URL-encoded path traversal sequences. When processed by the embedded web server, these inputs may… | |
| Analizada | Media (6.8) | 1.1% | — | Tp-link Tl-wr841n Firmware | 29/6/2026 | 1/7/2026 | An authenticated stack-based buffer overflow vulnerability exists in the web management interface of TP-Link TL-WR841N v14. A remote authenticated attacker can send crafted HTTP requests to cause the embedded web server to overflow a stack buffer, resulting in a crash of the affected process. Successful exploitation… | |
| Aplazada | Alta (7.1) | 0.25% | — | Linkwhisper Link Whisper FreeAI | 29/6/2026 | 29/6/2026 | Unauthenticated Cross Site Scripting (XSS) in Link Whisper Free <= 0.9.4 versions. | |
| Analizada | Alta (7.4) | 5.5% | — | Dlink Dcs-935l Firmware | 29/6/2026 | 30/6/2026 | A vulnerability has been found in D-Link DCS-935L 1.10.01. This affects the function sub_400E40 of the file setconf.cgi of the component POST Parameter Handler. Such manipulation of the argument UID leads to os command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may… |