Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

1191 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.2)3.4%—Tp-link Er7206 Firmware6/2/202417/6/2026
A post authentication command injection vulnerability exists in the GRE policy functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP request can lead to arbitrary command injection. An attacker can make an authenticated HTTP request to trigger this…
ModificadaAlta (7.2)3.4%—Tp-link Er7206 Firmware6/2/202417/6/2026
A post authentication command injection vulnerability exists when configuring the wireguard VPN functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP request can lead to arbitrary command injection . An attacker can make an authenticated HTTP request to…
ModificadaAlta (7.2)3.3%💥 PoCTp-link Er7206 Firmware6/2/202417/6/2026
A command execution vulnerability exists in the guest resource functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.
ModificadaAlta (7.2)3.4%—Tp-link Er7206 Firmware6/2/202417/6/2026
A post authentication command injection vulnerability exists when setting up the PPTP global configuration of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP request can lead to arbitrary command injection. An attacker can make an authenticated HTTP request to trigger…
ModificadaAlta (7.2)3.4%—Tp-link Er7206 Firmware6/2/202417/6/2026
A post-authentication command injection vulnerability exists in the PPTP client functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP request can lead to arbitrary command injection. An attacker can make an authenticated HTTP request to trigger this…
ModificadaMedia (4.6)0.36%—Tp-link Tapo C200 FirmwareTp-link Tapo Tc70 Firmware17/1/202417/6/2026
Insecure Permissiosn vulnerability in TP Link TC70 and C200 WIFI Camera v.3 firmware v.1.3.4 and fixed in v.1.3.11 allows a physically proximate attacker to obtain sensitive information via a connection to the UART pin components.
ModificadaAlta (8.8)1.1%—Tp-link Archer Ax3000 FirmwareTp-link Archer Ax5400 FirmwareTp-link Deco X50 FirmwareTp-link Deco Xe200 Firmware+111/1/202417/6/2026
Multiple TP-LINK products allow a network-adjacent unauthenticated attacker with access to the product to execute arbitrary OS commands. The affected device, with the initial configuration, allows login only from the LAN port or Wi-Fi.
ModificadaAlta (8)0.45%—Tp-link Archer Ax3000 FirmwareTp-link Archer Ax5400 FirmwareTp-link Archer Axe75 Firmware11/1/202417/6/2026
Multiple TP-LINK products allow a network-adjacent authenticated attacker with access to the product from the LAN port or Wi-Fi to execute arbitrary OS commands.
ModificadaAlta (8.8)0.53%—Tp-link Archer Ax3000 FirmwareTp-link Archer Ax5400 FirmwareTp-link Deco X50 FirmwareTp-link Deco Xe200 Firmware11/1/202417/6/2026
Multiple TP-LINK products allow a network-adjacent unauthenticated attacker with access to the product from the LAN port or Wi-Fi to execute arbitrary OS commands on the product that has pre-specified target devices and blocked URLs in parental control settings.
ModificadaAlta (7.5)0.38%—Tp-link Tapo9/1/20249/7/2026
TP-Link Tapo APK up to v2.12.703 uses hardcoded credentials for access to the login panel.
ModificadaMedia (6.5)0.25%—Tp-link Tapo28/12/202317/6/2026
Incorrect access control in TP-Link Tapo before v3.1.315 allows attackers to access user credentials in plaintext.
ModificadaAlta (8.8)0.29%—Wplinkspage WP Links Page18/11/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Robert Macchi WP Links Page.This issue affects WP Links Page: from n/a through 4.9.4.
ModificadaMedia (6.5)0.33%—Tp-link Tapo C100 Firmware31/10/202317/6/2026
An issue in TP-Link Tapo C100 v1.1.15 Build 211130 Rel.15378n(4555) and before allows attackers to cause a Denial of Service (DoS) via supplying a crafted web request.
AnalizadaAlta (8.8)4.5%⚠ Explotación activaF5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Carrier-grade NATF5 Big-ip Ddos Hybrid Defender+1626/10/202317/6/2026
An authenticated SQL injection vulnerability exists in the BIG-IP Configuration utility which may allow an authenticated attacker with network access to the Configuration utility through the BIG-IP management port and/or self IP addresses to execute arbitrary system commands. Note: Software versions which have reached…
AnalizadaCrítica (9.8)97%⚠ Explotación activa💥 ExploitF5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Carrier-grade NAT+1626/10/202317/6/2026
Undisclosed requests may bypass configuration utility authentication, allowing an attacker with network access to the BIG-IP system through the management port and/or self IP addresses to execute arbitrary system commands. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
ModificadaCrítica (9.8)1.0%—Tp-link Tl-wr886n Firmware25/10/202317/6/2026
TP-LINK TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin was discovered to contain a stack overflow via the function registerRequestHandle.
ModificadaCrítica (9.8)1.0%—Tp-link Tl-wr886n Firmware25/10/202317/6/2026
TP-LINK TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin was discovered to contain a stack overflow via the function chkResetVeriRegister.
ModificadaCrítica (9.8)1.0%—Tp-link Tl-wr886n Firmware25/10/202317/6/2026
TP-LINK TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin was discovered to contain a stack overflow via the function getRegVeriRegister.
ModificadaCrítica (9.8)1.0%—Tp-link Tl-wr886n Firmware25/10/202317/6/2026
TP-LINK TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin was discovered to contain a stack overflow via the function chkRegVeriRegister.
ModificadaCrítica (9.8)1.0%—Tp-link Tl-wr886n Firmware25/10/202317/6/2026
TP-LINK TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin was discovered to contain a stack overflow via the function getResetVeriRegister.
ModificadaCrítica (9.8)1.0%—Tp-link Tl-wr886n Firmware25/10/202317/6/2026
TP-LINK TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin was discovered to contain a stack overflow via the function modifyAccPwdRegister.
ModificadaCrítica (9.8)1.3%—Tp-link Tl-wr886n Firmware25/10/202317/6/2026
TP-LINK TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin and TL-WDR7660 2.0.30 was discovered to contain a stack overflow via the function bindRequestHandle.
ModificadaCrítica (9.8)1.0%—Tp-link Tl-wr886n Firmware25/10/202317/6/2026
TP-LINK TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin was discovered to contain a stack overflow via the function resetCloudPwdRegister.
ModificadaCrítica (9.8)1.0%—Tp-link Tl-wr886n Firmware25/10/202317/6/2026
TP-LINK TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin was discovered to contain a stack overflow via the function loginRegister.
ModificadaCrítica (9.8)1.0%—Tp-link Tl-wr886n Firmware25/10/202317/6/2026
TP-LINK TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin was discovered to contain a stack overflow via the function upgradeInfoRegister.