Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

6789 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.4)0.85%—Wavlink Wl-nu516u1-aAI29/6/202629/6/2026
A vulnerability was identified in Wavlink WL-NU516U1-A M16U1_V240425. The impacted element is the function sub_407504 of the file /cgi-bin/wireless.cgi of the component POST Parameter Handler. Such manipulation of the argument Guest_ssid leads to stack-based buffer overflow. The attack can be executed remotely. The…
AplazadaBaja (2.1)2.2%—Wavlink Wl-nu516u1-aAI29/6/202629/6/2026
A vulnerability was determined in Wavlink WL-NU516U1-A M16U1_V240425. The affected element is the function sub_401D68 of the file /cgi-bin/wireless.cgi of the component POST Parameter Handler. This manipulation of the argument SSID2G2/SSID5G2/AuthMethod2/WPAPSK12 causes command injection. Remote exploitation of the…
AnalizadaAlta (7.7)0.38%—Peplink Intcontrol 226/6/20262/7/2026
Peplink InControl 2 through 2.14.2 before 2026-06-03 allows use of a semicolon to bypass access-control rules for certain /rest/o/{orgId} endpoints.
Pendiente de análisisMedia (5.8)0.23%—Reolink Home HUBAI26/6/202626/6/2026
A vulnerability exists in the netclient and factory services of Reolink Home Hub (versions prior to v3.3.0.456_26031911) due to the possibility of brute-force cracking the credentials. This issue could allow attackers on the same local network to intercept traffic between the Hub and associated cameras and compromise…
AplazadaAlta (7.4)0.28%—Bootstrapped Visual Link PreviewAI25/6/202626/6/2026
Subscriber Sensitive Data Exposure in Visual Link Preview <= 2.3.1 versions.
AnalizadaAlta (7.1)0.36%—Tp-link Tapo C200 Firmware24/6/202629/6/2026
A denial-of-service (DoS) vulnerability has been identified in Tapo C200 v3 in the network packet handling logic due to improper handling of IPv4 fragmented packets. An unauthenticated adjacent attacker can send crafted packets to cause excessive resource consumption, leading to instability of the device.Successful…
AplazadaAlta (7.5)0.50%—Openlink Virtuoso-opensourceAI23/6/202623/6/2026
An issue in the sqlo_try_in_loop component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
AplazadaAlta (7.5)0.50%—Openlink Virtuoso-opensourceAI23/6/202623/6/2026
An issue in the sqlo_tb_col_preds component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
AplazadaAlta (7.5)0.35%—Openlink Virtuoso-opensourceAI23/6/202625/6/2026
An issue in the sqlo_natural_join_cond component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
AplazadaAlta (7.5)0.68%—Openlink Virtuoso-opensourceAI23/6/202615/7/2026
An issue in the sqlo_strip_in_join component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
AplazadaAlta (7.5)0.50%—Openlink Virtuoso-opensourceAI23/6/202625/6/2026
An issue in the sqlo_key_part_best component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
AplazadaAlta (7.5)0.68%—Openlink Virtuoso-opensourceAI23/6/202615/7/2026
An issue in the sqlo_place_dt_set component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
AplazadaAlta (7.5)0.42%—Openlink Virtuoso-opensourceAI23/6/20266/10/2026
An issue in the sqlo_untry component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
AplazadaAlta (7.5)0.58%—Openlink Virtuoso-opensourceAI23/6/20266/10/2026
An issue in the time_t_to_dt component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
AplazadaAlta (7.5)0.42%—Openlink Virtuoso-opensourceAI23/6/20266/10/2026
An issue in the t_set_push component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
AplazadaAlta (7.5)0.42%—Openlink Virtuoso-opensourceAI23/6/20266/10/2026
An issue in the sslr_qst_get component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
AplazadaAlta (7.5)0.58%—Openlink Virtuoso-opensourceAI23/6/20266/10/2026
An issue in the st_compare component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
AplazadaCrítica (9.4)0.31%—Totolink Ex1200lAI23/6/202623/6/2026
Totolink EX1200L router is vulnerable to Buffer Overflow in the login functionality in cgi-bin/cstecgi.cgi endpoint. This vulnerability could be exploited to cause the program to crash and to execute code remotely. This allows the attacker to perform actions as root including reading and editing data, as well as…
Pendiente de análisisAlta (8.7)0.66%💥 PoCTp-link RouterAI22/6/202626/6/2026
A command injection vulnerability has been identified in the DHCP option processing logic in multiple TP-Link router models, due to insufficient validation of externally supplied DHCP option data. An adjacent attacker may exploit this vulnerability by supplying crafted DHCP responses, potentially resulting in…
AplazadaBaja (2.1)0.40%—Zhilink ADP Application Developer PlatformAI21/6/202622/6/2026
A vulnerability was determined in zhilink 智互联(深圳)科技有限公司 ADP Application Developer Platform 应用开发者平台 1.0.0. This vulnerability affects unknown code of the file /adpweb/a/base/barcodeDetail/import of the component XML Parser. This manipulation causes xml external entity reference. It is possible to initiate the attack…
AplazadaBaja (2.1)0.41%—Zhilink ADP Application Developer PlatformAI21/6/202622/6/2026
A vulnerability was found in zhilink 智互联(深圳)科技有限公司 ADP Application Developer Platform 应用开发者平台 1.0.0. This affects an unknown part of the component testConnection Endpoint. The manipulation of the argument jdbcUrl results in deserialization. The attack may be performed from remote. The exploit has been made public and…
AnalizadaCrítica (9.3)46%⚠ Explotación activaPTC FlexplmPTC Windchill Pdmlink18/6/20261/8/2026
—
AplazadaMedia (6.4)0.33%—Permalink Manager LiteAI17/6/202617/6/2026
The Permalink Manager Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post titles in the admin URI Editor interface in all versions up to, and including, 2.5.3.3 due to insufficient output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above,…
AplazadaAlta (8.1)0.44%—TechlinkAI17/6/202617/6/2026
Unauthenticated PHP Object Injection in TechLink <= 1.3 versions.
AnalizadaAlta (8.5)2.8%—Tp-link Tl-wr940n Firmware17/6/202618/6/2026
An authenticated OS command injection vulnerability exists in the BigPond Cable (BPA) WAN configuration module in TL-WR940N v6 due to improper sanitization of user input. An attacker with administrative access may exploit this issue to execute arbitrary system commands with elevated privileges.