Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2678▼ 660 respecto a la semana anterior
Críticas / altas1266▼ 293 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
1843 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.7) | 1.6% | — | Dlink Di-8400 Firmware | 26/7/2025 | 17/6/2026 | A vulnerability was found in D-Link DI-8400 16.07.26A1. It has been classified as problematic. This affects an unknown part of the file usb_paswd.asp of the component jhttpd. The manipulation of the argument share_enable leads to null pointer dereference. It is possible to initiate the attack remotely. The exploit has… | |
| Analizada | Alta (7.4) | 1.7% | — | Dlink Dir-513 Firmware | 25/7/2025 | 17/6/2026 | A vulnerability classified as critical has been found in D-Link DIR-513 1.10. This affects the function formSetWanPPTPcallback of the file /goform/formSetWanPPTPpath of the component HTTP POST Request Handler. The manipulation of the argument curTime leads to buffer overflow. It is possible to initiate the attack… | |
| Analizada | Alta (7.4) | 1.6% | — | Dlink Dir-513 Firmware | 25/7/2025 | 17/6/2026 | A vulnerability was found in D-Link DIR-513 1.10. It has been rated as critical. Affected by this issue is the function websAspInit of the file /goform/formSetWanPPPoE. The manipulation of the argument curTime leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public… | |
| Analizada | Crítica (9.3) | 7.2% | 💥 Exploit | Dlink Dsp-w215 Firmware | 25/7/2025 | 17/6/2026 | A stack-based buffer overflow vulnerability in the my_cgi.cgi component of certain D-Link devices, including the DSP-W215 version 1.02, can be exploited via a specially crafted HTTP POST request to the /common/info.cgi endpoint. This flaw enables an unauthenticated attacker to achieve remote code execution with… | |
| Analizada | Alta (7.4) | 17% | — | Dlink Dir-513 Firmware | 25/7/2025 | 17/6/2026 | A vulnerability was found in D-Link DIR-513 1.0. It has been rated as critical. This issue affects the function formLanguageChange of the file /goform/formLanguageChange of the component HTTP POST Request Handler. The manipulation of the argument curTime leads to stack-based buffer overflow. The attack may be… | |
| Analizada | Baja (2) | 21% | — | Dlink Dcs-6010l Firmware | 25/7/2025 | 17/6/2026 | A vulnerability has been found in D-Link DCS-6010L 1.15.03 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /vb.htm of the component Management Application. The manipulation of the argument paratest leads to cross site scripting. The attack can be launched remotely.… | |
| Aplazada | Alta (8.7) | 5.7% | — | Dlink Dir-513AI | 22/7/2025 | 17/6/2026 | A vulnerability was found in D-Link DIR-513 up to 20190831. It has been declared as critical. This vulnerability affects the function formSetWanDhcpplus of the file /goform/formSetWanDhcpplus. The manipulation of the argument curTime leads to buffer overflow. The attack can be initiated remotely. This vulnerability… | |
| Analizada | Baja (2.1) | 5.0% | — | Dlink Dir-817l Firmware | 21/7/2025 | 17/6/2026 | A vulnerability classified as critical has been found in D-Link DIR‑817L up to 1.04B01. This affects the function lxmldbc_system of the file ssdpcgi. The manipulation leads to command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. | |
| Analizada | Alta (7.4) | 1.5% | — | Dlink Di-8100 Firmware | 20/7/2025 | 17/6/2026 | A vulnerability classified as critical was found in D-Link DI-8100 1.0. This vulnerability affects the function sprintf of the file /upnp_ctrl.asp of the component jhttpd. The manipulation of the argument remove_ext_proto/remove_ext_port leads to stack-based buffer overflow. The attack can be initiated remotely. The… | |
| Analizada | Alta (7.4) | 1.3% | — | Dlink Dir-513 Firmware | 20/7/2025 | 17/6/2026 | A vulnerability classified as critical has been found in D-Link DIR-513 1.10. This affects the function sprintf of the file /goform/formSetWanNonLogin of the component Boa Webserver. The manipulation of the argument curTime leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The… | |
| Analizada | Alta (7.4) | 1.3% | — | Dlink Dir-513 Firmware | 20/7/2025 | 17/6/2026 | A vulnerability was found in D-Link DIR-513 1.0. It has been rated as critical. Affected by this issue is the function sprintf of the file /goform/formLanSetupRouterSettings of the component Boa Webserver. The manipulation of the argument curTime leads to stack-based buffer overflow. The attack may be launched… | |
| Analizada | Alta (7.4) | 1.3% | — | Dlink Di-8100 Firmware | 20/7/2025 | 17/6/2026 | A vulnerability was found in D-Link DI-8100 1.0. It has been declared as critical. Affected by this vulnerability is the function sprintf of the file /ddns.asp?opt=add of the component jhttpd. The manipulation of the argument mx leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has… | |
| Analizada | Baja (2.1) | 5.2% | — | Dlink Dir-816l Firmware | 19/7/2025 | 17/6/2026 | A vulnerability has been found in D-Link DIR-816L up to 2.06B01 and classified as critical. Affected by this vulnerability is the function lxmldbc_system of the file /htdocs/cgibin of the component Environment Variable Handler. The manipulation leads to command injection. The attack can be launched remotely. The… | |
| Analizada | Alta (7.4) | 0.86% | — | Dlink Di-8100 Firmware | 18/7/2025 | 17/6/2026 | A vulnerability was found in D-Link DI-8100 16.07.26A1. It has been classified as critical. This affects an unknown part of the file /menu_nat.asp of the component HTTP Request Handler. The manipulation of the argument out_addr/in_addr/out_port/proto leads to stack-based buffer overflow. It is possible to initiate the… | |
| Analizada | Alta (7.4) | 5.6% | — | Dlink Di-8100 Firmware | 17/7/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in D-Link DI-8100 16.07.26A1. This issue affects some unknown processing of the file /menu_nat_more.asp of the component HTTP Request Handler. The manipulation leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has… | |
| Aplazada | Crítica (9.3) | 4.4% | 💥 Exploit | LighttpdAIDlink Dsp-w110a1AI | 16/7/2025 | 17/6/2026 | An unauthenticated command injection vulnerability exists in the cookie handling process of the lighttpd web server on D-Link DSP-W110A1 firmware version 1.05B01. This occurs when specially crafted cookie values are processed, allowing remote attackers to execute arbitrary commands on the underlying Linux operating… | |
| Analizada | Alta (7.3) | 1.2% | — | Dlink Di-8100 Firmware | 14/7/2025 | 17/6/2026 | A vulnerability was found in D-Link DI-8100 16.07.26A1. It has been classified as critical. Affected is an unknown function of the file /jingx.asp of the component HTTP Request Handler. The manipulation leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed… | |
| Analizada | Alta (7.3) | 1.2% | — | Dlink Di-8100 Firmware | 14/7/2025 | 17/6/2026 | A vulnerability was found in D-Link DI-8100 16.07.26A1 and classified as critical. This issue affects some unknown processing of the file /arp_sys.asp of the component HTTP Request Handler. The manipulation leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to… | |
| Analizada | Baja (2) | 3.7% | — | Dlink Dir-818lw Firmware | 14/7/2025 | 17/6/2026 | A vulnerability classified as critical has been found in D-Link DIR-818LW up to 20191215. This affects an unknown part of the component System Time Page. The manipulation of the argument NTP Server leads to os command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the… | |
| Analizada | Alta (8.9) | 18% | — | Dlink Dir-825 Firmware | 9/7/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in D-Link DIR-825 2.10. This issue affects the function sub_410DDC of the file switch_language.cgi of the component httpd. The manipulation of the argument Language leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit… | |
| Analizada | Alta (7.4) | 0.93% | — | Dlink Di-500wf Firmware | 8/7/2025 | 17/6/2026 | A vulnerability was found in D-Link DI-500WF 17.04.10A1T. It has been declared as critical. Affected by this vulnerability is the function sprintf of the file ip_position.asp of the component jhttpd. The manipulation of the argument ip leads to stack-based buffer overflow. The attack can be launched remotely. The… | |
| Analizada | Baja (2.1) | 4.3% | — | Dlink Dir-645 Firmware | 8/7/2025 | 17/6/2026 | A vulnerability was found in D-Link DIR-645 up to 1.05B01 and classified as critical. This issue affects the function ssdpcgi_main of the file /htdocs/cgibin of the component ssdpcgi. The manipulation leads to command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may… | |
| Analizada | Baja (2.9) | 1.3% | — | Dlink Dcs-7517 Firmware | 30/6/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in D-Link DCS-7517 up to 2.02.0. This affects the function g_F_n_GenPassForQlync of the file /bin/httpd of the component Qlync Password Generation Handler. The manipulation leads to use of hard-coded password. It is possible to initiate the attack… | |
| Analizada | Baja (2.9) | 2.2% | — | Dlink Dcs-6517 FirmwareDlink Dcs-7517 Firmware | 30/6/2025 | 17/6/2026 | A vulnerability classified as problematic was found in D-Link DCS-6517 and DCS-7517 up to 2.02.0. Affected by this vulnerability is the function generate_pass_from_mac of the file /bin/httpd of the component Root Password Generation Handler. The manipulation leads to insufficient entropy. The attack can be launched… | |
| Modificada | Crítica (9.8) | 1.0% | — | Dlink Dir-816 Firmware | 30/6/2025 | 5/7/2026 | An issue D-Link DIR-816-A2 DIR-816A2_FWv1.10CNB05_R1B011D88210 allows a remote attacker to execute arbitrary code via system() function in the bin/goahead file |