Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
6789 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.5) | 2.8% | — | Tp-link Tl-wr940n Firmware | 17/6/2026 | 18/6/2026 | An authenticated OS command injection vulnerability exists in the IPv6 PPPoE configuration handler in TL-WR940N v6 due to improper sanitization of user input. An attacker with administrative access may exploit this issue to execute arbitrary system commands with elevated privileges. | |
| Aplazada | Media (6.5) | 0.37% | — | Bootstrapped Visual Link PreviewAI | 15/6/2026 | 17/6/2026 | Subscriber Sensitive Data Exposure in Visual Link Preview <= 2.4.1 versions. | |
| Aplazada | Alta (7.7) | 0.47% | — | Ylefebvre Link LibraryAI | 15/6/2026 | 17/6/2026 | Contributor Arbitrary File Deletion in Link Library <= 7.8.8 versions. | |
| Aplazada | Crítica (9.1) | 0.40% | — | ShlinkAI | 15/6/2026 | 17/6/2026 | A Server-Side Request Forgery (SSRF) in the automatic short URL title resolution component of shlink v5.0.1 allows attackers to scan internal resources via supplying a crafted longUrl. | |
| Aplazada | Media (6.9) | 0.37% | — | Photocart LinkAI | 15/6/2026 | 17/6/2026 | WordPress Plugin Photocart Link 1.6 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by exploiting insufficient input validation in decode.php. Attackers can supply base64-encoded file paths in the 'id' parameter to the decode.php endpoint to retrieve… | |
| Aplazada | Baja (2) | 1.2% | — | Yealink Sip-t46uAI | 15/6/2026 | 24/7/2026 | A vulnerability was identified in Yealink SIP-T46U 108.86.0.118. Affected by this vulnerability is the function mod_webd.TFTPUploadIperf of the file /api/inner/tftpuploadiperf of the component Web FastCGI Service. The manipulation of the argument ip/port leads to command injection. The attack needs to be initiated… | |
| Aplazada | Alta (7.3) | 0.37% | — | Yealink Sip-t46uAI | 15/6/2026 | 24/7/2026 | A vulnerability was determined in Yealink SIP-T46U 108.86.0.118. Affected is the function mod_webd.BlueToothTest of the file /api/inner/bttest of the component Web FastCGI Service. Executing a manipulation of the argument btMac/pin/reserved can lead to stack-based buffer overflow. The attack needs to be done within… | |
| Aplazada | Alta (7.3) | 0.37% | — | Yealink Sip-t46uAI | 15/6/2026 | 24/7/2026 | A vulnerability was found in Yealink SIP-T46U 108.86.0.118. This impacts the function sprintf of the file /api/upgrade/upgrade of the component Firmware Chunk Upload Handler. Performing a manipulation of the argument uid/start_offset results in stack-based buffer overflow. The attack needs to be approached within the… | |
| Aplazada | Alta (7.3) | 0.37% | — | Yealink Sip-t46uAI | 15/6/2026 | 24/7/2026 | A vulnerability has been found in Yealink SIP-T46U 108.86.0.118. This affects the function mod_upgrade.SparePartsUpload of the file /api/upgrade/accupgradebychunk of the component Firmware Chunk Upload handler. Such manipulation of the argument uid leads to stack-based buffer overflow. The attack can only be initiated… | |
| Aplazada | Baja (2.1) | 1.1% | — | Yealink Sip-t46uAI | 15/6/2026 | 24/7/2026 | A flaw has been found in Yealink SIP-T46U 108.86.0.118. The impacted element is the function mod_diagnose.CommandShellByType of the file /api/diagnosis/start of the component Web FastCGI Service. This manipulation of the argument Time causes command injection. The attack can be initiated remotely. The exploit has been… | |
| Aplazada | Alta (7.3) | 0.37% | — | Yealink Sip-t46uAI | 15/6/2026 | 24/7/2026 | A vulnerability was detected in Yealink SIP-T46U 108.87.50.1. The affected element is the function StartReportInformation of the file /api/inner/beforewifitest of the component Web FastCGI Service. The manipulation of the argument port results in stack-based buffer overflow. Access to the local network is required for… | |
| Analizada | Alta (7.4) | 0.58% | — | Dlink Dcs-935l Firmware | 13/6/2026 | 23/7/2026 | A security vulnerability has been detected in D-Link DCS-935L 1.10.01. This issue affects the function snprintf of the file /web/cgi-bin/greece/rhea of the component HTTP Handler. Such manipulation of the argument data leads to format string. The attack may be launched remotely. The exploit has been disclosed publicly… | |
| Analizada | Alta (7) | 0.94% | — | Tp-link Tapo C110 Firmware | 11/6/2026 | 17/6/2026 | An authenticated format string vulnerability exists in the ONVIF service of Tapo C110 v2 due to improper handling of user-controlled input. Externally controlled data is interpreted as a format string, which can be used to manipulate stack memory, including control flow data such as return addresses. A remote… | |
| Aplazada | Media (5.1) | 0.24% | — | Quantumcloud Simple Link DirectoryAI | 10/6/2026 | 23/7/2026 | Simple Link Directory through 9.0.4 echoes embed shortcode attributes into HTML data attributes without escaping in the embedder template. Attackers with contributor access can craft a shortcode attribute that injects an event handler executing in a viewer's browser. | |
| Aplazada | Media (5.1) | 0.24% | — | Quantumcloud Simple Link DirectoryAI | 10/6/2026 | 23/7/2026 | Simple Link Directory through 9.0.4 interpolates the sld_no_results_found option into a JavaScript string literal without encoding. Because sanitize_text_field leaves quotes intact, a stored payload breaks out of the string and runs script for every page visitor. | |
| Aplazada | Alta (8.5) | 2.5% | — | Tp-link Archer Ax12AITp-link Archer Ax17AITp-link Archer Ax18AITp-link Archer Ax1300AI | 10/6/2026 | 17/6/2026 | An OS command injection vulnerability exists in the VPN module of TP-Link Archer AX12 v1, AX17 v1. AX18 v1, and AX1300 v1.6 routers. This vulnerability allows an adjacent, authenticated attacker to execute arbitrary commands on the device by importing a specially crafted VPN client configuration file. The issue stems… | |
| Aplazada | Media (5.5) | 0.29% | — | Totolink Ex200AIVsftpdAI | 9/6/2026 | 23/7/2026 | A security flaw has been discovered in TOTOLINK EX200 4.0.3c.7646. This affects an unknown function of the file /etc/vsftpd.conf of the component vsftpd. The manipulation results in least privilege violation. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for… | |
| Aplazada | Alta (8.5) | 2.1% | — | Tp-link Archer Mr600AI | 8/6/2026 | 23/7/2026 | A command Injection vulnerability exists in the WireGuard client configuration of Archer MR600 v5 due to improper neutralization of user-controlled input within the web management interface. An authenticated attacker with administrative privileges may be able to execute arbitrary commands when applying configuration… | |
| Analizada | Baja (2.9) | 0.40% | — | Dlink Dgs-1100-08pd Firmware | 8/6/2026 | 23/7/2026 | A vulnerability was identified in D-Link DGS-1100-08PD 1.00.006. This issue affects some unknown processing of the file /etc/boa.conf of the component Web Interface. Such manipulation leads to least privilege violation. The attack may be launched remotely. The attack requires a high level of complexity. The… | |
| Aplazada | Baja (2.1) | 0.21% | — | Totolink Cp450AIVsftpdAI | 8/6/2026 | 23/7/2026 | A vulnerability was determined in TOTOLINK CP450 4.1.0cu.747. This vulnerability affects unknown code of the file /etc/vsftpd.conf of the component vsftpd. This manipulation causes least privilege violation. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. | |
| Analizada | Media (5.5) | 0.43% | — | Dlink Dcs-5615 Firmware | 8/6/2026 | 23/7/2026 | A vulnerability has been found in D-Link DCS-5615 1.01.00. Affected by this vulnerability is an unknown functionality of the file /etc/conf.d/boa/boa.conf of the component Boa Webserver. Such manipulation leads to least privilege violation. The attack can be executed remotely. The exploit has been disclosed to the… | |
| Aplazada | Baja (2.1) | 0.21% | — | Totolink Ac1200 T8AIVsftpdAI | 8/6/2026 | 23/7/2026 | A security vulnerability has been detected in TOTOLINK AC1200 T8 4.1.5cu.8611. This affects an unknown function of the file /etc/vsftpd.conf of the component vsftpd. The manipulation leads to least privilege violation. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. | |
| Analizada | Baja (2.1) | 0.51% | — | Dlink Dir-823g Firmware | 8/6/2026 | 23/7/2026 | A security flaw has been discovered in D-Link DIR-823G 1.0.2B05. The affected element is an unknown function of the file /etc/vsftpd.conf of the component vsftpd. Performing a manipulation results in least privilege violation. The attack can be initiated remotely. The exploit has been released to the public and may be… | |
| Aplazada | Media (6.8) | 0.27% | — | Tp-link Tapo C520wsAI | 6/6/2026 | 23/7/2026 | An authenticated format string vulnerability exists in the ONVIF Subscribe service in Tapo C520WS v2 due to improper handling of externally supplied parameters within formatting functions. An attacker may inject crafted format strings into event subscription requests or notification generation path to disrupt normal… | |
| Aplazada | Media (6.8) | 0.26% | — | Tp-link Tapo C520wsAI | 6/6/2026 | 23/7/2026 | An authenticated format string vulnerability is present in the ONVIF AddScopes in Tapo C520WS v2, where user-controlled input is improperly passed to formatting functions without adequate sanitization. An attacker can inject format specifiers into ONVIF scope parameters to manipulate memory handling behavior.… |