Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2732▼ 549 respecto a la semana anterior
Críticas / altas1295▼ 233 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

49 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)0.46%💥 PoCOptilinknetwork Op-xt71000n Firmware23/11/202217/6/2026
A vulnerability in OPTILINK OP-XT71000N Hardware Version: V2.2, Firmware Version: OP_V3.3.1-191028 allows an unauthenticated, remote attacker to conduct a cross site request forgery (CSRF) attack to enable syslog mode through ' /mgm_log_cfg.asp.' The system starts to log events, 'Remote' mode or 'Both' mode on "Syslog…
ModificadaAlta (8.8)0.55%💥 PoCOptilinknetwork Op-xt71000n Firmware23/11/202217/6/2026
A remote attacker can conduct a cross-site request forgery (CSRF) attack on OPTILINK OP-XT71000N Hardware Version: V2.2 , Firmware Version: OP_V3.3.1-191028. The vulnerability is due to insufficient CSRF protections for the "mgm_config_file.asp" because of which attacker can create a crafted "csrf form" which sends "…
ModificadaCrítica (9.8)2.3%💥 PoCOptilinknetwork Op-xt71000n Firmware23/11/202217/6/2026
OPTILINK OP-XT71000N V2.2 is vulnerable to Remote Code Execution. The issue occurs when the attacker sends an arbitrary code on "/diag_ping_admin.asp" to "PingTest" interface that leads to COMMAND EXECUTION. An attacker can successfully trigger the COMMAND and can compromise full system.
ModificadaMedia (6.5)0.45%💥 PoCOptilinknetwork Op-xt71000n Firmware21/11/202217/6/2026
A vulnerability in the "/admin/wlmultipleap.asp" of optilink OP-XT71000N version: V2.2 could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack to create Multiple WLAN BSSID.
ModificadaMedia (5.4)0.67%—Dsknet18/7/202217/6/2026
An issue was discovered in DSK DSKNet 2.16.136.0 and 2.17.136.5. The new menu option within the general Parameters page is vulnerable to stored XSS. The attacker can create a menu option, make it visible to every application user, and conduct session hijacking, account takeover, or malicious code delivery, with the…
ModificadaAlta (7.1)0.93%—Dsknet18/7/202217/6/2026
An issue was discovered in DSK DSKNet 2.16.136.0 and 2.17.136.5. A SQL Injection vulnerability allows authenticated users to taint database data and extract sensitive information via crafted HTTP requests. The type of SQL Injection is blind boolean based.
ModificadaAlta (8.2)1.1%—Dsknet18/7/202217/6/2026
An issue was discovered in DSK DSKNet 2.16.136.0 and 2.17.136.5. A PresAbs.php SQL Injection vulnerability allows unauthenticated users to taint database data and extract sensitive information via crafted HTTP requests. The type of SQL Injection is blind boolean based. (An unauthenticated attacker can discover the…
ModificadaMedia (5.3)0.92%—Dsknet18/7/202217/6/2026
An issue was discovered in DSK DSKNet 2.16.136.0 and 2.17.136.5. It mishandles access control. This allows a remote attacker to access account information pages (including personal data) without being authenticated. The collected information includes the badge numbers that operate as user login names. They have a PIN…
ModificadaAlta (8.8)4.0%—Dsknet18/7/202217/6/2026
An issue was discovered in DSK DSKNet 2.16.136.0 and 2.17.136.5. The Touch settings allow unrestricted file upload (and consequently Remote Code Execution) via PDF upload with PHP content and a .php extension. The attacker must hijack or obtain privileged user access to the Parameters page in order to exploit this…
ModificadaAlta (7.5)1.1%—Mediateknet Netwave System25/5/202117/6/2026
An information disclosure vulnerability was discovered in /index.class.php (via port 8181) on NetWave System 1.0 which allows unauthenticated attackers to exfiltrate sensitive information from the system.
ModificadaMedia (6.1)0.78%—Desknets NEO3/12/202017/6/2026
Cross-site scripting vulnerability in desknet's NEO (desknet's NEO Small License V5.5 R1.5 and earlier, and desknet's NEO Enterprise License V5.5 R1.5 and earlier) allows remote attackers to inject arbitrary script via unspecified vectors.
ModificadaAlta (7.5)1.4%—Aicorporation Risknet Acquirer14/2/202016/6/2026
RiskNet Acquirer before hotfix 6.0 b7+ADHOC-443 ApplicationServiceBean contains a service information disclosure.
ModificadaAlta (8.8)43%—Linknet-usa Lw-n605r Firmware20/9/201817/6/2026
LINK-NET LW-N605R devices with firmware 12.20.2.1486 allow Remote Code Execution via shell metacharacters in the HOST field of the ping feature at adm/systools.asp. Authentication is needed but the default password of admin for the admin account may be used in some cases.
ModificadaMedia (6.1)0.61%—Knet Cisco Configuration Manager14/9/201817/6/2026
K-Net Cisco Configuration Manager through 2014-11-19 has XSS via devices.php.
ModificadaAlta (7.5)2.4%—Dinknetwork DfarcDinknetwork Dfarc2Debian Linux12/6/201817/6/2026
Directory traversal issues in the D-Mod extractor in DFArc and DFArc2 (as well as in RTsoft's Dink Smallwood HD / ProtonSDK version) before 3.14 allow an attacker to overwrite arbitrary files on the user's system.
ModificadaMedia (4)1.6%—Neojapan Desknet NEO5/9/201517/6/2026
Directory traversal vulnerability in zhtml.cgi in NEOJAPAN desknet NEO 2.0R1.0 through 2.5R1.4 allows remote authenticated users to read arbitrary files via a crafted parameter.
ModificadaMedia (5)3.0%💥 ExploitClicknet CMS5/7/200916/6/2026
Directory traversal vulnerability in index.php in Clicknet CMS 2.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the side parameter.
ModificadaAlta (10)8.6%💥 ExploitSlsknet Soulseek29/5/200916/6/2026
Stack-based buffer overflow in Soulseek 156 and 157 NS allows remote attackers to execute arbitrary code via a long search query.
ModificadaAlta (7.5)1.1%—Raknet Autopatcher Server3/6/200816/6/2026
SQL injection vulnerability in the Autopatcher server plugin in RakNet before 3.23 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
ModificadaMedia (6.5)2.8%—NEO Japan Desknets27/10/200616/6/2026
Buffer overflow in Desknet's (niokeru) before 5.0J R1.0 might allow remote authenticated users to execute arbitrary code via unspecified vectors. NOTE: some of these details are obtained from third party information.
ModificadaAlta (7.5)1.3%—Looknet Fineshop27/6/200616/6/2026
Multiple SQL injection vulnerabilities in index.php in FineShop 3.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) produkt, (2) id_produc, and (3) id_kat parameters.
ModificadaBaja (2.6)1.3%—Looknet Fineshop27/6/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in index.php in FineShop 3.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) promocja, (2) wysw, or (3) id_produc parameters.
ModificadaMedia (5)3.1%💥 ExploitRakkarsoft Raknet9/6/200516/6/2026
Rakkarsoft RakNet network library 2.33 and earlier, when released before 30 May 2005, and as used in multiple products including nFusion Elite Warriors: Vietnam, allows remote attackers to cause a denial of service (infinite loop) via a zero-byte UDP packet.
ModificadaAlta (7.5)7.8%💥 ExploitStormy Studios Knet2/5/200516/6/2026
Buffer overflow in Stormy Studios Knet 1.04c and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long HTTP GET request.
Orbitaley — Vulnerabilidades