Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2732▼ 549 respecto a la semana anterior
Críticas / altas1295▼ 233 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
49 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 0.46% | 💥 PoC | Optilinknetwork Op-xt71000n Firmware | 23/11/2022 | 17/6/2026 | A vulnerability in OPTILINK OP-XT71000N Hardware Version: V2.2, Firmware Version: OP_V3.3.1-191028 allows an unauthenticated, remote attacker to conduct a cross site request forgery (CSRF) attack to enable syslog mode through ' /mgm_log_cfg.asp.' The system starts to log events, 'Remote' mode or 'Both' mode on "Syslog… | |
| Modificada | Alta (8.8) | 0.55% | 💥 PoC | Optilinknetwork Op-xt71000n Firmware | 23/11/2022 | 17/6/2026 | A remote attacker can conduct a cross-site request forgery (CSRF) attack on OPTILINK OP-XT71000N Hardware Version: V2.2 , Firmware Version: OP_V3.3.1-191028. The vulnerability is due to insufficient CSRF protections for the "mgm_config_file.asp" because of which attacker can create a crafted "csrf form" which sends "… | |
| Modificada | Crítica (9.8) | 2.3% | 💥 PoC | Optilinknetwork Op-xt71000n Firmware | 23/11/2022 | 17/6/2026 | OPTILINK OP-XT71000N V2.2 is vulnerable to Remote Code Execution. The issue occurs when the attacker sends an arbitrary code on "/diag_ping_admin.asp" to "PingTest" interface that leads to COMMAND EXECUTION. An attacker can successfully trigger the COMMAND and can compromise full system. | |
| Modificada | Media (6.5) | 0.45% | 💥 PoC | Optilinknetwork Op-xt71000n Firmware | 21/11/2022 | 17/6/2026 | A vulnerability in the "/admin/wlmultipleap.asp" of optilink OP-XT71000N version: V2.2 could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack to create Multiple WLAN BSSID. | |
| Modificada | Media (5.4) | 0.67% | — | Dsknet | 18/7/2022 | 17/6/2026 | An issue was discovered in DSK DSKNet 2.16.136.0 and 2.17.136.5. The new menu option within the general Parameters page is vulnerable to stored XSS. The attacker can create a menu option, make it visible to every application user, and conduct session hijacking, account takeover, or malicious code delivery, with the… | |
| Modificada | Alta (7.1) | 0.93% | — | Dsknet | 18/7/2022 | 17/6/2026 | An issue was discovered in DSK DSKNet 2.16.136.0 and 2.17.136.5. A SQL Injection vulnerability allows authenticated users to taint database data and extract sensitive information via crafted HTTP requests. The type of SQL Injection is blind boolean based. | |
| Modificada | Alta (8.2) | 1.1% | — | Dsknet | 18/7/2022 | 17/6/2026 | An issue was discovered in DSK DSKNet 2.16.136.0 and 2.17.136.5. A PresAbs.php SQL Injection vulnerability allows unauthenticated users to taint database data and extract sensitive information via crafted HTTP requests. The type of SQL Injection is blind boolean based. (An unauthenticated attacker can discover the… | |
| Modificada | Media (5.3) | 0.92% | — | Dsknet | 18/7/2022 | 17/6/2026 | An issue was discovered in DSK DSKNet 2.16.136.0 and 2.17.136.5. It mishandles access control. This allows a remote attacker to access account information pages (including personal data) without being authenticated. The collected information includes the badge numbers that operate as user login names. They have a PIN… | |
| Modificada | Alta (8.8) | 4.0% | — | Dsknet | 18/7/2022 | 17/6/2026 | An issue was discovered in DSK DSKNet 2.16.136.0 and 2.17.136.5. The Touch settings allow unrestricted file upload (and consequently Remote Code Execution) via PDF upload with PHP content and a .php extension. The attacker must hijack or obtain privileged user access to the Parameters page in order to exploit this… | |
| Modificada | Alta (7.5) | 1.1% | — | Mediateknet Netwave System | 25/5/2021 | 17/6/2026 | An information disclosure vulnerability was discovered in /index.class.php (via port 8181) on NetWave System 1.0 which allows unauthenticated attackers to exfiltrate sensitive information from the system. | |
| Modificada | Media (6.1) | 0.78% | — | Desknets NEO | 3/12/2020 | 17/6/2026 | Cross-site scripting vulnerability in desknet's NEO (desknet's NEO Small License V5.5 R1.5 and earlier, and desknet's NEO Enterprise License V5.5 R1.5 and earlier) allows remote attackers to inject arbitrary script via unspecified vectors. | |
| Modificada | Alta (7.5) | 1.4% | — | Aicorporation Risknet Acquirer | 14/2/2020 | 16/6/2026 | RiskNet Acquirer before hotfix 6.0 b7+ADHOC-443 ApplicationServiceBean contains a service information disclosure. | |
| Modificada | Alta (8.8) | 43% | — | Linknet-usa Lw-n605r Firmware | 20/9/2018 | 17/6/2026 | LINK-NET LW-N605R devices with firmware 12.20.2.1486 allow Remote Code Execution via shell metacharacters in the HOST field of the ping feature at adm/systools.asp. Authentication is needed but the default password of admin for the admin account may be used in some cases. | |
| Modificada | Media (6.1) | 0.61% | — | Knet Cisco Configuration Manager | 14/9/2018 | 17/6/2026 | K-Net Cisco Configuration Manager through 2014-11-19 has XSS via devices.php. | |
| Modificada | Alta (7.5) | 2.4% | — | Dinknetwork DfarcDinknetwork Dfarc2Debian Linux | 12/6/2018 | 17/6/2026 | Directory traversal issues in the D-Mod extractor in DFArc and DFArc2 (as well as in RTsoft's Dink Smallwood HD / ProtonSDK version) before 3.14 allow an attacker to overwrite arbitrary files on the user's system. | |
| Modificada | Media (4) | 1.6% | — | Neojapan Desknet NEO | 5/9/2015 | 17/6/2026 | Directory traversal vulnerability in zhtml.cgi in NEOJAPAN desknet NEO 2.0R1.0 through 2.5R1.4 allows remote authenticated users to read arbitrary files via a crafted parameter. | |
| Modificada | Media (5) | 3.0% | 💥 Exploit | Clicknet CMS | 5/7/2009 | 16/6/2026 | Directory traversal vulnerability in index.php in Clicknet CMS 2.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the side parameter. | |
| Modificada | Alta (10) | 8.6% | 💥 Exploit | Slsknet Soulseek | 29/5/2009 | 16/6/2026 | Stack-based buffer overflow in Soulseek 156 and 157 NS allows remote attackers to execute arbitrary code via a long search query. | |
| Modificada | Alta (7.5) | 1.1% | — | Raknet Autopatcher Server | 3/6/2008 | 16/6/2026 | SQL injection vulnerability in the Autopatcher server plugin in RakNet before 3.23 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Media (6.5) | 2.8% | — | NEO Japan Desknets | 27/10/2006 | 16/6/2026 | Buffer overflow in Desknet's (niokeru) before 5.0J R1.0 might allow remote authenticated users to execute arbitrary code via unspecified vectors. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (7.5) | 1.3% | — | Looknet Fineshop | 27/6/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in index.php in FineShop 3.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) produkt, (2) id_produc, and (3) id_kat parameters. | |
| Modificada | Baja (2.6) | 1.3% | — | Looknet Fineshop | 27/6/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in index.php in FineShop 3.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) promocja, (2) wysw, or (3) id_produc parameters. | |
| Modificada | Media (5) | 3.1% | 💥 Exploit | Rakkarsoft Raknet | 9/6/2005 | 16/6/2026 | Rakkarsoft RakNet network library 2.33 and earlier, when released before 30 May 2005, and as used in multiple products including nFusion Elite Warriors: Vietnam, allows remote attackers to cause a denial of service (infinite loop) via a zero-byte UDP packet. | |
| Modificada | Alta (7.5) | 7.8% | 💥 Exploit | Stormy Studios Knet | 2/5/2005 | 16/6/2026 | Buffer overflow in Stormy Studios Knet 1.04c and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long HTTP GET request. |