Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2989▼ 73 respecto a la semana anterior
Críticas / altas1415▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
6788 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.6) | 0.45% | 💥 PoC | Dlink Dir-895lAI | 26/9/2026 | 28/9/2026 | A vulnerability was detected in D-Link DIR-895L A1_102b07. Impacted is the function tunnel_set_params of the file tunnel.c of the component L2TP Control Channel Parser. Performing a manipulation results in out-of-bounds write. The attack may be initiated remotely. The exploit is now public and may be used. | |
| Pendiente de análisis | Alta (8.8) | 1.3% | — | Dlink Dap-2610AI | 25/9/2026 | 25/9/2026 | D-Link DAP-2610 up to 2.06B08r099 contains an authenticated command injection vulnerability within the web interface at the /index.xgi endpoint. An attacker with authenticated access can exploit some parameters to execute arbitrary system commands. | |
| Aplazada | Media (4) | 0.16% | — | Ylefebvre Link LibraryAI | 25/9/2026 | 25/9/2026 | The Link Library WordPress plugin before 7.9.6 does not validate the destination of a user-supplied URL before falling back to an unprotected fetch when its safe request is rejected, allowing unauthenticated visitors to make the site issue requests to hosts on its internal network and to learn from the response… | |
| Aplazada | Media (4.1) | 0.24% | — | Ylefebvre Link LibraryAI | 25/9/2026 | 25/9/2026 | The Link Library WordPress plugin before 7.9.6 does not sanitize a user-supplied destination folder before writing a generated image to disk, allowing users with the Contributor role and above to create directories and write or overwrite image files anywhere the web server can write, including outside the site's… | |
| Aplazada | Media (6.1) | 0.15% | — | Ylefebvre Link LibraryAI | 25/9/2026 | 25/9/2026 | The Link Library WordPress plugin before 7.9.6 does not properly escape some parameters before outputting them in the addresses of links it generates on its front-end directory pages, leading to Reflected Cross-Site Scripting which could be used against any visitor, including logged-in administrators. | |
| Aplazada | Alta (8.6) | 0.31% | 💥 PoC | Netlink ICT Hg323rwAI | 24/9/2026 | 24/9/2026 | This vulnerability exists in the Netlink ICT HG323RW router due to insufficient authorization and input validation controls in the diagnostic script import functionality. An authenticated attacker could exploit this vulnerability by uploading and executing a specially crafted script through the web management… | |
| Aplazada | Crítica (9.3) | 0.65% | — | Dlink Dir-825AI | 24/9/2026 | 24/9/2026 | A vulnerability was identified in D-Link DIR-825 3.00b32. Affected is the function tunnel_set_params of the file tunnel.c of the component rp-l2tp. The manipulation of the argument peer_hostname leads to out-of-bounds write. The attack may be initiated remotely. | |
| Aplazada | Media (5.5) | 0.29% | — | Lb-link Bl-cpe600euAI | 23/9/2026 | 29/9/2026 | A security flaw has been discovered in LB-Link BL-CPE600EU 5.8.13. This vulnerability affects unknown code of the file Mifi_config.bin of the component Configuration Backup Handler. The manipulation results in information disclosure. The attack can be launched remotely. The exploit has been released to the public and… | |
| Pendiente de análisis | Media (6.5) | 0.27% | — | StreamlinkAI | 23/9/2026 | 29/9/2026 | Streamlink is a CLI utility which pipes video streams from various services into a video player. Prior to 8.6.0, HTTPSession mounts a FileAdapter for the file scheme and inherits redirect handling from requests.Session without rejecting cross-protocol redirects. A remote server controlling an HTTP or HTTPS URL reached… | |
| Pendiente de análisis | Crítica (9.3) | 2.1% | 💥 PoC | Dlink Dap-1360AI | 22/9/2026 | 22/9/2026 | D-Link DAP-1360 firmware version 6.14 and earlier contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary commands as root by sending crafted requests to the device's web management interface without valid credentials. Attackers can fully compromise the device… | |
| Aplazada | Crítica (9.3) | 0.98% | — | Dlink Dir-868lAI | 20/9/2026 | 22/9/2026 | A vulnerability was determined in D-Link DIR-868L 2.01b05. This issue affects the function strcpy of the file /webfa_authentication.cgi of the component Authentication Handler. Executing a manipulation of the argument id/password can lead to stack-based buffer overflow. The attack can be executed remotely. The exploit… | |
| Aplazada | Media (5.3) | 0.38% | — | Dlink Dir-x1860zAI | 20/9/2026 | 24/9/2026 | A vulnerability has been found in D-Link DIR-X1860Z up to 1.0.2.220120.165402. Affected is the function routerd.wificfg_get/routerd.get_rand_key of the component ubus JSON-RPC interface. Such manipulation leads to information disclosure. The attack must be carried out from within the local network. Upgrading to… | |
| Aplazada | Alta (7.4) | 0.56% | 💥 PoC | Dlink Dir-x1860AIDlink Dir-x1860zAI | 20/9/2026 | 21/9/2026 | A security flaw has been discovered in D-Link DIR-X1860 and DIR-X1860Z up to 1.0.2.220120.165402. The impacted element is an unknown function of the file /ubus of the component routerd. The manipulation of the argument passwd_set results in improper access controls. The attack must originate from the local network.… | |
| Aplazada | Alta (8.5) | 2.7% | 💥 PoC | Dlink R95 Be9500AI | 20/9/2026 | 21/9/2026 | A vulnerability was found in D-Link R95 BE9500_1.00.16. This vulnerability affects the function system of the file /bin/ssi of the component DHMAPI. The manipulation of the argument NTPServer results in os command injection. The attack can be executed remotely. The exploit has been made public and could be used. | |
| Aplazada | Alta (8.6) | 2.3% | — | Totolink A3002muAI | 19/9/2026 | 21/9/2026 | A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. Affected by this issue is the function formWsc of the file /boafrm/formWsc. This manipulation of the argument localPin causes command injection. The attack can be initiated remotely. The exploit has been made available to the public and could be… | |
| Aplazada | Crítica (9.3) | 0.66% | — | Totolink A3002muAI | 19/9/2026 | 22/9/2026 | A security flaw has been discovered in Totolink A3002MU Hh-B20211125.1046. Affected by this vulnerability is the function formWlWds of the file /boafrm/formWlWds. The manipulation of the argument submit-url results in buffer overflow. It is possible to launch the attack remotely. The exploit has been released to the… | |
| Aplazada | Crítica (9.3) | 0.88% | — | Totolink A3002muAI | 18/9/2026 | 21/9/2026 | A vulnerability was identified in Totolink A3002MU Hh-B20211125.1046. Affected is the function formWlEncrypt of the file /boafrm/formWlEncrypt. The manipulation of the argument submit-url leads to buffer overflow. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. | |
| Aplazada | Alta (8.6) | 0.85% | — | Totolink A3002muAI | 18/9/2026 | 23/9/2026 | A vulnerability was determined in Totolink A3002MU Hh-B20211125.1046. This impacts the function formWlAc of the file /boafrm/formWlAc. Executing a manipulation of the argument submit-url can lead to buffer overflow. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. | |
| Aplazada | Alta (8.6) | 0.85% | — | Totolink A3002muAI | 18/9/2026 | 22/9/2026 | A vulnerability was found in Totolink A3002MU Hh-B20211125.1046. This affects the function formSchedule of the file /boafrm/formSchedule. Performing a manipulation of the argument webpage results in buffer overflow. The attack is possible to be carried out remotely. The exploit has been made public and could be used. | |
| Aplazada | Alta (8.6) | 0.45% | — | WP Shortcut Link AND Advertisement BanerAI | 18/9/2026 | 18/9/2026 | The wp shortcut link and advertisement baner WordPress plugin through 1.2.0 does not sanitize and escape a parameter before using it in a SQL query on an AJAX action available to unauthenticated users, allowing unauthenticated attackers to perform SQL injection attacks and extract sensitive data from the database. | |
| Aplazada | Alta (7.1) | 0.41% | — | ShlinkAI | 16/9/2026 | 23/9/2026 | Shlink through 5.1.6 fails to enforce API key role restrictions when issuing Mercure subscription tokens, allowing restricted keys to subscribe to all topics. Attackers with author-only or domain-only keys can access the mercure-info endpoint to receive visit data including referrer, user agent, geolocation, and full… | |
| Pendiente de análisis | Alta (7.6) | 0.19% | — | Dd-wrtAITp-link Tl-wr740nAI | 16/9/2026 | 22/9/2026 | DD-WRT firmware, as deployed on TP-Link TL-WR740N v1 through v4 hardware, stores sensitive authentication credentials in cleartext within non-volatile memory. The exposed material includes SSH private keys, dynamic DNS passwords, email notification credentials and administrative passwords. An attacker with physical… | |
| Aplazada | Baja (2.1) | 1.8% | — | Totolink X5000rAI | 15/9/2026 | 16/9/2026 | A vulnerability has been found in TOTOLINK X5000R 9.1.0cu.2089_B20211224. The impacted element is the function exportOvpn of the file /cgi-bin/cstecgi.cgi?action=exportOvpn&type=user of the component Export Ovpn Handler. The manipulation of the argument filetype leads to os command injection. The attack can be… | |
| Aplazada | Alta (7.5) | 0.37% | — | Prolink 13A Smart Plug Ds-3202m-ukv3AIMezeeAI | 15/9/2026 | 22/9/2026 | An issue in Prolink 13A Smart Plug Model Version: DS-3202M-UKv3 Wi-Fi and Application Version mEzee 2.6.7 allows attackers to cause a Denial of Service (DoS) or connection to an attacker-controlled device via supplying a crafted packet during the provisioning phase. | |
| Aplazada | Crítica (9.8) | 0.51% | — | Totolink X5000rAI | 15/9/2026 | 22/9/2026 | TOTOLINK X5000R V9.1.0cu.2415_B20250515 was discovered to contain a hardcoded password for root access. |