Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

62 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)0.69%—Juplink Rx4-1500 Firmware18/9/202317/6/2026
Hard-coded credentials in Juplink RX4-1500 versions V1.0.2 through V1.0.5 allow unauthenticated attackers to log in to the web interface or telnet service as the 'user' user.
ModificadaAlta (8.8)0.86%—Juplink Rx4-1500 Firmware23/8/202317/6/2026
A stack-based buffer overflow exists in Juplink RX4-1500, a WiFi router, in versions 1.0.2 through 1.0.5. An authenticated attacker can exploit this vulnerability to achieve code execution as root.
ModificadaAlta (7.5)1.3%—Peplink Balance 20X FirmwarePeplink Balance 310x FirmwarePeplink MBX FirmwarePeplink EPX Firmware+517/10/202017/6/2026
Peplink Balance before 8.1.0rc1 allows an unauthenticated attacker to download PHP configuration files (/filemanager/php/connector.php) from Web Admin.
ModificadaMedia (5.5)0.40%—Juplink Rx4-1500 Firmware23/4/202017/6/2026
httpd in Juplink RX4-1500 v1.0.3-v1.0.5 allows remote attackers to change or access router settings by connecting to the unauthenticated setup3.htm endpoint from the local network.
ModificadaMedia (6.7)0.93%—Juplink Rx4-1500 Firmware23/4/202017/6/2026
Juplink RX4-1500 v1.0.3 allows remote attackers to gain root access to the Linux subsystem via an unsanitized exec call (aka Command Line Injection), if the undocumented telnetd service is enabled and the attacker can authenticate as admin from the local network.
ModificadaAlta (8.1)3.7%💥 ExploitPeplink B305hw2 FirmwarePeplink 380hw6 FirmwarePeplink 580hw2 FirmwarePeplink 710hw3 Firmware+25/6/201717/6/2026
Arbitrary file deletion exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-build2093. The attack methodology is absolute path traversal in cgi-bin/MANGA/firmware_process.cgi via the upfile.path parameter.
ModificadaMedia (5.3)3.6%💥 ExploitPeplink B305hw2 FirmwarePeplink 380hw6 FirmwarePeplink 580hw2 FirmwarePeplink 710hw3 Firmware+25/6/201717/6/2026
Debug information disclosure exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-build2093. A direct request to cgi-bin/HASync/hasync.cgi?debug=1 shows Master LAN Address, Serial Number, HA Group ID, Virtual IP, and Submitted…
ModificadaMedia (6.1)1.8%💥 ExploitPeplink B305hw2 FirmwarePeplink 380hw6 FirmwarePeplink 580hw2 FirmwarePeplink 710hw3 Firmware+25/6/201717/6/2026
XSS via orig_url exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-build2093. The affected script is guest/preview.cgi.
ModificadaMedia (6.1)1.8%💥 ExploitPeplink B305hw2 FirmwarePeplink 380hw6 FirmwarePeplink 580hw2 FirmwarePeplink 710hw3 Firmware+25/6/201717/6/2026
XSS via syncid exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-build2093. The affected script is cgi-bin/HASync/hasync.cgi.
ModificadaCrítica (9.8)4.9%💥 ExploitPeplink B305hw2 FirmwarePeplink 380hw6 FirmwarePeplink 580hw2 FirmwarePeplink 710hw3 Firmware+25/6/201717/6/2026
Cleartext password storage exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-build2093. The files in question are /etc/waipass and /etc/roapass. In case one of these devices is compromised, the attacker can gain access to…
ModificadaAlta (8.8)1.9%💥 ExploitPeplink B305hw2 FirmwarePeplink 380hw6 FirmwarePeplink 580hw2 FirmwarePeplink 710hw3 Firmware+25/6/201717/6/2026
CSRF exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-build2093. The CGI scripts in the administrative interface are affected. This allows an attacker to execute commands, if a logged in user visits a malicious website. This…
ModificadaCrítica (9.8)62%💥 ExploitPeplink B305hw2 FirmwarePeplink 380hw6 FirmwarePeplink 580hw2 FirmwarePeplink 710hw3 Firmware+25/6/201717/6/2026
SQL injection exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-build2093. An attack vector is the bauth cookie to cgi-bin/MANGA/admin.cgi. One impact is enumeration of user accounts by observing whether a session ID can be…
ModificadaAlta (8.1)4.5%—Oracle Toplink21/7/201617/6/2026
Unspecified vulnerability in the Oracle TopLink component in Oracle Fusion Middleware 12.1.3.0, 12.2.1.0, and 12.2.1.1 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JPA-RS.
ModificadaMedia (5)1.2%—Phplinkdirectory Phpld24/9/201116/6/2026
phpLD 2-151.2.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by libs/smarty/Smarty_Compiler.class.php and certain other files.
ModificadaMedia (6.8)0.97%💥 ExploitPhplinkdirectory PHP Link Directory25/1/201116/6/2026
Cross-site request forgery (CSRF) vulnerability in admin/conf_users_edit.php in PHP Link Directory (phpLD) 4.1.0 allows remote attackers to hijack the authentication of administrators for requests that add an administrator via the N action.
ModificadaMedia (5)2.9%💥 ExploitDew-code Dew-newphplinks12/5/200916/6/2026
Directory traversal vulnerability in index.php in Dew-NewPHPLinks 2.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the show parameter.
ModificadaMedia (4.3)1.4%💥 ExploitDew-code Dew-newphplinks12/5/200916/6/2026
Cross-site scripting (XSS) vulnerability in index.php in Dew-NewPHPLinks 2.0 allows remote attackers to inject arbitrary web script or HTML via the PID parameter.
ModificadaAlta (9.3)5.7%💥 ExploitChina-on-site Flexphplink20/4/200916/6/2026
Unrestricted file upload vulnerability in submitlink.php in FlexPHPLink Pro 0.0.7 allows remote attackers to execute arbitrary PHP code by uploading a file with an executable extension, then accessing it via a direct request to the renamed file in linkphoto/.
ModificadaMedia (6.8)2.0%💥 ExploitChina-on-site Flexphplink20/4/200916/6/2026
Multiple SQL injection vulnerabilities in admin/usercheck.php in FlexPHPLink Pro 0.0.6 and 0.0.7, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via (1) the checkuser parameter (aka username field), or (2) the checkpass parameter (aka password field), to admin/index.php.
ModificadaAlta (7.5)40%💥 ExploitBeerwin Phplinkadmin20/3/200916/6/2026
PHP remote file inclusion vulnerability in linkadmin.php in Beerwin PHPLinkAdmin 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter.
ModificadaAlta (7.5)1.3%💥 ExploitBeerwin Phplinkadmin20/3/200916/6/2026
Multiple SQL injection vulnerabilities in Beerwin PHPLinkAdmin 1.0 allow remote attackers to execute arbitrary SQL commands via the linkid parameter to edlink.php, and unspecified other vectors.
ModificadaAlta (7.5)1.00%💥 ExploitPowie Plink30/9/200816/6/2026
SQL injection vulnerability in linkto.php in Powie pLink 2.07 allows remote attackers to execute arbitrary SQL commands via the id parameter.
ModificadaMedia (4.3)1.5%💥 ExploitIdevspot Phplinkexchange14/8/200816/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in index.php in IDevSpot PhpLinkExchange 1.01 allow remote attackers to inject arbitrary web script or HTML via the catid parameter in a (1) user_add, (2) recip, (3) tellafriend, or (4) contact action, or (5) in a request without an action; or (6) the id parameter in…
ModificadaMedia (5)3.1%💥 ExploitPhplinkat31/7/200816/6/2026
phpLinkat 0.1 allows remote attackers to bypass authentication and access unspecified pages under admin/ by sending a login=right cookie.
ModificadaAlta (7.5)0.97%💥 ExploitPhplinkat31/7/200816/6/2026
SQL injection vulnerability in showcat.php in phpLinkat 0.1 allows remote attackers to execute arbitrary SQL commands via the catid parameter.
Orbitaley — Vulnerabilidades