Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
1843 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (2.1) | 4.7% | — | Dlink Di-7300g+ FirmwareDlink Di-8200g Firmware | 30/6/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in D-Link DI-7300G+ and DI-8200G 17.12.20A1/19.12.25A1. This affects an unknown part of the file msp_info.htm. The manipulation of the argument flag/cmd/iface leads to os command injection. It is possible to initiate the attack remotely. The exploit has been… | |
| Analizada | Baja (2.1) | 17% | — | Dlink Di-7300g+ Firmware | 30/6/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in D-Link DI-7300G+ 19.12.25A1. Affected by this issue is some unknown functionality of the file in proxy_client.asp. The manipulation of the argument proxy_srv/proxy_lanport/proxy_lanip/proxy_srvport leads to os command injection. The attack may be… | |
| Analizada | Baja (2) | 2.6% | — | Dlink Di-7300g+ Firmware | 30/6/2025 | 17/6/2026 | A vulnerability classified as critical was found in D-Link DI-7300G+ 19.12.25A1. Affected by this vulnerability is an unknown functionality of the file httpd_debug.asp. The manipulation of the argument Time leads to os command injection. The exploit has been disclosed to the public and may be used. | |
| Analizada | Baja (2.1) | 4.2% | — | Dlink Di-7300g+ Firmware | 30/6/2025 | 17/6/2026 | A vulnerability classified as critical has been found in D-Link DI-7300G+ 19.12.25A1. Affected is an unknown function of the file wget_test.asp. The manipulation of the argument url leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. | |
| Analizada | Alta (7.4) | 0.81% | — | Dlink Dir-513 Firmware | 30/6/2025 | 17/6/2026 | A vulnerability classified as critical has been found in D-Link DIR-513 1.0. This affects an unknown part of the file /goform/formSetWanPPTP. The manipulation of the argument curTime leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.… | |
| Analizada | Alta (7.4) | 0.98% | — | Dlink Di-8100 Firmware | 30/6/2025 | 17/6/2026 | A vulnerability was found in D-Link DI-8100 16.07.21. It has been rated as critical. Affected by this issue is some unknown functionality of the file /pppoe_base.asp of the component jhttpd. The manipulation of the argument mschap_en leads to buffer overflow. The attack may be launched remotely. The exploit has been… | |
| Modificada | Media (6.3) | 0.39% | — | Dlink Dir-823 PRO Firmware | 27/6/2025 | 1/7/2026 | D-Link DIR-823-Pro 1.02 has improper permission control, allowing unauthorized users to turn on and access Telnet services. | |
| Aplazada | Alta (8.7) | 0.68% | — | Dlink Dsl-2730uAIDlink Dsl-2750uAIDlink Dsl-2750eAI | 26/6/2025 | 17/6/2026 | A path traversal vulnerability exists in the web management interface of D-Link DSL-2730U, DSL-2750U, and DSL-2750E ADSL routers with firmware versions IN_1.02, SEA_1.04, and SEA_1.07. The vulnerability is due to insufficient input validation on the getpage parameter within the /cgi-bin/webproc CGI script. This flaw… | |
| Analizada | Alta (7.4) | 1.2% | — | Dlink Dir-619l Firmware | 25/6/2025 | 17/6/2026 | A vulnerability was found in D-Link DIR-619L 2.06B01 and classified as critical. This issue affects the function formAdvanceSetup of the file /goform/formAdvanceSetup. The manipulation of the argument webpage leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to… | |
| Analizada | Alta (7.4) | 1.3% | — | Dlink Dir-619l Firmware | 25/6/2025 | 17/6/2026 | A vulnerability has been found in D-Link DIR-619L 2.06B01 and classified as critical. This vulnerability affects the function formSetWAN_Wizard51 of the file /goform/formSetWAN_Wizard51. The manipulation of the argument curTime leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has… | |
| Analizada | Alta (7.4) | 1.2% | — | Dlink Dir-619l Firmware | 25/6/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in D-Link DIR-619L 2.06B01. This affects the function formAutoDetecWAN_wizard4 of the file /goform/formAutoDetecWAN_wizard4. The manipulation of the argument curTime leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The… | |
| Analizada | Alta (7.4) | 1.2% | — | Dlink Dir-619l Firmware | 25/6/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in D-Link DIR-619L 2.06B01. Affected by this issue is the function formSetWANType_Wizard5 of the file /goform/formSetWANType_Wizard5. The manipulation of the argument curTime leads to stack-based buffer overflow. The attack may be launched remotely. The… | |
| Analizada | Alta (7.4) | 1.2% | — | Dlink Dir-619l Firmware | 21/6/2025 | 17/6/2026 | A vulnerability was found in D-Link DIR-619L 2.06B01 and classified as critical. This issue affects the function formSetACLFilter of the file /goform/formSetACLFilter. The manipulation of the argument curTime leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to… | |
| Analizada | Alta (7.4) | 0.91% | — | Dlink Dir-619l Firmware | 21/6/2025 | 17/6/2026 | A vulnerability has been found in D-Link DIR-619L 2.06B01 and classified as critical. This vulnerability affects the function formSetWizard1 of the file /goform/formWlSiteSurvey. The manipulation of the argument curTime leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been… | |
| Analizada | Alta (7.4) | 1.2% | — | Dlink Dir-619l Firmware | 20/6/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in D-Link DIR-619L 2.06B01. This affects the function formSetWizard1 of the file /goform/formSetWizard1. The manipulation of the argument curTime leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been… | |
| Analizada | Alta (7.4) | 1.2% | — | Dlink Dir-619l Firmware | 20/6/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in D-Link DIR-619L 2.06B01. Affected by this issue is the function formSetEnableWizard of the file /goform/formSetEnableWizard. The manipulation of the argument curTime leads to stack-based buffer overflow. The attack may be launched remotely. The… | |
| Analizada | Alta (7.4) | 1.2% | — | Dlink Dir-619l Firmware | 20/6/2025 | 17/6/2026 | A vulnerability classified as critical was found in D-Link DIR-619L 2.06B01. Affected by this vulnerability is the function formWlanGuestSetup of the file /goform/formWlanGuestSetup. The manipulation of the argument curTime leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been… | |
| Analizada | Alta (7.4) | 1.2% | — | Dlink Dir-619l Firmware | 20/6/2025 | 17/6/2026 | A vulnerability classified as critical has been found in D-Link DIR-619L 2.06B01. Affected is the function formdumpeasysetup of the file /goform/formdumpeasysetup. The manipulation of the argument curTime/config.save_network_enabled leads to stack-based buffer overflow. It is possible to launch the attack remotely.… | |
| Analizada | Alta (7.4) | 1.2% | — | Dlink Dir-619l Firmware | 20/6/2025 | 17/6/2026 | A vulnerability was found in D-Link DIR-619L 2.06B01. It has been rated as critical. This issue affects the function formSetEmail of the file /goform/formSetEmail. The manipulation of the argument curTime/config.smtp_email_subject leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit… | |
| Analizada | Alta (7.4) | 1.2% | — | Dlink Dir-619l Firmware | 20/6/2025 | 17/6/2026 | A vulnerability was found in D-Link DIR-619L 2.06B01. It has been declared as critical. This vulnerability affects unknown code of the file /goform/formSetDomainFilter. The manipulation of the argument curTime/sched_name_%d/url_%d leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit… | |
| Analizada | Alta (7.4) | 0.95% | — | Dlink Dir-867 Firmware | 20/6/2025 | 17/6/2026 | A vulnerability has been found in D-Link DIR-867 1.0 and classified as critical. This vulnerability affects the function strncpy of the component Query String Handler. The manipulation leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be… | |
| Analizada | Alta (7.4) | 1.2% | — | Dlink Dir-815 Firmware | 20/6/2025 | 17/6/2026 | A vulnerability was found in D-Link DIR-815 1.01. It has been declared as critical. This vulnerability affects the function sub_403794 of the file hedwig.cgi. The manipulation leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. | |
| Analizada | Alta (7.4) | 1.3% | — | Dlink Dir-825 Firmware | 20/6/2025 | 17/6/2026 | A vulnerability has been found in D-Link DIR-825 2.03 and classified as critical. This vulnerability affects the function sub_4091AC of the component HTTP POST Request Handler. The manipulation leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and… | |
| Analizada | Alta (7.4) | 1.3% | — | Dlink Dir-825 Firmware | 20/6/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in D-Link DIR-825 2.03. This affects the function do_file of the component HTTP POST Request Handler. The manipulation leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may… | |
| Analizada | Crítica (9.8) | 0.56% | — | Dlink Dph-400se FirmwareDlink Dph-400s Firmware | 18/6/2025 | 17/6/2026 | D-Link DPH-400S/SE VoIP Phone v1.01 contains hardcoded provisioning variables, including PROVIS_USER_PASSWORD, which may expose sensitive user credentials. An attacker with access to the firmware image can extract these credentials using static analysis tools such as strings or xxd, potentially leading to unauthorized… |