Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2647▼ 688 respecto a la semana anterior
Críticas / altas1257▼ 290 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 277 respecto a la semana anterior
6789 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.6) | 0.46% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+17 | 13/5/2026 | 29/6/2026 | A vulnerability exists in iControl REST and the TMOS Shell (tmsh) where a highly privileged, authenticated attacker with at least the Manager role can create configuration objects that allow running arbitrary commands. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Modificada | Alta (8.7) | 0.46% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+17 | 13/5/2026 | 24/8/2026 | When a BIG-IP is configured with DNS caching (Such as a DNS profile with caching enabled, SSL Orchestrator, Advanced WAF DoS protection), undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Analizada | Alta (8.7) | 0.54% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+17 | 13/5/2026 | 29/6/2026 | When the BIG-IP Configuration utility is configured to use Lightweight Directory Access Protocol (LDAP) authentication, undisclosed traffic can cause the httpd process to exhaust the available file descriptors. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Analizada | Alta (7.1) | 0.34% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+17 | 13/5/2026 | 29/6/2026 | An authenticated iControl SOAP user may be able to obtain information of other accounts. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Analizada | Alta (8.5) | 0.90% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+17 | 13/5/2026 | 29/6/2026 | When running in Appliance mode, an authenticated remote command injection vulnerability exists in an undisclosed iControl REST endpoint. A successful exploit can allow the attacker to cross a security boundary. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Analizada | Media (6.3) | 0.40% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+17 | 13/5/2026 | 29/6/2026 | When Bidirectional Forwarding Detection (BFD) is configured in Static and Dynamic routing protocols, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to stop processing BFD packets and cause the configured routing protocol to fail over. Note: Software versions which have reached End of Technical… | |
| Analizada | Alta (8.5) | 0.41% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+17 | 13/5/2026 | 29/6/2026 | A vulnerability exists in BIG-IP scripted monitors that may allow an authenticated attacker with the Resource Administrator or Administrator role to execute arbitrary system commands with higher privileges. In appliance mode deployments, a successful exploit can allow the attacker to cross a security boundary. Note:… | |
| Analizada | Alta (8.5) | 0.26% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+18 | 13/5/2026 | 29/6/2026 | A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at least the Certificate Manager role can modify configuration objects that allow running arbitrary commands. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Analizada | Media (6.9) | 0.89% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+17 | 13/5/2026 | 29/6/2026 | When running in Appliance mode, a directory traversal vulnerability exists in an undisclosed iControl REST endpoint that may allow an authenticated attacker with administrator role privileges to cross a security boundary and delete files. Note: Software versions which have reached End of Technical Support (EoTS) are… | |
| Analizada | Baja (2.1) | 5.0% | — | Dlink Dir-816 Firmware | 12/5/2026 | 17/6/2026 | A vulnerability was detected in D-Link DIR-816 1.10CNB05_R1B011D88210. This affects the function portForward. Performing a manipulation of the argument ip_address results in command injection. The attack can be initiated remotely. The exploit is now public and may be used. | |
| Analizada | Baja (2.1) | 5.0% | — | Dlink Dir-816 Firmware | 11/5/2026 | 17/6/2026 | A security vulnerability has been detected in D-Link DIR-816 1.10CNB05_R1B011D88210. Affected by this issue is the function sub_445E7C of the file /goform/singlePortForward. Such manipulation of the argument ip_address leads to command injection. It is possible to launch the attack remotely. The exploit has been… | |
| Analizada | Baja (2.1) | 5.0% | — | Dlink Dir-816 Firmware | 11/5/2026 | 17/6/2026 | A weakness has been identified in D-Link DIR-816 1.10CNB05_R1B011D88210. Affected by this vulnerability is the function sub_445E7C of the file /goform/formDMZ.cgi. This manipulation causes command injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be… | |
| Aplazada | Alta (8.7) | 0.54% | — | Link Preview JSAI | 11/5/2026 | 17/6/2026 | Link Preview JS extracts web links information. Prior to 4.0.1, the library did not check for IPv6 loopback attacks. There was also a DNS attack, where an address could be resolved into an internal IP. This could cause internal data leaks. This vulnerability is fixed in 4.0.1. | |
| Analizada | Alta (7.3) | 2.3% | — | Dlink Dcs-932l Firmware | 11/5/2026 | 17/6/2026 | D-Link DCS-932L v2.18.01 is vulnerable to Command Injection in the function sub_42EF14 of the file /bin/alphapd. The manipulation of the argument LightSensorControl leads to command injection. | |
| Analizada | Media (5.1) | 6.1% | — | Dlink Dns-320 Firmware | 11/5/2026 | 17/6/2026 | A weakness has been identified in D-Link DNS-320 2.06B01. This impacts the function cgi_set_host/cgi_set_ntp/cgi_fan_control/cgi_merge_user of the file /cgi-bin/system_mgr.cgi. This manipulation causes os command injection. It is possible to initiate the attack remotely. | |
| Analizada | Baja (2) | 6.0% | — | Dlink Dns-320 Firmware | 11/5/2026 | 17/6/2026 | A security flaw has been discovered in D-Link DNS-320 2.06B01. This affects the function delete/rename/copy/move/chmod/chown of the file /cgi-bin/webfile_mgr.cgi. The manipulation results in os command injection. The attack may be performed from remote. The exploit has been released to the public and may be used for… | |
| Analizada | Baja (2) | 6.1% | — | Dlink Dns-320 Firmware | 11/5/2026 | 17/6/2026 | A vulnerability was identified in D-Link DNS-320 2.06B01. The impacted element is the function cgi_speed/cgi_dhcpd_lease/cgi_ddns/cgi_set_ip/cgi_upnp_del/cgi_dhcpd/cgi_upnp_add/cgi_upnp_edit of the file /cgi-bin/network_mgr.cgi. The manipulation leads to os command injection. The attack is possible to be carried out… | |
| Analizada | Alta (7.4) | 1.2% | — | Dlink Dcs-935l Firmware | 11/5/2026 | 23/7/2026 | Una vulnerabilidad fue encontrada en D-Link DCS-935L hasta 1.10.01. El elemento impactado es la función SetDeviceSettings del archivo /web/cgi-bin/hnap/hnap_service del componente HNAP Service. La manipulación del argumento AdminPassword resulta en desbordamiento de búfer. El ataque puede ser ejecutado remotamente. El… | |
| Analizada | Baja (2.1) | 8.5% | — | Wavlink Wl-nu516u1 Firmware | 10/5/2026 | 24/7/2026 | Se ha encontrado un fallo en Wavlink NU516U1 240425. El elemento afectado es la función sys_login1 del archivo /cgi-bin/login.cgi. La ejecución de una manipulación del argumento ipaddr puede llevar a una inyección de comandos del SO. El ataque puede ejecutarse de forma remota. El exploit ha sido publicado y puede ser… | |
| Analizada | Baja (2.1) | 8.5% | — | Wavlink Wl-nu516u1 Firmware | 10/5/2026 | 24/7/2026 | Una vulnerabilidad fue detectada en Wavlink NU516U1 240425. El elemento afectado es la función WifiBasic del archivo /cgi-bin/wireless.cgi. Realizar una manipulación del argumento AuthMethod/EncrypType resulta en inyección de comandos del sistema operativo. La explotación remota del ataque es posible. El exploit es… | |
| Analizada | Baja (2.1) | 8.5% | — | Wavlink Wl-nu516u1 Firmware | 10/5/2026 | 24/7/2026 | Se ha detectado una vulnerabilidad de seguridad en Wavlink NU516U1 240425. Afectada está la función advance del archivo /cgi-bin/wireless.cgi. Tal manipulación del argumento wlan_conf/Channel/skiplist/ieee_80211h conduce a inyección de comandos de SO. El ataque puede lanzarse remotamente. El exploit ha sido divulgado… | |
| Analizada | Baja (2.1) | 8.5% | — | Wavlink Wl-nu516u1 Firmware | 10/5/2026 | 24/7/2026 | Se ha identificado una debilidad en Wavlink NU516U1 240425. Este problema afecta a la función wzdapMesh del archivo /cgi-bin/adm.cgi. Esta manipulación causa inyección de comandos del sistema operativo. El ataque puede iniciarse de forma remota. El exploit se ha hecho público y podría usarse para ataques. Se contactó… | |
| Analizada | Baja (2.1) | 8.5% | — | Wavlink Wl-nu516u1 Firmware | 9/5/2026 | 24/7/2026 | Se ha descubierto una falla de seguridad en Wavlink NU516U1 M16U1_V240425. Esta vulnerabilidad afecta la función wzdap del archivo /cgi-bin/adm.cgi. Realizar una manipulación del argumento EncrypType/wl_Pass, que es pasado directamente por el atacante/por lo que podemos controlar el EncrypType/wl_Pass, resulta en… | |
| Analizada | Baja (2.1) | 8.5% | — | Wavlink Wl-nu516u1 Firmware | 9/5/2026 | 24/7/2026 | Una vulnerabilidad fue identificada en Wavlink NU516U1 M16U1_V240425. Esto afecta la función wifi_region del archivo /cgi-bin/adm.cgi. Dicha manipulación del argumento skiplist1/skiplist2 conduce a inyección de comandos del sistema operativo. El ataque puede ser lanzado de forma remota. El exploit está disponible… | |
| Analizada | Baja (2.1) | 8.5% | — | Wavlink Wl-nu516u1 Firmware | 9/5/2026 | 24/7/2026 | Se determinó una vulnerabilidad en Wavlink NU516U1 M16U1_V240425. Afectada por este problema es la función wan del archivo /cgi-bin/adm.cgi. Esta manipulación del argumento ppp_username/ppp_passwd/rwan_ip/rwan_mask/rwan_gateway es directamente pasada por el atacante/por lo que podemos controlar el… |