Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2674▼ 561 respecto a la semana anterior
Críticas / altas1270▼ 252 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)217▼ 222 respecto a la semana anterior
–

6789 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaBaja (2.1)8.5%—Wavlink Wl-nu516u1 Firmware9/5/202624/7/2026
Se encontró una vulnerabilidad en Wavlink NU516U1 M16U1_V240425. Afectada por esta vulnerabilidad está la función wzdrepeater del archivo /cgi-bin/adm.cgi. La manipulación del argumento wlan_bssid/sel_Automode/sel_EncrypTyp resulta en inyección de comandos del sistema operativo. Es posible lanzar el ataque de forma…
AnalizadaBaja (2.1)8.5%—Wavlink Wl-nu516u1 Firmware9/5/202624/7/2026
Se ha encontrado una vulnerabilidad en Wavlink NU516U1 M16U1_V240425. Afectada es la función change_wifi_password del archivo /cgi-bin/adm.cgi. La manipulación del argumento wl_channel/wl_Pass/EncrypType conduce a una inyección de comandos del sistema operativo. Es posible iniciar el ataque de forma remota. El exploit…
AplazadaCrítica (9.1)0.34%—LinkwardenAI9/5/202624/7/2026
Linkwarden es un gestor de marcadores colaborativo, autoalojado y de código abierto para recopilar, organizar y archivar páginas web. Antes de la versión 2.13.0, una vulnerabilidad de falsificación de petición del lado del servidor (SSRF) en la función fetchTitleAndHeaders permite a los usuarios autenticados realizar…
AplazadaAlta (8.8)0.55%—LinkwardenAI9/5/202624/7/2026
Linkwarden es un gestor de marcadores colaborativo, autohospedado y de código abierto para recopilar, organizar y archivar páginas web. En las versiones 2.14.0 y anteriores, el endpoint de carga de archivos (POST /API/v1/archives/[linkId]?format=4) acepta archivos HTML (text/html) sin sanear el contenido JavaScript.…
AplazadaAlta (7.2)0.51%—Flamescorpion Auto Affiliate LinksAI8/5/202617/6/2026
The Auto Affiliate Links plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.8.8 This is due to insufficient input sanitization on the 'url' POST parameter in the aal_url_stats_save_action() function and a complete absence of output escaping in aal_display_clicks(),…
AplazadaAlta (7.4)0.79%—Totolink X5000rAI8/5/202617/6/2026
A vulnerability has been found in Totolink X5000R 9.1.0u.6369_B20230113. This vulnerability affects the function sub_458E40 of the file /boafrm/formDdns. The manipulation of the argument submit-url leads to buffer overflow. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and…
Pendiente de análisisMedia (6.8)0.13%—Medtronic Mycarelinkpatient MonitorAI7/5/202617/6/2026
Medtronic MyCareLink Patient Monitor uses per-product credentials that are stored in a recoverable format. An attacker can use these credentials to modify encrypted drive data.
Pendiente de análisisMedia (6.8)0.16%—Medtronic Myarelink Patient MonitorAI7/5/202617/6/2026
Medtronic MyCareLink Patient Monitor has an internal serial interface, which allows an attacker with physical access to access a login prompt via a UART terminal.​
AnalizadaAlta (7.3)1.2%—Dlink Di-8100 Firmware5/5/202624/7/2026
Se ha encontrado una vulnerabilidad en D-Link DI-8100 16.07.26A1. Esta vulnerabilidad afecta a la función sprintf del archivo /user_group.asp del componente Gestor CGI. La manipulación conduce a desbordamiento de búfer. El ataque puede iniciarse de forma remota. El exploit ha sido divulgado al público y puede ser…
AnalizadaAlta (7.3)1.2%—Dlink Di-8100 Firmware5/5/202624/7/2026
Se ha encontrado una falla en D-Link DI-8100 16.07.26A1. Esto afecta una parte desconocida del archivo /url_member.asp del componente Interfaz de Gestión Web. La ejecución de una manipulación del argumento Name puede conducir a un desbordamiento de búfer. El ataque puede lanzarse remotamente. El exploit ha sido…
AnalizadaAlta (7.4)1.2%—Dlink Di-8100 Firmware5/5/202624/7/2026
Una vulnerabilidad fue detectada en D-Link DI-8100 16.07.26A1. Afectada por este problema es la función tggl_asp del archivo /tggl.asp del componente Gestor de Solicitudes HTTP. Realizar una manipulación del argumento Name resulta en desbordamiento de búfer. El ataque puede ser iniciado remotamente. El exploit es…
AnalizadaAlta (8.9)1.9%—Dlink Di-8100 Firmware5/5/202624/7/2026
Se ha detectado una vulnerabilidad de seguridad en D-Link DI-8100 16.07.26A1. Afectada por esta vulnerabilidad es la función url_rule_asp del archivo /url_rule.asp del componente Gestor de Parámetros POST. Dicha manipulación conduce a desbordamiento de búfer. Es posible lanzar el ataque de forma remota. El exploit ha…
AnalizadaAlta (8.9)1.9%—Dlink Di-8100 Firmware5/5/202624/7/2026
Se ha identificado una debilidad en D-Link DI-8100 16.07.26A1. Afecta a la función sprintf del archivo /auto_reboot.asp del componente HTTP Gestor. Esta manipulación del argumento enable/time causa desbordamiento de búfer. Es posible iniciar el ataque de forma remota. El exploit se ha puesto a disposición del público…
AnalizadaAlta (7.3)1.2%—Dlink Di-8100 Firmware5/5/202620/7/2026
Una vulnerabilidad fue identificada en D-Link DI-8100 16.07.26A1. Esto afecta la función sprintf del archivo yyxz.asp. La manipulación del argumento ID conduce a un desbordamiento de búfer basado en pila. El ataque puede ser llevado a cabo remotamente. El exploit está disponible públicamente y podría ser utilizado.
AplazadaAlta (8.9)3.3%—Totolink A8000ruAI5/5/202617/6/2026
A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. Affected is the function setAppFilterCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument enable results in os command injection. The attack may be launched remotely. The exploit has been released to the public and may be…
AplazadaAlta (8.3)0.57%—Tp-link Wdr201aAI4/5/202617/6/2026
WDR201A WiFi Extender (HW V2.1, FW LFMZX28040922V1.02) contains a stack-based buffer overflow vulnerability in the firewall.cgi and makeRequest.cgi binaries that allows unauthenticated attackers to overwrite the saved return address by sending a POST request with a Content-Length header exceeding 512 bytes. Attackers…
AplazadaCrítica (9.3)1.9%—Tp-link Wdr201aAI4/5/202617/6/2026
WDR201A WiFi Extender (HW V2.1, FW LFMZX28040922V1.02) contains an OS command injection vulnerability in the firewall.cgi binary across five request handlers that apply insufficient input validation. Attackers can inject arbitrary shell commands through vulnerable parameters like websURLFilter, websHostFilter,…
AplazadaCrítica (9.3)4.1%—Tp-link Wdr201aAI4/5/202617/6/2026
WDR201A WiFi Extender (HW V2.1, FW LFMZX28040922V1.02) contains an OS command injection vulnerability in the adm.cgi binary's reboot_time function that allows unauthenticated remote attackers to execute arbitrary shell commands by injecting malicious input into the reboot_time POST parameter. Attackers can send a…
AplazadaCrítica (9.3)3.3%—Tp-link Wdr201aAI4/5/202617/6/2026
WDR201A WiFi Extender (HW V2.1, FW LFMZX28040922V1.02) contains an OS command injection vulnerability in the makeRequest.cgi binary that allows unauthenticated remote attackers to execute arbitrary shell commands by injecting malicious input into the set_time or StartSniffer functions. Attackers can craft a POST…
AplazadaCrítica (9.3)3.2%—Dlink Wdr201aAI4/5/202617/6/2026
WDR201A WiFi Extender (HW V2.1, FW LFMZX28040922V1.02) contains an OS command injection vulnerability in the internet.cgi binary that allows unauthenticated remote attackers to execute arbitrary shell commands by injecting malicious input into the gateway POST parameter. Attackers can exploit unsanitized parameter…
AplazadaCrítica (9.3)6.7%—Dlink Wdr201aAI4/5/202617/6/2026
WDR201A WiFi Extender (HW V2.1, FW LFMZX28040922V1.02) contains an OS command injection vulnerability in the wireless.cgi binary that allows unauthenticated remote attackers to execute arbitrary shell commands by injecting malicious input into the sz11gChannel or PIN POST parameters. Attackers can exploit unsanitized…
AnalizadaCrítica (9.8)0.85%—Dlink Dir-456u Firmware4/5/202617/6/2026
D-Link DIR-456U Hardware Revision A1 (End-of-Life, EOL) contains a hardcoded telnet backdoor. The device starts a telnet daemon at boot via /etc/init0.d/S80telnetd.sh with the username "Alphanetworks" and the static password "whdrv01_dlob_dir456U" read from /etc/config/image_sign. The custom telnetd binary accepts a…
AnalizadaAlta (8.8)0.98%—Dlink Dir-600l Firmware4/5/202617/6/2026
D-Link DIR-600L Hardware Revision A1 (End-of-Life) contains a hardcoded telnet backdoor. The device starts a telnet daemon at boot via /bin/telnetd.sh with the username "Alphanetworks" and the static password "wrgn35_dlwbr_dir600l" read from /etc/alpha_config/image_sign. The custom telnetd binary accepts a -u…
AnalizadaAlta (8.8)0.98%—Dlink Dir-600l Firmware4/5/202617/6/2026
D-Link DIR-600L Hardware Revision B1 (End-of-Life) contains a hardcoded telnet backdoor. The device starts a telnet daemon at boot via /bin/telnetd.sh with the username "Alphanetworks" and the static password "wrgn61_dlwbr_dir600L" read from /etc/alpha_config/image_sign. The custom telnetd binary accepts a -u…
AnalizadaAlta (8.8)0.98%—Dlink Dir-605l Firmware4/5/202617/6/2026
D-Link DIR-605L Hardware Revision B2 (End-of-Life, EOL) contains a hardcoded telnet backdoor. The device starts a telnet daemon at boot via /bin/telnetd.sh with the username "Alphanetworks" and the static password "wrgn76_dlwbr_dir605L" read from /etc/alpha_config/image_sign. The custom telnetd binary accepts a -u…