Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 321 respecto a la semana anterior
Críticas / altas1271▼ 203 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 108 respecto a la semana anterior
–

26.302 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.4)1.2%—Dlink Dir-513 Firmware10/4/202617/6/2026
A vulnerability was detected in D-Link DIR-513 1.10. This vulnerability affects the function formSetRoute of the file /goform/formSetRoute of the component POST Request Handler. The manipulation of the argument curTime results in buffer overflow. The attack may be performed from remote. The exploit is now public and…
AnalizadaAlta (7.4)1.2%—Dlink Dir-513 Firmware10/4/202617/6/2026
A security vulnerability has been detected in D-Link DIR-513 1.10. This affects the function formSetPassword of the file /goform/formSetPassword of the component POST Request Handler. The manipulation of the argument curTime leads to buffer overflow. The attack is possible to be carried out remotely. The exploit has…
AnalizadaAlta (7.4)0.95%—Tenda F451 Firmware10/4/202617/6/2026
A vulnerability was determined in Tenda F451 1.0.0.7. This affects the function fromP2pListFilter of the file /goform/P2pListFilter. This manipulation of the argument page causes stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized.
AnalizadaAlta (7.4)0.95%—Tenda F451 Firmware10/4/202617/6/2026
A vulnerability was found in Tenda F451 1.0.0.7. Affected by this issue is the function formWrlExtraSet of the file /goform/WrlExtraSet. The manipulation of the argument GO results in stack-based buffer overflow. The attack may be launched remotely. The exploit has been made public and could be used.
AnalizadaAlta (7.4)0.95%—Tenda F451 Firmware10/4/202617/6/2026
A vulnerability has been found in Tenda F451 1.0.0.7. Affected by this vulnerability is the function fromSafeEmailFilter of the file /goform/SafeEmailFilter. The manipulation of the argument page leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public…
AnalizadaAlta (7.4)0.95%—Tenda F451 Firmware10/4/202617/6/2026
A flaw has been found in Tenda F451 1.0.0.7. Affected is the function fromRouteStatic of the file /goform/RouteStatic. Executing a manipulation of the argument page can lead to stack-based buffer overflow. The attack can be launched remotely. The exploit has been published and may be used.
AnalizadaAlta (7.4)0.95%—Tenda F451 Firmware9/4/202617/6/2026
A vulnerability was detected in Tenda F451 1.0.0.7. This impacts the function formWrlsafeset of the file /goform/AdvSetWrlsafeset. Performing a manipulation of the argument mit_ssid results in stack-based buffer overflow. The attack can be initiated remotely. The exploit is now public and may be used.
AnalizadaAlta (7.4)1.2%—Dlink Dir-605l Firmware9/4/202617/6/2026
A vulnerability was identified in D-Link DIR-605L 2.13B01. Impacted is the function formSetLog of the file /goform/formSetLog of the component POST Request Handler. The manipulation of the argument curTime leads to buffer overflow. The attack is possible to be carried out remotely. The exploit is publicly available…
AnalizadaAlta (7.4)1.2%—Dlink Dir-605l Firmware9/4/202617/6/2026
A vulnerability was determined in D-Link DIR-605L 2.13B01. This issue affects the function formSetDDNS of the file /goform/formSetDDNS of the component POST Request Handler. Executing a manipulation of the argument curTime can lead to buffer overflow. The attack can be executed remotely. The exploit has been publicly…
AnalizadaAlta (7.4)1.2%—Dlink Dir-605l Firmware9/4/202617/6/2026
A vulnerability was found in D-Link DIR-605L 2.13B01. This vulnerability affects the function formAdvNetwork of the file /goform/formAdvNetwork of the component POST Request Handler. Performing a manipulation of the argument curTime results in buffer overflow. Remote exploitation of the attack is possible. The exploit…
AnalizadaAlta (7.4)1.2%—Dlink Dir-605l Firmware9/4/202617/6/2026
A vulnerability has been found in D-Link DIR-605L 2.13B01. This affects the function formAdvFirewall of the file /goform/formAdvFirewall of the component POST Request Handler. Such manipulation of the argument curTime leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the…
AnalizadaAlta (7.4)1.2%—Dlink Dir-605l Firmware9/4/202617/6/2026
A flaw has been found in D-Link DIR-605L 2.13B01. Affected by this issue is the function formSetMACFilter of the file /goform/formSetMACFilter of the component POST Request Handler. This manipulation of the argument curTime causes buffer overflow. The attack may be initiated remotely. The exploit has been published…
AnalizadaAlta (7.4)1.2%—Dlink Dir-605l Firmware9/4/202617/6/2026
A vulnerability was detected in D-Link DIR-605L 2.13B01. Affected by this vulnerability is the function formVirtualServ of the file /goform/formVirtualServ of the component POST Request Handler. The manipulation of the argument curTime results in buffer overflow. The attack can be launched remotely. The exploit is now…
AnalizadaAlta (8.7)0.43%—Openplcproject Openplc V3 Firmware9/4/202617/6/2026
OpenPLC_V3 REST API endpoint checks for JWT presence but never verifies the caller's role. Any authenticated user with role=user can delete any other user, including administrators, by specifying their user ID or they can create new accounts with role=admin, escalating to full administrator access.
AnalizadaCrítica (9.2)0.40%—Openplcproject Openplc V3 Firmware9/4/202617/6/2026
OpenPLC_V3 is vulnerable to a Plaintext Storage of a Password vulnerability that could allow an attacker to retrieve credentials and access sensitive information.
AnalizadaCrítica (9.8)1.4%—Totolink A3300r Firmware9/4/202617/6/2026
An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stun-pass parameter to /cgi-bin/cstecgi.cgi.
AnalizadaCrítica (9.2)0.67%—Openplcproject Openplc V3 Firmware9/4/202617/6/2026
OpenPLC_V3 is vulnerable to an Initialization of a Resource with an Insecure Default vulnerability which could allow an attacker to gain access to the system by bypassing authentication via an API.
AnalizadaMedia (5.5)0.78%—Tenda Ch22 Firmware9/4/202617/6/2026
A vulnerability was detected in Tenda CH22 1.0.0.6(468). This issue affects the function R7WebsSecurityHandlerfunction of the component httpd. The manipulation results in path traversal. The attack may be launched remotely. The exploit is now public and may be used.
AnalizadaAlta (7.2)0.71%—Sonicwall Sma6210 FirmwareSonicwall Sma6200 FirmwareSonicwall Sma7200 FirmwareSonicwall Sma7210 Firmware+19/4/202617/6/2026
Improper handling of Unicode encoding in SonicWall SMA1000 series appliances allows a remote authenticated SSLVPN user to bypass Workplace/Connect Tunnel TOTP authentication.
AnalizadaMedia (6.6)0.74%—Sonicwall Sma6210 FirmwareSonicwall Sma6200 FirmwareSonicwall Sma7200 FirmwareSonicwall Sma7210 Firmware+19/4/202617/6/2026
Improper handling of Unicode encoding in SonicWall SMA1000 series appliances allows a remote authenticated SSLVPN admin to bypass AMC TOTP authentication.
AnalizadaAlta (7.2)0.60%—Sonicwall Sma6210 FirmwareSonicwall Sma8200vSonicwall Sma7200 FirmwareSonicwall Sma7210 Firmware+19/4/202617/6/2026
An observable response discrepancy vulnerability in the SonicWall SMA1000 series appliances allows a remote attacker to enumerate SSL VPN user credentials.
AnalizadaAlta (7.2)0.53%💥 PoCSonicwall Sma6210 FirmwareSonicwall Sma6200 FirmwareSonicwall Sma7200 FirmwareSonicwall Sma7210 Firmware+19/4/202617/6/2026
Improper neutralization of special elements used in an SQL command (“SQL Injection”) in SonicWall SMA1000 series appliances allows a remote authenticated attacker with read-only administrator privileges to escalate privileges to primary administrator.
AnalizadaMedia (5.5)0.78%—Tenda I12 Firmware9/4/202617/6/2026
A vulnerability was determined in Tenda i12 1.0.0.11(3862). The impacted element is an unknown function of the component HTTP Handler. Executing a manipulation can lead to path traversal. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.
AnalizadaAlta (7.3)6.2%—Dlink Dir-882 Firmware9/4/202617/6/2026
A vulnerability was found in D-Link DIR-882 1.01B02. Impacted is the function sprintf of the file prog.cgi of the component HNAP1 SetNetworkSettings Handler. The manipulation of the argument IPAddress results in os command injection. The attack may be performed from remote. The exploit has been made public and could…
AnalizadaMedia (5.5)0.78%—Tenda I3 Firmware9/4/202617/6/2026
A weakness has been identified in Tenda i3 1.0.0.6(2204). The affected element is the function R7WebsSecurityHandler of the component HTTP Handler. Executing a manipulation can lead to path traversal. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks.