Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2989▼ 87 respecto a la semana anterior
Críticas / altas1458▲ 97 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
56 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 33% | 💥 Exploit | Dlink Dns-320lAIDlink Dns-320lwAIDlink Dns-327lAI | 4/4/2024 | 17/6/2026 | ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability has been found in D-Link DNS-320L, DNS-320LW and DNS-327L up to 20240403 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /cgi-bin/info.cgi of the component HTTP GET Request Handler. The manipulation leads to… | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Dlink Dns-320l FirmwareDlink Dns-120 FirmwareDlink Dnr-202l FirmwareDlink Dns-315l Firmware+16 | 4/4/2024 | 17/6/2026 | ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, was found in D-Link DNS-320L, DNS-325, DNS-327L and DNS-340L up to 20240403. Affected is an unknown function of the file /cgi-bin/nas_sharing.cgi of the component HTTP GET Request Handler. The manipulation of the argument system leads… | |
| Analizada | Crítica (9.8) | 98% | ⚠ Explotación activa💥 Exploit | Dlink Dns-320l FirmwareDlink Dns-120 FirmwareDlink Dnr-202l FirmwareDlink Dns-315l Firmware+16 | 4/4/2024 | 17/6/2026 | ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as very critical, has been found in D-Link DNS-320L, DNS-325, DNS-327L and DNS-340L up to 20240403. This issue affects some unknown processing of the file /cgi-bin/nas_sharing.cgi of the component HTTP GET Request Handler. The manipulation of the… | |
| Modificada | Media (5.3) | 9.6% | — | D-link Dns-327l FirmwareD-link Dns-320l Firmware | 25/8/2017 | 17/6/2026 | The web/web_file/fb_publish.php script in D-Link DNS-320L before 1.04b12 and DNS-327L before 1.03b04 Build0119 does not authenticate requests, which allows remote attackers to obtain arbitrary photos and publish them to an arbitrary Facebook profile via a target album_id and access_token. | |
| Modificada | Crítica (9.8) | 21% | — | D-link Dns-322l FirmwareD-link Dns-320lw FirmwareD-link Dnr-326 FirmwareD-link Dns-327l Firmware+1 | 25/8/2017 | 17/6/2026 | Stack-based buffer overflow in login_mgr.cgi in D-Link firmware DNR-320L and DNS-320LW before 1.04b08, DNR-322L before 2.10 build 03, DNR-326 before 2.10 build 03, and DNS-327L before 1.04b01 allows remote attackers to execute arbitrary code by crafting malformed "Host" and "Referer" header values. | |
| Modificada | Crítica (9.8) | 15% | — | D-link Dns-322l FirmwareD-link Dns-325 FirmwareD-link Dns-345 FirmwareD-link Dns-320b Firmware+3 | 25/8/2017 | 17/6/2026 | D-Link DNS-320L firmware before 1.04b12, DNS-327L before 1.03b04 Build0119, DNR-326 1.40b03, DNS-320B 1.02b01, DNS-345 1.03b06, DNS-325 1.05b03, and DNS-322L 2.00b07 allow remote attackers to bypass authentication and log in with administrator permissions by passing the cgi_set_wto command in the cmd parameter, and… |