Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2989▼ 87 respecto a la semana anterior
Críticas / altas1458▲ 97 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

56 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.3)33%💥 ExploitDlink Dns-320lAIDlink Dns-320lwAIDlink Dns-327lAI4/4/202417/6/2026
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability has been found in D-Link DNS-320L, DNS-320LW and DNS-327L up to 20240403 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /cgi-bin/info.cgi of the component HTTP GET Request Handler. The manipulation leads to…
AnalizadaCrítica (9.8)100%⚠ Explotación activa💥 ExploitDlink Dns-320l FirmwareDlink Dns-120 FirmwareDlink Dnr-202l FirmwareDlink Dns-315l Firmware+164/4/202417/6/2026
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, was found in D-Link DNS-320L, DNS-325, DNS-327L and DNS-340L up to 20240403. Affected is an unknown function of the file /cgi-bin/nas_sharing.cgi of the component HTTP GET Request Handler. The manipulation of the argument system leads…
AnalizadaCrítica (9.8)98%⚠ Explotación activa💥 ExploitDlink Dns-320l FirmwareDlink Dns-120 FirmwareDlink Dnr-202l FirmwareDlink Dns-315l Firmware+164/4/202417/6/2026
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as very critical, has been found in D-Link DNS-320L, DNS-325, DNS-327L and DNS-340L up to 20240403. This issue affects some unknown processing of the file /cgi-bin/nas_sharing.cgi of the component HTTP GET Request Handler. The manipulation of the…
ModificadaMedia (5.3)9.6%—D-link Dns-327l FirmwareD-link Dns-320l Firmware25/8/201717/6/2026
The web/web_file/fb_publish.php script in D-Link DNS-320L before 1.04b12 and DNS-327L before 1.03b04 Build0119 does not authenticate requests, which allows remote attackers to obtain arbitrary photos and publish them to an arbitrary Facebook profile via a target album_id and access_token.
ModificadaCrítica (9.8)21%—D-link Dns-322l FirmwareD-link Dns-320lw FirmwareD-link Dnr-326 FirmwareD-link Dns-327l Firmware+125/8/201717/6/2026
Stack-based buffer overflow in login_mgr.cgi in D-Link firmware DNR-320L and DNS-320LW before 1.04b08, DNR-322L before 2.10 build 03, DNR-326 before 2.10 build 03, and DNS-327L before 1.04b01 allows remote attackers to execute arbitrary code by crafting malformed "Host" and "Referer" header values.
ModificadaCrítica (9.8)15%—D-link Dns-322l FirmwareD-link Dns-325 FirmwareD-link Dns-345 FirmwareD-link Dns-320b Firmware+325/8/201717/6/2026
D-Link DNS-320L firmware before 1.04b12, DNS-327L before 1.03b04 Build0119, DNR-326 1.40b03, DNS-320B 1.02b01, DNS-345 1.03b06, DNS-325 1.05b03, and DNS-322L 2.00b07 allow remote attackers to bypass authentication and log in with administrator permissions by passing the cgi_set_wto command in the cmd parameter, and…
Orbitaley — Vulnerabilidades