Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
6789 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.9) | 0.47% | — | Tp-link Omada ControllerAI | 11/9/2026 | 11/9/2026 | An information disclosure vulnerability in the SAML Single Sign-On (SSO) functionality of Omada Controller allows an authenticated user with SAML configuration privileges to access sensitive information due to insufficient validation of user-supplied SAML metadata. Successful exploitation could result in unauthorized… | |
| Aplazada | Alta (7.7) | 5.0% | — | Tp-link Deco Be11000AI | 10/9/2026 | 1/10/2026 | An OS command injection vulnerability in the TDDP module of Deco BE11000 and Deco M9 Plus allows an adjacent network attacker to execute arbitrary commands with root privileges by sending a crafted UDP packet. Successful exploitation may lead to complete device compromise, including unauthorized command execution,… | |
| Aplazada | Media (5.3) | 0.47% | — | Tp-link Archer Mr600AITp-link Tl-mr6400AI | 10/9/2026 | 11/9/2026 | A missing authentication vulnerability in the VPN configuration management has been identified in Archer MR600 (v2, v3 & v5) and TL-MR6400 v8 due to improper access control; a remote unauthenticated attacker may be able to access and modify VPN configuration information without valid credentials. Successful… | |
| Aplazada | Media (4.8) | 0.73% | — | Tp-link Archer Mr600AITp-link Tl-mr6400AI | 10/9/2026 | 11/9/2026 | An authenticated directory traversal vulnerability in file upload functionality has been identified in Archer MR600 (v2, v3 & v5) and TL-MR6400 v8. Due to insufficient validation of user-supplied file information, an authenticated remote attacker with access to the affected upload functionality could upload a… | |
| Pendiente de análisis | Alta (8.4) | 0.10% | — | NI SystemlinkAINI Systemlink ServerAI | 10/9/2026 | 16/9/2026 | There is a storage of sensitive information in cleartext vulnerability in NI SystemLink. This vulnerability may allow an attacker with local access to obtain sensitive information stored by the system in the clear. This vulnerability affects NI SystemLink and NI SystemLink Server versions prior to 2026 Q3. | |
| Pendiente de análisis | Alta (8.6) | 0.35% | — | NI SystemlinkAINI Systemlink ServerAI | 10/9/2026 | 16/9/2026 | There is an improper access control vulnerability in NI SystemLink that may allow an authenticated user with limited privileges to access host operating system files and directories that should be restricted. This vulnerability affects NI SystemLink and NI SystemLink Server versions prior to 2026 Q3. | |
| Aplazada | Crítica (9.3) | 0.37% | — | Avideo LivelinksAIWwbn AvideoAI | 10/9/2026 | 10/9/2026 | AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the LiveLinks plugin where title and description fields are stored without sanitization. A user with canStream permission can inject malicious scripts that execute in the browser of every visitor… | |
| Pendiente de análisis | Alta (8.4) | 0.16% | — | Maono LinkAI | 8/9/2026 | 14/9/2026 | Maono Link 3.8.13 MaonoAiServices Windows service allows local privilege escalation for a standard user account via improper write privileges in 'C:\ProgramData\Maono'. Fixed in 4.0.80. | |
| Aplazada | Media (6.9) | 0.67% | — | Tp-link Omada ControllerAI | 8/9/2026 | 21/9/2026 | An information disclosure vulnerability has been identified in Omada Controller. An API endpoint intended for Controller initialization remains accessible after completion and may disclose account-related information to unauthenticated remote users. Successful exploitation may allow an attacker to remote query the… | |
| Aplazada | Alta (8.6) | 0.51% | — | Dlink Dir-822aAI | 8/9/2026 | 8/9/2026 | A vulnerability has been found in D-Link DIR-822A A_101. Affected is the function tunnel_set_params of the component L2TP Control Message Parser. Such manipulation leads to out-of-bounds write. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. | |
| Aplazada | Alta (8.6) | 0.72% | — | Dlink Dir-895lAI | 8/9/2026 | 11/9/2026 | A flaw has been found in D-Link DIR-895L A1_102b07. This impacts the function sendOffer/sendACK of the file udhcpcd/serverpacket.c of the component udhcpcd. This manipulation causes stack-based buffer overflow. The attack can only be done within the local network. The exploit has been published and may be used. | |
| Aplazada | Alta (8.6) | 3.7% | — | Linksys Re7000AI | 7/9/2026 | 11/9/2026 | A vulnerability was detected in Linksys RE7000 2.0.15. This affects the function platform_event_pingTest of the file /cgi-bin/json.cgi?PingTest of the component PingTest Handler. The manipulation of the argument pingTestIp/pingTestPktSize/pingTestTimes results in os command injection. The attack can be launched… | |
| Aplazada | Alta (8.2) | 1.1% | — | Dlink Dir-605AI | 7/9/2026 | 9/9/2026 | A vulnerability was identified in D-Link DIR-605 B1v202WWB03. This issue affects the function tunnel_set_params of the file progs.gpl/pppd.alpha/l2tp/tunnel.c of the component L2TP Control Message Parser. Such manipulation of the argument peer_hostname leads to off-by-one. The attack may be performed from remote.… | |
| Aplazada | Crítica (9.3) | 1.7% | — | Dlink Dir-822aAI | 7/9/2026 | 8/9/2026 | A vulnerability was determined in D-Link DIR-822A A_101. This vulnerability affects the function strcpy of the file udhcpcd/serverpacket.c of the component udhcpcd. This manipulation causes stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may… | |
| Aplazada | Media (5.5) | 2.3% | — | Dlink Dir-895lAI | 7/9/2026 | 8/9/2026 | A vulnerability was found in D-Link DIR-895L A1_102b07. This affects the function sendACK of the file udhcpcd/serverpacket.c of the component udhcpcd. The manipulation of the argument Hostname results in command injection. The attack can be executed remotely. The exploit has been made public and could be used. | |
| Aplazada | Alta (7.1) | 0.42% | — | BlinkoAI | 4/9/2026 | 10/9/2026 | Blinko 1.8.7 contains a cross-user private note disclosure vulnerability in the noteReferenceList procedure that performs no ownership verification on supplied note identifiers. Authenticated attackers can enumerate sequential note IDs and retrieve complete content of other users' private notes including attachments… | |
| Aplazada | Alta (8.7) | 0.69% | — | BlinkoAI | 4/9/2026 | 10/9/2026 | Blinko 1.8.7 contains an authorization bypass (IDOR) vulnerability in multiple tRPC procedures (message.list, message.update, message.delete, message.clearAfter in server/routerTrpc/message.ts and conversation.clearMessages in server/routerTrpc/conversation.ts). Although these procedures require authentication, they… | |
| Aplazada | Media (6.9) | 0.55% | — | Slinkapp SlinkAI | 4/9/2026 | 23/9/2026 | Slink before 1.12.3 fails to properly authorize access to image comment endpoints, allowing unauthenticated attackers to read comment threads via GET /api/image/{imageId}/comments and server-sent-events subscriptions. Attackers who obtain image IDs out of band can retrieve full comment threads on public images and… | |
| Aplazada | Media (6.3) | 0.24% | — | Softing SmartlinkAI | 4/9/2026 | 9/9/2026 | Missing release of memory after effective lifetime vulnerability in Softing smartLink allows resource leak exposure. This issue affects smartLink HW-PN: from 1.04 before 1.10. | |
| Aplazada | Media (6.1) | 0.24% | — | Tp-link Archer Ax55AI | 3/9/2026 | 8/9/2026 | A hard-coded cryptographic key vulnerability exists in the web module of TP-Link Archer AX55 v4. A LAN attacker who captures an HTTP login session may use the known shared RSA private key to decrypt the administrator password; the weakened AES session key further reduces the effort required to compromise session… | |
| Aplazada | Alta (7.7) | 0.26% | — | Tp-link Archer Ax55AI | 3/9/2026 | 8/9/2026 | A stack-based buffer overflow vulnerability exists in the EasyMesh module of TP-Link Archer AX55 v4. When Mesh mode is enabled, a LAN attacker may submit crafted input that causes the easymesh daemon to crash and may potentially achieve remote code execution on the device. Successful exploitation may cause the… | |
| Aplazada | Alta (8.5) | 3.6% | — | Dlink Dns-320AI | 3/9/2026 | 4/9/2026 | A vulnerability was determined in D-Link DNS-320 ShareCenter 2.06B01. This affects an unknown part of the file /cgi/file_sharing.cgi of the component File Sharing. Executing a manipulation of the argument fileurl can lead to os command injection. The attack can be launched remotely. The exploit has been publicly… | |
| Aplazada | Alta (8.6) | 3.3% | — | Dlink Dns-340lAI | 3/9/2026 | 4/9/2026 | A vulnerability was found in D-Link DNS-340L 1.01B04. Affected by this issue is some unknown functionality of the file /cgi-bin/dropbox.cgi of the component CGI Handler. Performing a manipulation of the argument callback_url/sync_interval results in os command injection. The attack can be initiated remotely. The… | |
| Aplazada | Alta (8.5) | 3.6% | — | Dlink Dns-340lAI | 3/9/2026 | 4/9/2026 | A vulnerability has been found in D-Link DNS-340L 1.01B04. Affected by this vulnerability is an unknown functionality of the file /cgi-bin/addon_center.cgi of the component Add-On Center. Such manipulation of the argument f_name/f_url/f_flag/f_login_user leads to os command injection. It is possible to launch the… | |
| Aplazada | Alta (8.6) | 0.79% | — | Totolink Cp450AI | 3/9/2026 | 3/9/2026 | A vulnerability was found in TOTOLINK CP450 4.1.0. The impacted element is an unknown function of the file /cgi-bin/cstecgi.cgi. Performing a manipulation of the argument topicurl results in buffer overflow. Remote exploitation of the attack is possible. |