Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2753▼ 36 respecto a la semana anterior
Críticas / altas1269▼ 264 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)241▲ 206 respecto a la semana anterior
1843 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 32% | 💥 PoC | Dlink Dir-842v2 Firmware | 7/6/2023 | 9/7/2026 | Un problema en D-Link DIR-842V2 v1.0.3 permite a los atacantes ejecutar comandos arbitrarios mediante la importación de un archivo manipulado. | |
| Modificada | Crítica (9.8) | 32% | — | Dlink Dir-846 Firmware | 31/5/2023 | 17/6/2026 | D-Link DIR-846 v1.00A52 was discovered to contain a remote command execution (RCE) vulnerability via the tomography_ping_address parameter in the /HNAP1 interface. | |
| Modificada | Crítica (9.8) | 0.89% | — | Dlink Dir-300 Firmware | 23/5/2023 | 17/6/2026 | D-Link DIR-300 firmware <=REVA1.06 and <=REVB2.06 is vulnerable to File inclusion via /model/__lang_msg.php. | |
| Modificada | Alta (7.5) | 0.42% | — | Dell Cloudlink | 16/5/2023 | 17/6/2026 | CloudLink 7.1.2 and all prior versions contain a broken or risky cryptographic algorithm vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability leading to some information disclosure. | |
| Modificada | Crítica (9.8) | 1.2% | — | Dlink Dir-605l Firmware | 16/5/2023 | 17/6/2026 | D-Link DIR-605L firmware version 1.17B01 BETA is vulnerable to stack overflow via /goform/formTcpipSetup, | |
| Modificada | Crítica (9.8) | 0.90% | — | Dlink Dir-868l Firmware | 2/5/2023 | 17/6/2026 | D-Link DIR-868L Hardware version A1, firmware version 1.12 is vulnerable to Buffer Overflow. The vulnerability is in scandir.sgi binary. | |
| Modificada | Alta (7.5) | 1.1% | — | Dlink Dir-890l Firmware | 1/5/2023 | 17/6/2026 | D-Link DIR-890L FW1.10 A1 is vulnerable to Authentication bypass. | |
| Modificada | Alta (7.5) | 1.1% | — | Dlink Dir-879 Firmware | 1/5/2023 | 17/6/2026 | D-Link DIR-879 v105A1 is vulnerable to Authentication Bypass via phpcgi. | |
| Modificada | Crítica (9.8) | 1.2% | — | Dlink Dir-823g Firmware | 17/4/2023 | 17/6/2026 | D-Link DIR823G_V1.0.2B05 was discovered to contain a stack overflow via the NewPassword parameters in SetPasswdSettings. | |
| Modificada | Alta (7.5) | 7.5% | 💥 Exploit | Dlink Dir-819 Firmware | 16/4/2023 | 17/6/2026 | On D-Link DIR-819 Firmware Version 1.06 Hardware Version A1 devices, it is possible to trigger a Denial of Service via the sys_token parameter in a cgi-bin/webproc?getpage=html/index.html request. | |
| Modificada | Alta (8.8) | 3.0% | 💥 PoC | Dlink Dsl-3782 Firmware | 12/4/2023 | 9/7/2026 | An issue found in D-Link DSL-3782 v.1.03 allows remote authenticated users to execute arbitrary code as root via the network settings page. | |
| Modificada | Crítica (9.8) | 1.4% | — | Dlink Dir-878 Firmware | 9/4/2023 | 17/6/2026 | D-Link DIR878 1.30B08 was discovered to contain a stack overflow in the sub_48d630 function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload. | |
| Modificada | Crítica (9.8) | 1.4% | — | Dlink Dir878 Firmware | 9/4/2023 | 17/6/2026 | D-Link DIR878 1.30B08 was discovered to contain a stack overflow in the sub_478360 function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload. | |
| Modificada | Crítica (9.8) | 1.4% | — | Dlink Dir878 Firmware | 9/4/2023 | 17/6/2026 | D-Link DIR878 1.30B08 was discovered to contain a stack overflow in the sub_498308 function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload. | |
| Modificada | Crítica (9.8) | 1.3% | — | Dlink Dir-878 Firmware | 7/4/2023 | 17/6/2026 | D-Link DIR878 DIR_878_FW120B05 was discovered to contain a stack overflow in the sub_495220 function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload. | |
| Modificada | Crítica (9.8) | 1.1% | — | Dlink Dir-878 Firmware | 7/4/2023 | 17/6/2026 | D-Link DIR878 DIR_878_FW120B05 was discovered to contain a stack overflow in the sub_48AF78 function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload. | |
| Modificada | Crítica (9.8) | 1.1% | — | Dlink Dir-878 Firmware | 7/4/2023 | 17/6/2026 | Se ha descubierto que D-Link DIR878 DIR_878_FW120B05 contiene un desbordamiento de pila en la función sub_475FB0. Esta vulnerabilidad permite a los atacantes ocasionar una denegación de servicio (DoS) o ejecutar código arbitrario mediante unos parámetros manipulados. | |
| Modificada | Crítica (9.8) | 1.4% | — | Dlink Dir-882 A1 Firmware | 7/4/2023 | 17/6/2026 | D-Link DIR882 DIR882A1_FW110B02 was discovered to contain a stack overflow in the sub_48AC20 function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload. | |
| Modificada | Crítica (9.8) | 3.4% | — | Dlink Go-rt-ac750 Firmware | 1/4/2023 | 17/6/2026 | D-Link Go-RT-AC750 revA_v101b03 was discovered to contain a command injection vulnerability via the service parameter at soapcgi.main. | |
| Modificada | Alta (7.5) | 0.91% | — | Dlink Dir-882 Firmware | 31/3/2023 | 17/6/2026 | An information disclosure vulnerability exists in the Syslog functionality of D-LINK DIR-882 1.30. A specially crafted network request can lead to the disclosure of sensitive information. | |
| Modificada | Alta (8.8) | 0.91% | — | Dlink Dir-3040 Firmware | 29/3/2023 | 17/6/2026 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-3040 1.20B03 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the MiniDLNA service. The issue results from the lack of proper validation of the… | |
| Modificada | Alta (8.8) | 0.95% | — | Dlink Dir-825/ee FirmwareDlink Dir-825/ac Firmware | 29/3/2023 | 17/6/2026 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-825 1.0.9/EE routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the xupnpd service, which listens on TCP port 4044. The issue results from the lack… | |
| Modificada | Alta (8.8) | 0.95% | — | Dlink Dir-825/ee FirmwareDlink Dir-825/ac Firmware | 29/3/2023 | 17/6/2026 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-825 1.0.9/EE routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the Vimeo plugin for the xupnpd service, which listens on TCP port 4044. The issue… | |
| Modificada | Alta (8.8) | 0.95% | — | Dlink Dir-825/ee FirmwareDlink Dir-825/ac Firmware | 29/3/2023 | 17/6/2026 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-825 1.0.9/EE routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the IVI plugin for the xupnpd service, which listens on TCP port 4044. The issue… | |
| Modificada | Alta (8.8) | 0.95% | — | Dlink Dir-825/ee FirmwareDlink Dir-825/ac Firmware | 29/3/2023 | 17/6/2026 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-825 1.0.9/EE routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the Dreambox plugin for the xupnpd service, which listens on TCP port 4044. The… |