Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2753▼ 36 respecto a la semana anterior
Críticas / altas1269▼ 264 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)241▲ 206 respecto a la semana anterior
–

1843 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)32%💥 PoCDlink Dir-842v2 Firmware7/6/20239/7/2026
Un problema en D-Link DIR-842V2 v1.0.3 permite a los atacantes ejecutar comandos arbitrarios mediante la importación de un archivo manipulado.
ModificadaCrítica (9.8)32%—Dlink Dir-846 Firmware31/5/202317/6/2026
D-Link DIR-846 v1.00A52 was discovered to contain a remote command execution (RCE) vulnerability via the tomography_ping_address parameter in the /HNAP1 interface.
ModificadaCrítica (9.8)0.89%—Dlink Dir-300 Firmware23/5/202317/6/2026
D-Link DIR-300 firmware <=REVA1.06 and <=REVB2.06 is vulnerable to File inclusion via /model/__lang_msg.php.
ModificadaAlta (7.5)0.42%—Dell Cloudlink16/5/202317/6/2026
CloudLink 7.1.2 and all prior versions contain a broken or risky cryptographic algorithm vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability leading to some information disclosure.
ModificadaCrítica (9.8)1.2%—Dlink Dir-605l Firmware16/5/202317/6/2026
D-Link DIR-605L firmware version 1.17B01 BETA is vulnerable to stack overflow via /goform/formTcpipSetup,
ModificadaCrítica (9.8)0.90%—Dlink Dir-868l Firmware2/5/202317/6/2026
D-Link DIR-868L Hardware version A1, firmware version 1.12 is vulnerable to Buffer Overflow. The vulnerability is in scandir.sgi binary.
ModificadaAlta (7.5)1.1%—Dlink Dir-890l Firmware1/5/202317/6/2026
D-Link DIR-890L FW1.10 A1 is vulnerable to Authentication bypass.
ModificadaAlta (7.5)1.1%—Dlink Dir-879 Firmware1/5/202317/6/2026
D-Link DIR-879 v105A1 is vulnerable to Authentication Bypass via phpcgi.
ModificadaCrítica (9.8)1.2%—Dlink Dir-823g Firmware17/4/202317/6/2026
D-Link DIR823G_V1.0.2B05 was discovered to contain a stack overflow via the NewPassword parameters in SetPasswdSettings.
ModificadaAlta (7.5)7.5%💥 ExploitDlink Dir-819 Firmware16/4/202317/6/2026
On D-Link DIR-819 Firmware Version 1.06 Hardware Version A1 devices, it is possible to trigger a Denial of Service via the sys_token parameter in a cgi-bin/webproc?getpage=html/index.html request.
ModificadaAlta (8.8)3.0%💥 PoCDlink Dsl-3782 Firmware12/4/20239/7/2026
An issue found in D-Link DSL-3782 v.1.03 allows remote authenticated users to execute arbitrary code as root via the network settings page.
ModificadaCrítica (9.8)1.4%—Dlink Dir-878 Firmware9/4/202317/6/2026
D-Link DIR878 1.30B08 was discovered to contain a stack overflow in the sub_48d630 function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.
ModificadaCrítica (9.8)1.4%—Dlink Dir878 Firmware9/4/202317/6/2026
D-Link DIR878 1.30B08 was discovered to contain a stack overflow in the sub_478360 function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.
ModificadaCrítica (9.8)1.4%—Dlink Dir878 Firmware9/4/202317/6/2026
D-Link DIR878 1.30B08 was discovered to contain a stack overflow in the sub_498308 function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.
ModificadaCrítica (9.8)1.3%—Dlink Dir-878 Firmware7/4/202317/6/2026
D-Link DIR878 DIR_878_FW120B05 was discovered to contain a stack overflow in the sub_495220 function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.
ModificadaCrítica (9.8)1.1%—Dlink Dir-878 Firmware7/4/202317/6/2026
D-Link DIR878 DIR_878_FW120B05 was discovered to contain a stack overflow in the sub_48AF78 function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.
ModificadaCrítica (9.8)1.1%—Dlink Dir-878 Firmware7/4/202317/6/2026
Se ha descubierto que D-Link DIR878 DIR_878_FW120B05 contiene un desbordamiento de pila en la función sub_475FB0. Esta vulnerabilidad permite a los atacantes ocasionar una denegación de servicio (DoS) o ejecutar código arbitrario mediante unos parámetros manipulados.
ModificadaCrítica (9.8)1.4%—Dlink Dir-882 A1 Firmware7/4/202317/6/2026
D-Link DIR882 DIR882A1_FW110B02 was discovered to contain a stack overflow in the sub_48AC20 function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.
ModificadaCrítica (9.8)3.4%—Dlink Go-rt-ac750 Firmware1/4/202317/6/2026
D-Link Go-RT-AC750 revA_v101b03 was discovered to contain a command injection vulnerability via the service parameter at soapcgi.main.
ModificadaAlta (7.5)0.91%—Dlink Dir-882 Firmware31/3/202317/6/2026
An information disclosure vulnerability exists in the Syslog functionality of D-LINK DIR-882 1.30. A specially crafted network request can lead to the disclosure of sensitive information.
ModificadaAlta (8.8)0.91%—Dlink Dir-3040 Firmware29/3/202317/6/2026
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-3040 1.20B03 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the MiniDLNA service. The issue results from the lack of proper validation of the…
ModificadaAlta (8.8)0.95%—Dlink Dir-825/ee FirmwareDlink Dir-825/ac Firmware29/3/202317/6/2026
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-825 1.0.9/EE routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the xupnpd service, which listens on TCP port 4044. The issue results from the lack…
ModificadaAlta (8.8)0.95%—Dlink Dir-825/ee FirmwareDlink Dir-825/ac Firmware29/3/202317/6/2026
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-825 1.0.9/EE routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the Vimeo plugin for the xupnpd service, which listens on TCP port 4044. The issue…
ModificadaAlta (8.8)0.95%—Dlink Dir-825/ee FirmwareDlink Dir-825/ac Firmware29/3/202317/6/2026
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-825 1.0.9/EE routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the IVI plugin for the xupnpd service, which listens on TCP port 4044. The issue…
ModificadaAlta (8.8)0.95%—Dlink Dir-825/ee FirmwareDlink Dir-825/ac Firmware29/3/202317/6/2026
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-825 1.0.9/EE routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the Dreambox plugin for the xupnpd service, which listens on TCP port 4044. The…