Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2767▼ 5 respecto a la semana anterior
Críticas / altas1280▼ 248 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)240▲ 207 respecto a la semana anterior
1843 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 1.9% | — | Dlink Dir-825/ee FirmwareDlink Dir-825/ac Firmware | 29/3/2023 | 17/6/2026 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-825 1.0.9/EE routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the Generic plugin for the xupnpd service, which listens on TCP port 4044. The issue… | |
| Modificada | Alta (8.8) | 0.95% | — | Dlink Dir-825/ee FirmwareDlink Dir-825/ac Firmware | 29/3/2023 | 17/6/2026 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-825 1.0.9/EE routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the YouTube plugin for the xupnpd service, which listens on TCP port 4044. The issue… | |
| Modificada | Media (6.8) | 1.1% | — | Dlink Dir-1935 Firmware | 29/3/2023 | 17/6/2026 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the handling of… | |
| Modificada | Media (6.8) | 1.1% | — | Dlink Dir-1935 Firmware | 29/3/2023 | 17/6/2026 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the handling of… | |
| Modificada | Media (6.8) | 1.1% | — | Dlink Dir-1935 Firmware | 29/3/2023 | 17/6/2026 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the handling of… | |
| Modificada | Alta (8.8) | 0.99% | — | Dlink Dir-1935 Firmware | 29/3/2023 | 17/6/2026 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of http requests to the web management portal. When parsing the SOAPAction… | |
| Modificada | Media (6.8) | 1.1% | — | Dlink Dir-1935 Firmware | 29/3/2023 | 17/6/2026 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the handling of… | |
| Modificada | Media (6.8) | 0.86% | — | Dlink Dir-1935 Firmware | 29/3/2023 | 17/6/2026 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the handling of… | |
| Modificada | Media (6.8) | 1.1% | — | Dlink Dir-1935 Firmware | 29/3/2023 | 17/6/2026 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the handling of… | |
| Modificada | Media (6.8) | 1.1% | — | Dlink Dir-1935 Firmware | 29/3/2023 | 17/6/2026 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the handling of… | |
| Modificada | Media (6.8) | 1.1% | — | Dlink Dir-1935 Firmware | 29/3/2023 | 17/6/2026 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the handling of… | |
| Modificada | Media (6.8) | 1.1% | — | Dlink Dir-1935 Firmware | 29/3/2023 | 17/6/2026 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the handling of… | |
| Modificada | Media (6.8) | 1.1% | — | Dlink Dir-1935 Firmware | 29/3/2023 | 17/6/2026 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the handling of… | |
| Modificada | Alta (8.8) | 0.99% | — | Dlink Dir-1935 Firmware | 29/3/2023 | 17/6/2026 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of Login requests to the web management portal. When parsing the HNAP_AUTH… | |
| Modificada | Alta (8.8) | 2.1% | — | Dlink Dir-1935 Firmware | 29/3/2023 | 17/6/2026 | This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-1935 1.03 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of HNAP login requests. The issue results from an incorrectly implemented… | |
| Modificada | Alta (8.8) | 1.0% | — | Dlink Dir-1935 Firmware | 29/3/2023 | 17/6/2026 | This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-1935 1.03 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of HNAP login requests. The issue results from the lack of proper… | |
| Modificada | Media (6.8) | 0.80% | — | Dlink Dir-1935 Firmware | 29/3/2023 | 17/6/2026 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the handling of… | |
| Modificada | Alta (8.8) | 2.0% | — | Dlink Dir-2150 Firmware | 29/3/2023 | 17/6/2026 | This vulnerability allows network-adjacent attackers to execute arbitrary commands on affected installations of D-Link DIR-2150 4.0.1 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the xupnpd service, which listens on TCP port 4044 by default. The issue results… | |
| Analizada | Alta (7.5) | 1.1% | — | Dlink Dir-820l Firmware | 16/3/2023 | 17/6/2026 | A stack overflow vulnerability exists in pingV4Msg component in D-Link DIR820LA1_FW105B03, allows attackers to cause a denial of service via the nextPage parameter to ping.ccp. | |
| Analizada | Crítica (9.8) | 98% | ⚠ Explotación activa💥 Exploit | Dlink Dir-820l Firmware | 16/3/2023 | 17/6/2026 | OS Command injection vulnerability in D-Link DIR820LA1_FW105B03 allows attackers to escalate privileges to root via a crafted payload with the ping_addr parameter to ping.ccp. | |
| Analizada | Media (6.5) | 1.0% | — | Dlink Dir-820l Firmware | 15/3/2023 | 17/6/2026 | A heap overflow vulnerability in D-Link DIR820LA1_FW106B02 allows attackers to cause a denial of service via the config.log_to_syslog and log_opt_dropPackets parameters to mydlink_api.ccp. | |
| Analizada | Crítica (9.8) | 31% | — | Dlink Dir-820l Firmware | 13/3/2023 | 17/6/2026 | OS Command injection vulnerability in D-Link DIR820LA1_FW105B03 allows attackers to escalate privileges to root via a crafted payload. | |
| Modificada | Crítica (9.8) | 2.5% | — | Dlink Dir-867 Firmware | 13/3/2023 | 17/6/2026 | OS Command injection vulnerability in D-Link DIR-867 DIR_867_FW1.30B07 allows attackers to execute arbitrary commands via a crafted LocalIPAddress parameter for the SetVirtualServerSettings to HNAP1. | |
| Modificada | Alta (7.5) | 1.2% | — | Dlink Dir-820l Firmware | 13/3/2023 | 17/6/2026 | A stack overflow vulnerability in D-Link DIR820LA1_FW106B02 allows attackers to cause a denial of service via the reserveDHCP_HostName_1.1.1.0 parameter to lan.asp. | |
| Modificada | Alta (7.8) | 2.0% | — | Dlink Dwl-2600ap Firmware | 11/2/2023 | 17/6/2026 | A command injection vulnerability in the firmware_update command, in the device's restricted telnet interface, allows an authenticated attacker to execute arbitrary commands as root. |