Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2767▼ 5 respecto a la semana anterior
Críticas / altas1280▼ 248 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)240▲ 207 respecto a la semana anterior
–

1843 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)1.9%—Dlink Dir-825/ee FirmwareDlink Dir-825/ac Firmware29/3/202317/6/2026
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-825 1.0.9/EE routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the Generic plugin for the xupnpd service, which listens on TCP port 4044. The issue…
ModificadaAlta (8.8)0.95%—Dlink Dir-825/ee FirmwareDlink Dir-825/ac Firmware29/3/202317/6/2026
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-825 1.0.9/EE routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the YouTube plugin for the xupnpd service, which listens on TCP port 4044. The issue…
ModificadaMedia (6.8)1.1%—Dlink Dir-1935 Firmware29/3/202317/6/2026
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the handling of…
ModificadaMedia (6.8)1.1%—Dlink Dir-1935 Firmware29/3/202317/6/2026
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the handling of…
ModificadaMedia (6.8)1.1%—Dlink Dir-1935 Firmware29/3/202317/6/2026
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the handling of…
ModificadaAlta (8.8)0.99%—Dlink Dir-1935 Firmware29/3/202317/6/2026
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of http requests to the web management portal. When parsing the SOAPAction…
ModificadaMedia (6.8)1.1%—Dlink Dir-1935 Firmware29/3/202317/6/2026
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the handling of…
ModificadaMedia (6.8)0.86%—Dlink Dir-1935 Firmware29/3/202317/6/2026
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the handling of…
ModificadaMedia (6.8)1.1%—Dlink Dir-1935 Firmware29/3/202317/6/2026
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the handling of…
ModificadaMedia (6.8)1.1%—Dlink Dir-1935 Firmware29/3/202317/6/2026
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the handling of…
ModificadaMedia (6.8)1.1%—Dlink Dir-1935 Firmware29/3/202317/6/2026
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the handling of…
ModificadaMedia (6.8)1.1%—Dlink Dir-1935 Firmware29/3/202317/6/2026
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the handling of…
ModificadaMedia (6.8)1.1%—Dlink Dir-1935 Firmware29/3/202317/6/2026
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the handling of…
ModificadaAlta (8.8)0.99%—Dlink Dir-1935 Firmware29/3/202317/6/2026
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of Login requests to the web management portal. When parsing the HNAP_AUTH…
ModificadaAlta (8.8)2.1%—Dlink Dir-1935 Firmware29/3/202317/6/2026
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-1935 1.03 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of HNAP login requests. The issue results from an incorrectly implemented…
ModificadaAlta (8.8)1.0%—Dlink Dir-1935 Firmware29/3/202317/6/2026
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-1935 1.03 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of HNAP login requests. The issue results from the lack of proper…
ModificadaMedia (6.8)0.80%—Dlink Dir-1935 Firmware29/3/202317/6/2026
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the handling of…
ModificadaAlta (8.8)2.0%—Dlink Dir-2150 Firmware29/3/202317/6/2026
This vulnerability allows network-adjacent attackers to execute arbitrary commands on affected installations of D-Link DIR-2150 4.0.1 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the xupnpd service, which listens on TCP port 4044 by default. The issue results…
AnalizadaAlta (7.5)1.1%—Dlink Dir-820l Firmware16/3/202317/6/2026
A stack overflow vulnerability exists in pingV4Msg component in D-Link DIR820LA1_FW105B03, allows attackers to cause a denial of service via the nextPage parameter to ping.ccp.
AnalizadaCrítica (9.8)98%⚠ Explotación activa💥 ExploitDlink Dir-820l Firmware16/3/202317/6/2026
OS Command injection vulnerability in D-Link DIR820LA1_FW105B03 allows attackers to escalate privileges to root via a crafted payload with the ping_addr parameter to ping.ccp.
AnalizadaMedia (6.5)1.0%—Dlink Dir-820l Firmware15/3/202317/6/2026
A heap overflow vulnerability in D-Link DIR820LA1_FW106B02 allows attackers to cause a denial of service via the config.log_to_syslog and log_opt_dropPackets parameters to mydlink_api.ccp.
AnalizadaCrítica (9.8)31%—Dlink Dir-820l Firmware13/3/202317/6/2026
OS Command injection vulnerability in D-Link DIR820LA1_FW105B03 allows attackers to escalate privileges to root via a crafted payload.
ModificadaCrítica (9.8)2.5%—Dlink Dir-867 Firmware13/3/202317/6/2026
OS Command injection vulnerability in D-Link DIR-867 DIR_867_FW1.30B07 allows attackers to execute arbitrary commands via a crafted LocalIPAddress parameter for the SetVirtualServerSettings to HNAP1.
ModificadaAlta (7.5)1.2%—Dlink Dir-820l Firmware13/3/202317/6/2026
A stack overflow vulnerability in D-Link DIR820LA1_FW106B02 allows attackers to cause a denial of service via the reserveDHCP_HostName_1.1.1.0 parameter to lan.asp.
ModificadaAlta (7.8)2.0%—Dlink Dwl-2600ap Firmware11/2/202317/6/2026
A command injection vulnerability in the firmware_update command, in the device's restricted telnet interface, allows an authenticated attacker to execute arbitrary commands as root.