Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
1843 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.4) | 1.2% | — | Dlink Dir-825m Firmware | 28/4/2026 | 17/6/2026 | A vulnerability was found in D-Link DIR-825M 1.1.12. This issue affects the function sub_414BA8 of the file /boafrm/formWanConfigSetup. The manipulation of the argument submit-url results in buffer overflow. The attack can be executed remotely. The exploit has been made public and could be used. | |
| Analizada | Alta (7.4) | 1.2% | — | Dlink Dir-825m Firmware | 28/4/2026 | 17/6/2026 | A vulnerability has been found in D-Link DIR-825M 1.1.12. This vulnerability affects the function sub_4151FC of the file /boafrm/formVpnConfigSetup. The manipulation of the argument submit-url leads to buffer overflow. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may… | |
| Analizada | Alta (8.9) | 3.8% | — | Dlink Di-8100 Firmware | 28/4/2026 | 17/6/2026 | A vulnerability was found in D-Link DI-8100 16.07.26A1. This affects the function tgfile_htm of the file tgfile.htm of the component CGI Endpoint. The manipulation of the argument fn results in buffer overflow. The attack can be executed remotely. The exploit has been made public and could be used. | |
| Analizada | Alta (7.3) | 1.2% | — | Dlink Di-8100 Firmware | 28/4/2026 | 17/6/2026 | A vulnerability has been found in D-Link DI-8100 16.07.26A1. Affected by this issue is the function file_exten_asp of the file file_exten.asp of the component File Extension Handler. The manipulation of the argument Name leads to buffer overflow. Remote exploitation of the attack is possible. The exploit has been… | |
| Analizada | Alta (7.3) | 0.74% | — | Dlink Dir-825 Firmware | 27/4/2026 | 17/6/2026 | A security flaw has been discovered in D-Link DIR-825 up to 3.00b32. This impacts the function AddPortMapping of the file upnpsoap.c of the component miniupnpd. Performing a manipulation of the argument NewPortMappingDescription results in buffer overflow. The attack needs to be approached within the local network.… | |
| Analizada | Alta (7.4) | 1.1% | — | Dlink Dir-825 Firmware | 27/4/2026 | 17/6/2026 | A vulnerability was identified in D-Link DIR-825 3.00b32. This affects the function NMBD_process of the file sserver.c of the component nmbd. Such manipulation leads to buffer overflow. The attack can only be initiated within the local network. The exploit is publicly available and might be used. This vulnerability… | |
| Analizada | Media (5.5) | 3.5% | — | Dlink Dir-822 Firmware | 27/4/2026 | 17/6/2026 | A vulnerability was determined in D-Link DIR-822 A_101. The impacted element is the function system of the file /udhcpcd/dhcpd.c of the component udhcpd DHCP Service. This manipulation of the argument Hostname causes command injection. The attack can be initiated remotely. The exploit has been publicly disclosed and… | |
| Analizada | Baja (1.9) | 0.80% | — | Dlink Dsl-2740r Firmware | 26/4/2026 | 17/6/2026 | A vulnerability was identified in D-Link DSL-2740R EU_01.15. Impacted is an unknown function of the component Wireless Setup Section. Such manipulation of the argument Wireless Network Name leads to cross site scripting. The attack can be executed remotely. The exploit is publicly available and might be used. | |
| Analizada | Media (5.4) | 1.3% | — | Dlink Dgs-3420-28tc Firmware | 26/4/2026 | 17/6/2026 | A vulnerability was determined in D-Link DGS-3420 1.50.018. This issue affects some unknown processing of the component System Information Settings Page. This manipulation of the argument System Name causes cross site scripting. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and… | |
| Aplazada | Alta (8.7) | 0.54% | — | Dlink Dwm-222wAI | 24/4/2026 | 17/6/2026 | DWM-222W USB Wi-Fi Adapter developed by D-Link has a Brute-Force Protection Bypass vulnerability, allowing unauthenticated adjacent network attackers to bypass login attempt limits to perform brute-force attacks to gain control over the device. | |
| Analizada | Alta (7.4) | 1.2% | — | Dlink Dir-513 Firmware | 10/4/2026 | 17/6/2026 | A flaw has been found in D-Link DIR-513 1.10. This issue affects the function formAdvanceSetup of the file /goform/formAdvanceSetup of the component POST Request Handler. This manipulation of the argument webpage causes buffer overflow. It is possible to initiate the attack remotely. The exploit has been published and… | |
| Analizada | Alta (7.4) | 1.2% | — | Dlink Dir-513 Firmware | 10/4/2026 | 17/6/2026 | A vulnerability was detected in D-Link DIR-513 1.10. This vulnerability affects the function formSetRoute of the file /goform/formSetRoute of the component POST Request Handler. The manipulation of the argument curTime results in buffer overflow. The attack may be performed from remote. The exploit is now public and… | |
| Analizada | Alta (7.4) | 1.2% | — | Dlink Dir-513 Firmware | 10/4/2026 | 17/6/2026 | A security vulnerability has been detected in D-Link DIR-513 1.10. This affects the function formSetPassword of the file /goform/formSetPassword of the component POST Request Handler. The manipulation of the argument curTime leads to buffer overflow. The attack is possible to be carried out remotely. The exploit has… | |
| Analizada | Alta (7.4) | 1.2% | — | Dlink Dir-605l Firmware | 9/4/2026 | 17/6/2026 | A vulnerability was identified in D-Link DIR-605L 2.13B01. Impacted is the function formSetLog of the file /goform/formSetLog of the component POST Request Handler. The manipulation of the argument curTime leads to buffer overflow. The attack is possible to be carried out remotely. The exploit is publicly available… | |
| Analizada | Alta (7.4) | 1.2% | — | Dlink Dir-605l Firmware | 9/4/2026 | 17/6/2026 | A vulnerability was determined in D-Link DIR-605L 2.13B01. This issue affects the function formSetDDNS of the file /goform/formSetDDNS of the component POST Request Handler. Executing a manipulation of the argument curTime can lead to buffer overflow. The attack can be executed remotely. The exploit has been publicly… | |
| Analizada | Alta (7.4) | 1.2% | — | Dlink Dir-605l Firmware | 9/4/2026 | 17/6/2026 | A vulnerability was found in D-Link DIR-605L 2.13B01. This vulnerability affects the function formAdvNetwork of the file /goform/formAdvNetwork of the component POST Request Handler. Performing a manipulation of the argument curTime results in buffer overflow. Remote exploitation of the attack is possible. The exploit… | |
| Analizada | Alta (7.4) | 1.2% | — | Dlink Dir-605l Firmware | 9/4/2026 | 17/6/2026 | A vulnerability has been found in D-Link DIR-605L 2.13B01. This affects the function formAdvFirewall of the file /goform/formAdvFirewall of the component POST Request Handler. Such manipulation of the argument curTime leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the… | |
| Analizada | Alta (7.4) | 1.2% | — | Dlink Dir-605l Firmware | 9/4/2026 | 17/6/2026 | A flaw has been found in D-Link DIR-605L 2.13B01. Affected by this issue is the function formSetMACFilter of the file /goform/formSetMACFilter of the component POST Request Handler. This manipulation of the argument curTime causes buffer overflow. The attack may be initiated remotely. The exploit has been published… | |
| Analizada | Alta (7.4) | 1.2% | — | Dlink Dir-605l Firmware | 9/4/2026 | 17/6/2026 | A vulnerability was detected in D-Link DIR-605L 2.13B01. Affected by this vulnerability is the function formVirtualServ of the file /goform/formVirtualServ of the component POST Request Handler. The manipulation of the argument curTime results in buffer overflow. The attack can be launched remotely. The exploit is now… | |
| Analizada | Alta (7.3) | 6.2% | — | Dlink Dir-882 Firmware | 9/4/2026 | 17/6/2026 | A vulnerability was found in D-Link DIR-882 1.01B02. Impacted is the function sprintf of the file prog.cgi of the component HNAP1 SetNetworkSettings Handler. The manipulation of the argument IPAddress results in os command injection. The attack may be performed from remote. The exploit has been made public and could… | |
| Aplazada | Alta (7.4) | 0.91% | — | Dlink Dir-645AI | 9/4/2026 | 24/7/2026 | A vulnerability was detected in D-Link DIR-645 1.01/1.02/1.03. Impacted is the function hedwigcgi_main of the file /cgi-bin/hedwig.cgi. The manipulation results in stack-based buffer overflow. The attack can be launched remotely. The exploit is now public and may be used. This vulnerability only affects products that… | |
| Analizada | Alta (7.5) | 0.41% | — | Dlink Di-8003 Firmware | 8/4/2026 | 25/7/2026 | A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the http_lanport parameter in the /webgl.asp endpoint. | |
| Analizada | Alta (7.5) | 0.41% | — | Dlink Di-8003 Firmware | 8/4/2026 | 25/7/2026 | A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of parameters in the /yyxz_dlink.asp endpoint. | |
| Analizada | Alta (7.5) | 0.49% | — | Dlink Di-8003 Firmware | 8/4/2026 | 25/7/2026 | A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of parameters in the /xwgl_ref.asp endpoint. An attacker can exploit this vulnerability by sending a crafted HTTP GET request with excessively long strings in parameters name, en, user_id, shibie_name, time, act, log, and rpri. | |
| Analizada | Alta (7.5) | 0.49% | — | Dlink Di-8003 Firmware | 8/4/2026 | 25/7/2026 | A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of parameters in the /xwgl_bwr.asp endpoint. An attacker can exploit this vulnerability by sending a crafted HTTP GET request in the name, qq, and time parameters. |