Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
6789 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (2.3) | 0.23% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+17 | 2/9/2026 | 15/9/2026 | A vulnerability exists in an undisclosed BIG-IP Configuration utility page that may allow an attacker to spoof error messages Impact: An attacker may trick authenticated BIG-IP users into accessing malicious links and reflect a spoofed error message in the victim's BIG-IP Configuration utility web browser session.… | |
| Pendiente de análisis | Media (5.9) | 0.35% | — | Drupal LinkAI | 2/9/2026 | 2/9/2026 | Vulnerability in Drupal Link content parser. This issue affects Link content parser versions: *.*. | |
| Aplazada | Media (5.5) | 0.26% | — | Broken Link CheckerAI | 2/9/2026 | 3/9/2026 | Editor Server Side Request Forgery (SSRF) in Broken Link Checker <= 2.4.14 versions. | |
| Aplazada | Alta (7.2) | 0.53% | — | Broken Link CheckerAI | 2/9/2026 | 2/9/2026 | The Broken Link Checker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Author URL / Link Log in all versions up to, and including, 2.4.13 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in… | |
| Aplazada | Crítica (9.8) | 0.64% | — | Totolink T6AI | 1/9/2026 | 2/9/2026 | Incorrect access control in the sendToMasterQosConfig function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to forward attacker-controlled QoS settings to the master via sending a crafted MQTT message to the cs_broker component.. | |
| Aplazada | Crítica (9.8) | 0.64% | — | Totolink T6AI | 1/9/2026 | 2/9/2026 | Incorrect access control in the remoteCloudUpdateCheck function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to restart the cloud update check workflow via sending a crafted MQTT message to the cs_broker component. | |
| Aplazada | Alta (7.5) | 0.47% | — | Totolink T6AI | 1/9/2026 | 2/9/2026 | Incorrect access control in the setElinkQosConfig function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to modify privileged QoS policy on the master device via sending a crafted MQTT message to the cs_broker component. | |
| Aplazada | Crítica (9.8) | 0.64% | — | Totolink T6AI | 1/9/2026 | 3/9/2026 | Incorrect access control in the recvClearPairCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reset pairing state and reboot the device via sending a crafted MQTT message to the cs_broker component. | |
| Aplazada | Alta (7.5) | 0.60% | — | Totolink T6AI | 1/9/2026 | 1/9/2026 | Incorrect access control in the setDevReboot function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reboot the local device and, on a master, fan out reboot commands to mesh slaves via sending a crafted MQTT message to the cs_broker component. | |
| Aplazada | Crítica (9.8) | 0.64% | — | Totolink T6AI | 1/9/2026 | 2/9/2026 | Incorrect access control in the recvIndirectMeshInfo function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to insert or replace mesh neighbor records via sending a crafted MQTT message to the cs_broker component. | |
| Aplazada | Crítica (9.8) | 0.64% | — | Totolink T6AI | 1/9/2026 | 3/9/2026 | Incorrect access control in the recvSlaveCloudCheckStatus function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to overwrite cloud-result tracking files via sending a crafted MQTT message to the cs_broker component. | |
| Aplazada | Crítica (9.8) | 0.64% | — | Totolink T6AI | 1/9/2026 | 3/9/2026 | Incorrect access control in the freeStaClient function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to forcibly disconnect wireless clients via sending a crafted MQTT message to the cs_broker component. | |
| Aplazada | Crítica (9.8) | 0.64% | — | Totolink T6AI | 1/9/2026 | 3/9/2026 | Incorrect access control in the meshInfoKick function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to kick or clean stale mesh information/state and trigger regeneration of mesh metadata via sending a crafted MQTT message to the cs_broker component. | |
| Aplazada | Media (5.3) | 0.40% | — | Totolink T6AI | 1/9/2026 | 1/9/2026 | Incorrect access control in the updateLanIp function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to refresh the LAN address state via sending a crafted MQTT message to the cs_broker component. | |
| Aplazada | Crítica (9.8) | 0.64% | — | Totolink T6AI | 1/9/2026 | 3/9/2026 | Incorrect access control in the informSyncUpgfw function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to mass-trigger firmware update activity across mesh slaves via sending a crafted MQTT message to the cs_broker component. | |
| Aplazada | Crítica (9.8) | 0.64% | — | Totolink T6AI | 1/9/2026 | 3/9/2026 | Incorrect access control in the meshSlaveUpdate function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to start a firmware download or flash workflow on the slave device via sending a crafted MQTT message to the cs_broker component. | |
| Aplazada | Media (5.9) | 0.43% | — | Totolink T6AI | 1/9/2026 | 1/9/2026 | Incorrect access control in the meshSlaveUpgfw function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to start firmware flashing using existing upgrade files via sending a crafted MQTT message to the cs_broker component. | |
| Aplazada | Crítica (9.8) | 0.62% | — | Totolink T6AI | 1/9/2026 | 3/9/2026 | Incorrect access control in the updateSlaveIpList function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to overwrite the slave IP inventory state via sending a crafted MQTT message to the cs_broker component. | |
| Aplazada | Media (5.3) | 0.41% | — | Totolink T6AI | 1/9/2026 | 1/9/2026 | Incorrect access control in the staticInfoSend function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to trigger static information reporting to the configured master via sending a crafted MQTT message to the cs_broker component. | |
| Aplazada | Crítica (9.8) | 0.64% | — | Totolink T6AI | 1/9/2026 | 3/9/2026 | Incorrect access control in the delSlaveDevice function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove a specified slave device from local mesh management data and reboot the system via sending a crafted MQTT message to the cs_broker component. | |
| Aplazada | Crítica (9.8) | 0.64% | — | Totolink T6AI | 1/9/2026 | 3/9/2026 | Incorrect access control in the updatePriChannel function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to rescan and switch the primary mesh channel via sending a crafted MQTT message to the cs_broker component. | |
| Aplazada | Media (5.9) | 0.43% | — | Totolink T6AI | 1/9/2026 | 1/9/2026 | Incorrect access control in the sendStaticInfoToMaster function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to update stored slave inventory records via sending a crafted MQTT message to the cs_broker component. | |
| Aplazada | Crítica (9.8) | 0.64% | — | Totolink T6AI | 1/9/2026 | 3/9/2026 | Incorrect access control in the keepAlive function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to emit indirect mesh heartbeat information toward the master via sending a crafted MQTT message to the cs_broker component. | |
| Aplazada | Media (5.3) | 0.40% | — | Totolink T6AI | 1/9/2026 | 1/9/2026 | Incorrect access control in the updatePriStaList function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to refresh the primary station list via sending a crafted MQTT message to the cs_broker component. | |
| Aplazada | Crítica (9.8) | 0.64% | — | Totolink T6AI | 1/9/2026 | 3/9/2026 | Incorrect access control in the recv_mesh_info_sync function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to force mesh configuration synchronization from an attacker-controlled host via sending a crafted MQTT message to the cs_broker component. |