Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
621 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (2.1) | 6.8% | — | Linksys Re6250 FirmwareLinksys Re6300 FirmwareLinksys Re6350 FirmwareLinksys Re7000 Firmware+2 | 11/8/2025 | 17/6/2026 | A vulnerability was found in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. Affected by this vulnerability is the function setDeviceName of the file /goform/setDeviceName. The manipulation of the argument DeviceName leads to os command injection. The attack can be launched remotely. The… | |
| Analizada | Alta (7.4) | 1.0% | — | Linksys Re6250 FirmwareLinksys Re6300 FirmwareLinksys Re6350 FirmwareLinksys Re7000 Firmware+2 | 11/8/2025 | 17/6/2026 | A vulnerability has been found in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. Affected is the function algDisable of the file /goform/setOpMode. The manipulation of the argument opMode leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been… | |
| Analizada | Baja (2.1) | 6.8% | — | Linksys Re6250 FirmwareLinksys Re6300 FirmwareLinksys Re6350 FirmwareLinksys Re7000 Firmware+2 | 11/8/2025 | 17/6/2026 | A vulnerability was identified in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. This issue affects the function RP_setBasic of the file /goform/RP_setBasic. The manipulation of the argument bssid leads to os command injection. The attack may be initiated remotely. The exploit has been… | |
| Analizada | Alta (7.4) | 1.0% | — | Linksys Re6250 FirmwareLinksys Re6300 FirmwareLinksys Re6350 FirmwareLinksys Re7000 Firmware+2 | 11/8/2025 | 17/6/2026 | A vulnerability was determined in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. This vulnerability affects the function wirelessBasic of the file /goform/wirelessBasic. The manipulation of the argument submit_SSID1 leads to stack-based buffer overflow. The attack can be initiated remotely.… | |
| Analizada | Alta (7.4) | 1.0% | — | Linksys Re6250 FirmwareLinksys Re6300 FirmwareLinksys Re6350 FirmwareLinksys Re7000 Firmware+2 | 10/8/2025 | 17/6/2026 | A vulnerability was found in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. This affects the function setWan of the file /goform/setWan. The manipulation of the argument staticIp leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been… | |
| Analizada | Baja (2.1) | 6.5% | — | Linksys Re6250 FirmwareLinksys Re6300 FirmwareLinksys Re6350 FirmwareLinksys Re6500 Firmware+2 | 10/8/2025 | 17/6/2026 | A vulnerability has been found in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. Affected by this issue is the function setDFSSetting of the file /goform/setLan. The manipulation of the argument lanNetmask/lanIp leads to os command injection. The attack may be launched remotely. The exploit… | |
| Analizada | Alta (7.4) | 1.0% | — | Linksys Re6250 FirmwareLinksys Re6300 FirmwareLinksys Re6350 FirmwareLinksys Re7000 Firmware+2 | 10/8/2025 | 17/6/2026 | A vulnerability was identified in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. Affected by this vulnerability is the function setLan of the file /goform/setLan. The manipulation of the argument lan2enabled leads to stack-based buffer overflow. The attack can be launched remotely. The… | |
| Analizada | Alta (7.4) | 1.0% | — | Linksys Re6250 FirmwareLinksys Re6300 FirmwareLinksys Re6350 FirmwareLinksys Re7000 Firmware+2 | 10/8/2025 | 17/6/2026 | A vulnerability was determined in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. Affected is the function setOpMode of the file /goform/setOpMode. The manipulation of the argument ethConv leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been… | |
| Aplazada | Media (6.9) | 2.1% | — | Linksys E1500AI | 1/8/2025 | 16/6/2026 | A directory traversal vulnerability exists in Linksys router's web interface (tested on the E1500 model firmware versions 1.0.00, 1.0.04, and 1.0.05), specifically in the /apply.cgi endpoint. Authenticated attackers can exploit the next_page POST parameter to access arbitrary files outside the intended web root by… | |
| Aplazada | Alta (8.6) | 4.3% | 💥 Exploit | Linksys Wrt160nv2AI | 1/8/2025 | 16/6/2026 | An authenticated OS command injection vulnerability exists in various Linksys router models (tested on WRT160Nv2) running firmware version v2.0.03 via the apply.cgi endpoint. The web interface fails to properly sanitize user-supplied input passed to the ping_size parameter during diagnostic operations. An attacker… | |
| Aplazada | Media (5.3) | 1.1% | — | Linksys Wrt120nAI | 31/7/2025 | 17/6/2026 | A stack-based buffer overflow vulnerability exists in the tmUnblock.cgi endpoint of the Linksys WRT120N wireless router. The vulnerability is triggered by sending a specially crafted HTTP POST request with an overly long TM_Block_URL parameter to the endpoint. By exploiting this flaw, an unauthenticated remote… | |
| Modificada | Crítica (9.8) | 1.0% | — | Linksys E2500 Firmware | 21/7/2025 | 5/7/2026 | In Linksys E2500 3.0.04.002, the chroot_local_user option is enabled in the vsftpd configuration file. This could lead to unauthorized access to system files, privilege escalation, or use of the compromised server as a pivot point for internal network attacks. | |
| Modificada | Baja (3.9) | 0.28% | — | Linksys Ea6350 Firmware | 21/7/2025 | 5/7/2026 | In Linksys EA6350 V2.1.2, the chroot_local_user option is enabled in the dynamically generated vsftpd configuration file. This could lead to unauthorized access to system files, privilege escalation, or use of the compromised server as a pivot point for internal network attacks. | |
| Aplazada | Crítica (9.8) | 0.55% | — | MD Yeasin UL Haider URL Shortener Exact-linksAI | 16/7/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Md Yeasin Ul Haider URL Shortener exact-links allows Object Injection.This issue affects URL Shortener: from n/a through <= 3.0.7. | |
| Aplazada | Crítica (9.3) | 0.40% | — | MD Yeasin UL Haider URL Shortener Exact-linksAI | 16/7/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Md Yeasin Ul Haider URL Shortener exact-links allows SQL Injection.This issue affects URL Shortener: from n/a through <= 3.0.7. | |
| Aplazada | Alta (8.3) | 54% | 💥 Exploit | Linksys E1000AILinksys E1200AILinksys E3200AI | 11/7/2025 | 16/6/2026 | Linksys E1000 devices through 2.1.02, E1200 devices before 2.0.05, and E3200 devices through 1.0.04 allow OS command injection via shell metacharacters in the apply.cgi ping_ip parameter on TCP port 52000. | |
| Aplazada | Media (5.4) | 0.19% | — | MD Yeasin UL Haider URL Shortener Exact LinksAI | 4/7/2025 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in Md Yeasin Ul Haider URL Shortener exact-links allows Server Side Request Forgery.This issue affects URL Shortener: from n/a through <= 3.0.7. | |
| Aplazada | Media (5.9) | 0.25% | — | THE Website Flip ADD Replace Affiliate Links FOR AmazonAI | 27/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in The Website Flip Add & Replace Affiliate Links for Amazon add-replace-affiliate-links-for-amazon allows Stored XSS.This issue affects Add & Replace Affiliate Links for Amazon: from n/a through <= 1.0.6. | |
| Aplazada | Alta (7.4) | 1.1% | — | Linksys Wrt1900acsAILinksys Ea7200AILinksys Ea7450AILinksys Ea7500AI | 27/6/2025 | 17/6/2026 | A vulnerability has been found in Linksys WRT1900ACS, EA7200, EA7450 and EA7500 up to 20250619 and classified as critical. This vulnerability affects the function SetDefaultConnectionService of the file /upnp/control/Layer3Forwarding of the component IGD. The manipulation of the argument NewDefaultConnectionService… | |
| Aplazada | Alta (7.4) | 0.78% | — | Linksys E8450AI | 27/6/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in Linksys E8450 up to 1.2.00.360516. This affects the function set_device_language of the file portal.cgi of the component HTTP POST Request Handler. The manipulation of the argument dut_language leads to buffer overflow. It is possible to initiate the… | |
| Aplazada | Crítica (10) | 93% | 💥 Exploit | Linksys E-series RoutersAILinksys WAG Series RoutersAILinksys WAP Series RoutersAILinksys WES Series RoutersAI+2 | 24/6/2025 | 22/7/2026 | An OS command injection vulnerability exists in various models of E-Series Linksys routers via the /tmUnblock.cgi and /hndUnblock.cgi endpoints over HTTP on port 8080. The CGI scripts improperly process user-supplied input passed to the ttcp_ip parameter without sanitization, allowing unauthenticated attackers to… | |
| Aplazada | Alta (7.6) | 0.34% | — | Ruben Garcia ShortlinksproAI | 6/6/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ruben Garcia ShortLinks Pro shortlinkspro allows SQL Injection.This issue affects ShortLinks Pro: from n/a through <= 1.0.7. | |
| Analizada | Media (5.3) | 31% | — | Linksys Re9000 FirmwareLinksys Re6250 FirmwareLinksys Re6300 FirmwareLinksys Re6350 Firmware+2 | 2/6/2025 | 17/6/2026 | A vulnerability was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. It has been declared as critical. This vulnerability affects the function ssid1MACFilter of the file /goform/ssid1MACFilter. The manipulation of the argument… | |
| Analizada | Media (5.3) | 14% | — | Linksys Re9000 FirmwareLinksys Re6250 FirmwareLinksys Re6300 FirmwareLinksys Re6350 Firmware+2 | 2/6/2025 | 17/6/2026 | A vulnerability was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. It has been classified as critical. This affects the function RP_checkCredentialsByBBS of the file /goform/RP_checkCredentialsByBBS. The manipulation of the argument pwd leads… | |
| Analizada | Media (5.3) | 14% | — | Linksys Re9000 FirmwareLinksys Re6250 FirmwareLinksys Re6300 FirmwareLinksys Re6350 Firmware+2 | 2/6/2025 | 17/6/2026 | A vulnerability was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001 and classified as critical. Affected by this issue is the function RP_checkFWByBBS of the file /goform/RP_checkFWByBBS. The manipulation of the argument… |