Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

621 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaBaja (2.1)6.8%—Linksys Re6250 FirmwareLinksys Re6300 FirmwareLinksys Re6350 FirmwareLinksys Re7000 Firmware+211/8/202517/6/2026
A vulnerability was found in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. Affected by this vulnerability is the function setDeviceName of the file /goform/setDeviceName. The manipulation of the argument DeviceName leads to os command injection. The attack can be launched remotely. The…
AnalizadaAlta (7.4)1.0%—Linksys Re6250 FirmwareLinksys Re6300 FirmwareLinksys Re6350 FirmwareLinksys Re7000 Firmware+211/8/202517/6/2026
A vulnerability has been found in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. Affected is the function algDisable of the file /goform/setOpMode. The manipulation of the argument opMode leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been…
AnalizadaBaja (2.1)6.8%—Linksys Re6250 FirmwareLinksys Re6300 FirmwareLinksys Re6350 FirmwareLinksys Re7000 Firmware+211/8/202517/6/2026
A vulnerability was identified in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. This issue affects the function RP_setBasic of the file /goform/RP_setBasic. The manipulation of the argument bssid leads to os command injection. The attack may be initiated remotely. The exploit has been…
AnalizadaAlta (7.4)1.0%—Linksys Re6250 FirmwareLinksys Re6300 FirmwareLinksys Re6350 FirmwareLinksys Re7000 Firmware+211/8/202517/6/2026
A vulnerability was determined in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. This vulnerability affects the function wirelessBasic of the file /goform/wirelessBasic. The manipulation of the argument submit_SSID1 leads to stack-based buffer overflow. The attack can be initiated remotely.…
AnalizadaAlta (7.4)1.0%—Linksys Re6250 FirmwareLinksys Re6300 FirmwareLinksys Re6350 FirmwareLinksys Re7000 Firmware+210/8/202517/6/2026
A vulnerability was found in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. This affects the function setWan of the file /goform/setWan. The manipulation of the argument staticIp leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been…
AnalizadaBaja (2.1)6.5%—Linksys Re6250 FirmwareLinksys Re6300 FirmwareLinksys Re6350 FirmwareLinksys Re6500 Firmware+210/8/202517/6/2026
A vulnerability has been found in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. Affected by this issue is the function setDFSSetting of the file /goform/setLan. The manipulation of the argument lanNetmask/lanIp leads to os command injection. The attack may be launched remotely. The exploit…
AnalizadaAlta (7.4)1.0%—Linksys Re6250 FirmwareLinksys Re6300 FirmwareLinksys Re6350 FirmwareLinksys Re7000 Firmware+210/8/202517/6/2026
A vulnerability was identified in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. Affected by this vulnerability is the function setLan of the file /goform/setLan. The manipulation of the argument lan2enabled leads to stack-based buffer overflow. The attack can be launched remotely. The…
AnalizadaAlta (7.4)1.0%—Linksys Re6250 FirmwareLinksys Re6300 FirmwareLinksys Re6350 FirmwareLinksys Re7000 Firmware+210/8/202517/6/2026
A vulnerability was determined in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. Affected is the function setOpMode of the file /goform/setOpMode. The manipulation of the argument ethConv leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been…
AplazadaMedia (6.9)2.1%—Linksys E1500AI1/8/202516/6/2026
A directory traversal vulnerability exists in Linksys router's web interface (tested on the E1500 model firmware versions 1.0.00, 1.0.04, and 1.0.05), specifically in the /apply.cgi endpoint. Authenticated attackers can exploit the next_page POST parameter to access arbitrary files outside the intended web root by…
AplazadaAlta (8.6)4.3%💥 ExploitLinksys Wrt160nv2AI1/8/202516/6/2026
An authenticated OS command injection vulnerability exists in various Linksys router models (tested on WRT160Nv2) running firmware version v2.0.03 via the apply.cgi endpoint. The web interface fails to properly sanitize user-supplied input passed to the ping_size parameter during diagnostic operations. An attacker…
AplazadaMedia (5.3)1.1%—Linksys Wrt120nAI31/7/202517/6/2026
A stack-based buffer overflow vulnerability exists in the tmUnblock.cgi endpoint of the Linksys WRT120N wireless router. The vulnerability is triggered by sending a specially crafted HTTP POST request with an overly long TM_Block_URL parameter to the endpoint. By exploiting this flaw, an unauthenticated remote…
ModificadaCrítica (9.8)1.0%—Linksys E2500 Firmware21/7/20255/7/2026
In Linksys E2500 3.0.04.002, the chroot_local_user option is enabled in the vsftpd configuration file. This could lead to unauthorized access to system files, privilege escalation, or use of the compromised server as a pivot point for internal network attacks.
ModificadaBaja (3.9)0.28%—Linksys Ea6350 Firmware21/7/20255/7/2026
In Linksys EA6350 V2.1.2, the chroot_local_user option is enabled in the dynamically generated vsftpd configuration file. This could lead to unauthorized access to system files, privilege escalation, or use of the compromised server as a pivot point for internal network attacks.
AplazadaCrítica (9.8)0.55%—MD Yeasin UL Haider URL Shortener Exact-linksAI16/7/202517/6/2026
Deserialization of Untrusted Data vulnerability in Md Yeasin Ul Haider URL Shortener exact-links allows Object Injection.This issue affects URL Shortener: from n/a through <= 3.0.7.
AplazadaCrítica (9.3)0.40%—MD Yeasin UL Haider URL Shortener Exact-linksAI16/7/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Md Yeasin Ul Haider URL Shortener exact-links allows SQL Injection.This issue affects URL Shortener: from n/a through <= 3.0.7.
AplazadaAlta (8.3)54%💥 ExploitLinksys E1000AILinksys E1200AILinksys E3200AI11/7/202516/6/2026
Linksys E1000 devices through 2.1.02, E1200 devices before 2.0.05, and E3200 devices through 1.0.04 allow OS command injection via shell metacharacters in the apply.cgi ping_ip parameter on TCP port 52000.
AplazadaMedia (5.4)0.19%—MD Yeasin UL Haider URL Shortener Exact LinksAI4/7/202517/6/2026
Server-Side Request Forgery (SSRF) vulnerability in Md Yeasin Ul Haider URL Shortener exact-links allows Server Side Request Forgery.This issue affects URL Shortener: from n/a through <= 3.0.7.
AplazadaMedia (5.9)0.25%—THE Website Flip ADD Replace Affiliate Links FOR AmazonAI27/6/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in The Website Flip Add & Replace Affiliate Links for Amazon add-replace-affiliate-links-for-amazon allows Stored XSS.This issue affects Add & Replace Affiliate Links for Amazon: from n/a through <= 1.0.6.
AplazadaAlta (7.4)1.1%—Linksys Wrt1900acsAILinksys Ea7200AILinksys Ea7450AILinksys Ea7500AI27/6/202517/6/2026
A vulnerability has been found in Linksys WRT1900ACS, EA7200, EA7450 and EA7500 up to 20250619 and classified as critical. This vulnerability affects the function SetDefaultConnectionService of the file /upnp/control/Layer3Forwarding of the component IGD. The manipulation of the argument NewDefaultConnectionService…
AplazadaAlta (7.4)0.78%—Linksys E8450AI27/6/202517/6/2026
A vulnerability, which was classified as critical, was found in Linksys E8450 up to 1.2.00.360516. This affects the function set_device_language of the file portal.cgi of the component HTTP POST Request Handler. The manipulation of the argument dut_language leads to buffer overflow. It is possible to initiate the…
AplazadaCrítica (10)93%💥 ExploitLinksys E-series RoutersAILinksys WAG Series RoutersAILinksys WAP Series RoutersAILinksys WES Series RoutersAI+224/6/202522/7/2026
An OS command injection vulnerability exists in various models of E-Series Linksys routers via the /tmUnblock.cgi and /hndUnblock.cgi endpoints over HTTP on port 8080. The CGI scripts improperly process user-supplied input passed to the ttcp_ip parameter without sanitization, allowing unauthenticated attackers to…
AplazadaAlta (7.6)0.34%—Ruben Garcia ShortlinksproAI6/6/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ruben Garcia ShortLinks Pro shortlinkspro allows SQL Injection.This issue affects ShortLinks Pro: from n/a through <= 1.0.7.
AnalizadaMedia (5.3)31%—Linksys Re9000 FirmwareLinksys Re6250 FirmwareLinksys Re6300 FirmwareLinksys Re6350 Firmware+22/6/202517/6/2026
A vulnerability was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. It has been declared as critical. This vulnerability affects the function ssid1MACFilter of the file /goform/ssid1MACFilter. The manipulation of the argument…
AnalizadaMedia (5.3)14%—Linksys Re9000 FirmwareLinksys Re6250 FirmwareLinksys Re6300 FirmwareLinksys Re6350 Firmware+22/6/202517/6/2026
A vulnerability was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. It has been classified as critical. This affects the function RP_checkCredentialsByBBS of the file /goform/RP_checkCredentialsByBBS. The manipulation of the argument pwd leads…
AnalizadaMedia (5.3)14%—Linksys Re9000 FirmwareLinksys Re6250 FirmwareLinksys Re6300 FirmwareLinksys Re6350 Firmware+22/6/202517/6/2026
A vulnerability was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001 and classified as critical. Affected by this issue is the function RP_checkFWByBBS of the file /goform/RP_checkFWByBBS. The manipulation of the argument…
Orbitaley — Vulnerabilidades