Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2751▼ 38 respecto a la semana anterior
Críticas / altas1262▼ 270 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)246▲ 209 respecto a la semana anterior
–

6793 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.4)1.1%—Linksys Re6500 FirmwareLinksys Re6250 FirmwareLinksys Re6300 FirmwareLinksys Re6350 Firmware+26/12/202525/9/2026
Se ha descubierto una falla de seguridad en Linksys RE6500, RE6250, RE6300, RE6350, RE7000 y RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. Esta vulnerabilidad afecta a la función RE2000v2Repeater_get_wired_clientlist_setClientsName del archivo mod_form.so. La manipulación del argumento clientsname_0…
AnalizadaAlta (7.4)0.87%—Linksys Re6500 FirmwareLinksys Re6250 FirmwareLinksys Re6300 FirmwareLinksys Re6350 Firmware+26/12/202517/6/2026
Se determinó una vulnerabilidad en Linksys RE6500, RE6250, RE6300, RE6350, RE7000 y RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. Afectada por este problema es la función RE2000v2Repeater_get_wireless_clientlist_setClientsName del archivo mod_form.so. La ejecución de la manipulación del argumento…
AnalizadaAlta (7.4)0.87%—Linksys Re6500 FirmwareLinksys Re6250 FirmwareLinksys Re6300 FirmwareLinksys Re6350 Firmware+26/12/202525/9/2026
Se identificó una vulnerabilidad en Linksys RE6500, RE6250, RE6300, RE6350, RE7000 y RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. Esto afecta a la función AP_get_wired_clientlist_setClientsName del archivo mod_form.so. La manipulación del argumento clientsname_0 conduce a un desbordamiento de búfer…
AnalizadaAlta (7.4)0.87%—Linksys Re6500 FirmwareLinksys Re6250 FirmwareLinksys Re6300 FirmwareLinksys Re6350 Firmware+26/12/202525/9/2026
Una vulnerabilidad fue encontrada en Linksys RE6500, RE6250, RE6300, RE6350, RE7000 y RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. Afectada por esta vulnerabilidad es la función AP_get_wireless_clientlist_setClientsName del archivo mod_form.so. Realizar la manipulación del argumento clientsname_0…
AplazadaMedia (6.1)0.21%—Linkwhisper Link Whisper FreeAI6/12/202517/6/2026
The Link Whisper Free plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the type parameter in all versions up to, and including, 0.8.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that…
AplazadaMedia (6.4)0.24%—Easy Jump Links MenusAI5/12/202517/6/2026
The Easy Jump Links Menus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `h_tags` parameter in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to…
AnalizadaBaja (3.1)0.18%—Medtronic Carelink Network4/12/202525/9/2026
Vulnerabilidad de Referencia Directa a Objeto Insegura en Medtronic CareLink Network que permite a un atacante autenticado con acceso a información específica de dispositivos y usuarios enviar solicitudes web a un endpoint de API que expondría información sensible del usuario. Este problema afecta a CareLink Network:…
AnalizadaMedia (4.1)0.11%—Medtronic Carelink Network4/12/202525/9/2026
Medtronic CareLink Network permite a un atacante local con acceso a los archivos de registro en un servidor API interno ver contraseñas en texto plano de errores registrados bajo ciertas circunstancias. Este problema afecta a CareLink Network: antes del 4 de diciembre de 2025.
AnalizadaCrítica (9.8)0.33%—Medtronic Carelink Network4/12/202525/9/2026
Medtronic CareLink Network permite a un atacante remoto no autenticado realizar un ataque de fuerza bruta en un endpoint de API que podría utilizarse para determinar una contraseña válida bajo ciertas circunstancias. Este problema afecta a CareLink Network: antes del 4 de diciembre de 2025.
AnalizadaMedia (5.3)0.30%—Medtronic Carelink Network4/12/202525/9/2026
Medtronic CareLink Network permite a un atacante remoto no autenticado iniciar una solicitud de preguntas de seguridad a un API endpoint que podría utilizarse para determinar una cuenta de usuario válida. Este problema afecta a CareLink Network: antes del 4 de diciembre de 2025.
AplazadaCrítica (9.3)4.4%—Totolink N300rtAI3/12/202517/6/2026
TOTOLINK N300RT wireless router firmware versions prior to V3.4.0-B20250430 (discovered in V2.1.8-B20201030.1539) contain an OS command injection vulnerability in the Boa formWsc handling functionality. An unauthenticated attacker can send specially crafted requests to trigger command execution via the targetAPSsid…
AnalizadaCrítica (9.8)1.2%💥 PoCDlink R15 Firmware2/12/202517/6/2026
A vulnerability has been found in D-Link R15 (AX1500) 1.20.01 and below. By manipulating the model name parameter during a password change request in the web administrator page, it is possible to trigger a command injection in httpd.
AnalizadaMedia (5.3)1.2%—Kerlink Keros1/12/202517/6/2026
Due to a firewall misconfiguration, Kerlink devices running KerOS prior to 5.12 incorrectly accept specially crafted UDP packets. This allows an attacker to bypass the firewall and access UDP-based services that would otherwise be protected.
AnalizadaAlta (7.4)0.18%—Kerlink Keros1/12/202517/6/2026
Kerlink gateways running KerOS prior to version 5.10 expose their web interface exclusively over HTTP, without HTTPS support. This lack of transport layer security allows a man-in-the-middle attacker to intercept and modify traffic between the client and the device.
AnalizadaAlta (8.1)0.52%—Kerlink Keros1/12/202526/9/2026
El servicio wmp-agent de KerOS anterior a 5.12 no valida correctamente las denominadas 'magic URLs', permitiendo a un atacante remoto no autenticado ejecutar comandos arbitrarios del sistema operativo como root cuando el servicio es accesible a través de la red. Típicamente, el servicio está protegido mediante un…
AplazadaMedia (6.4)0.22%—Google Drive Upload AND Download LinkAI27/11/202517/6/2026
The Google Drive upload and download link plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link' parameter of the 'atachfilegoogle' shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…
AplazadaAlta (7.1)0.17%—Broken Link ManagerAI24/11/20258/10/2026
El plugin de WordPress Broken Link Manager hasta la versión 0.6.5 no sanitiza ni escapa un parámetro antes de devolverlo en la página, lo que lleva a un Cross-Site Scripting Reflejado que podría ser utilizado contra usuarios con altos privilegios, como administradores.
AnalizadaMedia (5.5)6.2%—Dlink Dir-852 Firmware23/11/20258/10/2026
Se identificó una vulnerabilidad en D-Link DIR-852 1.00. Este problema afecta a un procesamiento desconocido del archivo /gena.cgi. Dicha manipulación del argumento service conduce a una inyección de comandos. El ataque puede ejecutarse de forma remota. El exploit está disponible públicamente y podría ser utilizado.…
AnalizadaAlta (7.4)0.70%—Dlink Dwr-m920 Firmware23/11/202517/6/2026
A weakness has been identified in D-Link DWR-M920 1.1.50. This affects the function sub_41C7FC of the file /boafrm/formPinManageSetup. This manipulation of the argument submit-url causes buffer overflow. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be…
AnalizadaAlta (7.4)0.76%—Dlink Dir-822k FirmwareDlink Dwr-m920 Firmware23/11/202517/6/2026
A security flaw has been discovered in D-Link DIR-822K and DWR-M920 1.00_20250513164613/1.1.50. The impacted element is an unknown function of the file /boafrm/formWlEncrypt. The manipulation of the argument submit-url results in buffer overflow. The attack may be performed from remote. The exploit has been released…
AnalizadaAlta (7.4)0.76%—Dlink Dir-822k FirmwareDlink Dwr-m920 Firmware23/11/202517/6/2026
A vulnerability was identified in D-Link DIR-822K and DWR-M920 1.00_20250513164613/1.1.50. The affected element is an unknown function of the file /boafrm/formWanConfigSetup. The manipulation of the argument submit-url leads to buffer overflow. The attack is possible to be carried out remotely. The exploit is publicly…
AnalizadaAlta (7.4)0.76%—Dlink Dir-822k FirmwareDlink Dwr-m920 Firmware23/11/202517/6/2026
A vulnerability was determined in D-Link DIR-822K and DWR-M920 1.00_20250513164613/1.1.50. Impacted is an unknown function of the file /boafrm/formVpnConfigSetup. Executing manipulation of the argument submit-url can lead to buffer overflow. The attack can be executed remotely. The exploit has been publicly disclosed…
AnalizadaAlta (7.4)0.73%—Dlink Dir-822k Firmware23/11/202517/6/2026
A vulnerability was found in D-Link DIR-822K 1.00. This issue affects the function sub_455524 of the file /boafrm/formNtp. Performing manipulation of the argument submit-url results in buffer overflow. Remote exploitation of the attack is possible. The exploit has been made public and could be used.
AnalizadaAlta (7.4)0.79%—Dlink Dir-822k FirmwareDlink Dwr-m920 Firmware23/11/202517/6/2026
A vulnerability has been found in D-Link DIR-822K and DWR-M920 1.00_20250513164613/1.1.50. This vulnerability affects unknown code of the file /boafrm/formFirewallAdv. Such manipulation of the argument submit-url leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the…
AnalizadaAlta (7.4)0.74%—Dlink Dir-822k FirmwareDlink Dwr-m920 Firmware23/11/202517/6/2026
A flaw has been found in D-Link DIR-822K and DWR-M920 1.00_20250513164613/1.1.50. This affects an unknown part of the file /boafrm/formDdns. This manipulation of the argument submit-url causes memory corruption. The attack may be initiated remotely. The exploit has been published and may be used.