Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2753▼ 36 respecto a la semana anterior
Críticas / altas1269▼ 264 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)241▲ 206 respecto a la semana anterior
6793 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.19% | — | Tp-link Tl-wr940nAI | 20/11/2025 | 17/6/2026 | Improper input validation vulnerability in TP-Link System Inc. TL-WR940N V6 (UPnP modules), which allows unauthenticated adjacent attackers to perform DoS attack. This issue affects TL-WR940N V6 <= Build 220801. | |
| Analizada | Alta (7.3) | 7.6% | — | Dlink Dir-868l Firmware | 19/11/2025 | 17/6/2026 | D-Link Router DIR-868L A1 FW106KRb01.bin has an unauthenticated remote code execution vulnerability in the cgibin binary. The HNAP service provided by cgibin does not filter the HTTP SOAPAction header field. The unauthenticated remote attacker can execute the shell command. | |
| Aplazada | Media (5.4) | 0.22% | — | Aioseo Broken Link CheckerAI | 18/11/2025 | 17/6/2026 | The Broken Link Checker by AIOSEO – Easily Fix/Monitor Internal and External links plugin for WordPress is vulnerable to unauthorized post modification due to missing authorization in all versions up to, and including, 1.2.5. This is due to the plugin registering a REST API endpoint that only checks for a broad… | |
| Aplazada | Media (4.3) | 0.22% | — | Permalinks CascadeAI | 18/11/2025 | 17/6/2026 | The Permalinks Cascade plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.2. This is due to the plugin not properly verifying that a user is authorized to perform an action in the handleTPCAdminAjaxRequest function. This makes it possible for authenticated attackers,… | |
| Analizada | Baja (2.1) | 8.3% | — | Dlink Dwr-m920 FirmwareDlink Dwr-m921 FirmwareDlink Dir-822k FirmwareDlink Dir-825m Firmware | 18/11/2025 | 17/6/2026 | A security vulnerability has been detected in D-Link DWR-M920, DWR-M921, DIR-822K and DIR-825M 1.1.5. Impacted is the function system of the file /boafrm/formDebugDiagnosticRun. The manipulation of the argument host leads to command injection. Remote exploitation of the attack is possible. The exploit has been… | |
| Analizada | Alta (7.4) | 3.6% | — | Dlink Dir-825m FirmwareDlink Dwr-m920 FirmwareDlink Dwr-m921 FirmwareDlink Dwr-m961 Firmware+1 | 17/11/2025 | 17/6/2026 | A weakness has been identified in D-Link DWR-M920, DWR-M921, DWR-M960, DIR-822K and DIR-825M 1.01.07. This issue affects some unknown processing of the file /boafrm/formTracerouteDiagnosticRun. Executing manipulation of the argument host can lead to buffer overflow. The attack may be launched remotely. The exploit has… | |
| Analizada | Alta (7.4) | 0.81% | — | Dlink Dir-825m FirmwareDlink Dwr-m920 FirmwareDlink Dwr-m921 FirmwareDlink Dwr-m961 Firmware+1 | 17/11/2025 | 17/6/2026 | A security flaw has been discovered in D-Link DWR-M920, DWR-M921, DWR-M960, DWR-M961 and DIR-825M 1.01.07/1.1.47. This vulnerability affects unknown code of the file /boafrm/formPingDiagnosticRun. Performing manipulation of the argument host results in buffer overflow. The attack may be initiated remotely. The exploit… | |
| Analizada | Alta (7.4) | 0.90% | — | Dlink Dir-816l Firmware | 15/11/2025 | 17/6/2026 | A vulnerability was determined in D-Link DIR-816L 2_06_b09_beta. This issue affects the function soapcgi_main of the file /soap.cgi. This manipulation causes stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. This vulnerability only… | |
| Analizada | Alta (7.4) | 0.82% | — | Dlink Dir-816l Firmware | 15/11/2025 | 17/6/2026 | A vulnerability was found in D-Link DIR-816L 2_06_b09_beta. This vulnerability affects the function scandir_main of the file /portal/__ajax_exporer.sgi. The manipulation of the argument en results in stack-based buffer overflow. The attack may be performed from remote. The exploit has been made public and could be… | |
| Analizada | Alta (7.4) | 0.90% | — | Dlink Dir-816l Firmware | 15/11/2025 | 17/6/2026 | A vulnerability has been found in D-Link DIR-816L 2_06_b09_beta. This affects the function genacgi_main of the file gena.cgi. The manipulation of the argument SERVER_ID/HTTP_SID leads to stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may… | |
| Analizada | Alta (8.9) | 2.4% | — | Dlink Dir-816l Firmware | 14/11/2025 | 17/6/2026 | A vulnerability was detected in D-Link DIR-816L 2_06_b09_beta. Affected by this vulnerability is the function authenticationcgi_main of the file /authentication.cgi. Performing manipulation of the argument Password results in stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit is… | |
| Analizada | Media (6.5) | 2.5% | — | Totolink A950rg Firmware | 13/11/2025 | 17/6/2026 | A command injection vulnerability exists in the TOTOLINK A950RG Router firmware V5.9c.4592_B20191022_ALL within the `system.so` binary. The `setDiagnosisCfg` function retrieves the `ipDoamin` parameter from user input via `websGetVar` and concatenates it directly into a `ping` system command executed via… | |
| Analizada | Media (6.5) | 0.84% | — | Totolink A950rg Firmware | 13/11/2025 | 17/6/2026 | A buffer overflow vulnerability exists in the TOTOLINK A950RG Router firmware V5.9c.4592_B20191022_ALL within the `global.so` binary. The `getSaveConfig` function retrieves the `http_host` parameter from user input via `websGetVar` and copies it into a fixed-size stack buffer (`v13`) using `strcpy()` without… | |
| Modificada | Alta (8.8) | 0.67% | — | Dlink Dir-816 Firmware | 13/11/2025 | 5/7/2026 | A stack buffer overflow vulnerability exists in the D-Link DIR-816A2 router firmware DIR-816A2_FWv1.10CNB05_R1B011D88210.img in the upload.cgi module, which handles firmware version information. The vulnerability occurs because /proc/version is read into a 512-byte buffer and then concatenated using sprintf() into… | |
| Modificada | Media (6.5) | 3.5% | — | Dlink Dir-878 Firmware | 13/11/2025 | 5/7/2026 | An unauthenticated command injection vulnerability exists in the D-Link DIR-878A1 router firmware FW101B04.bin. The vulnerability occurs in the 'SetNetworkSettings' functionality of prog.cgi, where the 'IPAddress' and 'SubnetMask' parameters are directly concatenated into shell commands executed via system(). An… | |
| Modificada | Media (5.4) | 1.5% | — | Dlink Dir-823g Firmware | 13/11/2025 | 5/7/2026 | A command injection vulnerability exists in the D-Link DIR-823G router firmware DIR823G_V1.0.2B05_20181207.bin in the timelycheck and sysconf binaries, which process the /tmp/new_qos.rule configuration file. The vulnerability occurs because parsed fields from the configuration file are concatenated into command… | |
| Modificada | Media (6.8) | 0.56% | — | Dlink Dir-878 Firmware | 13/11/2025 | 5/7/2026 | A stack buffer overflow vulnerability exists in the D-Link DIR-878A1 router firmware FW101B04.bin in the rc binary's USB storage handling module. The vulnerability occurs when the "Serial Number" field from a USB device is read via sscanf into a 64-byte stack buffer, while fgets reads up to 127 bytes, causing a stack… | |
| Modificada | Media (6.5) | 3.5% | — | Dlink Dir-878 Firmware | 13/11/2025 | 5/7/2026 | An unauthenticated command injection vulnerability exists in the D-Link DIR-878A1 router firmware FW101B04.bin. The vulnerability occurs in the 'SetDMZSettings' functionality, where the 'IPAddress' parameter in prog.cgi is stored in NVRAM and later used by librcm.so to construct iptables commands executed via… | |
| Modificada | Media (6.5) | 3.6% | — | Dlink Dir-878 Firmware | 13/11/2025 | 5/7/2026 | An unauthenticated command injection vulnerability exists in the D-Link DIR-878A1 router firmware FW101B04.bin. The vulnerability occurs in the 'SetDynamicDNSSettings' functionality, where the 'ServerAddress' and 'Hostname' parameters in prog.cgi are stored in NVRAM and later used by rc to construct system commands… | |
| Analizada | Media (6.5) | 3.2% | — | Dlink Dir-882 Firmware | 13/11/2025 | 17/6/2026 | A command injection vulnerability exists in the D-Link DIR-882 Router firmware DIR882A1_FW102B02 within the `prog.cgi` and `rc` binaries. The `sub_433188` function in `prog.cgi` stores user-supplied email configuration parameters (`EmailFrom`, `EmailTo`, `SMTPServerAddress`, `SMTPServerPort`, `AccountName`) in NVRAM… | |
| Analizada | Media (6.5) | 3.2% | — | Dlink Dir-882 Firmware | 13/11/2025 | 17/6/2026 | A command injection vulnerability exists in the D-Link DIR-882 Router firmware DIR882A1_FW102B02 within the `prog.cgi` and `librcm.so` binaries. The `sub_4455BC` function in `prog.cgi` stores user-supplied `SetDMZSettings/IPAddress` values in NVRAM via `nvram_safe_set("dmz_ipaddr", ...)`. These values are later… | |
| Analizada | Alta (7.3) | 3.9% | — | Dlink Dir-882 Firmware | 13/11/2025 | 17/6/2026 | A command injection vulnerability exists in the D-Link DIR-882 Router firmware DIR882A1_FW102B02 within the `prog.cgi` and `rc` binaries. The `sub_432F60` function in `prog.cgi` stores user-supplied `SetSysLogSettings/IPAddress` values in NVRAM via `nvram_safe_set("SysLogRemote_IPAddress", ...)`. These values are… | |
| Analizada | Alta (7.3) | 3.8% | — | Dlink Dir-882 Firmware | 13/11/2025 | 17/6/2026 | A command injection vulnerability exists in the D-Link DIR-882 Router firmware DIR882A1_FW102B02 within the `prog.cgi` and `rc` binaries. The `sub_4438A4` function in `prog.cgi` stores user-supplied DDNS parameters (`ServerAddress` and `Hostname`) in NVRAM via `nvram_safe_set`. These values are later retrieved in the… | |
| Modificada | Media (6.5) | 0.77% | — | Linksys E1200 Firmware | 13/11/2025 | 5/7/2026 | A stack-based buffer overflow exists in the get_merge_mac function of the httpd binary on Linksys E1200 v2 routers (Firmware E1200_v2.0.11.001_us.tar.gz). The function concatenates up to six user-supplied CGI parameters matching <parameter>_0~5 into a fixed-size buffer (a2) without proper bounds checking, appending… | |
| Modificada | Media (5.4) | 1.4% | — | Dlink Dir-823g Firmware | 13/11/2025 | 5/7/2026 | A command injection vulnerability exists in the D-Link DIR-823G router firmware DIR823G_V1.0.2B05_20181207.bin in the timelycheck and sysconf binaries, which process the /var/system/linux_vlan_reinit file. The vulnerability occurs because content read from this file is only partially validated for a prefix and then… |