Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2774▲ 9 respecto a la semana anterior
Críticas / altas1289▼ 242 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)230▲ 212 respecto a la semana anterior
6793 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.37% | — | Dlink Dir-600l Firmware | 24/10/2025 | 17/6/2026 | D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formEasySetTimezone. | |
| Analizada | Alta (7.5) | 0.37% | — | Dlink Dir-600l Firmware | 24/10/2025 | 17/6/2026 | D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formAutoDetecWAN_wizard4. | |
| Analizada | Crítica (9.8) | 0.41% | — | Dlink Dir-600l Firmware | 24/10/2025 | 17/6/2026 | D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formLanSetupRouterSettings. | |
| Analizada | Alta (7.5) | 0.37% | — | Dlink Dir-600l Firmware | 24/10/2025 | 17/6/2026 | D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSetWAN_Wizard7. | |
| Analizada | Alta (7.5) | 0.46% | — | Dlink Dir-600l Firmware | 24/10/2025 | 17/6/2026 | D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formAdvNetwork. | |
| Analizada | Alta (7.5) | 0.46% | — | Dlink Dir-600l Firmware | 24/10/2025 | 17/6/2026 | D-Link DIR600LAx FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSetQoS. | |
| Analizada | Alta (7.5) | 0.46% | — | Dlink Dir-600l Firmware | 24/10/2025 | 17/6/2026 | D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formLogDnsquery. | |
| Analizada | Alta (7.5) | 0.51% | — | Dlink Dir-600l Firmware | 24/10/2025 | 17/6/2026 | D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSetRoute. | |
| Analizada | Alta (7.5) | 0.37% | — | Dlink Dir-600l Firmware | 24/10/2025 | 17/6/2026 | D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formAdvFirewall. | |
| Analizada | Alta (7.5) | 1.8% | — | Totolink N600r Firmware | 22/10/2025 | 17/6/2026 | A NULL pointer dereference in the sub_41773C function of TOTOLINK N600R v4.3.0cu.7866_B20220506 allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request. | |
| Analizada | Alta (7.5) | 2.1% | — | Totolink N600r Firmware | 22/10/2025 | 17/6/2026 | A NULL pointer dereference in the main function of TOTOLINK N600R v4.3.0cu.7866_B20220506 allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request. | |
| Analizada | Alta (7.5) | 0.59% | — | Totolink N600r Firmware | 22/10/2025 | 17/6/2026 | TOTOLINK N600R v4.3.0cu.7866_B20220506 was discovered to contain a stack overflow in the ssid parameter in the setWiFiBasicConfig function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input. | |
| Analizada | Alta (7.5) | 0.49% | — | Totolink N600r Firmware | 22/10/2025 | 17/6/2026 | TOTOLINK N600R v4.3.0cu.7866_B20220506 was discovered to contain a stack overflow in the wepkey2 parameter in the setWiFiMultipleConfig function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input. | |
| Analizada | Alta (7.5) | 5.0% | — | Dlink Dir-823g Firmware | 22/10/2025 | 17/6/2026 | A NULL pointer dereference in the SetWLanRadioSettings function of D-Link DIR-823G A1 v1.0.2B05 allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request. | |
| Analizada | Alta (7.5) | 0.62% | — | Dlink Dir-823g Firmware | 22/10/2025 | 17/6/2026 | D-Link DIR-823G A1 v1.0.2B05 was discovered to contain a buffer overflow in the FillMacCloneMac parameter in the /EXCU_SHELL endpoint. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input. | |
| Aplazada | Crítica (9.8) | 0.73% | 💥 PoC | Quantumcloud Simple Link DirectoryAI | 22/10/2025 | 8/10/2026 | Vulnerabilidad de omisión de autenticación usando una ruta o canal alternativo en quantumcloud Simple Link Directory qc-simple-link-directory permite el abuso de autenticación. Este problema afecta a Simple Link Directory: desde n/a hasta < 14.8.1. | |
| Analizada | Alta (8.8) | 0.54% | — | Dlink Dir-820l Firmware | 21/10/2025 | 17/6/2026 | The administrator password setting of the D-Link DIR-820L 1.06B02 is has Improper Access Control and is vulnerable to Unverified Password Change via crafted POST request to /get_set.ccp. | |
| Analizada | Media (5.1) | 0.13% | 💥 PoC | Reolink | 21/10/2025 | 17/6/2026 | The Reolink desktop application uses a hard-coded and predictable AES encryption key to encrypt user configuration files allowing attackers with local access to decrypt sensitive application data stored in %APPDATA%. A different vulnerability than CVE-2025-56801. NOTE: the Supplier's position is that material is not… | |
| Analizada | Media (5.1) | 0.14% | 💥 PoC | Reolink | 21/10/2025 | 17/6/2026 | The Reolink Desktop Application 8.18.12 contains hardcoded credentials as the Initialization Vector (IV) in its AES-CFB encryption implementation allowing attackers with access to the application environment to reliably decrypt encrypted configuration data. NOTE: the Supplier's position is that material is not… | |
| Analizada | Media (5.1) | 0.25% | 💥 PoC | Reolink | 21/10/2025 | 17/6/2026 | Reolink desktop application 8.18.12 contains a vulnerability in its local authentication mechanism. The application implements lock screen password logic entirely on the client side using JavaScript within an Electron resource file. Because the password is stored and returned via a modifiable JavaScript… | |
| Analizada | Media (6.5) | 1.2% | 💥 PoC | Reolink | 21/10/2025 | 17/6/2026 | Reolink desktop application 8.18.12 contains a command injection vulnerability in its scheduled cache-clearing mechanism via a crafted folder name. NOTE: this is disputed by the Supplier because a crafted folder name would arise only if the local user were attacking himself. | |
| Aplazada | Crítica (9.8) | 0.60% | — | Netlink Hg322gAI | 21/10/2025 | 17/6/2026 | Improper authentication in the web-based management interface of NETLINK HG322G V1.0.00-231017, allows a remote unauthenticated attacker to escalate privileges and lock out the legitimate administrator via crafted HTTP requests. | |
| Aplazada | Alta (8.6) | 11% | — | Dlink Dsr-150AIDlink Dsr-150nAIDlink Dsr-250nAI | 21/10/2025 | 8/10/2026 | Una vulnerabilidad de salto de ruta (salto de directorio) en los routers D-Link serie DSR permite a atacantes remotos no autenticados manipular parámetros de entrada utilizados para la resolución de rutas de archivos o directorios (por ejemplo, mediante secuencias como '../'). La explotación exitosa puede permitir el… | |
| Modificada | Alta (8.7) | 0.67% | — | Tp-link Fr307-m2 FirmwareTp-link Fr205 FirmwareTp-link Fr365 FirmwareTp-link G611 Firmware+9 | 21/10/2025 | 17/6/2026 | An attacker may obtain the root shell on the underlying OS system with the restricted conditions on Omada gateways. | |
| Modificada | Crítica (9.3) | 3.3% | — | Tp-link Er8411 FirmwareTp-link Er7412-m2 FirmwareTp-link Er707-m2 FirmwareTp-link Er7206 Firmware+9 | 21/10/2025 | 17/6/2026 | A command injection vulnerability may be exploited after the admin's authentication on the web portal on Omada gateways. |