Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2732▼ 9 respecto a la semana anterior
Críticas / altas1276▼ 237 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)230▲ 212 respecto a la semana anterior
–

6793 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.3)0.35%💥 PoCLinkace18/9/202517/6/2026
LinkAce is a self-hosted archive to collect website links. Prior to 2.3.1, a Stored Cross-Site Scripting (XSS) vulnerability has been identified on the /system/audit page. The application fails to properly sanitize the username field before it is rendered in the audit log. An authenticated attacker can set a malicious…
ModificadaAlta (7.4)3.4%💥 ExploitDlink Dir-825 Firmware18/9/202517/6/2026
A security flaw has been discovered in D-Link DIR-825 up to 2.10. Affected by this vulnerability is the function sub_4106d4 of the file apply.cgi. The manipulation of the argument countdown_time results in buffer overflow. The attack can be executed remotely. The exploit has been released to the public and may be…
AnalizadaBaja (2.1)5.4%—Dlink Dir-852 Firmware18/9/202517/6/2026
A vulnerability was determined in D-Link DIR-852 1.00CN B09. This issue affects the function ssdpcgi_main of the file htodcs/cgibin of the component Simple Service Discovery Protocol Service. Executing manipulation of the argument ST can lead to command injection. The attack may be performed from remote. The exploit…
AnalizadaBaja (2.1)9.3%—Dlink Dir-852 Firmware18/9/202517/6/2026
A vulnerability was found in D-Link DIR-852 1.00CN B09. This vulnerability affects unknown code of the file /htdocs/cgibin/hedwig.cgi of the component Web Management Interface. Performing manipulation results in command injection. The attack is possible to be carried out remotely. The exploit has been made public and…
AnalizadaBaja (2.1)7.4%—Dlink Dir-823x Firmware18/9/202530/9/2026
Se ha identificado una debilidad en D-Link DIR-823X 240126/240802/250416. El elemento afectado es la función sub_412E7C del archivo /usr/sbin/goahead del componente Gestor de Variables de Entorno. Esta manipulación del argumento terminal_addr/server_ip/server_port causa inyección de comandos. El ataque puede iniciarse…
AnalizadaAlta (8.8)0.43%—Mohammadzain2008 Linkr16/9/202517/6/2026
Linkr is a lightweight file delivery system that downloads files from a webserver. Linkr versions through 2.0.0 do not verify the integrity or authenticity of .linkr manifest files before using their contents, allowing a tampered manifest to inject arbitrary file entries into a package distribution. An attacker can…
AplazadaCrítica (9.8)0.44%💥 PoCBGS Interactive Sinav.linkAI16/9/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in BGS Interactive SINAV.LINK Exam Result Module allows SQL Injection. This issue affects SINAV.LINK Exam Result Module: before 1.2.
AnalizadaCrítica (9.8)4.4%—Totolink X6000r Firmware15/9/202517/6/2026
TOTOLINK X6000R V9.4.0cu.1360_B20241207 was found to contain a command injection vulnerability in the sub_417D74 function via the file_name parameter. This vulnerability allows unauthenticated attackers to execute arbitrary commands via a crafted request.
AplazadaBaja (2.1)12%—Dlink Di-8100gAIDlink Di-8200gAIDlink Di-8003gAI15/9/202517/6/2026
A vulnerability was found in D-Link DI-8100G, DI-8200G and DI-8003G 17.12.20A1/19.12.10A1. Affected by this issue is the function sub_433F7C of the file version_upgrade.asp of the component jhttpd. The manipulation of the argument path results in os command injection. The attack may be launched remotely. The exploit…
AplazadaBaja (2.1)12%—Dlink Di-8100AIDlink Di-8100gAIDlink Di-8200AIDlink Di-8200gAI+215/9/202517/6/2026
A vulnerability has been found in D-Link DI-8100, DI-8100G, DI-8200, DI-8200G, DI-8003 and DI-8003G 16.07.26A1/17.12.20A1/19.12.10A1. Affected by this vulnerability is the function sub_4621DC of the file usb_paswd.asp of the component jhttpd. The manipulation of the argument hname leads to os command injection. The…
AnalizadaBaja (2.1)0.40%—Rems Link Status Checker14/9/202517/6/2026
Se ha detectado una vulnerabilidad de seguridad en SourceCodester Link Status Checker 1.0. Esta vulnerabilidad afecta a código del fichero index.php. La manipulación del argumento proxy permite la falsificación de peticiones de lado servidor. El ataque puede efectuarse de manera remota. El exploit se encuentra…
AnalizadaBaja (2.1)8.5%—Dlink Dir-823x Firmware14/9/202517/6/2026
A vulnerability was detected in D-Link DIR-823x up to 250416. The affected element is an unknown function of the file /goform/diag_ping. Performing manipulation of the argument target_addr results in command injection. Remote exploitation of the attack is possible. The exploit is now public and may be used.
AnalizadaMedia (5.5)6.1%—Wavlink Wl-wn578w2 Firmware13/9/202517/6/2026
A vulnerability was detected in Wavlink WL-WN578W2 221110. This impacts the function sub_404DBC of the file /cgi-bin/wireless.cgi. The manipulation of the argument macAddr results in os command injection. The attack can be launched remotely. The exploit is now public and may be used. The vendor was contacted early…
AnalizadaMedia (5.5)6.1%—Wavlink Wl-wn578w2 Firmware13/9/202517/6/2026
A security vulnerability has been detected in Wavlink WL-WN578W2 221110. This affects the function sub_404850 of the file /cgi-bin/wireless.cgi. The manipulation of the argument delete_list leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used. The…
AnalizadaBaja (2.1)6.8%—Wavlink Wl-wn578w2 Firmware12/9/202517/6/2026
A vulnerability was identified in Wavlink WL-WN578W2 221110. This impacts the function sub_401340/sub_401BA4 of the file /cgi-bin/login.cgi. Such manipulation of the argument ipaddr leads to command injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The vendor…
AnalizadaMedia (5.5)8.1%—Wavlink Wl-wn578w2 Firmware12/9/202517/6/2026
A vulnerability was determined in Wavlink WL-WN578W2 221110. This affects the function sub_401C5C of the file firewall.cgi. This manipulation of the argument pingFrmWANFilterEnabled/blockSynFloodEnabled/blockPortScanEnabled/remoteManagementEnabled causes command injection. It is possible to initiate the attack…
AnalizadaMedia (5.5)8.1%—Wavlink Wl-wn578w2 Firmware12/9/202517/6/2026
A vulnerability was found in Wavlink WL-WN578W2 221110. The impacted element is the function sub_409184 of the file /wizard_rep.shtml. The manipulation of the argument sel_EncrypTyp results in command injection. The attack may be performed from remote. The exploit has been made public and could be used. The vendor was…
AnalizadaMedia (5.5)0.48%—Wavlink Wl-wn578w2 Firmware12/9/202517/6/2026
A vulnerability has been found in Wavlink WL-WN578W2 221110. The affected element is an unknown function of the file /sysinit.html. The manipulation of the argument newpass/confpass leads to weak password recovery. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may…
AnalizadaAlta (8)0.61%—Totolink X2000r Firmware12/9/202517/6/2026
An issue in TOTOLINK Wi-Fi 6 Router Series Device X2000R-Gh-V2.0.0 allows a remote attacker to execute arbitrary code via the default password
AnalizadaMedia (5.5)0.53%—Wavlink Wl-wn578w2 Firmware12/9/202530/9/2026
Se ha encontrado un fallo en Wavlink WL-WN578W2 221110. Afecta a una función desconocida del archivo /live_online.shtml. La ejecución de manipulación puede conducir a la revelación de información. El ataque puede ejecutarse remotamente. El exploit ha sido publicado y puede ser utilizado. Se contactó con el proveedor…
AnalizadaCrítica (10)1.3%—Deltaww Dialink11/9/202517/6/2026
Delta Electronics DIALink has an Directory Traversal Authentication Bypass Vulnerability.
AnalizadaAlta (7.3)15%—Deltaww Dialink11/9/202517/6/2026
Delta Electronics DIALink has an Directory Traversal Authentication Bypass Vulnerability.
AnalizadaAlta (8.8)0.43%—Lb-link Bl-cpe300m Firmware9/9/202517/6/2026
The LB-Link BL-CPE300M AX300 4G LTE Router firmware version BL-R8800_B10_ALK_SL_V01.01.02P42U14_06 does not implement proper session handling. After a user authenticates from a specific IP address, the router grants access to any other client using that same IP, without requiring credentials or verifying client…
AplazadaAlta (7.5)0.50%—Tp-link Ax10 Ax1500AI9/9/202517/6/2026
An issue in TP-Link AX10 Ax1500 v.1.3.10 Build (20230130) allows a remote attacker to obtain sensitive information
AnalizadaCrítica (9.3)0.66%—Opexustech Foiaxpress Public Access Link9/9/202530/9/2026
OPEXUS FOIAXpress Public Access Link (PAL) anterior a la versión 11.13.1.0 permite la inyección SQL a través de SearchPopularDocs.aspx. Un atacante remoto no autenticado podría leer, escribir o eliminar cualquier contenido en la base de datos subyacente.