Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2734▼ 7 respecto a la semana anterior
Críticas / altas1273▼ 240 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)230▲ 212 respecto a la semana anterior
6793 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.5) | 4.7% | — | Dlink Dir-823x Firmware | 9/9/2025 | 17/6/2026 | A vulnerability was determined in D-Link DIR-823X up to 250416. Affected by this vulnerability is the function sub_415028 of the file /goform/set_static_leases. Executing manipulation of the argument Hostname can lead to command injection. The attack can be launched remotely. The exploit has been publicly disclosed… | |
| Aplazada | Crítica (9) | 0.31% | — | Volkov Labs Business LinksAIGrafanaAI | 8/9/2025 | 17/6/2026 | The Volkov Labs Business Links panel for Grafana provides an interface to navigate using external links, internal dashboards, time pickers, and dropdown menus. Prior to version 2.4.0, a malicious actor with Editor privileges can escalate their privileges to Administrator and perform arbitrary administrative actions.… | |
| Analizada | Alta (8.4) | 0.27% | — | Linkace | 8/9/2025 | 17/6/2026 | LinkAce is a self-hosted archive to collect website links. A stored cross-site scripting (XSS) vulnerability was discovered in versions prior to 2.1.9 that allows an attacker to inject arbitrary JavaScript, which is then executed in the context of a user's browser when the malicious link is clicked. This is a… | |
| Analizada | Media (5.5) | 1.0% | — | Dlink Dir-852 Firmware | 8/9/2025 | 17/6/2026 | A vulnerability was identified in D-Link DIR-852 up to 1.00CN B09. Affected by this vulnerability is the function phpcgi_main of the file /getcfg.php of the component Device Configuration Handler. Such manipulation leads to information disclosure. The attack may be performed from remote. The exploit is publicly… | |
| Analizada | Alta (7.4) | 0.97% | — | Dlink Dir-825 Firmware | 6/9/2025 | 17/6/2026 | A vulnerability was found in D-Link DIR-825 1.08.01. This impacts the function get_ping6_app_stat of the file ping6_response.cg of the component httpd. Performing manipulation of the argument ping6_ipaddr results in buffer overflow. It is possible to initiate the attack remotely. The exploit has been made public and… | |
| Analizada | Crítica (9.2) | 0.85% | — | Ptzoptics Pt12x-sdi-xx-g2 FirmwarePtzoptics Pt12x-ndi-xx FirmwarePtzoptics Pt12x-usb-xx-g2 FirmwarePtzoptics Pt20x-sdi-xx-g2 Firmware+57 | 5/9/2025 | 17/6/2026 | PTZOptics and possibly other ValueHD-based pan-tilt-zoom cameras use default, shared credentials for the administrative web interface. | |
| Aplazada | Media (5.9) | 0.22% | — | Jimmywb Simple Link List WidgetAI | 5/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jimmywb Simple Link List Widget simple-link-list-widget allows Stored XSS.This issue affects Simple Link List Widget: from n/a through <= 0.3.2. | |
| Aplazada | Media (5.9) | 0.22% | — | Arjan Olsder Wpa-seo-auto-linkerAI | 5/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Arjan Olsder SEO Auto Linker wpa-seo-auto-linker allows Stored XSS.This issue affects SEO Auto Linker: from n/a through <= 1.5.3. | |
| Analizada | Alta (7.4) | 1.5% | — | Dlink Di-8400 Firmware | 4/9/2025 | 17/6/2026 | Se ha identificado una debilidad en D-Link DI-8400 16.07.26A1. El elemento afectado es la función yyxz_dlink_asp del archivo /yyxz.asp. Esta manipulación del argumento ID causa desbordamiento de búfer basado en pila. Es posible iniciar el ataque de forma remota. El exploit se ha puesto a disposición del público y… | |
| Analizada | Media (5.5) | 3.0% | — | Totolink N600r Firmware | 4/9/2025 | 17/6/2026 | A vulnerability was determined in TOTOLINK N600R 4.3.0cu.7866_B20220506. This vulnerability affects the function sub_4159F8 of the file /web_cste/cgi-bin/cstecgi.cgi. Executing manipulation can lead to command injection. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. | |
| Analizada | Baja (2.1) | 3.7% | — | Totolink X5000r Firmware | 4/9/2025 | 17/6/2026 | A vulnerability was found in TOTOLINK X5000R 9.1.0cu.2415_B20250515. This affects the function sub_410C34 of the file /cgi-bin/cstecgi.cgi. Performing manipulation of the argument pid results in command injection. Remote exploitation of the attack is possible. The exploit has been made public and could be used. | |
| Analizada | Media (5.3) | 0.33% | — | 3/9/2025 | 17/6/2026 | LinkedIn Mobile Application for Android version 4.1.1087.2 fails to update link preview metadata (image, title, description) when a user replaces the original URL in a post or comment before publishing. As a result, the stale preview remains visible while the clickable link points to a different URL, which can be… | ||
| Analizada | Media (5.3) | 1.7% | — | Prolink2u Pgn6401v Firmware | 3/9/2025 | 17/6/2026 | An OS command injection vulnerability exists in PLDT WiFi Router's Prolink PGN6401V Firmware 8.1.2 web management interface. The ping6.asp page submits user input to the /boaform/formPing6 endpoint via the pingAddr parameter, which is not properly sanitized. An authenticated attacker can exploit this flaw by injecting… | |
| Analizada | Media (6.1) | 0.27% | — | Slinkapp Slink | 3/9/2025 | 17/6/2026 | Slink v1.4.9 allows stored cross-site scripting (XSS) via crafted SVG uploads. When a user views the shared image in a new browser tab, the embedded JavaScript executes. The issue affects both authenticated and unauthenticated users. | |
| Analizada | Media (6.5) | 1.8% | — | Wavlink Wl-wn535k3 Firmware | 2/9/2025 | 17/6/2026 | Wavlink WN535K3 20191010 was found to contain a command injection vulnerability in the set_sys_adm function via the username parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request. | |
| Analizada | Media (6.5) | 1.1% | — | Wavlink Wl-wn535k3 Firmware | 2/9/2025 | 17/6/2026 | Wavlink WN535K3 20191010 was found to contain a command injection vulnerability in the set_sys_cmd function via the command parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request. | |
| Modificada | Media (6.5) | 3.4% | 💥 PoC | Wavlink Wl-wn531p3 Firmware | 2/9/2025 | 5/7/2026 | Wavlink AC1200 with firmware versions M32A3_V1410_230602 and M32A3_V1410_240222 are vulnerable to a post-authentication command injection while resetting the password. This vulnerability is specifically found within the "set_sys_adm" function of the "adm.cgi" binary, and is due to improper santization of the user… | |
| Analizada | Alta (7.4) | 0.66% | — | Totolink A702r Firmware | 1/9/2025 | 25/9/2026 | Se determinó una vulnerabilidad en TOTOLINK A702R 4.0.0-B20211108.1423. Este problema afecta a la función sub_418030 del archivo /boafrm/formParentControl. La manipulación del argumento submit-url puede conducir a un desbordamiento de búfer. El ataque puede lanzarse de forma remota. El exploit ha sido divulgado… | |
| Analizada | Alta (7.4) | 0.66% | — | Totolink A702r Firmware | 1/9/2025 | 25/9/2026 | Se encontró una vulnerabilidad en TOTOLINK A702R 4.0.0-B20211108.1423. Esta vulnerabilidad afecta a la función sub_4466F8 del archivo /boafrm/formOneKeyAccessButton. La manipulación del argumento submit-url provoca un desbordamiento de búfer. El ataque puede iniciarse remotamente. El exploit se ha hecho público y… | |
| Analizada | Alta (7.4) | 0.66% | — | Totolink A702r Firmware | 1/9/2025 | 25/9/2026 | Se ha encontrado una vulnerabilidad en TOTOLINK A702R 4.0.0-B20211108.1423. Esto afecta a la función sub_4162DC del archivo /boafrm/formFilter. Dicha manipulación del argumento ip6addr conduce a un desbordamiento de búfer. El ataque puede lanzarse remotamente. El exploit se ha divulgado al público y puede utilizarse. | |
| Analizada | Alta (7.4) | 0.66% | — | Totolink A702r Firmware | 1/9/2025 | 25/9/2026 | Se ha encontrado una falla en TOTOLINK A702R 4.0.0-B20211108.1423. Afectada por este problema es la función sub_419BE0 del archivo /boafrm/formIpQoS. Esta manipulación del argumento mac causa desbordamiento de búfer. El ataque puede iniciarse de forma remota. El exploit ha sido publicado y puede ser utilizado. | |
| Analizada | Alta (7.4) | 0.66% | — | Totolink A702r Firmware | 1/9/2025 | 25/9/2026 | Se detectó una vulnerabilidad en TOTOLINK A702R 4.0.0-B20211108.1423. La función sub_4162DC del archivo /boafrm/formFilter está afectada por esta vulnerabilidad. La manipulación del argumento ip6addr provoca un desbordamiento de búfer. Es posible lanzar el ataque de forma remota. El exploit ya es público y puede ser… | |
| Analizada | Baja (0.9) | 29% | — | Dlink Di-7400g+ Firmware | 1/9/2025 | 17/6/2026 | A security flaw has been discovered in D-Link DI-7400G+ 19.12.25A1. Affected is the function sub_478D28 of the file /mng_platform.asp. The manipulation of the argument addr with the input `echo 12345 > poc.txt` results in command injection. An attack on the physical device is feasible. The exploit has been released to… | |
| Analizada | Media (5.5) | 18% | — | Dlink Dir-852 Firmware | 1/9/2025 | 17/6/2026 | A security vulnerability has been detected in D-Link DIR-852 1.00CN B09. Impacted is the function soapcgi_main of the file soap.cgi of the component SOAP Service. Such manipulation of the argument service leads to os command injection. The attack can be launched remotely. The exploit has been disclosed publicly and… | |
| Analizada | Baja (2) | 11% | — | Dlink Di-500wf Firmware | 31/8/2025 | 17/6/2026 | A security vulnerability has been detected in D-Link DI-500WF 14.04.10A1T. The impacted element is an unknown function of the file /version_upgrade.asp of the component jhttpd. The manipulation of the argument path leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed… |