Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2991▼ 71 respecto a la semana anterior
Críticas / altas1367▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)458▼ 52 respecto a la semana anterior
–

5 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaBaja (2.1)8.9%—Dlink Dcs-930l Firmware8/12/202517/6/2026
A vulnerability was determined in D-Link DCS-930L 1.15.04. This affects an unknown part of the file /setSystemAdmin of the component alphapd. Executing manipulation of the argument AdminID can lead to command injection. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized.…
AnalizadaAlta (7.2)69%⚠ Explotación activaDlink Dcs-930l Firmware9/3/202017/6/2026
setSystemCommand on D-Link DCS-930L devices before 2.12 allows a remote attacker to execute code via an OS command in the SystemCommand parameter.
ModificadaAlta (8.8)3.6%—Dlink Dcs-930l FirmwareDlink Dcs-931l FirmwareDlink Dcs-932l FirmwareDlink Dcs-933l Firmware+66/5/201917/6/2026
The D-Link DCS series of Wi-Fi cameras contains a stack-based buffer overflow in alphapd, the camera's web server. The overflow allows a remotely authenticated attacker to execute arbitrary code by providing a long string in the WEPEncryption parameter when requesting wireless.htm. Vulnerable devices include DCS-5009L…
ModificadaAlta (7.5)1.9%—D-link Dcs-936l FirmwareDlink Dcs-942l FirmwareD-link Dcs-8000lh FirmwareD-link Dcs-942lb1 Firmware+1420/12/201817/6/2026
D-Link DCS series Wi-Fi cameras expose sensitive information regarding the device configuration. The affected devices include many of DCS series, such as: DCS-936L, DCS-942L, DCS-8000LH, DCS-942LB1, DCS-5222L, DCS-825L, DCS-2630L, DCS-820L, DCS-855L, DCS-2121, DCS-5222LB1, DCS-5020L, and many more. There are many…
ModificadaAlta (8.8)4.3%—Dlink Dcs-2230l FirmwareDlink Dcs-2310l FirmwareDlink Dcs-2332l FirmwareDlink Dcs-6010l Firmware+2224/4/201717/6/2026
D-Link DCS cameras have a weak/insecure CrossDomain.XML file that allows sites hosting malicious Flash objects to access and/or change the device's settings via a CSRF attack. This is because of the 'allow-access-from domain' child element set to *, thus accepting requests from any domain. If a victim logged into the…