Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2989▼ 73 respecto a la semana anterior
Críticas / altas1415▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

6 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.3)5.3%—Dlink Dcs-931l Firmware10/2/202617/6/2026
A vulnerability was found in D-Link DCS-931L up to 1.13.0. This affects an unknown part of the file /goform/setSysAdmin. The manipulation of the argument AdminID results in os command injection. The attack can be executed remotely. The exploit has been made public and could be used. This vulnerability only affects…
ModificadaBaja (2)6.2%—Dlink Dcs-931l Firmware9/2/202617/6/2026
A vulnerability was found in D-Link DCS-931L up to 1.13.0. Impacted is the function doSystem of the file /setSystemAdmin. Performing a manipulation of the argument AdminID results in command injection. The attack may be initiated remotely. The exploit has been made public and could be used. This vulnerability only…
ModificadaAlta (8.8)3.6%💥 PoCDlink Dcs-930l FirmwareDlink Dcs-931l FirmwareDlink Dcs-932l FirmwareDlink Dcs-933l Firmware+66/5/201917/6/2026
The D-Link DCS series of Wi-Fi cameras contains a stack-based buffer overflow in alphapd, the camera's web server. The overflow allows a remotely authenticated attacker to execute arbitrary code by providing a long string in the WEPEncryption parameter when requesting wireless.htm. Vulnerable devices include DCS-5009L…
ModificadaAlta (8.8)4.3%💥 ExploitDlink Dcs-2230l FirmwareDlink Dcs-2310l FirmwareDlink Dcs-2332l FirmwareDlink Dcs-6010l Firmware+2224/4/201717/6/2026
D-Link DCS cameras have a weak/insecure CrossDomain.XML file that allows sites hosting malicious Flash objects to access and/or change the device's settings via a CSRF attack. This is because of the 'allow-access-from domain' child element set to *, thus accepting requests from any domain. If a victim logged into the…
ModificadaAlta (9)67%💥 ExploitDlink Dcs-931l Firmware23/2/201517/6/2026
Unrestricted file upload vulnerability in D-Link DCS-931L with firmware 1.04 and earlier allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension.
ModificadaMedia (6.8)0.93%—Dlink Dcs-931l Firmware23/2/201517/6/2026
Cross-site request forgery (CSRF) vulnerability in D-Link DCS-931L with firmware 1.04 and earlier allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.