Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
4 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (2.1) | 4.0% | — | Dlink Dcs-933l Firmware | 9/2/2026 | 17/6/2026 | A vulnerability was determined in D-Link DCS-933L up to 1.14.11. This affects an unknown function of the file /setSystemAdmin of the component alphapd. This manipulation of the argument AdminID causes command injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be… | |
| Modificada | Alta (8.8) | 3.6% | — | Dlink Dcs-930l FirmwareDlink Dcs-931l FirmwareDlink Dcs-932l FirmwareDlink Dcs-933l Firmware+6 | 6/5/2019 | 17/6/2026 | The D-Link DCS series of Wi-Fi cameras contains a stack-based buffer overflow in alphapd, the camera's web server. The overflow allows a remotely authenticated attacker to execute arbitrary code by providing a long string in the WEPEncryption parameter when requesting wireless.htm. Vulnerable devices include DCS-5009L… | |
| Modificada | Alta (7.5) | 1.9% | — | D-link Dcs-936l FirmwareDlink Dcs-942l FirmwareD-link Dcs-8000lh FirmwareD-link Dcs-942lb1 Firmware+14 | 20/12/2018 | 17/6/2026 | D-Link DCS series Wi-Fi cameras expose sensitive information regarding the device configuration. The affected devices include many of DCS series, such as: DCS-936L, DCS-942L, DCS-8000LH, DCS-942LB1, DCS-5222L, DCS-825L, DCS-2630L, DCS-820L, DCS-855L, DCS-2121, DCS-5222LB1, DCS-5020L, and many more. There are many… | |
| Modificada | Alta (8.8) | 4.3% | — | Dlink Dcs-2230l FirmwareDlink Dcs-2310l FirmwareDlink Dcs-2332l FirmwareDlink Dcs-6010l Firmware+22 | 24/4/2017 | 17/6/2026 | D-Link DCS cameras have a weak/insecure CrossDomain.XML file that allows sites hosting malicious Flash objects to access and/or change the device's settings via a CSRF attack. This is because of the 'allow-access-from domain' child element set to *, thus accepting requests from any domain. If a victim logged into the… |