Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2663▼ 380 respecto a la semana anterior
Críticas / altas1289▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 274 respecto a la semana anterior
6 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (10) | 7.7% | — | Dlink Di-524upDlink Di-604+Dlink Di-604sDlink Di-604up+9 | 19/10/2013 | 16/6/2026 | The web interface on D-Link DIR-100, DIR-120, DI-624S, DI-524UP, DI-604S, DI-604UP, DI-604+, and TM-G5240 routers; Planex BRL-04R, BRL-04UR, and BRL-04CW routers; and Alpha Networks routers allows remote attackers to bypass authentication and modify settings via an xmlset_roodkcableoj28840ybtide User-Agent HTTP… | |
| Modificada | Media (6.8) | 1.2% | — | D-link Di-604 | 15/6/2010 | 16/6/2026 | The Ping tools web interface in Dlink Di-604 router allows remote authenticated users to cause a denial of service via a large "ip textfield" size. | |
| Modificada | Media (4.3) | 0.89% | — | D-link Di-604 | 15/6/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Ping tools web interface in Dlink Di-604 router allows remote attackers to inject arbitrary web script or HTML via the IP field. | |
| Modificada | Media (4.3) | 0.97% | — | D-link Di-604 | 10/3/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in prim.htm on the D-Link DI-604 router allows remote attackers to inject arbitrary web script or HTML via the rf parameter. | |
| Modificada | Alta (7.5) | 19% | — | D-link Di-604 Broadband RouterD-link Di-784D-link Ebr-2310 Ethernet Broadband RouterD-link Wbr-1310 Wireless G Router+3 | 21/7/2006 | 16/6/2026 | Stack-based buffer overflow in the Universal Plug and Play (UPnP) service in D-Link DI-524, DI-604 Broadband Router, DI-624, D-Link DI-784, WBR-1310 Wireless G Router, WBR-2310 RangeBooster G Router, and EBR-2310 Ethernet Broadband Router allows remote attackers to execute arbitrary code via a long M-SEARCH request to… | |
| Modificada | Media (5) | 2.3% | — | D-link Di-604D-link Di-614+D-link Di-624 | 6/8/2004 | 16/6/2026 | Integer signedness error in D-Link AirPlus DI-614+ running firmware 2.30 and earlier allows remote attackers to cause a denial of service (IP lease depletion) via a DHCP request with the LEASETIME option set to -1, which makes the DHCP lease valid for thirteen or more years. |