Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2883▼ 179 respecto a la semana anterior
Críticas / altas1280▼ 58 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)487▼ 22 respecto a la semana anterior
7 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.4) | 1.2% | — | Dlink Dir-655 Firmware | 17/6/2025 | 17/6/2026 | A vulnerability classified as critical has been found in D-Link DIR-665 1.00. This affects the function sub_AC78 of the component HTTP POST Request Handler. The manipulation leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be… | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa | Dlink Dir-655 FirmwareDlink Dir-866l FirmwareDlink Dir-652 FirmwareDlink Dhp-1565 Firmware+6 | 27/9/2019 | 17/6/2026 | Unauthenticated remote code execution occurs in D-Link products such as DIR-655C, DIR-866L, DIR-652, and DHP-1565. The issue occurs when the attacker sends an arbitrary input to a "PingTest" device common gateway interface that could lead to common injection. An attacker who successfully triggers the command injection… | |
| Modificada | Alta (8.8) | 1.0% | — | Dlink Dir-655 Firmware | 11/7/2019 | 17/6/2026 | D-Link DIR-655 C devices before 3.02B05 BETA03 allow CSRF for the entire management console. | |
| Modificada | Media (6.1) | 1.8% | — | Dlink Dir-655 Firmware | 11/7/2019 | 17/6/2026 | D-Link DIR-655 C devices before 3.02B05 BETA03 allow XSS, as demonstrated by the /www/ping_response.cgi ping_ipaddr parameter, the /www/ping6_response.cgi ping6_ipaddr parameter, and the /www/apply_sec.cgi html_response_return_page parameter. | |
| Modificada | Crítica (9.8) | 8.4% | — | Dlink Dir-655 Firmware | 11/7/2019 | 17/6/2026 | D-Link DIR-655 C devices before 3.02B05 BETA03 allow remote attackers to execute arbitrary commands via shell metacharacters in the online_firmware_check.cgi check_fw_url parameter. | |
| Modificada | Crítica (9.8) | 3.6% | — | Dlink Dir-655 Firmware | 11/7/2019 | 17/6/2026 | D-Link DIR-655 C devices before 3.02B05 BETA03 allow remote attackers to force a blank password via the apply_sec.cgi setup_wizard parameter. | |
| Modificada | Media (4.3) | 1.0% | — | D-link Dir-655 FirmwareD-link Dir-655 | 5/1/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in login.cgi in D-Link router DIR-655 (rev Bx) with firmware before 2.12b01 allows remote attackers to inject arbitrary web script or HTML via the html_response_page parameter. |