cve,link,title,description,vendor,products,score,severity,epss,cisa,article,ransomware,exploited,poc,trended,trended_no_1,published,trended_score CVE-2022-28956,https://securityvulnerability.io/vulnerability/CVE-2022-28956,,An issue in the getcfg.php component of D-Link DIR816L_FW206b01 allows attackers to access the device via a crafted payload.,D-Link,Dir-816l Firmware,9.8,CRITICAL,0.01331000030040741,false,false,false,false,,false,false,2022-05-18T11:50:42.000Z,0 CVE-2022-28955,https://securityvulnerability.io/vulnerability/CVE-2022-28955,,An access control issue in D-Link DIR816L_FW206b01 allows unauthenticated attackers to access folders folder_view.php and category_view.php.,D-Link,Dir-816l Firmware,7.5,HIGH,0.022120000794529915,false,false,false,false,,false,false,2022-05-18T11:50:41.000Z,0 CVE-2020-15893,https://securityvulnerability.io/vulnerability/CVE-2020-15893,,An issue was discovered on D-Link DIR-816L devices 2.x before 1.10b04Beta02. Universal Plug and Play (UPnP) is enabled by default on port 1900. An attacker can perform command injection by injecting a payload into the Search Target (ST) field of the SSDP M-SEARCH discover packet.,D-Link,Dir-816l Firmware,9.8,CRITICAL,0.027400000020861626,false,false,false,false,,false,false,2020-07-22T18:56:05.000Z,0 CVE-2020-15894,https://securityvulnerability.io/vulnerability/CVE-2020-15894,,"An issue was discovered on D-Link DIR-816L devices 2.x before 1.10b04Beta02. There exists an exposed administration function in getcfg.php, which can be used to call various services. It can be utilized by an attacker to retrieve various sensitive information, such as admin login credentials, by setting the value of _POST_SERVICES in the query string to DEVICE.ACCOUNT.",D-Link,Dir-816l Firmware,7.5,HIGH,0.0015300000086426735,false,false,false,false,,false,false,2020-07-22T18:55:56.000Z,0 CVE-2020-15895,https://securityvulnerability.io/vulnerability/CVE-2020-15895,,"An XSS issue was discovered on D-Link DIR-816L devices 2.x before 1.10b04Beta02. In the file webinc/js/info.php, no output filtration is applied to the RESULT parameter, before it's printed on the webpage.",D-Link,Dir-816l Firmware,6.1,MEDIUM,0.0014400000218302011,false,false,false,false,,false,false,2020-07-22T18:55:44.000Z,0 CVE-2015-5999,https://securityvulnerability.io/vulnerability/CVE-2015-5999,,"Multiple cross-site request forgery (CSRF) vulnerabilities in the D-Link DIR-816L Wireless Router with firmware before 2.06.B09_BETA allow remote attackers to hijack the authentication of administrators for requests that (1) change the admin password, (2) change the network policy, or (3) possibly have other unspecified impact via crafted requests to hedwig.cgi and pigwidgeon.cgi.",D-Link,Dir-816l Firmware,,,0.8809199929237366,false,false,false,false,,false,false,2015-11-18T16:00:00.000Z,0