Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3029▼ 65 respecto a la semana anterior
Críticas / altas1425▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

1878 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisCrítica (9.2)——SmartyAI6/10/20266/10/2026
Smarty before 4.5.8 and 5.x before 5.8.5 contains a code injection vulnerability where the top-level nocache_hash is never restored during extends:/multi-component template inheritance, leaving it null. Attackers can supply assigned data containing a forged SmartyNocache marker that is copied verbatim into the…
AplazadaAlta (7.1)0.24%—Storegrowth Smart Sales Booster FOR WoocommerceAI6/10/20266/10/2026
Unauthenticated Cross Site Scripting (XSS) in StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart <= 2.0.6 versions.
AplazadaAlta (7.2)0.26%—PDF Smart ViewerAI6/10/20266/10/2026
Unauthenticated Server Side Request Forgery (SSRF) in PDF Smart Viewer for Elementor <= 1.0.4 versions.
AplazadaAlta (7.1)0.24%—Rednao Smart FormsAI6/10/20266/10/2026
Unauthenticated Cross Site Scripting (XSS) in Smart Forms <= 2.6.104 versions.
AplazadaAlta (8.8)0.37%—Smart ManagerAI3/10/20266/10/2026
The Smart Manager – Advanced WooCommerce Bulk Edit & Inventory Management plugin for WordPress is vulnerable to generic SQL Injection via the 'access_privileges' parameter in all versions up to, and including, 8.97.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the…
AplazadaMedia (6.1)0.31%—Wpclever WPC Smart Quick ViewAI3/10/20266/10/2026
The WPC Smart Quick View for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'woosq-redirect' parameter in all versions up to, and including, 4.4.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject…
AplazadaMedia (5.3)0.20%—Chiranjit Hazarika Smart ONE Click SetupAI2/10/20262/10/2026
Insertion of Sensitive Information Into Sent Data vulnerability in Chiranjit Hazarika Smart One Click Setup – Complete Demo Import &amp; Export smart-one-click-setup allows Retrieve Embedded Sensitive Data.This issue affects Smart One Click Setup – Complete Demo Import &amp; Export: from n/a through 1.4.3.
AplazadaCrítica (9.8)0.48%—Trex Digital Smart Manufacturing Systems Trex MESAI30/9/202630/9/2026
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Trex Digital Smart Manufacturing Systems Inc. Trex MES allows Command Line Execution through SQL Injection. This issue affects Trex MES: through 2026-09-29.
AplazadaMedia (6.4)0.16%—Nextendweb Smart Slider 3AI30/9/202630/9/2026
The Smart Slider 3 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data-href' parameter in all versions up to, and including, 3.5.1.38 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to…
AplazadaMedia (5.9)0.17%—Mh-developer Smart Home ModuleAI28/9/202628/9/2026
mH-DEVELOPER smart home module is vulnerable to Denial of Service due to uncontrolled resource consumption. The Express bodyParser is configured with a 250 MB limit for JSON and URL-encoded request bodies. An authenticated attacker on the LAN can send large request bodies that exhausts buffers in RAM, causing…
AplazadaMedia (6.9)0.37%—Mh-developer Smart Home ModuleAI28/9/202628/9/2026
mH-DEVELOPER smart home module ships with an end-of-life, unsupported Debian 8 and Node.js runtime v17.0.1 in its production firmware. This exposes the device to publicly known vulnerabilities that will not receive security patches. An attacker could exploit these known flaws to execute arbitrary code, access…
AplazadaMedia (6)0.21%—Mh-developer Smart Home ModuleAI28/9/202628/9/2026
mH-DEVELOPER smart home module sends its web interface and API traffic over unencrypted HTTP. Passwords, authentication tokens, and device commands are transmitted in cleartext. An attacker on the same network can intercept this traffic, steal credentials and tokens, and hijack sessions. This issue was fixed in…
AplazadaMedia (5.3)0.17%—Mh-developer Smart Home ModuleAI28/9/202628/9/2026
mH-DEVELOPER smart home module does not load any firewall rules at startup. This leaves all listening services, including SSH, HTTP, WebSocket, and Node-RED, fully exposed on the LAN without access control. Any client on the same network can reach every service. This issue was fixed in version 3.0.30
AplazadaMedia (6.4)0.21%—Mh-developer Smart Home ModuleAI28/9/202628/9/2026
mH-DEVELOPER smart home module does not verify tokens in its authorization middleware, leaving all HTTP API and WebSocket endpoints accessible without authentication. An unauthenticated attacker on the LAN can query these endpoints, access system information, and send raw control commands to manipulate building…
AplazadaMedia (6.3)0.24%—Mh-developer Smart Home ModuleAI28/9/202628/9/2026
mH-DEVELOPER smart home module uses the same hard-coded SSH host keys on every device, with no per-device key generation. An attacker who extracts these keys from the firmware can set up a rogue SSH server that clients will trust without warning, enabling man-in-the-middle attacks and credential interception. This…
AplazadaAlta (7.7)0.18%—Mh-developer Smart Home ModuleAI28/9/202628/9/2026
mH-DEVELOPER smart home module contains a hardcoded SSH public key in /root/.ssh/authorized_keys, serving as a potential backdoor. The SSH daemon allows root login via key authentication and starts automatically. An attacker with the matching private key can gain a root shell on any affected device, resulting in full…
AplazadaMedia (4.8)0.37%—Teldat Regesta Smart Hd-plcAI25/9/202630/9/2026
An attacker with access via network to the Regesta Smart HD-PLC of the provider Teldat (in this case, registration action is required) who has the vulnerable firmware version could inject a specific payload via the parameter "cmdcookie" withing the /upgrade/index.html resulting in to a Cross-Site Scripting (XSS). This…
AplazadaMedia (5.3)0.21%—Wpclever WPC Smart CompareAI23/9/202623/9/2026
The WPC Smart Compare for WooCommerce WordPress plugin before 6.6.1 does not apply WordPress's post-password protection when returning product content through its comparison handler, allowing unauthenticated users to read the description of password-protected products.
AplazadaBaja (2.1)0.27%—Sourcecodester Smart Attendance System With QR Code ScannerAI23/9/202623/9/2026
A vulnerability was found in SourceCodester Smart Attendance System with QR Code Scanner 1.0. This issue affects the function prepend of the file student_signup.php of the component Self-Registration. Performing a manipulation of the argument full_name results in cross site scripting. Remote exploitation of the attack…
AplazadaMedia (6.2)0.20%—ZTE SmartlifeAI20/9/202622/9/2026
The ZTE SmartLife application has a hardcoded key. The key used to decrypt account server information is stored in plaintext in the code. Once the key is obtained, the server information can be decrypted, thus exposing it.
AplazadaMedia (4.3)0.33%—Smartlife APPAI20/9/202622/9/2026
SmartLife app dynamically generates brand‑new SmartLife application authentication parameters within its runtime process. With the obtained SmartLife application authentication parameters, attackers can directly invoke the backend interface /account/verify.serv to determine whether a target email address is registered…
AplazadaAlta (8.8)0.52%—Smartlife APPAI20/9/202622/9/2026
SmartLife app dynamically generates fresh SmartLife application authentication parameters inside its runtime process. Using the acquired SmartLife application authentication parameters, an attacker can directly call the backend interface /account/verify.serv to obtain the real account ID corresponding to a registered…
AplazadaMedia (5.4)0.36%—Smartlife APPAI20/9/202622/9/2026
SmartLife app dynamically generates brand‑new SmartLife application authentication parameters at runtime. With the acquired SmartLife application authentication credentials, an attacker can directly complete registration using any arbitrary email address via the backend interface /account/person/signup.serv. Email…
AplazadaMedia (6.5)0.34%—Wpgraphql Smart CacheAI19/9/202621/9/2026
The WPGraphQL Smart Cache WordPress plugin before 2.3.2 does not require authorisation or validate a caller-supplied query identifier before storing a persisted query from a request, allowing unauthenticated users to publish arbitrary query documents and claim query aliases before a site's own frontend registers them.
En análisisBaja (3.5)0.24%—Dell Smartfabric ManagerAI17/9/202618/9/2026
Dell SmartFabric Manager, versions prior to 2.2.1, contains an Improper Handling of Insufficient Permissions or Privileges vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.