Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
1906 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (2) | 0.45% | — | Ligerosmart | 16/2/2026 | 17/6/2026 | A vulnerability was detected in LigeroSmart up to 6.1.26. The impacted element is the function AgentDashboard of the file /otrs/index.pl. Performing a manipulation of the argument Subaction results in cross site scripting. Remote exploitation of the attack is possible. The exploit is now public and may be used. The… | |
| Analizada | Baja (2) | 0.45% | — | Ligerosmart | 16/2/2026 | 17/6/2026 | A security vulnerability has been detected in LigeroSmart up to 6.1.26. The affected element is an unknown function of the file /otrs/index.pl. Such manipulation of the argument SortBy leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. The… | |
| Analizada | Baja (2) | 0.37% | — | Ligerosmart | 16/2/2026 | 17/6/2026 | A weakness has been identified in LigeroSmart up to 6.1.26. Impacted is an unknown function of the file /otrs/index.pl?Action=AgentTicketSearch. This manipulation of the argument Profile causes cross site scripting. The attack may be initiated remotely. The exploit has been made available to the public and could be… | |
| Modificada | Alta (8.7) | 0.53% | — | Jung-group Enet Smart Home | 15/2/2026 | 24/8/2026 | eNet SMART HOME server 2.2.1 and 2.3.1 contains a privilege escalation vulnerability due to insufficient authorization checks in the setUserGroup JSON-RPC method. A low-privileged user (UG_USER) can send a crafted POST request to /jsonrpc/management specifying their own username to elevate their account to the… | |
| Analizada | Alta (8.7) | 0.50% | — | Jung-group Enet Smart Home | 15/2/2026 | 17/6/2026 | eNet SMART HOME server 2.2.1 and 2.3.1 contains a missing authorization vulnerability in the resetUserPassword JSON-RPC method that allows any authenticated low-privileged user (UG_USER) to reset the password of arbitrary accounts, including those in the UG_ADMIN and UG_SUPER_ADMIN groups, without supplying the… | |
| Modificada | Alta (7.1) | 0.46% | — | Jung-group Enet Smart Home | 15/2/2026 | 17/6/2026 | eNet SMART HOME server 2.2.1 and 2.3.1 contains a missing authorization vulnerability in the deleteUserAccount JSON-RPC method that permits any authenticated low-privileged user (UG_USER) to delete arbitrary user accounts, except for the built-in admin account. The application does not enforce role-based access… | |
| Analizada | Crítica (9.3) | 0.60% | — | Jung-group Enet Smart Home | 15/2/2026 | 17/6/2026 | eNet SMART HOME server 2.2.1 and 2.3.1 ships with default credentials (user:user, admin:admin) that remain active after installation and commissioning without enforcing a mandatory password change. Unauthenticated attackers can use these default credentials to gain administrative access to sensitive smart home… | |
| Aplazada | Media (4.3) | 0.27% | — | Rednao Smart FormsAI | 14/2/2026 | 17/6/2026 | The Smart Forms plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'rednao_smart_forms_get_campaigns' AJAX action in all versions up to, and including, 2.6.99. This makes it possible for authenticated attackers, with Subscriber-level access and above, to retrieve… | |
| Analizada | Crítica (9.3) | 2.7% | 💥 Exploit | Calero Verasmart | 13/2/2026 | 17/6/2026 | Calero VeraSMART versions prior to 2022 R1 use static ASP.NET/IIS machineKey values configured for the VeraSMART web application and stored in C:\\Program Files (x86)\\Veramark\\VeraSMART\\WebRoot\\web.config. An attacker who obtains these keys can craft a valid ASP.NET ViewState payload that passes integrity… | |
| Analizada | Alta (8.5) | 0.10% | — | Calero Verasmart | 13/2/2026 | 17/6/2026 | Calero VeraSMART versions prior to 2026 R1 contain hardcoded static AES encryption keys within Veramark.Framework.dll (Veramark.Core.Config class). These keys are used to encrypt the password of the service account stored in C:\\VeraSMART Data\\app.settings. An attacker with local access to the system can extract the… | |
| Analizada | Crítica (10) | 1.3% | — | Calero Verasmart | 13/2/2026 | 17/6/2026 | Calero VeraSMART versions prior to 2022 R1 expose an unauthenticated .NET Remoting HTTP service on TCP port 8001. The service publishes default ObjectURIs (including EndeavorServer.rem and RemoteFileReceiver.rem) and permits the use of SOAP and binary formatters with TypeFilterLevel set to Full. An unauthenticated… | |
| Aplazada | Alta (8.8) | 0.34% | — | Bosch Smart HomeAI | 12/2/2026 | 17/6/2026 | Thrive Smart Home 1.1 contains an SQL injection vulnerability in the checklogin.php endpoint that allows unauthenticated attackers to bypass authentication by manipulating the 'user' POST parameter. Attackers can inject malicious SQL code like ' or 1=1# to manipulate login queries and gain unauthorized access to the… | |
| Aplazada | Crítica (9.8) | 0.41% | — | NTN Information Processing Services Computer Software Hardware Industry AND Trade Smart PanelAI | 12/2/2026 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in NTN Information Processing Services Computer Software Hardware Industry and Trade Ltd. Co. Smart Panel allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Smart Panel: before 20251215. | |
| Analizada | Alta (8.7) | 2.0% | 💥 Exploit | Jung-group Smart Visu Server Firmware | 12/2/2026 | 17/6/2026 | JUNG Smart Visu Server 1.1.1050 contains a denial of service vulnerability that allows unauthenticated attackers to remotely shutdown or reboot the server. Attackers can send a single POST request to trigger the server reboot without requiring any authentication. | |
| Analizada | Alta (8.7) | 0.55% | — | Jung-group Smart Visu Server Firmware | 12/2/2026 | 17/6/2026 | JUNG Smart Visu Server 1.1.1050 contains a request header manipulation vulnerability that allows unauthenticated attackers to override request URLs by injecting arbitrary values in the X-Forwarded-Host header. Attackers can manipulate proxied requests to generate tainted responses, enabling cache poisoning, potential… | |
| Aplazada | Media (6.9) | 0.84% | — | Jung Smart Panel KNXAI | 10/2/2026 | 17/6/2026 | JUNG Smart Panel KNX firmware version L1.12.22 and prior contain an unauthenticated path traversal vulnerability in the embedded web interface. The application fails to properly validate file path input, allowing remote, unauthenticated attackers to access arbitrary files on the underlying filesystem within the… | |
| Analizada | Baja (2.1) | 0.58% | — | Flycatcher Smart Pixelator Firmware | 6/2/2026 | 17/6/2026 | A security flaw has been discovered in Flycatcher Toys smART Pixelator 2.0. Affected by this issue is some unknown functionality of the component Bluetooth Low Energy Interface. Performing a manipulation results in missing authentication. The attack can only be performed from the local network. The exploit has been… | |
| Aplazada | Media (4.3) | 0.15% | — | IBM Operations Analytics LOG AnalysisAIIBM Smartcloud Analytics LOG AnalysisAI | 4/2/2026 | 17/6/2026 | IBM Operations Analytics – Log Analysis versions 1.3.5.0 through 1.3.8.3 and IBM SmartCloud Analytics – Log Analysis are vulnerable to a cross-site request forgery (CSRF) vulnerability that could allow an attacker to trick a trusted user into performing unauthorized actions. | |
| Analizada | Media (6.1) | 0.18% | — | Bordeaux-metropole AT Internet Smarttag | 4/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal AT Internet SmartTag allows Cross-Site Scripting (XSS).This issue affects AT Internet SmartTag: from 0.0.0 before 1.0.1. | |
| Aplazada | Media (6.4) | 0.30% | — | Smart Appointment BookingAI | 4/2/2026 | 17/6/2026 | The Smart Appointment & Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the saab_save_form_data AJAX action in all versions up to, and including, 1.0.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Analizada | Crítica (9.8) | 0.72% | — | Sdkede IOT Smart Water Meter Firmware | 3/2/2026 | 17/6/2026 | SQL Injection vulnerability in Shandong Kede Electronics Co., Ltd IoT smart water meter monitoring platform v.1.0 allows a remote attacker to execute arbitrary code via the imei_list.aspx file. | |
| Analizada | Alta (7.8) | 0.11% | — | Qualcomm Sa9000p FirmwareQualcomm Sar2130p FirmwareQualcomm Snapdragon 8 Gen1 5G FirmwareQualcomm Sd662 Firmware+149 | 2/2/2026 | 17/6/2026 | Memory Corruption while deallocating graphics processing unit memory buffers due to improper handling of memory pointers. | |
| Analizada | Alta (7.8) | 0.11% | — | Qualcomm Wsa8845h FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Flight RB5 5G Firmware+143 | 2/2/2026 | 17/6/2026 | Memory Corruption when initiating GPU memory mapping using scatter-gather lists due to unchecked IOMMU mapping errors. | |
| Analizada | Media (6.9) | 0.31% | — | Smartertools Smartermail | 29/1/2026 | 17/6/2026 | SmarterTools SmarterMail versions prior to build 9518 contain an unauthenticated path coercion vulnerability in the background-of-the-day preview endpoint. The application base64-decodes attacker-supplied input and uses it as a filesystem path without validation. On Windows systems, this allows UNC paths to be… | |
| Analizada | Alta (8.8) | 0.33% | — | Smartdatasoft Smartblog | 28/1/2026 | 17/6/2026 | SmartBlog 2.0.1 contains a blind SQL injection vulnerability in the 'id_post' parameter of the details controller that allows attackers to extract database information. Attackers can systematically test and retrieve database contents by injecting crafted SQL queries that compare character-by-character of database… |