Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
495 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.17% | 💥 PoC | Home-assistant Home Assistant Companion | 19/10/2023 | 17/6/2026 | Home assistant is an open source home automation. The Home Assistant Companion for Android app up to version 2023.8.2 is vulnerable to arbitrary URL loading in a WebView. This enables all sorts of attacks, including arbitrary JavaScript execution, limited native code execution, and credential theft. This issue has… | |
| Modificada | Crítica (9.6) | 0.95% | — | Home-assistant | 19/10/2023 | 17/6/2026 | Home assistant is an open source home automation. Home Assistant server does not set any HTTP security headers, including the X-Frame-Options header, which specifies whether the web page is allowed to be framed. The omission of this and correlating headers facilitates covert clickjacking attacks and alternative… | |
| Modificada | Crítica (9) | 0.27% | — | Home-assistantHome-assistant-js-websocket | 19/10/2023 | 17/6/2026 | Home assistant is an open source home automation. Whilst auditing the frontend code to identify hidden parameters, Cure53 detected `auth_callback=1`, which is leveraged by the WebSocket authentication logic in tandem with the `state` parameter. The state parameter contains the `hassUrl`, which is subsequently utilized… | |
| Modificada | Crítica (9.6) | 0.67% | — | Home-assistant | 19/10/2023 | 17/6/2026 | Home assistant is an open source home automation. The Home Assistant login page allows users to use their local Home Assistant credentials and log in to another website that specifies the `redirect_uri` and `client_id` parameters. Although the `redirect_uri` validation typically ensures that it matches the `client_id`… | |
| Modificada | Media (4.8) | 0.34% | — | Davidlingren Media Library Assistant | 17/10/2023 | 17/6/2026 | Auth. (author+) Stored Cross-Site Scripting (XSS) vulnerability in David Lingren Media Library Assistant plugin <= 3.11 versions. | |
| Modificada | Alta (8.8) | 0.21% | — | Rayhan1 AI Content Writing Assistant | 12/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in ReCorp AI Content Writing Assistant (Content Writer, GPT 3 & 4, ChatGPT, Image Generator) All in One plugin <= 1.1.5 versions. | |
| Analizada | Alta (7.5) | 100% | ⚠ Explotación activa💥 Exploit | Siemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Sinec INSSiemens Sinec NMSSiemens ST7 Scadaconnect+161 | 10/10/2023 | 11/8/2026 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. | |
| Modificada | Alta (8.8) | 1.3% | — | Atos Unify Openscape 4000 AssistantAtos Unify Openscape 4000 Manager | 9/10/2023 | 17/6/2026 | Atos Unify OpenScape 4000 Platform V10 R1 before Hotfix V10 R1.42.2 4000 and Manager Platform V10 R1 before Hotfix V10 R1.42.2 allow command injection by an authenticated attacker into the platform operating system, leading to administrative access, via dtb pages of the platform portal. This is also known as… | |
| Modificada | Alta (8.8) | 1.3% | — | Atos Unify Openscape 4000 AssistantAtos Unify Openscape 4000 Manager | 9/10/2023 | 17/6/2026 | Atos Unify OpenScape 4000 Platform V10 R1 before Hotfix V10 R1.42.2 and 4000 and Manager Platform V10 R1 before Hotfix V10 R1.42.2 allow command injection by an authenticated attacker into the platform operating system, leading to administrative access via the webservice. This is also known as OSFOURK-24120. | |
| Modificada | Alta (8.8) | 1.3% | — | Atos Unify Openscape 4000 AssistantAtos Unify Openscape 4000 Manager | 9/10/2023 | 17/6/2026 | Atos Unify OpenScape 4000 Assistant V10 R1 before V10 R1.42.1, 4000 Assistant V10 R0, 4000 Manager V10 R1 before V10 R1.42.1, and 4000 Manager V10 R0 allow Authenticated Command Injection via AShbr. This is also known as OSFOURK-24039. | |
| Modificada | Alta (7.5) | 0.47% | — | Atos Unify Openscape 4000 AssistantAtos Unify Openscape 4000 Manager | 9/10/2023 | 17/6/2026 | Atos Unify OpenScape 4000 Assistant V10 R1 before V10 R1.34.7, 4000 Assistant V10 R1.42.0, 4000 Assistant V10 R0, 4000 Manager V10 R1 before V10 R1.34.7, 4000 Manager V10 R1.42.0, and 4000 Manager V10 R0 expose sensitive information that may allow lateral movement to the backup system via AShbr. This is also known as… | |
| Modificada | Media (5.4) | 0.26% | — | Samsung Assistant | 4/10/2023 | 17/6/2026 | Improper authorization in PushMsgReceiver of Samsung Assistant prior to version 8.7.00.1 allows attacker to execute javascript interface. To trigger this vulnerability, user interaction is required. | |
| Modificada | Baja (3.3) | 0.14% | — | Samsung Sassistant | 4/10/2023 | 17/6/2026 | Improper Preservation of Permissions vulnerability in SAssistant prior to version 8.7 allows local attackers to access backup data in SAssistant. | |
| Modificada | Media (6.5) | 0.84% | — | Gladysassistant Gladys Assistant | 25/9/2023 | 17/6/2026 | A path traversal in Gladys Assistant v4.26.1 and below allows authenticated attackers to extract sensitive files in the host machine by exploiting a non-sanitized user input. | |
| Modificada | Media (5.4) | 0.55% | — | Davidlingren Media Library Assistant | 22/9/2023 | 17/6/2026 | The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mla_gallery' shortcode in versions up to, and including, 3.10 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with… | |
| Modificada | Alta (7.4) | 0.24% | — | Mimsoftware AssistantMimsoftware Client | 19/9/2023 | 17/6/2026 | Improper Restriction of XML External Entity Reference vulnerability in MIM Assistant and Client DICOM RTst Loading modules allows XML Entity Linking / XML External Entities Blowup. In order to take advantage of this vulnerability, an attacker must craft a malicious XML document, embed this document into specific 3rd… | |
| Modificada | Crítica (9.8) | 2.0% | — | Wibu Codemeter RuntimeTrumpf OseonTrumpf ProgrammingtubeTrumpf Teczonebend+20 | 13/9/2023 | 17/6/2026 | A heap buffer overflow vulnerability in Wibu CodeMeter Runtime network service up to version 7.60b allows an unauthenticated, remote attacker to achieve RCE and gain full access of the host system. | |
| Modificada | Crítica (9.8) | 86% | 💥 Exploit | Davidlingren Media Library Assistant | 6/9/2023 | 17/6/2026 | The Media Library Assistant plugin for WordPress is vulnerable to Local File Inclusion and Remote Code Execution in versions up to, and including, 3.09. This is due to insufficient controls on file paths being supplied to the 'mla_stream_file' parameter from the ~/includes/mla-stream-image.php file, where images are… | |
| Modificada | Alta (7.5) | 1.6% | — | LG LED Assistant | 4/9/2023 | 17/6/2026 | This vulnerability allows remote attackers to disclose sensitive information on affected installations of LG LED Assistant. Authentication is not required to exploit this vulnerability. The specific flaw exists within the /api/thumbnail endpoint. The issue results from the lack of proper validation of a user-supplied… | |
| Modificada | Alta (7.5) | 1.6% | — | LG LED Assistant | 4/9/2023 | 17/6/2026 | This vulnerability allows remote attackers to disclose sensitive information on affected installations of LG LED Assistant. Authentication is not required to exploit this vulnerability. The specific flaw exists within the /api/download/updateFile endpoint. The issue results from the lack of proper validation of a… | |
| Modificada | Crítica (9.8) | 2.5% | — | LG LED Assistant | 4/9/2023 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of LG LED Assistant. Authentication is not required to exploit this vulnerability. The specific flaw exists within the /api/installation/setThumbnailRc endpoint. The issue results from the lack of proper validation of a… | |
| Modificada | Crítica (9.8) | 2.5% | — | LG LED Assistant | 4/9/2023 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of LG LED Assistant. Authentication is not required to exploit this vulnerability. The specific flaw exists within the /api/settings/upload endpoint. The issue results from the lack of proper validation of a user-supplied… | |
| Modificada | Media (4.8) | 0.44% | — | Bitapps BIT Assist | 21/8/2023 | 17/6/2026 | The Bit Assist WordPress plugin before 1.1.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Alta (8.1) | 0.47% | — | SAP Contributor License Agreement Assistant | 15/8/2023 | 17/6/2026 | A missing authorization check allows an arbitrary authenticated user to perform certain operations through the API of CLA-assistant by executing specific additional steps. This allows an arbitrary authenticated user to read CLA information including information of the persons who signed them as well as custom fields… | |
| Modificada | Crítica (9.6) | 0.57% | — | Intel Driver & Support Assistant | 11/8/2023 | 17/6/2026 | Cross-site scripting (XSS) for the Intel(R) DSA software before version 23.1.9 may allow unauthenticated user to potentially enable escalation of privilege via network access. |