Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
1046 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 0.49% | — | Chargepoint Home Flex Nema 14-50 Plug FirmwareChargepoint Home Flex Hardwired FirmwareChargepoint Home Flex Nema 6-50 Plug Firmware | 31/1/2025 | 17/6/2026 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of ChargePoint Home Flex charging stations. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of OCPP messages. The issue results from the lack of proper… | |
| Analizada | Media (6.5) | 0.23% | — | Chargepoint Home Flex Nema 14-50 Plug FirmwareChargepoint Home Flex Hardwired FirmwareChargepoint Home Flex Nema 6-50 Plug Firmware | 31/1/2025 | 17/6/2026 | This vulnerability allows network-adjacent attackers to compromise transport security on affected installations of ChargePoint Home Flex charging stations. Authentication is not required to exploit this vulnerability. The specific flaw exists within the CURLOPT_SSL_VERIFYHOST setting. The issue results from the lack… | |
| Analizada | Alta (8.8) | 0.47% | — | Chargepoint Home Flex Nema 14-50 Plug FirmwareChargepoint Home Flex Hardwired FirmwareChargepoint Home Flex Nema 6-50 Plug Firmware | 31/1/2025 | 17/6/2026 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of ChargePoint Home Flex charging stations. Authentication is not required to exploit this vulnerability. The specific flaw exists within the wlanchnllst function. The issue results from the lack of proper… | |
| Analizada | Alta (8.8) | 0.47% | — | Chargepoint Home Flex Nema 14-50 Plug FirmwareChargepoint Home Flex Hardwired FirmwareChargepoint Home Flex Nema 6-50 Plug Firmware | 31/1/2025 | 17/6/2026 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of ChargePoint Home Flex charging stations. Authentication is not required to exploit this vulnerability. The specific flaw exists within the SrvrToSmSetAutoChnlListMsg function. The issue results from the lack of… | |
| Aplazada | Media (6.5) | 0.32% | — | Midea Group CO LTD Midea Home IOSAI | 27/1/2025 | 17/6/2026 | An issue in Midea Group Co., Ltd Midea Home iOS 9.3.12 allows attackers to access sensitive user information via supplying a crafted link. | |
| Aplazada | Media (6.5) | 0.32% | — | Shenzhen Intellirocks Tech CO LTD Govee HomeAI | 27/1/2025 | 17/6/2026 | An issue in Shenzhen Intellirocks Tech Co. Ltd Govee Home iOS 6.5.01 allows attackers to access sensitive user information via supplying a crafted payload. | |
| Analizada | Crítica (9.5) | 0.38% | — | Ecovacs Home | 23/1/2025 | 17/6/2026 | ECOVACS HOME mobile app plugins for specific robots do not properly validate TLS certificates. An unauthenticated attacker can read or modify TLS traffic and obtain authentication tokens. | |
| Analizada | Media (6) | 0.48% | — | Ecovacs Home | 23/1/2025 | 17/6/2026 | The cloud service used by ECOVACS robot lawnmowers and vacuums allows authenticated attackers to bypass the PIN entry required to access the live video feed. | |
| Aplazada | Crítica (9.8) | 0.43% | — | Favethemes Homey Login RegisterAI | 21/1/2025 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in favethemes Homey Login Register homey-login-register allows Privilege Escalation.This issue affects Homey Login Register: from n/a through <= 2.4.0. | |
| Aplazada | Alta (7.2) | 0.53% | — | Iocharger HomeAI | 9/1/2025 | 17/6/2026 | Patch traversal, External Control of File Name or Path vulnerability in Iocharger Home allows deletion of arbitrary files This issue affects Iocharger firmware for AC model before firmware version 25010801. Likelihood: High, but requires authentication Impact: Critical – The vulnerability can be used to delete any… | |
| Analizada | Media (5.1) | 0.68% | — | Acetech Home Clean Services Management System | 7/1/2025 | 17/6/2026 | A vulnerability has been found in SourceCodester Home Clean Services Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /public_html/admin/process.php. The manipulation of the argument type/length/business leads to sql injection. The attack can be… | |
| Analizada | Alta (7.5) | 0.36% | — | Qualcomm Ar8035 FirmwareQualcomm Csr8811 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 Firmware+179 | 6/1/2025 | 17/6/2026 | Transient DOS can occur when the driver parses the per STA profile IE and tries to access the EXTN element ID without checking the IE length. | |
| Aplazada | Alta (7.3) | 0.28% | — | Huawei Home Music SystemAI | 28/12/2024 | 17/6/2026 | Some Huawei home music system products have a path traversal vulnerability. Successful exploitation of this vulnerability may cause unauthorized file deletion or file permission change.(Vulnerability ID:HWPSIRT-2023-53450) This vulnerability has been assigned a (CVE)ID:CVE-2023-7263 | |
| Aplazada | Alta (8) | 0.30% | — | Huawei Home Music SystemAI | 26/12/2024 | 17/6/2026 | Huawei Home Music System has a path traversal vulnerability. Successful exploitation of this vulnerability may cause the music host file to be deleted or the file permission to be changed.(Vulnerability ID:HWPSIRT-2023-60613) | |
| Analizada | Alta (8.8) | 0.55% | — | Dell Supportassist FOR Business PCSDell Supportassist FOR Home PCS | 25/12/2024 | 17/6/2026 | Dell SupportAssist for Home PCs versions 4.6.1 and prior and Dell SupportAssist for Business PCs versions 4.5.0 and prior, contain a symbolic link (symlink) attack vulnerability in the software remediation component. A low-privileged authenticated user could potentially exploit this vulnerability, gaining privileges… | |
| Aplazada | Media (6.3) | 0.56% | — | Home-galleryAI | 23/12/2024 | 17/6/2026 | Home-Gallery.org is a self-hosted open-source web gallery to browse personal photos and videos. In 1.15.0 and earlier, an open CORS policy in app.js may allow an attacker to view the images of home-gallery when it is using the default settings. The following express middleware allows any website to make a cross site… | |
| Aplazada | Media (5.3) | 0.28% | — | Home-galleryAI | 23/12/2024 | 17/6/2026 | Home-Gallery.org is a self-hosted open-source web gallery to browse personal photos and videos. In 1.15.0 and earlier, the default setup of home-gallery is vulnerable to DNS rebinding. Home-gallery is set up without TLS and user authentication by default, leaving it vulnerable to DNS rebinding. In this attack, an… | |
| Aplazada | Alta (7.8) | 0.20% | — | Evoko HomeAI | 23/12/2024 | 17/6/2026 | Incorrect default permissions vulnerability in Evoko Home, affecting version 2.4.2 to 2.7.4. A non-admin user could exploit weak file and folder permissions to escalate privileges, execute arbitrary code and maintain persistence on the compromised machine. It has been identified that full control permissions exist on… | |
| Aplazada | Alta (7.2) | 1.2% | — | Home 5G Hr02AIHome Wi-fi Station Sh-54cAI | 23/12/2024 | 17/6/2026 | home 5G HR02 and Wi-Fi STATION SH-54C contain an OS command injection vulnerability in the configuration restore function. An arbitrary OS command may be executed with the root privilege by an administrative user. | |
| Aplazada | Media (5.3) | 0.58% | — | Home 5G Hr02AIWi-fi Station SH 52BAIWi-fi Station SH 54CAI | 23/12/2024 | 17/6/2026 | home 5G HR02, Wi-Fi STATION SH-52B, and Wi-Fi STATION SH-54C contain a buffer overflow vulnerability in the hidden debug function. A remote unauthenticated attacker may get the web console of the product down. | |
| Aplazada | Alta (7.2) | 1.2% | — | Home 5G Hr02AIWi-fi Station Sh-52bAIWi-fi Station Sh-54cAI | 23/12/2024 | 17/6/2026 | home 5G HR02, Wi-Fi STATION SH-52B, and Wi-Fi STATION SH-54C contain an OS command injection vulnerability in the HOST name configuration screen. An arbitrary OS command may be executed with the root privilege by an administrative user. | |
| Aplazada | Crítica (10) | 0.61% | — | Govee HomeAI | 19/12/2024 | 17/6/2026 | Incorrect authorization vulnerability in HTTP POST method in Govee Home application on Android and iOS allows remote attacker to control devices owned by other users via changing "device", "sku" and "type" fields' values. This issue affects Govee Home applications on Android and iOS in versions before 5.9. | |
| Aplazada | Alta (7.5) | 0.60% | — | Matter Project ChipAIConnectedhomeipAI | 18/12/2024 | 17/6/2026 | In raw\TCP.cpp in Matter (aka connectedhomeip or Project CHIP) through 1.4.0.0 before 27ca6ec, there is a NULL pointer dereference in TCPBase::ProcessSingleMessage via TCP packets with zero messageSize, leading to denial of service. | |
| Aplazada | Alta (7.5) | 0.39% | — | MatterAIConnectedhomeipAI | 18/12/2024 | 17/6/2026 | In Matter (aka connectedhomeip or Project CHIP) through 1.4.0.0, the WriteAcl function deletes all existing ACL entries first, and then attempts to recreate them based on user input. If input validation fails during decoding, the process stops, and no entries are restored by access-control-server.cpp, i.e., a denial… | |
| Aplazada | Media (6.4) | 0.37% | — | MY IDX Home SearchAI | 14/12/2024 | 17/6/2026 | The My IDX Home Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'homeasap-idx-landing' shortcode in all versions up to, and including, 2.1.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… |