Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
1906 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.3) | 1.6% | — | Juniper Networks Session Smart RouterAIJuniper Networks Session Smart ConductorAIJuniper Networks WAN Assurance Managed RoutersAI | 27/1/2026 | 17/6/2026 | An Authentication Bypass Using an Alternate Path or Channel vulnerability in Juniper Networks Session Smart Router may allows a network-based attacker to bypass authentication and take administrative control of the device. This issue affects Session Smart Router: This issue affects Session Smart Conductor: This issue… | |
| Aplazada | Media (5.5) | 0.39% | — | Hisense Transtech Smart BUS Management SystemAI | 27/1/2026 | 17/6/2026 | A flaw has been found in Hisense TransTech Smart Bus Management System up to 20260113. Affected is the function Page_Load of the file YZSoft/Forms/XForm/BM/BusComManagement/TireMng.aspx. Executing a manipulation of the argument key can lead to sql injection. It is possible to launch the attack remotely. The exploit… | |
| Aplazada | Media (6.3) | 0.41% | — | Pymumu SmartdnsAI | 26/1/2026 | 17/6/2026 | A security flaw has been discovered in pymumu SmartDNS up to 47.1. This vulnerability affects the function _dns_decode_rr_head/_dns_decode_SVCB_HTTPS of the file src/dns.c of the component SVBC Record Parser. The manipulation results in stack-based buffer overflow. It is possible to launch the attack remotely. A high… | |
| Analizada | Crítica (9.3) | 88% | ⚠ Explotación activa💥 Exploit | Smartertools Smartermail | 23/1/2026 | 4/8/2026 | SmarterTools SmarterMail versions prior to build 9511 contain an unauthenticated remote code execution vulnerability in the ConnectToHub API method. The attacker could point the SmarterMail to the malicious HTTP server, which serves the malicious OS command. This command will be executed by the vulnerable application. | |
| Aplazada | Media (4.3) | 0.26% | — | Topdevs Smart Product ViewerAI | 23/1/2026 | 17/6/2026 | Missing Authorization vulnerability in topdevs Smart Product Viewer smart-product-viewer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Smart Product Viewer: from n/a through <= 1.5.4. | |
| Aplazada | Media (5.4) | 0.20% | — | Smartdatasoft ElectricianAI | 22/1/2026 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in SmartDataSoft Electrician - Electrical Service WordPress electrician allows Server Side Request Forgery.This issue affects Electrician - Electrical Service WordPress: from n/a through <= 5.6. | |
| Aplazada | Media (5.4) | 0.24% | — | Smartdatasoft Pool ServicesAI | 22/1/2026 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in SmartDataSoft Pool Services pool-services allows Server Side Request Forgery.This issue affects Pool Services: from n/a through <= 3.3. | |
| Aplazada | Media (6.5) | 0.32% | — | Jthemes XsmartAI | 22/1/2026 | 17/6/2026 | Missing Authorization vulnerability in Jthemes xSmart xsmart allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects xSmart: from n/a through <= 1.2.9.4. | |
| Aplazada | Alta (8.8) | 0.47% | — | Jthemes XsmartAI | 22/1/2026 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in Jthemes xSmart xsmart allows Privilege Escalation.This issue affects xSmart: from n/a through <= 1.2.9.4. | |
| Aplazada | Alta (7.1) | 0.27% | — | Jthemes XsmartAI | 22/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jthemes xSmart xsmart allows Reflected XSS.This issue affects xSmart: from n/a through <= 1.2.9.4. | |
| Analizada | Alta (7.4) | 0.36% | 💥 PoC | Atomberg Erica Smart FAN Firmware | 22/1/2026 | 17/6/2026 | An issue in Atomberg Atomberg Erica Smart Fan Firmware Version: V1.0.36 allows an attacker to obtain sensitive information and escalate privileges via a crafted deauth frame | |
| Analizada | Alta (7.4) | 0.44% | 💥 PoC | Beatxp Vega Smartwatch Firmware | 22/1/2026 | 17/6/2026 | An issue in Beat XP VEGA Smartwatch (Firmware Version - RB303ATV006229) allows an attacker to cause a denial of service via the BLE connection | |
| Analizada | Crítica (9.3) | 97% | ⚠ Explotación activa💥 Exploit | Smartertools Smartermail | 22/1/2026 | 4/8/2026 | SmarterTools SmarterMail versions prior to build 9511 contain an authentication bypass vulnerability in the password reset API. The force-reset-password endpoint permits anonymous requests and fails to verify the existing password or a reset token when resetting system administrator accounts. An unauthenticated… | |
| Analizada | Crítica (9.8) | 3.8% | 💥 PoC | Iptime N104s-r1 FirmwareIptime N104v FirmwareIptime N1E FirmwareIptime N1plus Firmware+159 | 20/1/2026 | 17/6/2026 | A command injection vulnerability exists in the upnp_relay() function in multiple ipTIME router models because the controlURL value used to pass port-forwarding information to an upper router is passed to system() without proper validation or sanitization, allowing OS command injection. | |
| Analizada | Baja (2) | 0.23% | — | Ligerosmart | 17/1/2026 | 17/6/2026 | A security vulnerability has been detected in LigeroSmart up to 6.1.26. The affected element is an unknown function of the file /otrs/index.pl. Such manipulation of the argument TicketID leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be… | |
| Analizada | Baja (2) | 0.33% | — | Ligerosmart | 17/1/2026 | 17/6/2026 | A weakness has been identified in LigeroSmart up to 6.1.26. Impacted is an unknown function of the file /otrs/index.pl?Action=AgentTicketZoom. This manipulation of the argument TicketID causes cross site scripting. It is possible to initiate the attack remotely. The exploit has been made available to the public and… | |
| Analizada | Media (4.6) | 0.53% | — | Smartftp | 16/1/2026 | 17/6/2026 | SmartFTP Client 10.0.2909.0 contains multiple denial of service vulnerabilities that allow attackers to crash the application through specific input manipulation. Attackers can trigger crashes by entering malformed paths, using invalid IP addresses, or clearing connection history in the client's interface. | |
| Analizada | Media (6.9) | 0.57% | — | Smartertools Smartertrack | 16/1/2026 | 17/6/2026 | SmarterTrack 7922 contains an information disclosure vulnerability in the Chat Management search form that reveals agent identification details. Attackers can access the vulnerable /Management/Chat/frmChatSearch.aspx endpoint to retrieve agents' first and last names along with their unique identifiers. | |
| Aplazada | Alta (8.8) | 0.25% | — | Build Smart ERPAI | 15/1/2026 | 17/6/2026 | Build Smart ERP 21.0817 contains an unauthenticated SQL injection vulnerability in the 'eidValue' parameter of the login validation endpoint. Attackers can inject stacked SQL queries using payloads like ';WAITFOR DELAY '0:0:3'-- to manipulate database queries and potentially extract or modify database information. | |
| Aplazada | Media (6.8) | 0.14% | — | Lenovo VantageAILenovo SmartperformanceaddinAI | 14/1/2026 | 17/6/2026 | An improper link following vulnerability was reported in the SmartPerformanceAddin for Lenovo Vantage that could allow an authenticated local user to perform an arbitrary file deletion with elevated privileges. | |
| Modificada | Media (4.6) | 0.17% | 💥 PoC | Airth Smart Home AQI Monitor Bootloader | 14/1/2026 | 5/7/2026 | An issue in AIRTH SMART HOME AQI MONITOR Bootloader v.1.005 allows a physically proximate attacker to obtain sensitive information via the UART port of the BK7231N controller (Wi-Fi and BLE module) on the device is open to access | |
| Aplazada | Baja (2.1) | 0.38% | 💥 PoC | Flycatcher Toys Smart SketcherAI | 11/1/2026 | 17/6/2026 | A flaw has been found in Flycatcher Toys smART Sketcher up to 2.0. This affects an unknown part of the component Bluetooth Low Energy Interface. This manipulation causes missing authentication. The attack can only be done within the local network. The exploit has been published and may be used. The vendor was… | |
| Aplazada | Crítica (9.3) | 0.43% | — | Inim Electronics Smartliving SmartlanAI | 8/1/2026 | 17/6/2026 | INIM Electronics Smartliving SmartLAN/G/SI <=6.x contains hard-coded credentials in its Linux distribution image that cannot be changed through normal device operations. Attackers can exploit these persistent credentials to log in and gain unauthorized system access across multiple SmartLiving device models. | |
| Aplazada | Media (6.9) | 0.38% | — | Smartliving Smartlan G SIAI | 8/1/2026 | 17/6/2026 | Smartliving SmartLAN/G/SI <=6.x contains an unauthenticated server-side request forgery vulnerability in the GetImage functionality through the 'host' parameter. Attackers can exploit the onvif.cgi endpoint by specifying external domains to bypass firewalls and perform network enumeration through arbitrary HTTP… | |
| Aplazada | Alta (8.7) | 1.9% | — | Smartliving SmartlanAI | 8/1/2026 | 17/6/2026 | SmartLiving SmartLAN <=6.x contains an authenticated remote command injection vulnerability in the web.cgi binary through the 'par' POST parameter with the 'testemail' module. Attackers can exploit the unsanitized parameter and system() function call to execute arbitrary system commands with root privileges using… |