Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

1046 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.4)0.35%—MY IDX Home SearchAI14/12/202417/6/2026
The My IDX Home Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'homeasap-idx-search' shortcode in all versions up to, and including, 2.1.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated…
AplazadaAlta (7.1)0.16%—Homejunction Spatialmatch IDXAI2/12/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in homejunction SpatialMatch IDX spatialmatch-free-lifestyle-search allows Stored XSS.This issue affects SpatialMatch IDX: from n/a through <= 3.0.9.
AnalizadaAlta (7.8)0.10%—Qualcomm Apq8017 FirmwareQualcomm Apq8037 FirmwareQualcomm Fastconnect 6800 FirmwareQualcomm Fastconnect 6900 Firmware+872/12/202417/6/2026
Memory corruption while processing API calls to NPU with invalid input.
AnalizadaAlta (7.5)0.26%—Qualcomm Ar8035 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Immersive Home 3210 Platform Firmware+1202/12/202417/6/2026
Transient DOS while parsing the ML IE when a beacon with common info length of the ML IE greater than the ML IE inside which this element is present.
AnalizadaAlta (7.8)0.10%—Qualcomm 315 5G IOT Modem FirmwareQualcomm 9205 LTE Modem FirmwareQualcomm 9206 LTE Modem FirmwareQualcomm 9207 LTE Modem Firmware+3252/12/202417/6/2026
Memory corruption when allocating and accessing an entry in an SMEM partition continuously.
AnalizadaMedia (6.5)0.56%—Chargepoint Home Flex Firmware22/11/202417/6/2026
ChargePoint Home Flex Bluetooth Low Energy Denial-of-Service Vulnerability. This vulnerability allows network-adjacent attackers to create a denial-of-service condition on affected installations of ChargePoint Home Flex charging devices. Authentication is not required to exploit this vulnerability. The specific flaw…
AnalizadaMedia (5.7)0.46%—Chargepoint Home Flex Firmware22/11/202417/6/2026
ChargePoint Home Flex Bluetooth Low Energy Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of ChargePoint Home Flex charging devices. User interaction is required to exploit this vulnerability. The specific flaw…
ModificadaMedia (6.8)0.26%—Homeserve8/11/20245/7/2026
An incorrect access control issue in HomeServe Home Repair' android app - 3.3.4 allows a physically proximate attacker to escalate privileges via the fingerprint authentication function.
AplazadaAlta (8.8)0.23%—Epson Expression Home Xp255AI7/11/202417/6/2026
An issue was discovered on Epson Expression Home XP255 20.08.FM10I8 devices. POST requests don't require (anti-)CSRF tokens or other mechanisms for validating that the request is from a legitimate source. In addition, CSRF attacks can be used to send text directly to the RAW printer interface. For example, an attack…
AplazadaAlta (8.4)0.26%—Epson Expression Home Xp255AI7/11/202417/6/2026
An issue was discovered on Epson Expression Home XP255 20.08.FM10I8 devices. With the SNMPv1 public community, all values can be read, and with the epson community, all the changeable values can be written/updated, as demonstrated by permanently disabling the network card or changing the DNS servers.
AplazadaAlta (8.8)0.43%—Epson Expression Home Xp255AI7/11/202417/6/2026
An issue was discovered on Epson Expression Home XP255 20.08.FM10I8 devices. By default, the device comes (and functions) without a password. The user is at no point prompted to set up a password on the device (leaving a number of devices without a password). In this case, anyone connecting to the web admin panel is…
AnalizadaCrítica (9.1)0.14%—Qualcomm Wsa8845h FirmwareQualcomm Wsa8845 FirmwareQualcomm Wsa8840 FirmwareQualcomm Wsa8835 Firmware+2314/11/202417/6/2026
Cryptographic issue when a controller receives an LMP start encryption command under unexpected conditions.
AnalizadaMedia (6.5)0.25%—Qualcomm Wsa8845h FirmwareQualcomm Wsa8845 FirmwareQualcomm Wsa8840 FirmwareQualcomm Wsa8835 Firmware+1184/11/202417/6/2026
Transient DOS while parsing fragments of MBSSID IE from beacon frame.
AplazadaMedia (4.8)0.27%—Fiberhome Hg6544cAI1/11/202417/6/2026
Cross Site Scripting vulnerability in FiberHome HG6544C RP2743 allows an attacker to execute arbitrary code via the SSID field in the WIFI Clients List not being sanitized
AplazadaCrítica (10)1.1%💥 PoCMasterhomepage Automatic TranslationAI29/10/202417/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in masterhomepage Automatic Translation automatic-translation allows Upload a Web Shell to a Web Server.This issue affects Automatic Translation: from n/a through <= 1.0.4.
AplazadaAlta (8.4)0.20%—Bosch Smart HomeAI24/10/20245/7/2026
Incorrect access control in the firmware update and download processes of Sylvania Smart Home v3.0.3 allows attackers to access sensitive information by analyzing the code and data within the APK file.
AplazadaMedia (5.3)0.28%—Com.ilife.home.globalAI14/10/202417/6/2026
An issue in ILIFE com.ilife.home.global 1.8.7 allows a remote attacker to obtain sensitive information via the firmware update process.
AplazadaAlta (7.5)0.51%—Inatronic Drivedeck.homeAI14/10/202417/6/2026
An issue in INATRONIC com.inatronic.drivedeck.home 2.6.23 allows a remote attacker to obtain sensitve information via the firmware update process.
AplazadaCrítica (9.8)0.52%—Sampmax HomemaxAI11/10/20245/7/2026
An Incorrect Access Control issue in SAMPMAX com.sampmax.homemax 2.1.2.7 allows a remote attacker to obtain sensitive information via the firmware update process.
AplazadaAlta (7.5)0.45%—Com.home.shellyAI11/10/20245/7/2026
An issue in Shelly com.home.shelly 1.0.4 allows a remote attacker to obtain sensitive information via the firmware update process
AplazadaMedia (4.9)0.80%—Adguard HomeAI8/10/202417/6/2026
An arbitrary file read vulnerability in Adguard Home before v0.107.52 allows authenticated attackers to access arbitrary files as root on the underlying Operating System via placing a crafted file into a readable directory.
AnalizadaAlta (7.5)0.32%—Qualcomm Snapdragon 8+ GEN 2 Mobile Platform FirmwareQualcomm Wsa8845h FirmwareQualcomm Wsa8845 FirmwareQualcomm Wsa8840 Firmware+1127/10/202417/6/2026
Transient DOS while parsing probe response and assoc response frame.
AnalizadaAlta (8.2)0.35%—Qualcomm Wsa8845h FirmwareQualcomm Wsa8845 FirmwareQualcomm Wsa8840 FirmwareQualcomm Wsa8835 Firmware+1557/10/202417/6/2026
Information disclosure while parsing the BSS parameter change count or MLD capabilities fields of the ML IE.
AnalizadaCrítica (9.8)0.60%—Qualcomm Snapdragon X65 5G Modem-rf System FirmwareQualcomm Sdx65m FirmwareQualcomm Sdx55 FirmwareQualcomm Qxm8083 Firmware+677/10/202417/6/2026
Memory corruption while redirecting log file to any file location with any file name.
AnalizadaAlta (7.5)0.32%—Qualcomm Snapdragon W5+ GEN 1 Wearable Platform FirmwareQualcomm Wsa8835 FirmwareQualcomm Wsa8830 FirmwareQualcomm Wsa8810 Firmware+1277/10/202417/6/2026
Transient DOS while parsing noninheritance IE of Extension element when length of IE is 2 of beacon frame.
Orbitaley — Vulnerabilidades