Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

1906 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.4)0.28%—Smart APP BannersAI7/1/202617/6/2026
The Smart App Banners plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'size' and 'verticalalign' parameters of the 'app-store-download' shortcode in all versions up to, and including, 1.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it…
AnalizadaMedia (5.5)0.13%—Qualcomm Ar8035 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 FirmwareQualcomm Fastconnect 6200 Firmware+1717/1/20267/10/2026
Information disclosure when a weak hashed value is returned to userland code in response to a IOCTL call to obtain a session ID.
AnalizadaAlta (7.8)0.13%—Qualcomm Aqt1000 FirmwareQualcomm Ar8035 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 Firmware+2007/1/20267/10/2026
Memory corruption while processing identity credential operations in the trusted application.
AnalizadaMedia (6.7)0.14%—Qualcomm Csra6620 FirmwareQualcomm Csra6640 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 Firmware+1427/1/20267/10/2026
Memory corruption while processing shared command buffer packet between camera userspace and kernel.
AnalizadaMedia (6.6)0.12%—Qualcomm Sa6150p FirmwareQualcomm Sa6155 FirmwareQualcomm Sa6155p FirmwareQualcomm Sa7255p Firmware+2357/1/20267/10/2026
Memory corruption while handling buffer mapping operations in the cryptographic driver.
AnalizadaMedia (6.1)0.13%—Qualcomm Ar8031 FirmwareQualcomm Ar8035 FirmwareQualcomm Csr8811 FirmwareQualcomm Csra6620 Firmware+2957/1/20267/10/2026
Information disclosure while processing a firmware event.
AnalizadaMedia (5.5)0.12%—Qualcomm Qca6678aq FirmwareQualcomm Qca6688aq FirmwareQualcomm Qca6696 FirmwareQualcomm Qca6698aq Firmware+2197/1/20267/10/2026
Transient DOS while parsing video packets received from the video firmware.
AplazadaMedia (5.3)0.33%💥 PoCAuntyfey Smart Combination LockAI7/1/20267/10/2026
AuntyFey Smart Combination Lock firmware versions as of 2025-12-24 contain a vulnerability that allows an unauthenticated attacker within Bluetooth Low Energy (BLE) range to cause a denial of service by repeatedly initiating BLE connections. Sustained connection attempts interrupt keypad authentication input and…
AnalizadaBaja (2)0.27%—Ligerosmart2/1/202625/7/2026
A vulnerability was found in LigeroSmart up to 6.1.24. This affects an unknown part of the component Environment Variable Handler. Performing a manipulation of the argument REQUEST_URI results in cross site scripting. The attack may be initiated remotely. The exploit has been made public and could be used. Upgrading…
AnalizadaCrítica (10)86%⚠ Explotación activa💥 ExploitSmartertools Smartermail29/12/20257/10/2026
Successful exploitation of the vulnerability could allow an unauthenticated attacker to upload arbitrary files to any location on the mail server, potentially enabling remote code execution.
AplazadaAlta (8.8)0.48%—Smartwares Home EasyAI24/12/202517/6/2026
Smartwares HOME easy 1.0.9 contains an authentication bypass vulnerability that allows unauthenticated attackers to access administrative web pages by disabling JavaScript. Attackers can navigate to multiple administrative endpoints and to bypass client-side validation and access sensitive system information.
AplazadaMedia (5.1)0.17%—Smarthouse WebappAI24/12/202517/6/2026
SmartHouse Webapp 6.5.33 contains multiple cross-site request forgery and cross-site scripting vulnerabilities that allow attackers to perform unauthorized actions. Attackers can exploit these vulnerabilities by tricking logged-in users into visiting malicious websites or injecting malicious scripts into various…
AnalizadaAlta (8.8)0.34%💥 PoCLSC Smart Connect Indoor IP Camera Firmware22/12/202517/6/2026
LSC Smart Connect Indoor IP Camera 1.4.13 contains a RCE vulnerability in start_app.sh.
ModificadaAlta (8.1)0.50%—Axiomthemes Smartseo18/12/202517/6/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes smart SEO smartSEO allows PHP Local File Inclusion.This issue affects smart SEO: from n/a through <= 2.12.
AplazadaCrítica (9.3)0.35%—Smartcms Advance Seat Reservation Management FOR WoocommerceAI18/12/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in smartcms Advance Seat Reservation Management for WooCommerce scw-seat-reservation allows SQL Injection.This issue affects Advance Seat Reservation Management for WooCommerce: from n/a through <= 3.1.
AnalizadaAlta (7.8)0.10%—Qualcomm Ar8031 FirmwareQualcomm Ar8035 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 Firmware+10718/12/202517/6/2026
Memory corruption while handling IOCTL calls to set mode.
AnalizadaAlta (7.8)0.08%—Qualcomm Ar8031 FirmwareQualcomm Ar8035 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 Firmware+11118/12/202517/6/2026
Memory corruption while copying packets received from unix clients.
AnalizadaAlta (7.8)0.08%—Qualcomm 9206 LTE Modem FirmwareQualcomm Apq8017 FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 Firmware+20918/12/202517/6/2026
Memory corruption while processing MFC channel configuration during music playback.
AplazadaBaja (2.1)0.23%—Xiongwei Smart Catering Cloud PlatformAI16/12/202517/6/2026
A vulnerability was detected in Xiongwei Smart Catering Cloud Platform 2.1.6446.28761. The affected element is an unknown function of the file /dishtrade/dish_trade_detail_get. The manipulation of the argument filter results in sql injection. The attack can be executed remotely. The exploit is now public and may be…
AplazadaBaja (1.9)0.20%—Smartbit Commv SmartschoolAI15/12/20257/10/2026
A flaw has been found in Smartbit CommV Smartschool App up to 10.4.4. Impacted is an unknown function of the component be.smartschool.mobile.SplashActivity. Executing manipulation can lead to path traversal. The attack requires local access. The exploit has been published and may be used. The vendor was contacted…
AplazadaMedia (6.4)0.18%—Smartwp Lightweight AccordionAI15/12/20257/10/2026
The Lightweight Accordion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `lightweight-accordion` shortcode in all versions up to, and including, 1.5.20 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated…
AplazadaAlta (8.7)0.35%—Commax Smart Home SystemAI9/12/202517/6/2026
COMMAX Smart Home System is a smart IoT home solution that allows an unauthenticated attacker to disclose RTSP credentials in plain-text by exploiting the /overview.asp endpoint. Attackers can access sensitive information, including login credentials and DVR settings, by submitting a GET request to this endpoint.
AplazadaAlta (8.7)0.35%—Commax Smart Home SystemAI9/12/202517/6/2026
COMMAX Smart Home System allows an unauthenticated attacker to change configuration and cause denial-of-service through the setconf endpoint. Attackers can trigger a denial-of-service scenario by sending a malformed request to the setconf endpoint.
AplazadaCrítica (9.3)0.53%—Commax Smart Home System Cdp-1020nAI9/12/202517/6/2026
COMMAX Smart Home System CDP-1020n contains an SQL injection vulnerability that allows attackers to bypass authentication by injecting arbitrary SQL code through the 'id' parameter in 'loginstart.asp'. Attackers can exploit this by sending a POST request with malicious 'id' values to manipulate database queries and…
AnalizadaMedia (6.5)0.43%—Samsung Smart Touch Call2/12/202525/9/2026
Improper verification of source of a communication channel in SmartTouchCall prior to version 1.0.1.1 allows remote attackers to access sensitive information. User interaction is required for triggering this vulnerability.