Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
1906 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.6) | 0.31% | — | Smart Video DoorbellAI | 26/11/2025 | 17/6/2026 | Smart Video Doorbell firmware versions prior to 2.01.078 contain an active debug code vulnerability that allows an attacker to connect via Telnet and gain access to the device. | |
| Aplazada | Alta (8.8) | 0.35% | — | Sircom Smart AlertAI | 25/11/2025 | 17/6/2026 | SiRcom SMART Alert (SiSA) allows unauthorized access to backend APIs. This allows an unauthenticated attacker to bypass the login screen using browser developer tools, gaining access to restricted parts of the application. | |
| Modificada | Alta (8.8) | 0.17% | — | Tuya SmartlifeTuyaTuya Smart | 24/11/2025 | 5/7/2026 | Cross-Site Request Forgery (CSRF) vulnerability in the OAuth implementation of the Tuya SDK 6.5.0 for Android and iOS, affects the Tuya Smart and Smartlife mobile applications, as well as other third-party applications that integrate the SDK, allows an attacker to link their own Amazon Alexa account to a victim's Tuya… | |
| Analizada | Alta (8.8) | 1.2% | — | Dell Smartfabric Os10 | 12/11/2025 | 17/6/2026 | Dell SmartFabric OS10 Software, versions prior to 10.6.1.0, contain an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Code execution. | |
| Analizada | Alta (8.8) | 1.2% | — | Dell Smartfabric Os10 | 12/11/2025 | 17/6/2026 | Dell SmartFabric OS10 Software, versions prior to 10.6.1.0, contain an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution. | |
| Analizada | Media (6.7) | 0.17% | — | Dell Smartfabric Os10 | 12/11/2025 | 6/10/2026 | Dell SmartFabric OS10 Software, versions prior to 10.6.1.0, contain an Improper Control of Generation of Code ('Code Injection') vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution. | |
| Analizada | Media (5.1) | 0.19% | — | Qdocs Smart School | 10/11/2025 | 7/10/2026 | Stored Cross Site Scripting (XSS) vulnerability in Smart School 7.0 due to lack of proper validation of user input when sending a POST request to '/online_admission', wich affects the parameters 'firstname', 'lastname', 'guardian_name' and others. This vulnerability could allow a remote user to send a specially… | |
| Aplazada | Alta (7.2) | 0.64% | 💥 PoC | Alex Reservations Smart Restaurant BookingAI | 8/11/2025 | 7/10/2026 | The Alex Reservations: Smart Restaurant Booking plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the /wp-json/srr/v1/app/upload/file REST endpoint in all versions up to, and including, 2.2.3. This makes it possible for authenticated attackers, with Administrator-level… | |
| Aplazada | Alta (8.8) | 0.52% | — | Smart Auto Upload ImagesAI | 8/11/2025 | 7/10/2026 | The Smart Auto Upload Images plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the auto-image creation functionality in all versions up to, and including, 1.2.0. This makes it possible for authenticated attackers, with Contributor-level access and above, to upload… | |
| Modificada | Alta (8.5) | 0.33% | — | Axiomthemes Smartseo | 6/11/2025 | 7/10/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in axiomthemes smart SEO smartSEO allows SQL Injection.This issue affects smart SEO: from n/a through <= 4.0. | |
| Analizada | Media (6.5) | 0.23% | — | Samsung Smart Switch | 5/11/2025 | 17/6/2026 | Use of insufficiently random value of secretKey in Smart Switch prior to version 3.7.68.6 allows adjacent attackers to access backup data from applications. | |
| Aplazada | Media (4.3) | 0.22% | — | Webtoffee Smart Coupons FOR WoocommerceAI | 31/10/2025 | 17/6/2026 | Missing Authorization vulnerability in WebToffee Smart Coupons for WooCommerce wt-smart-coupons-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Smart Coupons for WooCommerce: from n/a through <= 2.2.3. | |
| Aplazada | Media (5.1) | 0.35% | — | Urve Smart OfficeAI | 30/10/2025 | 17/6/2026 | URVE Smart Office is vulnerable to Stored XSS in report problem functionality. An attacker with a low-privileged account can upload an SVG file containing a malicious payload, which will be executed when a victim visits the URL of the uploaded resource. The resource is available to anyone without any form of… | |
| Aplazada | Alta (7.5) | 0.39% | — | Themesphere Smart-magAI | 29/10/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeSphere SmartMag smart-mag allows PHP Local File Inclusion.This issue affects SmartMag: from n/a through <= 10.3.0. | |
| Aplazada | Media (6.5) | 0.17% | — | Theme-sphere SmartmagAI | 29/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeSphere SmartMag smart-mag allows Stored XSS.This issue affects SmartMag: from n/a through <= 10.3.1. | |
| Aplazada | Alta (7.2) | 0.23% | — | Softing Industrial Automation Gmbh Smartlink Hw-pnAISofting Smartlink Hw-dpAI | 28/10/2025 | 17/6/2026 | Improper locking vulnerability in Softing Industrial Automation GmbH gateways allows infected memory and/or resource leak exposure.This issue affects smartLink HW-PN: from 1.02 through 1.03 smartLink HW-DP: 1.31 | |
| Aplazada | Alta (8.7) | 0.26% | — | Softing Industrial Automation Gmbh Smartlink Hw-pnAISofting Smartlink Hw-dpAI | 28/10/2025 | 17/6/2026 | Webserver crash caused by scanning on TCP port 80 in Softing Industrial Automation GmbH gateways and switch.This issue affects smartLink HW-PN: from 1.02 through 1.03 smartLink HW-DP: 1.31 | |
| Aplazada | Media (4.3) | 0.26% | — | Jthemes XsmartAI | 27/10/2025 | 17/6/2026 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Jthemes xSmart xsmart allows Code Injection.This issue affects xSmart: from n/a through <= 1.2.9.4. | |
| Aplazada | Media (4.3) | 0.31% | — | Mrityunjay Smart WetransferAI | 27/10/2025 | 17/6/2026 | Missing Authorization vulnerability in mrityunjay Smart WeTransfer smart-wetransfer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Smart WeTransfer: from n/a through <= 1.3. | |
| Aplazada | Media (6.5) | 0.21% | — | Wpclever WPC Smart MessagesAI | 27/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPClever WPC Smart Messages for WooCommerce wpc-smart-messages allows Stored XSS.This issue affects WPC Smart Messages for WooCommerce: from n/a through <= 4.2.8. | |
| Aplazada | Media (6.8) | 0.14% | — | Nous W3 Smart Wifi CameraAI | 24/10/2025 | 5/7/2026 | An issue in the firmware update mechanism of Nous W3 Smart WiFi Camera v1.33.50.82 allows unauthenticated and physically proximate attackers to escalate privileges to root via supplying a crafted update.tar archive file stored on a FAT32-formatted SD card. | |
| Aplazada | Media (5.4) | 0.23% | — | Wpmudev SmartcrawlAI | 22/10/2025 | 17/6/2026 | Missing Authorization vulnerability in WPMU DEV - Your All-in-One WordPress Platform SmartCrawl smartcrawl-seo.This issue affects SmartCrawl: from n/a through <= 3.14.3. | |
| Aplazada | Alta (7.1) | 0.25% | — | Rajan Vijayan WP Smart FlexsliderAI | 22/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rajan Vijayan WP Smart Flexslider wp-smart-flexslider allows Reflected XSS.This issue affects WP Smart Flexslider: from n/a through <= 2.5. | |
| Analizada | Alta (7.2) | 0.53% | 💥 PoC | Qdocs Smart School | 21/10/2025 | 17/6/2026 | QDocs Smart School Management System 7.1 allows authenticated users with roles such as "accountant" or "admin" to bypass file type restrictions in the media upload feature by abusing the alternate YouTube URL option. This logic flaw permits uploading of arbitrary PHP files, which are stored in a web-accessible… | |
| Aplazada | Media (5.3) | 0.34% | — | Wpclever WPC Smart Quick ViewAI | 18/10/2025 | 17/6/2026 | The WPC Smart Quick View for WooCommerce plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 4.2.5 via the 'woosq_quickview' AJAX endpoint due to insufficient restrictions on which posts can be included. This makes it possible for unauthenticated attackers to extract data… |