Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
1906 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.28% | — | Wpclever WPC Smart WishlistAI | 18/10/2025 | 17/6/2026 | The WPC Smart Wishlist for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'wishlist_quickview' AJAX action in all versions up to, and including, 5.0.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to… | |
| Aplazada | Crítica (9.2) | 0.53% | — | SmartbiAI | 15/10/2025 | 3/9/2026 | SmartBI V8, V9, and V10 contain an unrestricted file upload vulnerability via the RMIServlet request handling logic. Under certain configurations or usage patterns, attackers can send specially crafted requests that cause the application to perform sensitive operations or execute arbitrary code on the host. The vendor… | |
| Aplazada | Media (5.3) | 0.23% | — | Wpclever WPC Smart WishlistAI | 11/10/2025 | 17/6/2026 | The WPC Smart Wishlist for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.0.3 via several wishlist AJAX functions due to missing validation on a user controlled key that is exposed when wishlists are shared. This makes it possible for… | |
| Analizada | Alta (7.8) | 0.10% | — | Samsung Smart Switch | 10/10/2025 | 17/6/2026 | Use of a broken or risky cryptographic algorithm in Smart Switch prior to version 3.7.67.2 allows local attackers to replace the restoring application. User interaction is required for triggering this vulnerability. | |
| Analizada | Media (5.5) | 0.10% | — | Samsung Smart Switch | 10/10/2025 | 17/6/2026 | Cleartext storage of sensitive information in Smart Switch prior to version 3.7.67.2 allows local attackers to access sensitive data. User interaction is required for triggering this vulnerability. | |
| Analizada | Media (6.5) | 0.27% | — | Samsung Smart Switch | 10/10/2025 | 30/9/2026 | Improper authentication in Smart Switch prior to version 3.7.66.6 allows adjacent attackers to access transferring data. | |
| Analizada | Media (5.5) | 0.10% | — | Samsung Smart Switch | 10/10/2025 | 30/9/2026 | Cleartext storage of sensitive information in Smart Switch prior to version 3.7.67.2 allows local attackers to access backup data from applications. User interaction is required for triggering this vulnerability. | |
| Analizada | Alta (7.8) | 0.09% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm 9205 LTE Modem FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 Firmware+295 | 9/10/2025 | 17/6/2026 | Memory corruption while processing a malformed license file during reboot. | |
| Analizada | Alta (7.8) | 0.09% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm 9205 LTE Modem FirmwareQualcomm Mdm9650 FirmwareQualcomm Msm8996au Firmware+315 | 9/10/2025 | 17/6/2026 | Memory corruption during PlayReady APP usecase while processing TA commands. | |
| Aplazada | Baja (3.5) | 0.31% | — | Yosmart YolinkAI | 6/10/2025 | 17/6/2026 | The YoSmart YoLink application through 2025-10-02 has session tokens with unexpectedly long lifetimes. | |
| Aplazada | Media (4.3) | 0.11% | — | Yosmart Yolink Smart HUBAI | 6/10/2025 | 17/6/2026 | The YoSmart YoLink Smart Hub firmware 0382 is unencrypted, and data extracted from it can be used to determine network access credentials. | |
| Aplazada | Media (4.9) | 0.28% | — | Yosmart YolinkAI | 6/10/2025 | 17/6/2026 | The YoSmart YoLink MQTT broker through 2025-10-02 does not enforce sufficient authorization controls to prevent cross-account attacks, allowing an attacker to remotely operate affected devices if the attacker obtains the associated device IDs. Because YoLink device IDs are predictable, an attacker can exploit this to… | |
| Aplazada | Media (4.7) | 0.18% | — | Yosmart Yolink HUBAIYosmart Yolink Mobile ApplicationAIYosmart Yolink Mqtt BrokerAI | 6/10/2025 | 17/6/2026 | Components of the YoSmart YoLink ecosystem through 2025-10-02 leverage unencrypted MQTT to communicate over the internet. An attacker with the ability to monitor network traffic could therefore obtain sensitive information or tamper with the traffic to control affected devices. This affects YoLink Hub 0382, YoLink… | |
| Aplazada | Baja (2.2) | 0.18% | — | Yosmart Yolink Smart HUB 0382AI | 6/10/2025 | 17/6/2026 | The YoSmart YoLink Smart Hub device 0382 exposes a UART debug interface. An attacker with direct physical access can leverage this interface to read a boot log, which includes network access credentials. | |
| Aplazada | Media (5.8) | 0.44% | — | Yosmart Yolink APIAI | 6/10/2025 | 30/9/2026 | The YoSmart YoLink API through 2025-10-02 uses an endpoint URL that is derived from a device's MAC address along with an MD5 hash of non-secret information, such as a key that begins with cf50. | |
| Aplazada | Media (5.5) | 0.22% | — | Archalj Smart DocsAI | 3/10/2025 | 17/6/2026 | The Smart Docs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject… | |
| Aplazada | Media (4.3) | 0.23% | — | Wpmudev SmartcrawlAI | 30/9/2025 | 17/6/2026 | The SmartCrawl SEO checker, analyzer & optimizer plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the update_submodule() function in all versions up to, and including, 3.14.3. This makes it possible for authenticated attackers, with Subscriber-level access… | |
| Aplazada | Media (5.9) | 0.24% | — | Sharkthemes Smart Related ProductsAI | 26/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sharkthemes Smart Related Products ai-related-products allows Stored XSS.This issue affects Smart Related Products: from n/a through <= 2.0.8. | |
| Analizada | Media (6.5) | 0.53% | — | Smartbear Swagger Petstore | 25/9/2025 | 17/6/2026 | An issue in petstore v.1.0.7 allows a remote attacker to execute arbitrary code via accessing a non-existent endpoint/cart, the server returns a 404-error page exposing sensitive information including the Servlet name (default) and server version | |
| Analizada | Media (6.1) | 0.38% | — | Smartbear Swagger Petstore | 25/9/2025 | 17/6/2026 | Cross Site Scripting vulnerability in petstore v.1.0.7 allows a remote attacker to execute arbitrary code via a crafted script to the /api/v3/pet | |
| Analizada | Media (6.5) | 0.43% | — | Smartbear Swagger Petstore | 25/9/2025 | 17/6/2026 | An issue in petstore v.1.0.7 allows a remote attacker to execute arbitrary code via the DELETE endpoint | |
| Analizada | Alta (7.5) | 0.21% | — | Qualcomm Apq8017 FirmwareQualcomm Apq8064au FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 Firmware+199 | 24/9/2025 | 17/6/2026 | Transient DOS while parsing the EPTM test control message to get the test pattern. | |
| Analizada | Crítica (9.8) | 0.40% | — | Qualcomm Apq8017 FirmwareQualcomm Apq8064au FirmwareQualcomm Aqt1000 FirmwareQualcomm Fastconnect 6200 Firmware+223 | 24/9/2025 | 17/6/2026 | Memory corruption when the UE receives an RTP packet from the network, during the reassembly of NALUs. | |
| Analizada | Alta (7.8) | 0.07% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 FirmwareQualcomm Ar8035 Firmware+245 | 24/9/2025 | 17/6/2026 | Memory corruption while performing private key encryption in trusted application. | |
| Analizada | Alta (8.2) | 0.26% | — | Qualcomm Apq8017 FirmwareQualcomm Apq8064au FirmwareQualcomm Aqt1000 FirmwareQualcomm Fastconnect 6200 Firmware+223 | 24/9/2025 | 25/9/2026 | Information disclosure while decoding RTP packet received by UE from the network, when payload length mentioned is greater than the available buffer length. |