Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
–

1906 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.2)0.26%—Qualcomm Sm8750 FirmwareQualcomm Sm8750p FirmwareQualcomm Sm8850 FirmwareQualcomm Sm8850p Firmware+16924/9/202525/9/2026
Information disclosure when UE receives the RTP packet from the network, while decoding and reassembling the fragments from RTP packet.
AnalizadaAlta (7.1)0.08%—Qualcomm 315 5G IOT Modem FirmwareQualcomm 9205 LTE Modem FirmwareQualcomm 9206 LTE Modem FirmwareQualcomm 9207 LTE Modem Firmware+28324/9/202525/9/2026
Cryptographic issue while performing RSA PKCS padding decoding.
AplazadaMedia (5.3)0.16%—Indian Bank IndsmartAIGoogle AndroidAI23/9/202517/6/2026
Indian Bank IndSMART Android App 3.8.1 is vulnerable to Missing SSL Certificate Validation in NuWebViewActivity.
AplazadaMedia (4.3)0.25%—Hashthemes Smart BlocksAI22/9/202517/6/2026
Missing Authorization vulnerability in hashthemes Smart Blocks smart-blocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Smart Blocks: from n/a through <= 2.4.
AplazadaMedia (6.5)0.21%—Wpo-hr NGG Smart Image SearchAI22/9/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpo-HR NGG Smart Image Search ngg-smart-image-search allows Stored XSS.This issue affects NGG Smart Image Search: from n/a through <= 3.4.3.
AplazadaMedia (5.4)0.21%—Smartdatasoft Dricub Driving SchoolAI22/9/202517/6/2026
Server-Side Request Forgery (SSRF) vulnerability in SmartDataSoft DriCub dricub-driving-school allows Server Side Request Forgery.This issue affects DriCub: from n/a through <= 2.9.
AplazadaMedia (5.3)0.27%—Smartdatasoft DricubAI22/9/202517/6/2026
Missing Authorization vulnerability in SmartDataSoft DriCub dricub-driving-school allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects DriCub: from n/a through <= 2.9.
AplazadaMedia (4.6)0.24%—Akilli Ticaret Software Technologies Smart Trade E-commerceAI22/9/202517/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Akıllı Ticaret Software Technologies Ltd. Co. Smart Trade E-Commerce allows Reflected XSS. This issue affects Smart Trade E-Commerce: before 4.5.0.0.1.
AplazadaBaja (2.3)0.24%—SmartstoreAI22/9/202517/6/2026
A vulnerability has been found in Smartstore up to 6.2.0. The affected element is an unknown function of the file /checkout/confirm/ of the component Gift Voucher Handler. The manipulation leads to race condition. The attack may be initiated remotely. The attack's complexity is rated as high. The exploitability is…
AplazadaAlta (7.8)0.11%—Smartvista SuiteAI18/9/202517/6/2026
Cross Site Request Forgery (CSRF) vulnerability in Smartvista BackOffice SmartVista Suite 2.2.22 via crafted GET request.
AplazadaAlta (7.1)0.48%💥 ExploitAC Smart IIAI14/9/202517/6/2026
A vulnerability has been discovered in AC Smart II where passwords can be changed without authorization. This page contains a hidden form for resetting the administrator password. The attacker can manipulate the page using developer tools to display and use the form. This form allows you to change the administrator…
AnalizadaBaja (2.1)0.34%—Fcba ZZM Smart Park Management System14/9/202517/6/2026
A security flaw has been discovered in fcba_zzm ics-park Smart Park Management System 2.0. This vulnerability affects unknown code of the file FileUploadUtils.java. The manipulation of the argument File results in unrestricted upload. The attack can be launched remotely. The exploit has been released to the public and…
AnalizadaBaja (2)0.43%—Fcba ZZM Smart Park Management System14/9/202517/6/2026
A vulnerability has been found in fcba_zzm ics-park Smart Park Management System 2.0. Affected is an unknown function of the file ruoyi-quartz/src/main/java/com/ruoyi/quartz/controller/JobController.java of the component Scheduled Task Module. Such manipulation leads to code injection. The attack may be performed from…
AplazadaMedia (6.5)0.32%—Smartcat Translator FOR WpmlAI11/9/202517/6/2026
The Smartcat Translator for WPML plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ parameter in all versions up to, and including, 3.1.72 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for…
AplazadaAlta (7.5)0.33%—Convers LAB WP SmartpayAI9/9/202517/6/2026
Improper Validation of Specified Quantity in Input vulnerability in Convers Lab WP SmartPay smartpay.This issue affects WP SmartPay: from n/a through <= 2.8.2.
ModificadaAlta (8.1)0.35%💥 PoCMezereon Smart Search AND Filter8/9/202517/6/2026
A cross-site scripting (XSS) vulnerability in Smart Search & Filter Shopify and BigCommerce apps allows a remote attacker to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into several filter parameter
AplazadaMedia (6.4)0.24%—Smart Table BuilderAI6/9/202517/6/2026
The Smart Table Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 1.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject…
AplazadaCrítica (9.8)0.44%—Axiomthemes Smart SEOAI5/9/202517/6/2026
Incorrect Privilege Assignment vulnerability in axiomthemes smart SEO smartSEO allows Privilege Escalation.This issue affects smart SEO: from n/a through <= 4.0.
AnalizadaMedia (5.3)0.38%—Samsung AndroidSamsung Smart Suggestions3/9/202517/6/2026
Improper authorization in Smart suggestions prior to SMR Apr-2023 Release 1 in Android 13 and 4.1.01.0 in Android 12 allows remote attackers to register a schedule.
AnalizadaBaja (1.1)0.22%—Seeedstudio Linkit Smart 7688 Firmware28/8/202525/9/2026
A vulnerability was identified in seeedstudio ReSpeaker LinkIt7688. Impacted is an unknown function of the file /etc/shadow of the component Administrative Interface. The manipulation leads to use of default credentials. An attack has to be approached locally. A high degree of complexity is needed for the attack. The…
AplazadaMedia (6.5)0.21%—Smart Widgets Better Post Filter Widgets FOR ElementorAI28/8/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Smart Widgets Better Post & Filter Widgets for Elementor better-post-filter-widgets-for-elementor allows Stored XSS.This issue affects Better Post & Filter Widgets for Elementor: from n/a through <= 1.6.1.
AplazadaCrítica (10)0.81%—Dahua Smart Park Integrated Management PlatformAI27/8/20253/9/2026
A path traversal vulnerability exists in the Dahua Smart Park Integrated Management Platform (also referred to as the Dahua Smart Campus Integrated Management Platform), affecting the SOAP-based GIS bitmap upload interface. The flaw allows unauthenticated remote attackers to upload arbitrary files to the server via…
AnalizadaCrítica (9.8)1.7%—Reolink Smart 2K+ Plug-in Wi-fi Video Doorbell With Chime Firmware22/8/202517/6/2026
Reolink Smart 2K+ Plug-in Wi-Fi Video Doorbell with Chime - firmware v3.0.0.4662_2503122283 was discovered to contain a command injection vulnerability via the setddns_pip_system() function.
AnalizadaAlta (7.5)0.52%—Reolink Smart 2K+ Plug-in Wi-fi Video Doorbell With Chime Firmware22/8/202517/6/2026
Incorrect access control in the RTMP server settings of Reolink Smart 2K+ Plug-in Wi-Fi Video Doorbell with Chime - firmware v3.0.0.4662_2503122283 allows unauthorized attackers to cause a Denial of Service (DoS) via initiating a large number of simultaneous ffmpeg-based stream pushes.
AplazadaMedia (4)0.14%—Reolink Smart 2K+ Plug-in Wi-fi Video DoorbellAI22/8/202517/6/2026
Reolink Smart 2K+ Plug-in Wi-Fi Video Doorbell with Chime - firmware v3.0.0.4662_2503122283 was discovered to manage users' sessions system wide instead of an account-by-account basis, potentially leading to a Denial of Service (DoS) via resource exhaustion. NOTE: the Supplier reports that the system-wide limit is…