Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
1906 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.3) | 0.27% | — | Reolink Smart 2K+ Plug-in Wi-fi Video Doorbell With Chime Firmware | 22/8/2025 | 17/6/2026 | A discrepancy in the error message returned by the login function of Reolink Smart 2K+ Plug-in Wi-Fi Video Doorbell with Chime - firmware v3.0.0.4662_2503122283 when entering the wrong username and password allows attackers to enumerate existing accounts. | |
| Aplazada | Media (6.5) | 0.21% | — | Reolink Smart 2K Plug-in Wi-fi Video Doorbell With ChimeAI | 22/8/2025 | 17/6/2026 | Insecure permissions in Reolink Smart 2K+ Plug-in Wi-Fi Video Doorbell with Chime - firmware v3.0.0.4662_2503122283 allow attackers to arbitrarily change other users' passwords via manipulation of the userName value. | |
| Aplazada | Media (5.3) | 0.24% | — | Reolink Smart 2K+ Plug-in Wi-fi Video Doorbell With ChimeAI | 22/8/2025 | 17/6/2026 | Insufficient privilege verification in Reolink Smart 2K+ Plug-in Wi-Fi Video Doorbell with Chime - firmware v3.0.0.4662_2503122283 allows authenticated attackers to create accounts with elevated privileges. | |
| Aplazada | Media (5.3) | 0.24% | — | Reolink Smart 2K Plus Plug IN WI FI Video Doorbell With ChimeAI | 22/8/2025 | 17/6/2026 | An Insecure Direct Object Reference (IDOR) vulnerability in Reolink Smart 2K+ Plug-in Wi-Fi Video Doorbell with Chime - firmware v3.0.0.4662_2503122283 allows unauthorized attackers to access the Admin-only settings and edit the session storage. | |
| Analizada | Crítica (9.8) | 0.34% | — | PDQ Smart Deploy | 22/8/2025 | 17/6/2026 | An issue in PDQ Smart Deploy V.3.0.2040 allows an attacker to escalate privileges via the Credential encryption routines in SDCommon.dll | |
| Analizada | Alta (7.8) | 0.19% | — | PDQ Smart Deploy | 22/8/2025 | 17/6/2026 | Insecure Permissions vulnerability in PDQ Smart Deploy V.3.0.2040 allows a local attacker to execute arbtirary code via the \HKLM\SYSTEM\Setup\SmartDeploy component | |
| Aplazada | Crítica (9.3) | 0.72% | — | Mitsubishielectric SmartrtuAI | 21/8/2025 | 17/6/2026 | A remote unauthenticated attacker who has bypassed authentication could execute arbitrary OS commands to disclose, tamper with, destroy or delete information in Mitsubishi Electric smartRTU, or cause a denial-of service condition on the product. | |
| Aplazada | Media (6.5) | 0.34% | — | Crocoblock JetsmartfiltersAI | 20/8/2025 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Crocoblock JetSmartFilters jet-smart-filters allows Retrieve Embedded Sensitive Data.This issue affects JetSmartFilters: from n/a through <= 3.6.7. | |
| Aplazada | Media (6.4) | 0.24% | — | Wpclever WPC Smart Quick ViewAI | 20/8/2025 | 17/6/2026 | The WPC Smart Quick View for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's woosq_btn shortcode in all versions up to, and including, 4.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Modificada | Baja (1.9) | 0.26% | — | Verkehrsauskunft Smartride | 19/8/2025 | 17/6/2026 | A vulnerability was detected in Verkehrsauskunft Österreich SmartRide, cleVVVer, BusBahnBim and Salzburg Verkehr up to 12.1.1(258) on Android. The impacted element is an unknown function of the file AndroidManifest.xml. The manipulation results in improper export of android application components. The attack must be… | |
| Aplazada | Media (6.4) | 0.21% | — | Wpclever WPC Smart CompareAI | 19/8/2025 | 17/6/2026 | The WPC Smart Compare for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via DOM elements in all versions up to, and including, 6.4.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above,… | |
| Analizada | Alta (7.5) | 0.28% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 FirmwareQualcomm Ar8035 Firmware+368 | 6/8/2025 | 17/6/2026 | Transient DOS while processing an ANQP message. | |
| Analizada | Alta (7.8) | 0.08% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm Apq8064au FirmwareQualcomm Ar8035 FirmwareQualcomm C-v2x 9150 Firmware+149 | 6/8/2025 | 17/6/2026 | Memory corruption while handling client exceptions, allowing unauthorized channel access. | |
| Analizada | Media (6.5) | 0.09% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm 9205 LTE Modem FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 Firmware+345 | 6/8/2025 | 17/6/2026 | Information disclosure while processing the hash segment in an MBN file. | |
| Analizada | Media (6.5) | 0.09% | — | Qualcomm Qcm4490 FirmwareQualcomm Qcm5430 FirmwareQualcomm Qcm6125 FirmwareQualcomm Qcm6490 Firmware+338 | 6/8/2025 | 17/6/2026 | Information disclosure while reading data from an image using specified offset and size parameters. | |
| Aplazada | Crítica (9.8) | 0.41% | — | Smartdatasoft Reveal ListingAI | 6/8/2025 | 17/6/2026 | The Reveal Listing plugin by smartdatasoft for WordPress is vulnerable to privilege escalation in versions up to, and including, 3.3. This is due to the plugin allowing users who are registering new accounts to set their own role or by supplying 'listing_user_role' field. This makes it possible for unauthenticated… | |
| Modificada | Media (4.3) | 0.82% | — | Commscope Ruckus Smartzone FirmwareCommscope Ruckus Network Director | 4/8/2025 | 17/6/2026 | RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build allows ../ directory traversal to read files. | |
| Modificada | Alta (8.8) | 2.1% | — | Commscope Ruckus Smartzone FirmwareCommscope Ruckus Network Director | 4/8/2025 | 17/6/2026 | In RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build, OS command injection can occur via an IP address field provided by an authenticated user. | |
| Modificada | Alta (8.8) | 1.8% | — | Commscope Ruckus Smartzone FirmwareCommscope Ruckus Network Director | 4/8/2025 | 17/6/2026 | RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build allows OS command injection via a certain parameter in an API route. | |
| Modificada | Alta (8.8) | 0.98% | — | Commscope Ruckus Smartzone FirmwareCommscope Ruckus Network Director | 4/8/2025 | 17/6/2026 | Ruckus SmartZone (SZ) before 6.1.2p3 Refresh Build allows authentication bypass via a valid API key and crafted HTTP headers. | |
| Analizada | Crítica (9.8) | 0.73% | — | Commscope Ruckus Smartzone Firmware | 4/8/2025 | 17/6/2026 | RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build has a hardcoded SSH private key for a root-equivalent user account. | |
| Modificada | Alta (7.8) | 0.15% | 💥 PoC | Aziot 2MP Full HD Smart Wi-fi Cctv Home Security Camera Firmware | 30/7/2025 | 5/7/2026 | The firmware of the AZIOT 2MP Full HD Smart Wi-Fi CCTV Home Security Camera (version V1.00.02) contains an Incorrect Access Control vulnerability that allows local attackers to gain root shell access. Once accessed, the device exposes critical data including Wi-Fi credentials and ONVIF service credentials stored in… | |
| Analizada | Alta (7.8) | 0.13% | — | Dell Smartfabric Os10 | 30/7/2025 | 17/6/2026 | Dell SmartFabric OS10 Software, versions prior to 10.6.0.5, contains a Use of Hard-coded Password vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. | |
| Analizada | Media (6.5) | 0.49% | — | Dell Smartfabric Os10 | 30/7/2025 | 17/6/2026 | Dell SmartFabric OS10 Software, versions prior to 10.6.0.5, contains an Improper Restriction of XML External Entity Reference vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access. | |
| Analizada | Media (5.5) | 0.17% | — | Dell Smartfabric Os10 | 30/7/2025 | 17/6/2026 | Dell SmartFabric OS10 Software, versions prior to 10.6.0.5 contains a Files or Directories Accessible to External Parties vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Filesystem access for attacker. |