Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

1906 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (4.9)0.37%—Nextendweb Smart Slider 3AI30/7/202517/6/2026
The Smart Slider 3 plugin for WordPress is vulnerable to time-based SQL Injection via the ‘sliderid’ parameter in all versions up to, and including, 3.5.1.28 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for…
AplazadaAlta (8.6)0.93%—Apache ActivemqAIHanwha-security Smart Security ManagerAI25/7/202517/6/2026
A client-side remote code execution vulnerability exists in Hanwha Techwin Smart Security Manager (SSM) versions 1.32 and 1.4, due to improper restrictions on the PUT method exposed by the bundled Apache ActiveMQ instance (running on port 8161). An attacker can exploit this flaw through a Cross-Origin Resource Sharing…
AnalizadaMedia (5.5)0.12%—IBM Smartcloud Analytics LOG Analysis23/7/202517/6/2026
IBM SmartCloud Analytics - Log Analysis 1.3.7.0, 1.3.7.1, 1.3.7.2, 1.3.8.0, 1.3.8.1, and 1.3.8.2 could allow a local, authenticated attacker to bypass client-side enforcement of security to manipulate data.
AnalizadaMedia (5.5)0.12%—IBM Smartcloud Analytics LOG Analysis23/7/202517/6/2026
IBM SmartCloud Analytics - Log Analysis 1.3.7.0, 1.3.7.1, 1.3.7.2, 1.3.8.0, 1.3.8.1, and 1.3.8.2 could allow a local, authenticated attacker to bypass client-side enforcement of security to manipulate data.
AnalizadaMedia (6.1)0.18%—IBM Smartcloud Analytics LOG Analysis23/7/202517/6/2026
IBM SmartCloud Analytics - Log Analysis 1.3.7.0, 1.3.7.1, 1.3.7.2, 1.3.8.0, 1.3.8.1, and 1.3.8.2 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting,…
AnalizadaMedia (5.5)0.11%—IBM Smartcloud Analytics LOG Analysis23/7/202517/6/2026
IBM SmartCloud Analytics - Log Analysis 1.3.7.0, 1.3.7.1, 1.3.7.2, 1.3.8.0, 1.3.8.1, and 1.3.8.2 could allow a local user to cause a denial of service due to improper validation of specified type of input.
AplazadaMedia (5.1)0.12%—Motorola Smart ConnectAI17/7/202517/6/2026
A vulnerability was reported in version 1.0 of the Bluetooth Transmission Alliance protocol adopted by Motorola Smart Connect Android Application that could allow a nearby attacker within the Bluetooth interaction range to intercept files when transferred to a device not paired in Smart Connect.
AplazadaAlta (7.1)0.16%—Motorola Software FIX Rescue AND Smart AssistantAI17/7/202517/6/2026
A DLL hijacking vulnerability was reported in the Motorola Software Fix (Rescue and Smart Assistant) installer that could allow a local attacker to escalate privileges during installation of the software.
AplazadaMedia (6.5)0.18%—Crocoblock JetsmartfiltersAI16/7/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetSmartFilters jet-smart-filters allows Stored XSS.This issue affects JetSmartFilters: from n/a through <= 3.6.8.
AnalizadaMedia (5.4)0.24%—Wpclever WPC Smart Compare FOR Woocommerce11/7/202517/6/2026
The WPC Smart Compare for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'shortcode_btn' shortcode in all versions up to, and including, 6.4.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated…
AplazadaCrítica (9.9)0.32%—Radiflow Isap Smart CollectorAI9/7/202517/6/2026
An unauthenticated user with management network access can get and modify the Radiflow iSAP Smart Collector (CentOS 7 - VSAP 1.20) configuration. The device has two web servers that expose unauthenticated REST APIs on the management network (TCP ports 8084 and 8086). An attacker can use these APIs to get access to all…
AplazadaAlta (8.7)0.36%—Radiflow Isap Smart CollectorAICentos 7AI9/7/202517/6/2026
The Linux distribution underlying the Radiflow iSAP Smart Collector (CentOS 7 - VSAP 1.20) is obsolete and reached end of life (EOL) on June 30, 2024. Thus, any unmitigated vulnerability could be exploited to affect this product.
AplazadaMedia (6.8)0.29%—Radiflow Isap Smart CollectorAI9/7/202517/6/2026
The Linux deprivileged user vpuser in Radiflow iSAP Smart Collector (CentOS 7 - VSAP 1.20) can read the entire file system content, including files belonging to other users and having restricted access (like, for example, the root password hash).
AnalizadaAlta (7.8)0.09%—Qualcomm 315 5G IOT FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 FirmwareQualcomm Ar8035 Firmware+3408/7/202517/6/2026
Memory corruption whhile handling the subsystem failure memory during the parsing of video packets received from the video firmware.
AnalizadaAlta (7.8)0.09%—Qualcomm 315 5G IOT Modem FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 FirmwareQualcomm Ar8035 Firmware+3408/7/202517/6/2026
Memory corruption while processing video packets received from video firmware.
AnalizadaAlta (7.5)0.22%—Qualcomm Sa8620p FirmwareQualcomm Sa8650p FirmwareQualcomm Sa8770p FirmwareQualcomm Sa8775p Firmware+1888/7/202517/6/2026
Transient DOS while processing received beacon frame.
AnalizadaAlta (7.5)0.22%—Qualcomm Sm8635p FirmwareQualcomm Sm8650q FirmwareQualcomm Sm8735 FirmwareQualcomm Sm8750 Firmware+1818/7/202517/6/2026
Transient DOS may occur while processing malformed length field in SSID IEs.
AnalizadaMedia (5.5)0.08%—Qualcomm Apq8017 FirmwareQualcomm Apq8037 FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8035 Firmware+2718/7/202517/6/2026
Transient DOS when importing a PKCS#8-encoded RSA private key with a zero-sized modulus.
AnalizadaAlta (7.8)0.09%—Qualcomm Aqt1000 FirmwareQualcomm Ar8035 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 Firmware+2428/7/202517/6/2026
Memory corruption while retrieving the CBOR data from TA.
AnalizadaAlta (8.2)0.22%—Qualcomm Sm6250 FirmwareQualcomm Sm6370 FirmwareQualcomm Sm7315 FirmwareQualcomm Sm7325p Firmware+1758/7/202517/6/2026
Information disclosure while decoding this RTP packet Payload when UE receives the RTP packet from the network.
AplazadaCrítica (9.3)0.32%—Wpo-hr NGG Smart Image SearchAI4/7/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in wpo-HR NGG Smart Image Search ngg-smart-image-search allows SQL Injection.This issue affects NGG Smart Image Search: from n/a through <= 3.4.1.
ModificadaMedia (5.4)0.26%—Archalj Smart Docs4/7/202517/6/2026
The Smart Docs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'smartdocs_search' shortcode in all versions up to, and including, 1.1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with…
AplazadaAlta (8.7)0.51%—Dahua Smart Cloud GatewayAI1/7/202517/6/2026
An SQL injection vulnerability exists in the Dahua Smart Cloud Gateway Registration Management Platform via the username parameter in the /index.php/User/doLogin endpoint. The application fails to properly sanitize user input, allowing unauthenticated attackers to inject arbitrary SQL statements and potentially…
AnalizadaAlta (7.2)0.21%—Checkpoint Smartconsole29/6/202517/6/2026
Credentials are not cleared from memory after being used. A user with Administrator permissions can execute memory dump for SmartConsole process and fetch them.
AplazadaMedia (6.5)0.23%—Smart AgendaAI27/6/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Smart Agenda Smart Agenda smart-agenda-prise-de-rendez-vous-en-ligne allows Stored XSS.This issue affects Smart Agenda: from n/a through <= 4.9.