Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

1906 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.1)0.25%—Smartiolabs Smart NotificationAI27/6/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in smartiolabs Smart Notification allows Reflected XSS. This issue affects Smart Notification: from n/a through 10.3.
AplazadaAlta (8.8)0.49%—Convers LAB WP SmartpayAI27/6/202517/6/2026
Authentication Bypass Using an Alternate Path or Channel vulnerability in Convers Lab WP SmartPay smartpay allows Authentication Abuse.This issue affects WP SmartPay: from n/a through <= 2.7.13.
AnalizadaAlta (7.8)2.7%—Checkpoint Smartconsole19/6/202517/6/2026
Untrusted DLLs in the installer's directory may be loaded and executed, leading to potentially arbitrary code execution with the installer's privileges (admin).
AplazadaAlta (8.4)0.23%—Fujielectric Smart EditorAI17/6/202517/6/2026
Fuji Electric Smart Editor is vulnerable to an out-of-bounds write, which may allow an attacker to execute arbitrary code.
AplazadaAlta (8.4)0.22%—Fujielectric Smart EditorAI17/6/202517/6/2026
Fuji Electric Smart Editor is vulnerable to a stack-based buffer overflow, which may allow an attacker to execute arbitrary code.
AplazadaAlta (8.4)0.19%—Fujielectric Smart EditorAI17/6/202517/6/2026
Fuji Electric Smart Editor is vulnerable to an out-of-bounds read, which may allow an attacker to execute arbitrary code.
AplazadaCrítica (9.3)0.40%—Smartiolabs Smart NotificationAI17/6/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in smartiolabs Smart Notification allows Blind SQL Injection. This issue affects Smart Notification: from n/a through 10.3.
AplazadaCrítica (9.4)0.22%—Cyclone Matrix TRF Smart Keyless Entry SystemAIKIA SolutoAI13/6/202517/6/2026
Use of fixed learning codes, one code to lock the car and the other code to unlock it, in the Key Fob Transmitter in Cyclone Matrix TRF Smart Keyless Entry System, which allows a replay attack. Research was completed on the 2024 KIA Soluto. Attack confirmed on other KIA Models in Ecuador.
AplazadaCrítica (9.4)0.68%—KIA Smart Keyless Entry SystemAI13/6/202517/6/2026
Use of fixed learning codes, one code to lock the car and the other code to unlock it, the Key Fob Transmitter in KIA-branded Aftermarket Generic Smart Keyless Entry System, primarily distributed in Ecuador, which allows a replay attack. Manufacture is unknown at the time of release. CVE Record will be updated once…
AnalizadaMedia (5.5)0.14%—Dell PRO Smart Dock Sd25 FirmwareDell PRO Thunderbolt 4 Smart Dock Sd25tb4 Firmware12/6/202517/6/2026
Dell Smart Dock Firmware, versions prior to 01.00.08.01, contain an Insertion of Sensitive Information into Log File vulnerability. A user with local access could potentially exploit this vulnerability, leading to Information disclosure.
AplazadaAlta (8.7)0.63%—Honding Technology Smart Parking Management SystemAI9/6/202517/6/2026
Smart Parking Management System from Honding Technology has a Missing Authorization vulnerability, allowing remote attackers with regular privileges to access a specific functionality to create administrator accounts, and subsequently log into the system using those accounts.
AplazadaCrítica (9.3)0.48%—Honding Technology Smart Parking Management SystemAI9/6/202517/6/2026
Smart Parking Management System from Honding Technology has an Exposure of Sensitive Information vulnerability, allowing unauthenticated remote attackers to access a specific page and obtain plaintext administrator credentials.
AplazadaMedia (5.4)0.25%—Smartdatasoft CAR Repair ServicesAI6/6/202517/6/2026
Server-Side Request Forgery (SSRF) vulnerability in SmartDataSoft Car Repair Services car-repair-services allows Server Side Request Forgery.This issue affects Car Repair Services: from n/a through <= 5.0.
AnalizadaMedia (5)0.13%—Samsung Smart Switch4/6/202517/6/2026
Improper authorization in Smart Switch installed on non-Samsung Device prior to version 3.7.64.10 allows local attackers to read data with the privilege of Smart Switch. User interaction is required for triggering this vulnerability.
AplazadaMedia (6.4)0.29%—Smartwpress Music Player FOR ElementorAI3/6/202517/6/2026
The Music Player for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘album_buy_url’ parameter in all versions up to, and including, 2.4.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access…
AnalizadaAlta (7.5)1.0%⚠ Explotación activaQualcomm Ar8031 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 FirmwareQualcomm Fastconnect 7800 Firmware+403/6/202517/6/2026
Memory corruption while rendering graphics using Adreno GPU drivers in Chrome.
AnalizadaAlta (8.2)0.30%—Qualcomm Apq8017 FirmwareQualcomm Apq8064au FirmwareQualcomm Aqt1000 FirmwareQualcomm Fastconnect 6200 Firmware+2303/6/202517/6/2026
Information disclosure when an invalid RTCP packet is received during a VoLTE/VoWiFi IMS call.
AnalizadaAlta (8.2)0.24%—Qualcomm Apq8017 FirmwareQualcomm Aqt1000 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 Firmware+2213/6/202517/6/2026
Information disclosure may occur while processing goodbye RTCP packet from network.
AnalizadaAlta (8.2)0.24%—Qualcomm Apq8017 FirmwareQualcomm Apq8064au FirmwareQualcomm Aqt1000 FirmwareQualcomm Fastconnect 6200 Firmware+2303/6/202517/6/2026
Information disclosure may occur while decoding the RTP packet with invalid header extension from network.
AplazadaAlta (8.3)0.20%—Kruger Matz SmartphoneAISpsoftmobile ApplockAI30/5/202517/6/2026
An application "com.pri.applock", which is pre-loaded on Kruger&Matz smartphones, allows a user to encrypt any application using user-provided PIN code or by using biometric data. Exposed ”com.pri.applock.LockUI“ activity allows any other malicious application, with no granted Android system permissions, to inject an…
AplazadaMedia (4.4)0.29%—Rednao Smart FormsAI24/5/202517/6/2026
The Smart Forms – when you need more than just a contact form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.6.98 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
ModificadaCrítica (9.8)0.71%—Xylusthemes WP Smart Import23/5/202517/6/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Xylus Themes WP Smart Import wp-smart-import allows PHP Local File Inclusion.This issue affects WP Smart Import: from n/a through <= 1.1.3.
AplazadaCrítica (9.3)0.45%—Smartcms BUS Ticket Booking With Seat ReservationAI23/5/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in smartcms Bus Ticket Booking with Seat Reservation for WooCommerce scw-bus-seat-reservation allows SQL Injection.This issue affects Bus Ticket Booking with Seat Reservation for WooCommerce: from n/a through <= 1.7.
AnalizadaAlta (8.7)94%⚠ Explotación activa💥 ExploitSmartbedded Meteobridge VMSmartbedded Meteobridge Firmware21/5/202517/6/2026
The Meteobridge web interface let meteobridge administrator manage their weather station data collection and administer their meteobridge system through a web application written in CGI shell scripts and C. This web interface exposes an endpoint that is vulnerable to command injection. Remote unauthenticated attackers…
AplazadaCrítica (9.8)0.48%—Themegusta Smart Sections Theme Builder - Wpbakery Page Builder AddonAI19/5/202517/6/2026
Deserialization of Untrusted Data vulnerability in themegusta Smart Sections Theme Builder - WPBakery Page Builder Addon.This issue affects Smart Sections Theme Builder - WPBakery Page Builder Addon: from n/a through 1.7.8.