Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

1906 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (4.8)0.30%—Shapedplugin Smart Post Show15/5/202517/6/2026
The Smart Post Show WordPress plugin before 3.0.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
ModificadaBaja (3.5)0.32%—Shapedplugin Smart Post Show15/5/202517/6/2026
The Smart Post Show WordPress plugin before 2.4.28 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
AnalizadaMedia (6.1)0.33%—Smartdatasoft Clasify Classified Listing15/5/202517/6/2026
The Clasify Classified Listing WordPress plugin through 1.0.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
AplazadaBaja (3.9)0.14%—Hitachi Jp1/it Desktop Management 2 - Smart Device ManagerAI15/5/202517/6/2026
Information Exposure vulnerability in Hitachi JP1/IT Desktop Management 2 - Smart Device Manager on Windows.This issue affects JP1/IT Desktop Management 2 - Smart Device Manager: from 12-00 before 12-00-08, from 11-10 through 11-10-08, from 11-00 through 11-00-05, from 10-50 through 10-50-06.
AplazadaMedia (5.3)0.16%—Hitachi Jp1/it Desktop Management 2 - Smart Device ManagerAI15/5/202517/6/2026
Weak encryption vulnerability in Hitachi JP1/IT Desktop Management 2 - Smart Device Manager on Windows.This issue affects JP1/IT Desktop Management 2 - Smart Device Manager: from 12-00 before 12-00-08, from 11-10 through 11-10-08, from 11-00 through 11-00-05, from 10-50 through 10-50-06.
AplazadaAlta (8.7)0.38%—Hitachi JP1 IT Desktop Management 2 Smart Device ManagerAI15/5/202517/6/2026
XXE vulnerability in Hitachi JP1/IT Desktop Management 2 - Smart Device Manager on Windows.This issue affects JP1/IT Desktop Management 2 - Smart Device Manager: from 12-00 before 12-00-08, from 11-10 through 11-10-08, from 11-00 through 11-00-05, from 10-50 through 10-50-06.
AplazadaMedia (6.5)0.26%—Wpo-hr NGG Smart Image SearchAI7/5/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpo-HR NGG Smart Image Search ngg-smart-image-search allows Stored XSS.This issue affects NGG Smart Image Search: from n/a through <= 3.3.3.
AplazadaMedia (4.3)0.29%—WpsmartpayAI7/5/202517/6/2026
The Download Manager and Payment Form WordPress Plugin – WP SmartPay plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions 1.1.0 to 2.7.13 via the show() function due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-level…
AnalizadaAlta (7.8)0.11%—Qualcomm Ar8035 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 FirmwareQualcomm Fastconnect 6200 Firmware+1476/5/202517/6/2026
Memory corruption while reading response from FW, when buffer size is changed by FW while driver is using this size to write null character at the end of buffer.
AnalizadaAlta (7.8)0.11%—Qualcomm Csra6620 FirmwareQualcomm Csra6640 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 Firmware+1026/5/202517/6/2026
Memory corruption while reading the FW response from the shared queue.
AnalizadaAlta (7.8)0.11%—Qualcomm 315 5G IOT Modem FirmwareQualcomm Apq8017 FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8035 Firmware+2626/5/202517/6/2026
Memory corruption while processing a data structure, when an iterator is accessed after it has been removed, potential failures occur.
AnalizadaAlta (7.8)0.11%—Qualcomm Aqt1000 FirmwareQualcomm Ar8035 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 Firmware+2086/5/202517/6/2026
Memory corruption while reading secure file.
AnalizadaAlta (7.5)0.41%—Smartcmsmarket Advance Seat Reservation Management FOR Woocommerce2/5/202517/6/2026
The Advance Seat Reservation Management for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'profileId' parameter in all versions up to, and including, 3.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it…
AplazadaCrítica (9.8)0.51%—Coresmartcontracts UniswapAI29/4/202517/6/2026
An issue in Coresmartcontracts Uniswap v.3.0 and fixed in v.4.0 allows a remote attacker to escalate privileges via the _modifyPosition function
AplazadaAlta (7.3)0.54%—Create Custom Forms FOR Wordpress With A Smart Form Plugin FOR Smart BusinessesAI26/4/202517/6/2026
The The Create custom forms for WordPress with a smart form plugin for smart businesses plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.2.4. This is due to the software allowing users to execute an action that does not properly validate a value before running…
AplazadaMedia (4.3)0.29%—Peter Raschendorfer Smart HashtagsAI24/4/202517/6/2026
Missing Authorization vulnerability in Peter Raschendorfer Smart Hashtags [#hashtagger] hashtagger allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Smart Hashtags [#hashtagger]: from n/a through <= 7.2.3.
AplazadaCrítica (9.8)0.79%—Smart Product ReviewAI19/4/202517/6/2026
The Wordpress Plugin Smart Product Review plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 1.0.4. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code…
AplazadaAlta (7.5)0.70%—Teamzt Smart AgreementsAIPHPAI17/4/202517/6/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in teamzt Smart Agreements smart-agreements allows PHP Local File Inclusion.This issue affects Smart Agreements: from n/a through <= 1.0.3.
AplazadaAlta (7.1)0.29%—AT Internet SmarttagAI17/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BenDlz AT Internet SmartTag at-internet allows Reflected XSS.This issue affects AT Internet SmartTag: from n/a through <= 0.2.
AnalizadaCrítica (10)99%⚠ Explotación activa💥 ExploitErlang/otpCisco Confd BasicCisco Network Services OrchestratorCisco Cloud Native Broadband Network Gateway+1916/4/202517/6/2026
Erlang/OTP is a set of libraries for the Erlang programming language. Prior to versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20, a SSH server may allow an attacker to perform unauthenticated remote code execution (RCE). By exploiting a flaw in SSH protocol message handling, a malicious actor could gain…
AnalizadaMedia (5.7)0.30%—Oracle Smart View FOR Office15/4/202517/6/2026
Vulnerability in the Oracle Smart View for Office product of Oracle Hyperion (component: Core Smart View). The supported version that is affected is 24.200. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Smart View for Office. Successful attacks…
AnalizadaAlta (7.5)0.46%—Intumit Smartrobot14/4/202517/6/2026
SmartRobot from INTUMIT has a Server-Side Request Forgery vulnerability, allowing unauthenticated remote attackers to probe internal network and even access arbitrary local files on the server.
AplazadaCrítica (9.3)0.65%—Lisandro Martinez Wp-smart-contractsAI11/4/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Lisandro Martinez WPSmartContracts wp-smart-contracts allows Blind SQL Injection.This issue affects WPSmartContracts: from n/a through <= 2.0.12.
AplazadaAlta (7.1)0.42%—Dolby UK Mobile SmartAI11/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dolby_uk Mobile Smart mobile-smart allows Reflected XSS.This issue affects Mobile Smart: from n/a through <= v1.3.16.
AplazadaAlta (7.1)0.21%—Shameem Reza Smart Product Gallery SliderAI9/4/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Shameem Reza Smart Product Gallery Slider smart-product-gallery-slider allows Cross Site Request Forgery.This issue affects Smart Product Gallery Slider: from n/a through <= 1.0.4.