Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
495 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.17% | — | Home-assistant Companion APPAI | 7/8/2026 | 9/9/2026 | Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.5.3, the Companion app treats tag links (NFC or QR) delivered through an OS-level routing mechanism as if they were physically scanned, without validating the calling app or prompting the user. As a result, any… | |
| Aplazada | Media (4.3) | 0.38% | — | Home-assistant Android Companion APPAI | 7/8/2026 | 9/9/2026 | Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.6.1, the Android Companion app is vulnerable to an open redirect. The app passes the URL fragment from a homeassistant://invite deep link into the onboarding flow without ever displaying the destination hostname.… | |
| Aplazada | Alta (7.1) | 0.25% | — | Media Library AssistantAI | 6/8/2026 | 12/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Media LIbrary Assistant <= 3.38 versions. | |
| Analizada | Alta (7.3) | 0.15% | — | Synology Assistant | 3/8/2026 | 21/8/2026 | An incorrect default permissions vulnerability in Synology Assistant before 7.0.7-50095 allows local users to read or write arbitrary files and conduct denial-of-service during installation. | |
| Aplazada | Crítica (9) | 0.58% | — | Home-assistant CoreAI | 21/7/2026 | 21/7/2026 | Home Assistant Core before 2026.6.0 contains a path traversal vulnerability that allows unauthenticated attackers to write arbitrary files to any directory on the host filesystem by uploading a crafted backup archive during the initial onboarding window. Attackers can manipulate the 'name' field inside the uploaded… | |
| Aplazada | Crítica (9.3) | 0.80% | 💥 PoC | Home-assistant Home Assistant CoreAI | 21/7/2026 | 21/7/2026 | Home Assistant Core before 2026.7.0 contains a path traversal vulnerability in the backup-restore function that allows attackers to write files to arbitrary absolute filesystem paths by supplying a crafted tar archive with a SYMTYPE entry containing a benign member name paired with an absolute linkname pointing… | |
| Aplazada | Baja (2.1) | 0.30% | — | ShellyAIHome-assistant CoreAI | 21/7/2026 | 22/7/2026 | Home Assistant Core before 2026.5.4 contains a cross-site scripting vulnerability in the Shelly integration's async_get_media_image() method that allows attackers controlling a Shelly device's thumb field to serve arbitrary HTML content by supplying a data URI with a text/html content type without validation against… | |
| Aplazada | Alta (8.8) | 0.46% | — | Github ActionsAIMaaassistantarknightsAI | 15/7/2026 | 12/8/2026 | MaaAssistantArknights is a one-click tool for daily Arknights tasks. In the current dev-v2 workflow, .github/workflows/release-preparation.yml inlined attacker-controlled github.event.pull_request.title into a run: shell command during the pull_request opened, reopened, and ready_for_review events, so a non-draft fork… | |
| En análisis | Media (6.3) | 0.44% | — | Deloitte AI Assist FOR Customer | 10/7/2026 | 3/8/2026 | Deloitte AI Assist for Customer exposed unauthenticated API endpoints that allowed an attacker with knowledge of additional parameters to read from or inject content into the retrieval-augmented generation (RAG) corpus. On 2026-03-25, AI Assist for Customer restricted network access and enforced authentication for the… | |
| En análisis | Media (6.9) | 0.60% | — | Deloitte AI Assist FOR Customer | 10/7/2026 | 3/8/2026 | Deloitte AI Assist for Customer accepted unauthenticated POST requests through public-facing API endpoints that allowed a remote attacker to make limited additions to the configuration. These additions were not used by the system. On 2026-03-25, AI Assist for Customer restricted network access and enforced… | |
| Analizada | Media (6.9) | 0.51% | — | Deloitte AI Assist FOR Customer | 10/7/2026 | 21/7/2026 | Deloitte AI Assist for Customer disclosed some configuration information through public-facing API endpoints that accepted unauthenticated requests. This information could reduce an attacker’s reconnaissance effort. On 2026-03-25, AI Assist for Customer restricted network access and enforced authentication for the… | |
| Aplazada | Alta (7.5) | 0.26% | — | Home-assistant IOS Companion APPAI | 29/6/2026 | 30/6/2026 | Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2025.5.0, The iOS companion app ignores the SSID allowlist for internal networks. The app uses SSID to detect when to use the internal URL, but whenever the app cannot find any other URL to be used, it fallbacks… | |
| Aplazada | Media (4.3) | 0.33% | — | AssistioAI | 24/6/2026 | 25/6/2026 | The Assistio plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce verification on the assistio_plugin_delete_assistio_settings() function in versions up to, and including, 1.1.2. This makes it possible for authenticated attackers, with… | |
| Analizada | Alta (7.1) | 0.17% | — | Home-assistant Home Assistant Companion | 23/6/2026 | 26/6/2026 | Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2026.5.3, the LocationSensorManager BroadcastReceiver is exported with no permission. Any installed app, with zero runtime permissions, can broadcast a forged Google Play Services LocationResult directly to it;… | |
| Modificada | Alta (7.6) | 0.31% | — | Home-assistant | 23/6/2026 | 26/6/2026 | Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2026.6.0, the Konnected integration registers an HTTP endpoint, KonnectedView (homeassistant/components/konnected/__init__.py), that is marked as not requiring authentication (requires_auth = False). A comment… | |
| Aplazada | Alta (7.1) | 0.16% | — | Aomei Partition AssistantAI | 21/6/2026 | 22/6/2026 | A vulnerability has been found in AOMEI Partition Assistant up to 10.10.1. This vulnerability affects unknown code in the library ampa10.sys of the component Kernel Driver. Such manipulation leads to improper access controls. The attack must be carried out locally. The exploit has been disclosed to the public and may… | |
| Aplazada | Alta (8.5) | 0.36% | — | Davidlingren Media Library AssistantAI | 18/6/2026 | 18/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in David Lingren Media LIbrary Assistant allows Blind SQL Injection. This issue affects Media LIbrary Assistant: from n/a through 3.35. | |
| Aplazada | Alta (7.1) | 0.25% | — | Media Library AssistantAI | 16/6/2026 | 17/6/2026 | Unauthenticated Cross Site Scripting (XSS) in Media LIbrary Assistant <= 3.35 versions. | |
| Analizada | Crítica (9.6) | 0.43% | — | Kubev2v Assisted Migration Agent | 10/6/2026 | 17/6/2026 | A flaw was found in assisted-migration-agent. An unauthenticated attacker, located on the same local area network (LAN), can exploit a path traversal vulnerability. By crafting a specially designed gzipped tarball, the attacker can bypass security checks and write arbitrary files to the system. This could ultimately… | |
| Analizada | Alta (7.4) | 0.50% | — | Kubev2v Assisted Migration Agent | 10/6/2026 | 17/6/2026 | A flaw was found in assisted-migration-agent. The application hardcodes insecure Transport Layer Security (TLS) connections when communicating with vCenter. This vulnerability allows a Man-in-the-Middle (MITM) attacker to intercept and harvest vCenter administrator credentials. This can lead to unauthorized access to… | |
| Pendiente de análisis | Alta (7.8) | 0.13% | — | Omnissa Workspace ONE AssistAI | 9/6/2026 | 23/7/2026 | Omnissa Workspace ONE® Assist for macOS contains a Local Privilege Escalation Vulnerability. | |
| Analizada | Media (6.9) | 0.09% | — | Samsung Assistant | 5/6/2026 | 17/6/2026 | Improper export of android application components in ExpressHomeWidgetReceiver of Samsung Assistant prior to version 9.3.14 allows local attacker to execute arbitrary script. | |
| Analizada | Media (6.9) | 0.09% | — | Samsung Assistant | 5/6/2026 | 17/6/2026 | Improper export of android application components in SmartHomeWidgetReceiver of Samsung Assistant prior to version 9.3.14 allows local attacker to execute arbitrary script. | |
| Aplazada | Media (6.1) | 0.15% | — | Transsion AiassistantlifestyleAI | 2/6/2026 | 22/7/2026 | Cross-Site Scripting (XSS) in GeniexWebView component in Transsion AI Assistant Lifestyle application (com.transsion.aiassistantlifestyle) all versions on Android allows remote attacker to execute arbitrary JavaScript in the WebView context via crafted web_action_data URL parameter. | |
| Pendiente de análisis | Alta (8.3) | 0.17% | — | Home-assistant CompanionAIHome-assistant Home AssistantAI | 29/5/2026 | 21/7/2026 | Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2026.4.1 for iOS and 2026.4.4 for Android, he Home Assistant Companion apps for Android and iOS expose a JavaScript bridge to the in-app WebView window.externalApp on Android and… |