Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3023▼ 71 respecto a la semana anterior
Críticas / altas1419▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
338 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.3) | 0.80% | — | Home-assistant Home Assistant CoreAI | 21/7/2026 | 21/7/2026 | Home Assistant Core before 2026.7.0 contains a path traversal vulnerability in the backup-restore function that allows attackers to write files to arbitrary absolute filesystem paths by supplying a crafted tar archive with a SYMTYPE entry containing a benign member name paired with an absolute linkname pointing… | |
| Aplazada | Baja (2.1) | 0.30% | — | ShellyAIHome-assistant CoreAI | 21/7/2026 | 22/7/2026 | Home Assistant Core before 2026.5.4 contains a cross-site scripting vulnerability in the Shelly integration's async_get_media_image() method that allows attackers controlling a Shelly device's thumb field to serve arbitrary HTML content by supplying a data URI with a text/html content type without validation against… | |
| Aplazada | Alta (8.8) | 0.46% | — | Github ActionsAIMaaassistantarknightsAI | 15/7/2026 | 12/8/2026 | MaaAssistantArknights is a one-click tool for daily Arknights tasks. In the current dev-v2 workflow, .github/workflows/release-preparation.yml inlined attacker-controlled github.event.pull_request.title into a run: shell command during the pull_request opened, reopened, and ready_for_review events, so a non-draft fork… | |
| Aplazada | Alta (7.5) | 0.26% | — | Home-assistant IOS Companion APPAI | 29/6/2026 | 30/6/2026 | Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2025.5.0, The iOS companion app ignores the SSID allowlist for internal networks. The app uses SSID to detect when to use the internal URL, but whenever the app cannot find any other URL to be used, it fallbacks… | |
| Analizada | Alta (7.1) | 0.17% | — | Home-assistant Home Assistant Companion | 23/6/2026 | 26/6/2026 | Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2026.5.3, the LocationSensorManager BroadcastReceiver is exported with no permission. Any installed app, with zero runtime permissions, can broadcast a forged Google Play Services LocationResult directly to it;… | |
| Modificada | Alta (7.6) | 0.31% | — | Home-assistant | 23/6/2026 | 26/6/2026 | Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2026.6.0, the Konnected integration registers an HTTP endpoint, KonnectedView (homeassistant/components/konnected/__init__.py), that is marked as not requiring authentication (requires_auth = False). A comment… | |
| Aplazada | Alta (7.1) | 0.16% | — | Aomei Partition AssistantAI | 21/6/2026 | 22/6/2026 | A vulnerability has been found in AOMEI Partition Assistant up to 10.10.1. This vulnerability affects unknown code in the library ampa10.sys of the component Kernel Driver. Such manipulation leads to improper access controls. The attack must be carried out locally. The exploit has been disclosed to the public and may… | |
| Aplazada | Alta (8.5) | 0.36% | — | Davidlingren Media Library AssistantAI | 18/6/2026 | 18/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in David Lingren Media LIbrary Assistant allows Blind SQL Injection. This issue affects Media LIbrary Assistant: from n/a through 3.35. | |
| Aplazada | Alta (7.1) | 0.25% | — | Media Library AssistantAI | 16/6/2026 | 17/6/2026 | Unauthenticated Cross Site Scripting (XSS) in Media LIbrary Assistant <= 3.35 versions. | |
| Analizada | Media (6.9) | 0.09% | — | Samsung Assistant | 5/6/2026 | 17/6/2026 | Improper export of android application components in ExpressHomeWidgetReceiver of Samsung Assistant prior to version 9.3.14 allows local attacker to execute arbitrary script. | |
| Analizada | Media (6.9) | 0.09% | — | Samsung Assistant | 5/6/2026 | 17/6/2026 | Improper export of android application components in SmartHomeWidgetReceiver of Samsung Assistant prior to version 9.3.14 allows local attacker to execute arbitrary script. | |
| Aplazada | Media (6.1) | 0.15% | — | Transsion AiassistantlifestyleAI | 2/6/2026 | 22/7/2026 | Cross-Site Scripting (XSS) in GeniexWebView component in Transsion AI Assistant Lifestyle application (com.transsion.aiassistantlifestyle) all versions on Android allows remote attacker to execute arbitrary JavaScript in the WebView context via crafted web_action_data URL parameter. | |
| Pendiente de análisis | Alta (8.3) | 0.17% | — | Home-assistant CompanionAIHome-assistant Home AssistantAI | 29/5/2026 | 21/7/2026 | Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2026.4.1 for iOS and 2026.4.4 for Android, he Home Assistant Companion apps for Android and iOS expose a JavaScript bridge to the in-app WebView window.externalApp on Android and… | |
| Aplazada | Alta (8.1) | 0.32% | — | Media Library AssistantAI | 29/5/2026 | 21/7/2026 | The Media Library Assistant plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.35 This is due to missing nonce verification on the bulk action handlers in the settings tab handlers. This makes it possible for unauthenticated attackers to trick an administrator into… | |
| Analizada | Media (5.6) | 0.09% | — | Synology Assistant | 27/5/2026 | 30/9/2026 | An origin validation error vulnerability in Synology Assistant before 7.0.6-50085 allows local users to write arbitrary files with restricted content and conduct denial-of-service during installation. | |
| Analizada | Alta (8.7) | 0.50% | — | Hacs Home Assistant Community Store | 16/5/2026 | 17/6/2026 | Home Assistant Community Store (HACS) prior to 1.10.0 contains a path traversal vulnerability that allows unauthenticated attackers to read sensitive files by traversing directories via the /hacsfiles/ endpoint. Attackers can retrieve the .storage/auth file containing user credentials and refresh tokens, then craft… | |
| Analizada | Alta (8.7) | 0.22% | — | Intel Endpoint Management Assistant | 12/5/2026 | 21/7/2026 | Improper input validation for some Intel Endpoint Management Assistant (EMA) software before version 1.14.5 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an unauthenticated user combined with a low complexity attack may enable escalation of privilege. This… | |
| Analizada | Crítica (9.8) | 0.21% | — | Oppo Coloros Assistant | 30/4/2026 | 17/6/2026 | ColorOS Assistant has an unauthenticated start-download channel, leading to file path traversal. | |
| Analizada | Media (5.6) | 0.14% | — | Home-assistant-ecosystem Home Assistant Command-line Interface | 21/4/2026 | 17/6/2026 | The Home Assistant Command-line interface (hass-cli) is a command-line tool for Home Assistant. Up to 1.0.0 of home-assitant-cli an unrestricted environment was used to handle Jninja2 templates instead of a sandboxed one. The user-supplied input within Jinja2 templates was rendered locally with no restrictions. This… | |
| Aplazada | Media (6.5) | 0.22% | — | Davidlingren Media Library AssistantAI | 6/4/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Lingren Media LIbrary Assistant allows Stored XSS.This issue affects Media LIbrary Assistant: from n/a through 3.34. | |
| Aplazada | Alta (8.5) | 1.2% | — | Davidlingren Media Library AssistantAI | 6/4/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in David Lingren Media LIbrary Assistant allows SQL Injection.This issue affects Media LIbrary Assistant: from n/a through 3.34. | |
| Pendiente de análisis | Crítica (9.6) | 0.35% | — | Home-assistant Home AssistantAIHome-assistant SupervisorAI | 27/3/2026 | 17/6/2026 | Home Assistant is open source home automation software that puts local control and privacy first. Home Assistant apps (formerly add-ons) configured with host network mode expose unauthenticated endpoints bound to the internal Docker bridge interface to the local network. On Linux, this configuration does not restrict… | |
| Modificada | Alta (7.3) | 0.25% | — | Home-assistant | 27/3/2026 | 17/6/2026 | Home Assistant is open source home automation software that puts local control and privacy first. Starting in version 2025.02 and prior to version 2026.01 the "remaining charge time"-sensor for mobile phones (imported/included from Android Auto it appears) is vulnerable cross-site scripting, similar to CVE-2025-62172.… | |
| Analizada | Alta (7.3) | 0.28% | — | Home-assistant | 27/3/2026 | 17/6/2026 | Home Assistant is open source home automation software that puts local control and privacy first. Starting in version 2020.02 and prior to version 2026.01, an authenticated party can add a malicious name to their device entity, allowing for Cross-Site Scripting attacks against anyone who can see a dashboard with a… | |
| Analizada | Media (4.8) | 0.09% | — | Samsung Assistant | 16/3/2026 | 17/6/2026 | Improper export of android application components in Samsung Assistant prior to version 9.3.10.7 allows local attacker to access saved information. |