Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3023▼ 71 respecto a la semana anterior
Críticas / altas1419▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

338 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.3)0.80%—Home-assistant Home Assistant CoreAI21/7/202621/7/2026
Home Assistant Core before 2026.7.0 contains a path traversal vulnerability in the backup-restore function that allows attackers to write files to arbitrary absolute filesystem paths by supplying a crafted tar archive with a SYMTYPE entry containing a benign member name paired with an absolute linkname pointing…
AplazadaBaja (2.1)0.30%—ShellyAIHome-assistant CoreAI21/7/202622/7/2026
Home Assistant Core before 2026.5.4 contains a cross-site scripting vulnerability in the Shelly integration's async_get_media_image() method that allows attackers controlling a Shelly device's thumb field to serve arbitrary HTML content by supplying a data URI with a text/html content type without validation against…
AplazadaAlta (8.8)0.46%—Github ActionsAIMaaassistantarknightsAI15/7/202612/8/2026
MaaAssistantArknights is a one-click tool for daily Arknights tasks. In the current dev-v2 workflow, .github/workflows/release-preparation.yml inlined attacker-controlled github.event.pull_request.title into a run: shell command during the pull_request opened, reopened, and ready_for_review events, so a non-draft fork…
AplazadaAlta (7.5)0.26%—Home-assistant IOS Companion APPAI29/6/202630/6/2026
Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2025.5.0, The iOS companion app ignores the SSID allowlist for internal networks. The app uses SSID to detect when to use the internal URL, but whenever the app cannot find any other URL to be used, it fallbacks…
AnalizadaAlta (7.1)0.17%—Home-assistant Home Assistant Companion23/6/202626/6/2026
Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2026.5.3, the LocationSensorManager BroadcastReceiver is exported with no permission. Any installed app, with zero runtime permissions, can broadcast a forged Google Play Services LocationResult directly to it;…
ModificadaAlta (7.6)0.31%—Home-assistant23/6/202626/6/2026
Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2026.6.0, the Konnected integration registers an HTTP endpoint, KonnectedView (homeassistant/components/konnected/__init__.py), that is marked as not requiring authentication (requires_auth = False). A comment…
AplazadaAlta (7.1)0.16%—Aomei Partition AssistantAI21/6/202622/6/2026
A vulnerability has been found in AOMEI Partition Assistant up to 10.10.1. This vulnerability affects unknown code in the library ampa10.sys of the component Kernel Driver. Such manipulation leads to improper access controls. The attack must be carried out locally. The exploit has been disclosed to the public and may…
AplazadaAlta (8.5)0.36%—Davidlingren Media Library AssistantAI18/6/202618/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in David Lingren Media LIbrary Assistant allows Blind SQL Injection. This issue affects Media LIbrary Assistant: from n/a through 3.35.
AplazadaAlta (7.1)0.25%—Media Library AssistantAI16/6/202617/6/2026
Unauthenticated Cross Site Scripting (XSS) in Media LIbrary Assistant <= 3.35 versions.
AnalizadaMedia (6.9)0.09%—Samsung Assistant5/6/202617/6/2026
Improper export of android application components in ExpressHomeWidgetReceiver of Samsung Assistant prior to version 9.3.14 allows local attacker to execute arbitrary script.
AnalizadaMedia (6.9)0.09%—Samsung Assistant5/6/202617/6/2026
Improper export of android application components in SmartHomeWidgetReceiver of Samsung Assistant prior to version 9.3.14 allows local attacker to execute arbitrary script.
AplazadaMedia (6.1)0.15%—Transsion AiassistantlifestyleAI2/6/202622/7/2026
Cross-Site Scripting (XSS) in GeniexWebView component in Transsion AI Assistant Lifestyle application (com.transsion.aiassistantlifestyle) all versions on Android allows remote attacker to execute arbitrary JavaScript in the WebView context via crafted web_action_data URL parameter.
Pendiente de análisisAlta (8.3)0.17%—Home-assistant CompanionAIHome-assistant Home AssistantAI29/5/202621/7/2026
Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2026.4.1 for iOS and 2026.4.4 for Android, he Home Assistant Companion apps for Android and iOS expose a JavaScript bridge to the in-app WebView window.externalApp on Android and…
AplazadaAlta (8.1)0.32%—Media Library AssistantAI29/5/202621/7/2026
The Media Library Assistant plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.35 This is due to missing nonce verification on the bulk action handlers in the settings tab handlers. This makes it possible for unauthenticated attackers to trick an administrator into…
AnalizadaMedia (5.6)0.09%—Synology Assistant27/5/202630/9/2026
An origin validation error vulnerability in Synology Assistant before 7.0.6-50085 allows local users to write arbitrary files with restricted content and conduct denial-of-service during installation.
AnalizadaAlta (8.7)0.50%—Hacs Home Assistant Community Store16/5/202617/6/2026
Home Assistant Community Store (HACS) prior to 1.10.0 contains a path traversal vulnerability that allows unauthenticated attackers to read sensitive files by traversing directories via the /hacsfiles/ endpoint. Attackers can retrieve the .storage/auth file containing user credentials and refresh tokens, then craft…
AnalizadaAlta (8.7)0.22%—Intel Endpoint Management Assistant12/5/202621/7/2026
Improper input validation for some Intel Endpoint Management Assistant (EMA) software before version 1.14.5 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an unauthenticated user combined with a low complexity attack may enable escalation of privilege. This…
AnalizadaCrítica (9.8)0.21%—Oppo Coloros Assistant30/4/202617/6/2026
ColorOS Assistant has an unauthenticated start-download channel, leading to file path traversal.
AnalizadaMedia (5.6)0.14%—Home-assistant-ecosystem Home Assistant Command-line Interface21/4/202617/6/2026
The Home Assistant Command-line interface (hass-cli) is a command-line tool for Home Assistant. Up to 1.0.0 of home-assitant-cli an unrestricted environment was used to handle Jninja2 templates instead of a sandboxed one. The user-supplied input within Jinja2 templates was rendered locally with no restrictions. This…
AplazadaMedia (6.5)0.22%—Davidlingren Media Library AssistantAI6/4/202617/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Lingren Media LIbrary Assistant allows Stored XSS.This issue affects Media LIbrary Assistant: from n/a through 3.34.
AplazadaAlta (8.5)1.2%—Davidlingren Media Library AssistantAI6/4/202617/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in David Lingren Media LIbrary Assistant allows SQL Injection.This issue affects Media LIbrary Assistant: from n/a through 3.34.
Pendiente de análisisCrítica (9.6)0.35%—Home-assistant Home AssistantAIHome-assistant SupervisorAI27/3/202617/6/2026
Home Assistant is open source home automation software that puts local control and privacy first. Home Assistant apps (formerly add-ons) configured with host network mode expose unauthenticated endpoints bound to the internal Docker bridge interface to the local network. On Linux, this configuration does not restrict…
ModificadaAlta (7.3)0.25%—Home-assistant27/3/202617/6/2026
Home Assistant is open source home automation software that puts local control and privacy first. Starting in version 2025.02 and prior to version 2026.01 the "remaining charge time"-sensor for mobile phones (imported/included from Android Auto it appears) is vulnerable cross-site scripting, similar to CVE-2025-62172.…
AnalizadaAlta (7.3)0.28%—Home-assistant27/3/202617/6/2026
Home Assistant is open source home automation software that puts local control and privacy first. Starting in version 2020.02 and prior to version 2026.01, an authenticated party can add a malicious name to their device entity, allowing for Cross-Site Scripting attacks against anyone who can see a dashboard with a…
AnalizadaMedia (4.8)0.09%—Samsung Assistant16/3/202617/6/2026
Improper export of android application components in Samsung Assistant prior to version 9.3.10.7 allows local attacker to access saved information.