Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3005▼ 85 respecto a la semana anterior
Críticas / altas1403▲ 41 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
1878 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| En análisis | Alta (8.1) | 0.20% | — | Dell Smartfabric ManagerAI | 17/9/2026 | 18/9/2026 | Dell SmartFabric Manager, versions prior to 2.2.1, contains an Insufficient Verification of Data Authenticity vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges. | |
| Analizada | Alta (7.5) | 0.19% | — | Qualcomm Q-7790 FirmwareQualcomm Qam8255p FirmwareQualcomm Qam8295p FirmwareQualcomm Qamsrv1h Firmware+372 | 17/9/2026 | 22/9/2026 | Transient DOS when processing authentication frames with invalid FILS information element header lengths. | |
| Aplazada | Alta (7.1) | 0.33% | — | TCH Qring Smart Ring R20 B006AI | 16/9/2026 | 22/9/2026 | TCH QRing smart ring model R20_B006 running firmware RT09R20_1.00.00_250318 contains an unauthenticated Bluetooth Low Energy access vulnerability that allows any nearby attacker to connect to the device without pairing, authentication, or user approval by exploiting the exposed Nordic UART Service which enforces no… | |
| Aplazada | Alta (7.5) | 0.37% | — | Prolink 13A Smart Plug Ds-3202m-ukv3AIMezeeAI | 15/9/2026 | 22/9/2026 | An issue in Prolink 13A Smart Plug Model Version: DS-3202M-UKv3 Wi-Fi and Application Version mEzee 2.6.7 allows attackers to cause a Denial of Service (DoS) or connection to an attacker-controlled device via supplying a crafted packet during the provisioning phase. | |
| Pendiente de análisis | Crítica (9.1) | 0.30% | — | Dell Smartfabric Os10AI | 15/9/2026 | 16/9/2026 | Dell SmartFabric OS10 Software, versions prior to 10.6.1.3, contains a Download of Code Without Integrity Check vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Code execution. | |
| Pendiente de análisis | Crítica (9.8) | 0.50% | — | Dell Smartfabric Os10AI | 15/9/2026 | 16/9/2026 | Dell SmartFabric OS10 Software, versions prior to 10.6.1.3, contains a Session Fixation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Session theft. | |
| Aplazada | Media (4.3) | 0.28% | — | Smartadmin APIAIOracle JavaAIVmware Spring BootAI | 15/9/2026 | 22/9/2026 | SmartAdmin API Java17 SpringBoot3 version 3.30.0 contains an improper authorization vulnerability in the /employee/queryAll endpoint. The endpoint does not enforce the required function-level permission or data-scope authorization, allowing an authenticated low-privileged employee to retrieve employee records… | |
| Aplazada | Alta (8.1) | 0.36% | — | Lab1024 SmartadminAI | 15/9/2026 | 22/9/2026 | 1024-lab SmartAdmin v3.30.0 contains a missing authorization vulnerability in the scheduled-job management module. The AdminSmartJobController exposes scheduled-job management endpoints without method-level permission checks, allowing a low-privileged authenticated user to access functionality intended for authorized… | |
| Aplazada | Media (6.5) | 0.34% | — | Lab1024 SmartadminAI | 15/9/2026 | 22/9/2026 | 1024-lab SmartAdmin v3.30.0 contains a stored cross-site scripting vulnerability in its file upload functionality. This allows a remote attacker to execute arbitrary code. | |
| Aplazada | Crítica (9.8) | 0.61% | — | Lab1024 SmartadminAI | 15/9/2026 | 22/9/2026 | SmartAdmin v3.30.0 contains an authorization flaw in the configuration query endpoint. This allows a remote attacker to escalate privileges. | |
| Aplazada | Media (6.5) | 0.45% | — | E-goi Smart Marketing SMS AND Newsletters FormsAI | 12/9/2026 | 14/9/2026 | The Smart Marketing SMS and Newsletters Forms plugin for WordPress is vulnerable to generic SQL Injection via Parameter Name in all versions up to, and including, 5.1.24 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for… | |
| Aplazada | Media (6.1) | 0.25% | — | Ideasoft Smart E-commerceAI | 11/9/2026 | 25/9/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in IdeaSoft Software Industry and Trade Inc. Smart E-Commerce allows Reflected XSS. This issue affects Smart E-Commerce: before 8.4.2.0. | |
| Aplazada | Media (6.9) | 0.54% | — | Kingdom Communication Associated Smart Video Intercom SystemAI | 11/9/2026 | 11/9/2026 | Smart Video Intercom System developed by Kingdom Communication Associated has a Client-Side Authentication vulnerability. Unauthenticated remote attackers can bypass authentication to access specific pages and obtain partial system configuration values. | |
| Aplazada | Alta (8.7) | 0.51% | — | Kingdom Communication Associated Smart Video Intercom SystemAI | 11/9/2026 | 11/9/2026 | Smart Video Intercom System developed by Kingdom Communication Associated has a Missing Brute-force Protection vulnerability. Unauthenticated remote attackers can gain access to valid accounts through a large number of login attempts. | |
| Aplazada | Media (6.9) | 0.44% | — | Kingdom Communication Associated Smart Video Intercom SystemAI | 11/9/2026 | 11/9/2026 | Smart Video Intercom System developed by Kingdom Communication Associated has a Sensitive Data Exposure vulnerability. Unauthenticated remote attackers can enumerate valid user accounts by exploiting differences in system responses. | |
| Aplazada | Media (5.5) | 0.51% | — | Beijing Meite Software Technology U Smart Enjoyment WebsiteAI | 7/9/2026 | 8/9/2026 | A vulnerability was determined in Beijing Meite Software Technology U+Smart Enjoyment WebSite 18.6001.1096.1000. This impacts an unknown function of the file /Report/Upload/UploadFormImg.ashx. Executing a manipulation of the argument File can lead to unrestricted upload. It is possible to launch the attack remotely.… | |
| Aplazada | Baja (2.7) | 0.30% | — | Smart PostAI | 5/9/2026 | 8/9/2026 | The Smart Post WordPress plugin before 4.0.8 does not check the type, ownership or status of the post it is asked to duplicate, allowing users with contributor privileges and above to copy any private or password protected post into a draft of their own and read its content and metadata. | |
| Aplazada | Media (5.3) | 0.34% | — | Smart PostAI | 5/9/2026 | 8/9/2026 | The Smart Post WordPress plugin before 4.0.8 does not check whether a post is password protected before returning its content and its stored password through an unauthenticated AJAX action, allowing unauthenticated users to read protected post content and the password that guards it. | |
| Aplazada | Media (6.3) | 0.24% | — | Softing SmartlinkAI | 4/9/2026 | 9/9/2026 | Missing release of memory after effective lifetime vulnerability in Softing smartLink allows resource leak exposure. This issue affects smartLink HW-PN: from 1.04 before 1.10. | |
| Aplazada | Media (6.9) | 0.41% | — | Lightstar Smartit Desktop ManagerAILightstar Smartit AgentAI | 4/9/2026 | 8/9/2026 | SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can obtain the SFTP service credentials of the SmartIT Agent application from the source code, thereby browsing the file system of the user's host. | |
| Aplazada | Crítica (9.3) | 0.63% | — | Lightstar Smartit Desktop ManagerAI | 4/9/2026 | 8/9/2026 | SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can exploit a fixed password to remotely access user hosts. | |
| Aplazada | Alta (8.7) | 0.33% | — | Lightstar Smartit Desktop ManagerAI | 4/9/2026 | 8/9/2026 | SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can obtain a specific password from the source code, which can be used to retrieve the AES encryption key used for communication. | |
| Aplazada | Crítica (9.3) | 0.63% | — | Lightstar Smartit Desktop ManagerAI | 4/9/2026 | 8/9/2026 | SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can obtain the SSH service account credentials and passwords for the SmartIT Agent directly from the application source code. | |
| En análisis | Media (5) | 0.84% | — | Dell Smartfabric Os10AI | 3/9/2026 | 4/9/2026 | Dell SmartFabric OS10 Software, versions prior to 10.5.6.14, contains an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution. | |
| En análisis | Media (5) | 0.84% | — | Dell Smartfabric Os10AI | 3/9/2026 | 4/9/2026 | Dell SmartFabric OS10 Software, versions prior to 10.5.6.14, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution. |