Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

1906 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.1)0.23%—Smartdevth Advanced Advertising SystemAI8/4/202517/6/2026
The Advanced Advertising System plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 1.3.1. This is due to insufficient validation on the redirect url supplied via the 'redir' parameter. This makes it possible for unauthenticated attackers to redirect users to potentially malicious…
AnalizadaAlta (7.5)0.26%—Qualcomm 315 5G IOT Modem FirmwareQualcomm Apq8017 FirmwareQualcomm Apq8064au FirmwareQualcomm Aqt1000 Firmware+2217/4/202517/6/2026
Transient DOS while connecting STA to AP and initiating ADD TS request from AP to establish TSpec session.
AnalizadaAlta (7.5)0.26%—Qualcomm Sa9000p FirmwareQualcomm Sd626 FirmwareQualcomm Sd660 FirmwareQualcomm Sd670 Firmware+1787/4/202517/6/2026
Memory corruption occurs while connecting a STA to an AP and initiating an ADD TS request.
AnalizadaAlta (7.5)0.25%—Qualcomm Snapdragon 439 Mobile Platform FirmwareQualcomm Snapdragon 625 Mobile Platform FirmwareQualcomm Snapdragon 626 Mobile Platform FirmwareQualcomm Snapdragon 632 Mobile Platform Firmware+657/4/202517/6/2026
Memory corruption occurs while connecting a STA to an AP and initiating an ADD TS request from the AP to establish a TSpec session.
AnalizadaAlta (8.2)0.26%—Qualcomm Apq8064au FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6800 Firmware+1427/4/202517/6/2026
Information disclosure may occur during a video call if a device resets due to a non-conforming RTCP packet that doesn`t adhere to RFC standards.
AnalizadaMedia (6.2)0.11%—Qualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6800 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 Firmware+2387/4/202517/6/2026
Cryptographic issue occurs during PIN/password verification using Gatekeeper, where RPMB writes can be dropped on verification failure, potentially leading to a user throttling bypass.
AnalizadaMedia (5.5)0.11%—Qualcomm Csr8811 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 FirmwareQualcomm Fastconnect 6200 Firmware+3067/4/202517/6/2026
There may be information disclosure during memory re-allocation in TZ Secure OS.
AplazadaMedia (6.5)0.40%—Smartwpress Musicians Pack FOR ElementorAI4/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in smartwpress Musician's Pack For Elementor music-pack-for-elementor allows DOM-Based XSS.This issue affects Musician's Pack For Elementor: from n/a through <= 1.8.7.
AnalizadaMedia (5.3)0.44%—Fcba ZZM Smart Park Management System3/4/202517/6/2026
A vulnerability classified as critical was found in fcba_zzm ics-park Smart Park Management System 2.1. This vulnerability affects unknown code of the file /api/system/dept/update. The manipulation leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be…
AplazadaMedia (6.4)0.33%—Smart Icons FOR WordpressAI2/4/202517/6/2026
The Smart Icons For WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Editor-level access and above, to inject…
AplazadaAlta (8.8)0.51%—Wpclever WPC Smart Linked ProductsAI1/4/202517/6/2026
Missing Authorization vulnerability in WPClever WPC Smart Linked Products - Upsells & Cross-sells for WooCommerce wpc-smart-linked-products allows Privilege Escalation.This issue affects WPC Smart Linked Products - Upsells & Cross-sells for WooCommerce: from n/a through <= 1.3.5.
AplazadaMedia (5.9)0.28%—Erez Hadas-sonnenschein Smartarget PopupAI1/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Erez Hadas-Sonnenschein Smartarget Popup smartarget-popup allows Stored XSS.This issue affects Smartarget Popup: from n/a through <= 1.5.
AplazadaMedia (6.5)0.21%—Crocoblock JET Smart FiltersAI31/3/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetSmartFilters jet-smart-filters allows DOM-Based XSS.This issue affects JetSmartFilters: from n/a through <= 3.6.3.
AplazadaAlta (8.8)0.63%💥 PoCWpclever WPC Smart Upsell FunnelAI27/3/202517/6/2026
Missing Authorization vulnerability in WPClever WPC Smart Upsell Funnel for WooCommerce wpc-smart-upsell-funnel allows Privilege Escalation.This issue affects WPC Smart Upsell Funnel for WooCommerce: from n/a through <= 3.0.4.
AplazadaAlta (8.8)0.29%💥 PoCXiaomi SmarthomeAI27/3/202517/6/2026
An code execution vulnerability exists in the Xiaomi smarthome application product. The vulnerability is caused by improper input validation and can be exploited by attackers to execute malicious code.
AnalizadaBaja (3.5)0.28%—Brijeshk89 Smart Maintenance Mode26/3/202517/6/2026
The Smart Maintenance Mode WordPress plugin before 1.5.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
AplazadaMedia (6.1)0.32%—Brijeshk89 Smart Maintenance ModeAI26/3/202517/6/2026
The Smart Maintenance Mode plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘setstatus’ parameter in all versions up to, and including, 1.5.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in…
AnalizadaMedia (6.1)0.27%—Brijeshk89 Smart Maintenance Mode25/3/202517/6/2026
The Smart Maintenance Mode WordPress plugin before 1.5.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
AplazadaMedia (6.5)0.36%—Smartredfox Pretty File LinksAI24/3/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in smartredfox Pretty file links pretty-file-links allows Stored XSS.This issue affects Pretty file links: from n/a through <= 0.9.
AplazadaAlta (8.3)0.26%—SmartosAIJoyent Triton Data CenterAIDebianAI19/3/202517/6/2026
SmartOS, as used in Triton Data Center and other products, has static host SSH keys in the 60f76fd2-143f-4f57-819b-1ae32684e81b image (a Debian 12 LX zone image from 2024-07-26).
AnalizadaAlta (7.8)0.70%—Dell Smartfabric Os1017/3/202517/6/2026
Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution.
AnalizadaAlta (7.8)0.83%—Dell Smartfabric Os1017/3/202517/6/2026
Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to execution of commands…
AnalizadaAlta (7.8)0.16%—Dell Smartfabric Os1017/3/202517/6/2026
Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Incorrect Privilege Assignment vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.
AnalizadaAlta (8.8)0.46%—Dell Smartfabric Os1017/3/202517/6/2026
Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Use of Default Password vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.
AnalizadaAlta (8.4)0.17%—Dell Smartfabric Os1017/3/202517/6/2026
Dell SmartFabric OS10 Software, version(s) 10.5.6.x, contain(s) a Use of Hard-coded Password vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Unauthorized access.