Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
1906 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.1) | 0.23% | — | Smartdevth Advanced Advertising SystemAI | 8/4/2025 | 17/6/2026 | The Advanced Advertising System plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 1.3.1. This is due to insufficient validation on the redirect url supplied via the 'redir' parameter. This makes it possible for unauthenticated attackers to redirect users to potentially malicious… | |
| Analizada | Alta (7.5) | 0.26% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm Apq8017 FirmwareQualcomm Apq8064au FirmwareQualcomm Aqt1000 Firmware+221 | 7/4/2025 | 17/6/2026 | Transient DOS while connecting STA to AP and initiating ADD TS request from AP to establish TSpec session. | |
| Analizada | Alta (7.5) | 0.26% | — | Qualcomm Sa9000p FirmwareQualcomm Sd626 FirmwareQualcomm Sd660 FirmwareQualcomm Sd670 Firmware+178 | 7/4/2025 | 17/6/2026 | Memory corruption occurs while connecting a STA to an AP and initiating an ADD TS request. | |
| Analizada | Alta (7.5) | 0.25% | — | Qualcomm Snapdragon 439 Mobile Platform FirmwareQualcomm Snapdragon 625 Mobile Platform FirmwareQualcomm Snapdragon 626 Mobile Platform FirmwareQualcomm Snapdragon 632 Mobile Platform Firmware+65 | 7/4/2025 | 17/6/2026 | Memory corruption occurs while connecting a STA to an AP and initiating an ADD TS request from the AP to establish a TSpec session. | |
| Analizada | Alta (8.2) | 0.26% | — | Qualcomm Apq8064au FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6800 Firmware+142 | 7/4/2025 | 17/6/2026 | Information disclosure may occur during a video call if a device resets due to a non-conforming RTCP packet that doesn`t adhere to RFC standards. | |
| Analizada | Media (6.2) | 0.11% | — | Qualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6800 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 Firmware+238 | 7/4/2025 | 17/6/2026 | Cryptographic issue occurs during PIN/password verification using Gatekeeper, where RPMB writes can be dropped on verification failure, potentially leading to a user throttling bypass. | |
| Analizada | Media (5.5) | 0.11% | — | Qualcomm Csr8811 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 FirmwareQualcomm Fastconnect 6200 Firmware+306 | 7/4/2025 | 17/6/2026 | There may be information disclosure during memory re-allocation in TZ Secure OS. | |
| Aplazada | Media (6.5) | 0.40% | — | Smartwpress Musicians Pack FOR ElementorAI | 4/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in smartwpress Musician's Pack For Elementor music-pack-for-elementor allows DOM-Based XSS.This issue affects Musician's Pack For Elementor: from n/a through <= 1.8.7. | |
| Analizada | Media (5.3) | 0.44% | — | Fcba ZZM Smart Park Management System | 3/4/2025 | 17/6/2026 | A vulnerability classified as critical was found in fcba_zzm ics-park Smart Park Management System 2.1. This vulnerability affects unknown code of the file /api/system/dept/update. The manipulation leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be… | |
| Aplazada | Media (6.4) | 0.33% | — | Smart Icons FOR WordpressAI | 2/4/2025 | 17/6/2026 | The Smart Icons For WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Editor-level access and above, to inject… | |
| Aplazada | Alta (8.8) | 0.51% | — | Wpclever WPC Smart Linked ProductsAI | 1/4/2025 | 17/6/2026 | Missing Authorization vulnerability in WPClever WPC Smart Linked Products - Upsells & Cross-sells for WooCommerce wpc-smart-linked-products allows Privilege Escalation.This issue affects WPC Smart Linked Products - Upsells & Cross-sells for WooCommerce: from n/a through <= 1.3.5. | |
| Aplazada | Media (5.9) | 0.28% | — | Erez Hadas-sonnenschein Smartarget PopupAI | 1/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Erez Hadas-Sonnenschein Smartarget Popup smartarget-popup allows Stored XSS.This issue affects Smartarget Popup: from n/a through <= 1.5. | |
| Aplazada | Media (6.5) | 0.21% | — | Crocoblock JET Smart FiltersAI | 31/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetSmartFilters jet-smart-filters allows DOM-Based XSS.This issue affects JetSmartFilters: from n/a through <= 3.6.3. | |
| Aplazada | Alta (8.8) | 0.63% | 💥 PoC | Wpclever WPC Smart Upsell FunnelAI | 27/3/2025 | 17/6/2026 | Missing Authorization vulnerability in WPClever WPC Smart Upsell Funnel for WooCommerce wpc-smart-upsell-funnel allows Privilege Escalation.This issue affects WPC Smart Upsell Funnel for WooCommerce: from n/a through <= 3.0.4. | |
| Aplazada | Alta (8.8) | 0.29% | 💥 PoC | Xiaomi SmarthomeAI | 27/3/2025 | 17/6/2026 | An code execution vulnerability exists in the Xiaomi smarthome application product. The vulnerability is caused by improper input validation and can be exploited by attackers to execute malicious code. | |
| Analizada | Baja (3.5) | 0.28% | — | Brijeshk89 Smart Maintenance Mode | 26/3/2025 | 17/6/2026 | The Smart Maintenance Mode WordPress plugin before 1.5.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Aplazada | Media (6.1) | 0.32% | — | Brijeshk89 Smart Maintenance ModeAI | 26/3/2025 | 17/6/2026 | The Smart Maintenance Mode plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘setstatus’ parameter in all versions up to, and including, 1.5.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in… | |
| Analizada | Media (6.1) | 0.27% | — | Brijeshk89 Smart Maintenance Mode | 25/3/2025 | 17/6/2026 | The Smart Maintenance Mode WordPress plugin before 1.5.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Aplazada | Media (6.5) | 0.36% | — | Smartredfox Pretty File LinksAI | 24/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in smartredfox Pretty file links pretty-file-links allows Stored XSS.This issue affects Pretty file links: from n/a through <= 0.9. | |
| Aplazada | Alta (8.3) | 0.26% | — | SmartosAIJoyent Triton Data CenterAIDebianAI | 19/3/2025 | 17/6/2026 | SmartOS, as used in Triton Data Center and other products, has static host SSH keys in the 60f76fd2-143f-4f57-819b-1ae32684e81b image (a Debian 12 LX zone image from 2024-07-26). | |
| Analizada | Alta (7.8) | 0.70% | — | Dell Smartfabric Os10 | 17/3/2025 | 17/6/2026 | Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution. | |
| Analizada | Alta (7.8) | 0.83% | — | Dell Smartfabric Os10 | 17/3/2025 | 17/6/2026 | Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to execution of commands… | |
| Analizada | Alta (7.8) | 0.16% | — | Dell Smartfabric Os10 | 17/3/2025 | 17/6/2026 | Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Incorrect Privilege Assignment vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. | |
| Analizada | Alta (8.8) | 0.46% | — | Dell Smartfabric Os10 | 17/3/2025 | 17/6/2026 | Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Use of Default Password vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access. | |
| Analizada | Alta (8.4) | 0.17% | — | Dell Smartfabric Os10 | 17/3/2025 | 17/6/2026 | Dell SmartFabric OS10 Software, version(s) 10.5.6.x, contain(s) a Use of Hard-coded Password vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Unauthorized access. |