Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

1906 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.4)0.24%—Novachron Zeitsysteme Gmbh & CO. KG Smart Time PlusAI24/2/202517/6/2026
NovaCHRON Zeitsysteme GmbH & Co. KG Smart Time Plus v8.x to v8.6 was discovered to contain a SQL injection vulnerability via the addProject method in the smarttimeplus/MySQLConnection endpoint.
AplazadaMedia (6.5)0.24%—Novachron Zeitsysteme Smart Time PlusAI24/2/202517/6/2026
Incorrect access control in the component /iclock/Settings?restartNCS=1 of NovaCHRON Zeitsysteme GmbH & Co. KG Smart Time Plus v8.x to v8.6 allows attackers to arbitrarily restart the NCServiceManger via a crafted GET request.
AplazadaAlta (7.1)0.14%—Gmnazmul Smart-maintenance-countdownAI24/2/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in gmnazmul Smart Maintenance & Countdown smart-maintenance-countdown allows Stored XSS.This issue affects Smart Maintenance & Countdown: from n/a through <= 1.2.
AplazadaMedia (6.5)0.23%—Erez Hadas-sonnenschein SmartargetAI18/2/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Erez Hadas-Sonnenschein Smartarget smartarget-contact-us allows Stored XSS.This issue affects Smartarget: from n/a through <= 1.5.3.
AplazadaBaja (1.3)0.42%—Smartbanner.jsAI18/2/202517/6/2026
smartbanner.js is a customizable smart app banner for iOS and Android. Prior to version 1.14.1, clicking on smartbanner `View` link and navigating to 3rd party page leaves `window.opener` exposed. It may allow hostile third parties to abuse `window.opener`, e.g. by redirection or injection on the original page with…
AnalizadaCrítica (9.8)0.55%—Presslayouts Pressmart18/2/202517/6/2026
The PressMart - Modern Elementor WooCommerce WordPress Theme theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.2.16. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes…
ModificadaAlta (8.1)0.22%—Smartzminds Reset18/2/202517/6/2026
The Reset plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.6. This is due to missing or incorrect nonce validation on the reset_db_page() function. This makes it possible for unauthenticated attackers to reset several tables in the database like comments, themes,…
AnalizadaAlta (8.3)0.97%—HP Futuresmart 3HP Futuresmart 4HP Futuresmart 5HP 499m7a Firmware+9414/2/202517/6/2026
Certain HP LaserJet Pro, HP LaserJet Enterprise, and HP LaserJet Managed Printers may potentially be vulnerable to Remote Code Execution and Elevation of Privilege when processing a PostScript print job.
AnalizadaMedia (6.3)0.94%—HP Futuresmart 3HP Futuresmart 5HP Futuresmart 414/2/202517/6/2026
Certain HP LaserJet Pro, HP LaserJet Enterprise, and HP LaserJet Managed Printers may potentially be vulnerable to Remote Code Execution and Elevation of Privilege when processing a PostScript print job.
ModificadaMedia (6.1)0.26%—Smartdatasoft Essential WP Real Estate14/2/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SmartDataSoft Essential WP Real Estate essential-wp-real-estate allows Reflected XSS.This issue affects Essential WP Real Estate: from n/a through <= 1.1.3.
AnalizadaMedia (5.4)0.30%—Wpo-hr NGG Smart Image Search12/2/202517/6/2026
The NGG Smart Image Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'hr_SIS_nextgen_searchbox' shortcode in all versions up to, and including, 3.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated…
AplazadaAlta (7.1)0.14%—Lukaszwiecek Smart DofollowAI7/2/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in LukaszWiecek Smart DoFollow smart-dofollow allows Stored XSS.This issue affects Smart DoFollow: from n/a through <= 1.0.2.
AplazadaMedia (6.5)0.28%—Alex Polonski Smart Countdown FXAI7/2/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Alex Polonski Smart Countdown FX smart-countdown-fx allows Stored XSS.This issue affects Smart Countdown FX: from n/a through <= 1.5.5.
AplazadaMedia (5.7)0.23%—Smartcom Bulgaria AD Smartcom Ralink CPEAISmartcom Bulgaria AD Sam-4g1g-tt-w-vcAISmartcom Bulgaria AD Sam-4f1f-tt-w-a1AI6/2/20255/7/2026
An issue in Smartcom Bulgaria AD Smartcom Ralink CPE/WiFi router SAM-4G1G-TT-W-VC, SAM-4F1F-TT-W-A1 allows a remote attacker to obtain sensitive information via the Weak default WiFi password generation algorithm in WiFi routers.
AplazadaAlta (7.5)0.59%—Netplex Json-smartAI5/2/202517/6/2026
A security issue was found in Netplex Json-smart 2.5.0 through 2.5.1. When loading a specially crafted JSON input, containing a large number of ’{’, a stack exhaustion can be trigger, which could allow an attacker to cause a Denial of Service (DoS). This issue exists because of an incomplete fix for CVE-2023-1370.
AplazadaAlta (7.5)0.38%—Tuya SmartlifeAI3/2/20255/7/2026
Nedis SmartLife android app v1.4.0 was discovered to contain an API key disclosure vulnerability.
AplazadaAlta (7.5)0.37%—Nedis Smartlife Video DoorbellAINedis Smartlife IOSAI3/2/20255/7/2026
An issue in Nedis SmartLife Video Doorbell (WIFICDP10GY), Nedis SmartLife IOS v1.4.0 causes users who are disconnected from a previous peer-to-peer connection with the device to still have access to live video feed.
AnalizadaAlta (7.8)0.11%—Qualcomm Csra6620 FirmwareQualcomm Csra6640 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 Firmware+1233/2/202517/6/2026
Memory corruption while power-up or power-down sequence of the camera sensor.
AnalizadaMedia (6.8)0.60%—Smartdatasoft Essential WP Real Estate3/2/202517/6/2026
The Essential WP Real Estate WordPress plugin through 1.1.3 does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting.
AplazadaMedia (6.4)0.33%—Alex Reservations Smart Restaurant BookingAI30/1/202517/6/2026
The Alex Reservations: Smart Restaurant Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'rr_form' shortcode in all versions up to, and including, 2.0.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for…
AplazadaMedia (6.5)0.26%—Nurul Amin WP Smart Tool TIPAI27/1/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nurul Amin WP Smart Tooltip wp-smart-tool-tip allows Stored XSS.This issue affects WP Smart Tooltip: from n/a through <= 1.0.0.
AplazadaMedia (6.9)0.47%—Telstra Smart Modem GEN 2AI24/1/202517/6/2026
A vulnerability, which was classified as problematic, was found in Telstra Smart Modem Gen 2 up to 20250115. This affects an unknown part of the component HTTP Header Handler. The manipulation of the argument Content-Disposition leads to injection. It is possible to initiate the attack remotely. The vendor was…
AplazadaAlta (7.6)0.83%💥 PoCStoreapps Smart Manager FOR WP E CommerceAI21/1/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in storeapps Smart Manager smart-manager-for-wp-e-commerce allows Blind SQL Injection.This issue affects Smart Manager: from n/a through <= 8.52.0.
AplazadaAlta (8.5)0.34%—Fujielectric Alpha5 SmartAI17/1/202517/6/2026
Fuji Electric Alpha5 SMART is vulnerable to a stack-based buffer overflow, which may allow an attacker to execute arbitrary code.
AplazadaAlta (7.1)0.18%—Itmooti Theme MY Ontraport SmartformAI16/1/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in itmooti Theme My Ontraport Smartform theme-my-ontraport-smartform allows Stored XSS.This issue affects Theme My Ontraport Smartform: from n/a through <= 1.2.11.