Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
1906 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 72% | 💥 PoC | Samba RsyncAlmalinuxArchlinux Arch LinuxGentoo Linux+4 | 15/1/2025 | 29/6/2026 | A heap-based buffer overflow flaw was found in the rsync daemon. This issue is due to improper handling of attacker-controlled checksum lengths (s2length) in the code. When MAX_DIGEST_LEN exceeds the fixed SUM_LENGTH (16 bytes), an attacker can write out of bounds in the sum2 buffer. | |
| Aplazada | Media (6.4) | 0.27% | — | WP Smart TVAI | 15/1/2025 | 17/6/2026 | The WP Smart TV plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tv-video-player' shortcode in all versions up to, and including, 2.1.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Modificada | Alta (7.5) | 4.7% | — | Samba RsyncRedhat DiscoveryRedhat Openshift Container PlatformRedhat Enterprise Linux+16 | 14/1/2025 | 30/6/2026 | A flaw was found in rsync. When using the `--safe-links` option, the rsync client fails to properly verify if a symbolic link destination sent from the server contains another symbolic link within it. This results in a path traversal vulnerability, which may lead to arbitrary file write outside the desired directory. | |
| Modificada | Alta (7.5) | 2.3% | — | Samba RsyncAlmalinuxArchlinux Arch LinuxGentoo Linux+14 | 14/1/2025 | 30/6/2026 | A path traversal vulnerability exists in rsync. It stems from behavior enabled by the `--inc-recursive` option, a default-enabled option for many client options and can be enabled by the server even if not explicitly enabled by the client. When using the `--inc-recursive` option, a lack of proper symlink verification… | |
| Modificada | Media (6.8) | 1.8% | — | Samba RsyncRedhat Openshift Container PlatformRedhat Enterprise LinuxAlmalinux+5 | 14/1/2025 | 21/8/2026 | A flaw was found in rsync. It could allow a server to enumerate the contents of an arbitrary file from the client's machine. This issue occurs when files are being copied from a client to a server. During this process, the rsync server will send checksums of local data to the client to compare with in order to… | |
| Modificada | Alta (7.5) | 8.8% | 💥 PoC | Samba RsyncRedhat OpenshiftRedhat Openshift Container PlatformRedhat Enterprise Linux+18 | 14/1/2025 | 21/9/2026 | A flaw was found in rsync which could be triggered when rsync compares file checksums. This flaw allows an attacker to manipulate the checksum length (s2length) to cause a comparison between a checksum and uninitialized memory and leak one byte of uninitialized stack data at a time. | |
| Analizada | Alta (8.2) | 1.1% | 💥 PoC | Cs-grp NEO ImpactGreenware GreenguardHowyar SysreturnRadix Smart Recovery+3 | 14/1/2025 | 17/6/2026 | Howyar UEFI Application "Reloader" (32-bit and 64-bit) is vulnerable to execution of unsigned software in a hardcoded path. | |
| Aplazada | Alta (7.1) | 0.26% | — | Smart AgendaAI | 13/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Smart Agenda Smart Agenda smart-agenda-prise-de-rendez-vous-en-ligne allows Stored XSS.This issue affects Smart Agenda: from n/a through <= 4.7. | |
| Aplazada | Media (6.4) | 0.32% | — | Gatormail SmartformsAI | 11/1/2025 | 17/6/2026 | The GatorMail SmartForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gatormailsmartform' shortcode in all versions up to, and including, 1.1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Analizada | Media (5.3) | 0.34% | — | Smartdatasoft Essential WP Real Estate | 10/1/2025 | 17/6/2026 | The Essential WP Real Estate plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the cl_delete_listing_func() function in all versions up to, and including, 1.1.3. This makes it possible for unauthenticated attackers to delete arbitrary pages and posts. | |
| Aplazada | Alta (7.5) | 0.50% | — | Smart Toilet LAB MotiusAIDjangoAI | 9/1/2025 | 17/6/2026 | Smart Toilet Lab - Motius 1.3.11 is running with debug mode turned on (DEBUG = True) and exposing sensitive information defined in Django settings file through verbose error page. | |
| Analizada | Crítica (9.1) | 0.35% | — | Smart IP BAN Project Smart IP BAN | 9/1/2025 | 17/6/2026 | Incorrect Authorization vulnerability in Drupal Smart IP Ban allows Forceful Browsing.This issue affects Smart IP Ban: from 7.X-1.0 before 7.X-1.1. | |
| Analizada | Crítica (9.8) | 0.55% | — | Apple Smart Card Services | 8/1/2025 | 17/6/2026 | This issue is fixed in SCSSU-201801. A potential stack based buffer overflow existed in GemaltoKeyHandle.cpp. | |
| Aplazada | Media (6.5) | 0.26% | — | Takashi Kitajima Smart Custom FieldsAI | 7/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Takashi Kitajima Smart Custom Fields smart-custom-fields allows Stored XSS.This issue affects Smart Custom Fields: from n/a through <= 5.0.0. | |
| Aplazada | Media (6.1) | 0.36% | — | SmartemailingAI | 7/1/2025 | 17/6/2026 | The SmartEmailing.cz plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'se-lists-updated' parameter in all versions up to, and including, 2.2.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in… | |
| Aplazada | Media (6.1) | 0.36% | — | Xylusthemes WP Smart ImportAI | 4/1/2025 | 17/6/2026 | The WP Smart Import : Import any XML File to WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘ page’ parameter in all versions up to, and including, 1.1.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject… | |
| Aplazada | Media (6.5) | 0.22% | — | Smartsupp Live ChatAI | 2/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Smartsupp Smartsupp – live chat, chatbots, AI and lead generation smartsupp-live-chat allows Cross Site Request Forgery.This issue affects Smartsupp – live chat, chatbots, AI and lead generation: from n/a through <= 3.6. | |
| Aplazada | Media (4.3) | 0.29% | — | Storeapps Smart Manager FOR WP E CommerceAI | 31/12/2024 | 17/6/2026 | Missing Authorization vulnerability in storeapps Smart Manager smart-manager-for-wp-e-commerce.This issue affects Smart Manager: from n/a through <= 8.45.0. | |
| Aplazada | Media (6.5) | 0.38% | — | Yulio Aleman Jimenez Smart Shopify ProductAI | 31/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Yulio Aleman Jimenez Smart Shopify Product smart-shopify-product allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Smart Shopify Product: from n/a through <= 1.0.2. | |
| Aplazada | Alta (7.5) | 0.59% | — | Smarts-srl Smart AgentAI | 27/12/2024 | 17/6/2026 | A Server-Side Request Forgery (SSRF) in smarts-srl.com Smart Agent v.1.1.0 allows a remote attacker to obtain sensitive information via a crafted script to the /FB/getFbVideoSource.php component. | |
| Analizada | Crítica (9.8) | 0.89% | — | Smarts-srl Smart Agent | 27/12/2024 | 17/6/2026 | SQL injection vulnerability in Smart Agent v.1.1.0 allows a remote attacker to execute arbitrary code via the client parameter in the /recuperaLog.php component. | |
| Analizada | Crítica (9.8) | 0.89% | — | Smarts-srl Smart Agent | 27/12/2024 | 17/6/2026 | SQL injection vulnerability in Smart Agent v.1.1.0 allows a remote attacker to execute arbitrary code via the id parameter in the /sendPushManually.php component. | |
| Analizada | Alta (7.5) | 1.4% | — | Smarts-srl Smart Agent | 27/12/2024 | 17/6/2026 | An issue in smarts-srl.com Smart Agent v.1.1.0 allows a remote attacker to obtain sensitive information via command injection through a vulnerable unsanitized parameter defined in the /youtubeInfo.php component. | |
| Analizada | Crítica (9.8) | 0.53% | — | Smarts-srl Smart Agent | 27/12/2024 | 17/6/2026 | SmartAgent v1.1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /tests/interface.php. | |
| Analizada | Crítica (9.3) | 0.78% | — | Intumit Smartrobot | 26/12/2024 | 17/6/2026 | A Improper Control of Generation of Code ('Code Injection') vulnerability in groovy script function in SmartRobot′s Conversational AI Platform before v7.2.0 allows remote authenticated users to perform arbitrary system commands via Groovy code. |