Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
1043 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.9) | 0.38% | — | Igloohome Smart Lock Mobile APPAI | 28/7/2026 | 30/7/2026 | In igloohome Smart Lock Mobile App versions 3.2.3 and prior, an Inclusion of Sensitive Information in Source Code vulnerability could allow an unauthorized actor to access functions or backend services that were not sufficiently protected by authentication controls. | |
| Aplazada | Media (5.3) | 0.33% | — | Homebrew JANAI | 24/7/2026 | 17/9/2026 | Jan through 0.8.4, fixed in commit 3e1c1e7, contains a CORS misconfiguration vulnerability in its local API server that allows network-adjacent attackers to bypass trusted host restrictions by exploiting the server's replacement of user-configured trusted hosts with a wildcard that reflects arbitrary origins with… | |
| Pendiente de análisis | Media (5.5) | 0.14% | — | Systemd-homedAIFreedesktop AccountsserviceAI | 24/7/2026 | 24/7/2026 | A flaw was found in accountsservice. The systemd-homed code path for SetIconFile opens a user-supplied filename as root without the validation and privilege drop performed by the classic handler. A local attacker with a systemd-homed-managed account can read arbitrary files accessible to the accounts-daemon process. | |
| Aplazada | Crítica (9) | 0.58% | — | Home-assistant CoreAI | 21/7/2026 | 21/7/2026 | Home Assistant Core before 2026.6.0 contains a path traversal vulnerability that allows unauthenticated attackers to write arbitrary files to any directory on the host filesystem by uploading a crafted backup archive during the initial onboarding window. Attackers can manipulate the 'name' field inside the uploaded… | |
| Aplazada | Crítica (9.3) | 0.80% | 💥 PoC | Home-assistant Home Assistant CoreAI | 21/7/2026 | 21/7/2026 | Home Assistant Core before 2026.7.0 contains a path traversal vulnerability in the backup-restore function that allows attackers to write files to arbitrary absolute filesystem paths by supplying a crafted tar archive with a SYMTYPE entry containing a benign member name paired with an absolute linkname pointing… | |
| Aplazada | Baja (2.1) | 0.30% | — | ShellyAIHome-assistant CoreAI | 21/7/2026 | 22/7/2026 | Home Assistant Core before 2026.5.4 contains a cross-site scripting vulnerability in the Shelly integration's async_get_media_image() method that allows attackers controlling a Shelly device's thumb field to serve arbitrary HTML content by supplying a data URI with a text/html content type without validation against… | |
| Analizada | Media (6.3) | 0.14% | — | Adguardhome | 15/7/2026 | 30/7/2026 | AdGuard Home is a network-wide software for blocking ads and tracking. Prior to 0.107.75, AdGuard Home's client-triggered DoQ forwarding path to a udp:// upstream reduced backend UDP DNS state by producing dns_id=0 or txid=0 and exposed a quoted-port ICMP source-port oracle, weakening DNS response matching for… | |
| Aplazada | Media (6.9) | 0.41% | — | Sergomanov SmarthomeadatumAI | 12/7/2026 | 13/7/2026 | A vulnerability was identified in sergomanov SmartHomeAdatum up to cf495353d81b680675eb8d9aa14a318aa45ce12c. This impacts an unknown function of the file users.php of the component Login. Such manipulation of the argument Login leads to sql injection. The attack may be launched remotely. This product operates on a… | |
| Analizada | Alta (8.8) | 0.11% | — | Qualcomm Wsa8835 FirmwareQualcomm 5G Fixed Wireless Access Platform FirmwareQualcomm Ar8035 FirmwareQualcomm Cq7790 Firmware+124 | 6/7/2026 | 7/7/2026 | Memory Corruption when processing invalid HT40 channel layouts during dynamic channel switching operations. | |
| Aplazada | Crítica (9.5) | 0.65% | 💥 PoC | Gardyn Home KITAIGardyn StudioAI | 3/7/2026 | 6/7/2026 | Gardyn devices expose a privileged iothubowner key. Access to this key will allow a malicious user to invoke an IoTHub Registry Manager function which returns connection information for all Gardyn Home Kit and Studio devices. Access to this key also allows a malicious user to execute arbitrary commands on a specific… | |
| Aplazada | Alta (7.5) | 0.26% | — | Home-assistant IOS Companion APPAI | 29/6/2026 | 30/6/2026 | Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2025.5.0, The iOS companion app ignores the SSID allowlist for internal networks. The app uses SSID to detect when to use the internal URL, but whenever the app cannot find any other URL to be used, it fallbacks… | |
| Aplazada | Alta (8.8) | 0.52% | — | PHPAIInspirythemes RealhomesAI | 26/6/2026 | 26/6/2026 | Subscriber PHP Object Injection in RealHomes <= 4.5.3 versions. | |
| Pendiente de análisis | Media (5.8) | 0.23% | — | Reolink Home HUBAI | 26/6/2026 | 26/6/2026 | A vulnerability exists in the netclient and factory services of Reolink Home Hub (versions prior to v3.3.0.456_26031911) due to the possibility of brute-force cracking the credentials. This issue could allow attackers on the same local network to intercept traffic between the Hub and associated cameras and compromise… | |
| Analizada | Alta (7.1) | 0.17% | — | Home-assistant Home Assistant Companion | 23/6/2026 | 26/6/2026 | Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2026.5.3, the LocationSensorManager BroadcastReceiver is exported with no permission. Any installed app, with zero runtime permissions, can broadcast a forged Google Play Services LocationResult directly to it;… | |
| Modificada | Alta (7.6) | 0.31% | — | Home-assistant | 23/6/2026 | 26/6/2026 | Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2026.6.0, the Konnected integration registers an HTTP endpoint, KonnectedView (homeassistant/components/konnected/__init__.py), that is marked as not requiring authentication (requires_auth = False). A comment… | |
| Aplazada | Alta (8.1) | 0.42% | — | HomeroofierAI | 17/6/2026 | 6/10/2026 | Unauthenticated Local File Inclusion in HomeRoofer <= 2.11.0 versions. | |
| Analizada | Alta (7.4) | 0.41% | — | Aqara Home | 12/6/2026 | 9/7/2026 | Aqara Home Android (com.lumiunited.aqarahome) 6.0.0 (and white-label clients embedding the same liblumidevsdk.so) uses hard-coded cryptographic keys, which is an instance of "CWE-321: Use of Hard-coded Cryptographic Key" and has an estimated CVSS of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N (9.1 Critical). | |
| Aplazada | Crítica (9.2) | 0.84% | — | Adguard HomeAI | 8/6/2026 | 23/7/2026 | AdGuard Home, when started with the --glinet flag, contains an authentication bypass vulnerability that allows unauthenticated attackers to gain full admin access by supplying a path traversal sequence in the Admin-Token cookie, exploiting unsanitized string concatenation in the token file path construction within the… | |
| Analizada | Alta (8.2) | 0.07% | 💥 PoC | Qualcomm Ar9380 FirmwareQualcomm Csr8811 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 Firmware+242 | 1/6/2026 | 22/7/2026 | Cryptographic Issue while processing a specific partition which allows unauthorized write access to load a customized bootloader. | |
| Analizada | Media (5.5) | 0.09% | — | Qualcomm 5G Fixed Wireless Access Platform FirmwareQualcomm Ar8035 FirmwareQualcomm Csr8811 FirmwareQualcomm Fastconnect 6700 Firmware+183 | 1/6/2026 | 22/7/2026 | Information Disclosure when processing advertisement frames with malformed MBSSID elements of insufficient length. | |
| Pendiente de análisis | Alta (8.3) | 0.17% | — | Home-assistant CompanionAIHome-assistant Home AssistantAI | 29/5/2026 | 21/7/2026 | Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2026.4.1 for iOS and 2026.4.4 for Android, he Home Assistant Companion apps for Android and iOS expose a JavaScript bridge to the in-app WebView window.externalApp on Android and… | |
| Analizada | Alta (8.7) | 0.50% | — | Hacs Home Assistant Community Store | 16/5/2026 | 17/6/2026 | Home Assistant Community Store (HACS) prior to 1.10.0 contains a path traversal vulnerability that allows unauthenticated attackers to read sensitive files by traversing directories via the /hacsfiles/ endpoint. Attackers can retrieve the .storage/auth file containing user credentials and refresh tokens, then craft… | |
| Analizada | Alta (7.5) | 0.22% | — | Qualcomm Snapdragon X65 5G Modem-rf FirmwareQualcomm Snapdragon X72 5G Modem-rf FirmwareQualcomm Snapdragon X75 5G Modem-rf FirmwareQualcomm Srv1h Firmware+253 | 4/5/2026 | 30/9/2026 | Transient DOS when processing a malformed Fast Transition response frame with an invalid header structure during wireless roaming. | |
| Analizada | Alta (7.5) | 0.22% | — | Qualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 Firmware+241 | 4/5/2026 | 30/9/2026 | Transient DOS when processing target power rate tables during channel configuration. | |
| Aplazada | Baja (2.1) | 0.45% | 💥 PoC | Code-projects Home Service SystemAI | 27/4/2026 | 17/6/2026 | A security vulnerability has been detected in code-projects Home Service System 1.0. The impacted element is an unknown function of the file /booking.php of the component Appointment Booking. The manipulation of the argument fname/lname leads to cross site scripting. The attack may be initiated remotely. The exploit… |