Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

1878 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.3)0.40%—Smart Marketing SMS AND Newsletters FormsAI31/8/20262/9/2026
Unauthenticated SQL Injection in Smart Marketing SMS and Newsletters Forms <= 5.1.24 versions.
AplazadaMedia (6.9)0.57%—SmartyAI31/8/20268/9/2026
Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prior to 4.5.7 and 5.8.2, depending on the release line, Smarty's {fetch} handling in libs/plugins/function.fetch.php and src/FunctionHandler/Fetch.php used Security::isTrustedUri() to validate only the…
AplazadaAlta (7.7)0.19%—SmartaipressAI29/8/202631/8/2026
The SmartAIPress WordPress plugin through 1.2.0 does not perform a capability check on one of its AJAX actions and does not validate a user-supplied URL before fetching it server-side, allowing users with subscriber-level access and above to make the site retrieve arbitrary internal or external URLs and read the…
AplazadaMedia (6.4)0.32%—Nextendweb Smart Slider 3AI28/8/202628/8/2026
The Smart Slider 3 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'slider' Block Attribute in all versions up to, and including, 3.5.1.38 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to…
AplazadaCrítica (9.8)0.69%—Smart-web2AI26/8/20261/9/2026
The report module in the backend of smart-web2 v1.3.1 is vulnerable to arbitrary SQL execution. The sqlResource.sql parameter is stored in the t_report_sql_resource table through the ReportController.save() interface and directly embedded into Hibernate native queries without any parameterization or filtering.
AplazadaAlta (8.7)0.35%—Bosch Smart HomeAI26/8/20268/9/2026
Rently Smart Home versions 20.1.0 and prior are vulnerable to an Insufficiently Protected Credentials vulnerability. This could allow an attacker to retrieve pins including the Master Pin, overriding standard user permissions.
AplazadaCrítica (9.8)0.64%💥 PoCBaylan Measuring Instruments Industry AND Trade INC Baylan Smart Meter Management ApplicationAI20/8/202626/8/2026
Missing authentication for critical function vulnerability in Baylan Measuring Instruments Industry and Trade Inc. Baylan Smart Meter Management Application (BMS) allows Authentication Bypass. This issue affects Baylan Smart Meter Management Application (BMS): before v1.1.10.142.
AplazadaCrítica (9.9)0.48%—Smart CleaningAI20/8/202620/8/2026
Subscriber Arbitrary File Upload in Smart Cleaning <= 4.8.6 versions.
AplazadaAlta (7.1)0.25%—SmartsmtpAI20/8/202620/8/2026
Unauthenticated Cross Site Scripting (XSS) in SmartSMTP <= 1.2.0 versions.
AplazadaCrítica (9.3)0.40%—Wpo-hr NGG Smart Image SearchAI19/8/202620/8/2026
Unauthenticated SQL Injection in NGG Smart Image Search < 4.0.0 versions.
AplazadaMedia (4.3)0.27%—Wpmudev SmartcrawlAI19/8/202626/8/2026
The SmartCrawl SEO checker, analyzer & optimizer WordPress plugin before 3.16.3 does not perform capability checks on two of its AJAX actions, allowing users with at least the Subscriber role to read the titles of private and draft posts by ID and to enumerate stored post-meta key names.
AplazadaAlta (7.2)0.27%—PDF Smart ViewerAI18/8/202620/8/2026
Unauthenticated Server Side Request Forgery (SSRF) in PDF Smart Viewer for Elementor <= 1.0.4 versions.
AplazadaMedia (6.9)0.45%—HP Smart Tank All-in-oneAI17/8/202631/8/2026
Certain HP Smart Tank All-in-One printers may be potentially vulnerable to a denial of service condition that allows an unauthenticated attacker to cause the device to become unavailable by sending multiple concurrent HTTP requests.
AplazadaMedia (5.3)0.32%—Shopsmart LoyaltyAI17/8/202626/8/2026
The ShopSmart Loyalty for WooCommerce WordPress plugin through 1.0.0 does not perform any authorization or ownership check on a phone-number lookup exposed to unauthenticated users, allowing anyone who knows a customer's phone number to retrieve that customer's loyalty profile, including name, email, and account…
AplazadaAlta (7.1)0.25%—Zaytech Smart Online Order FOR CloverAI13/8/202614/8/2026
Unauthenticated Cross Site Scripting (XSS) in Smart Online Order for Clover <= 1.6.1 versions.
AplazadaAlta (7.5)0.35%—Storegrowth Smart Sales Booster FOR WoocommerceAI13/8/202614/8/2026
Unauthenticated Broken Access Control in StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart <= 2.1.1 versions.
Pendiente de análisisMedia (6.9)0.13%—Samsung SmartthingsAI10/8/202618/8/2026
Improper access control in SmartThings prior to version 1.8.47.24 allows local attackers to access sensitive information.
AnalizadaMedia (6.8)0.26%—Samsung Smart Switch10/8/202619/8/2026
Improper input validation in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to access sensitive data.
AnalizadaMedia (6.9)0.17%—Samsung Smart Switch10/8/202619/8/2026
Cleartext storage of sensitive information in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to access sensitive data.
AnalizadaAlta (7)0.10%—Samsung Smart Switch10/8/202619/8/2026
Missing encryption of sensitive data in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to intercept transmitted data.
AnalizadaMedia (4.7)0.16%—Samsung Smart Switch10/8/202619/8/2026
Insufficient verification of data authenticity in Smart Switch trouble scanning mode prior to version 3.7.72.6 allows adjacent attackers to spoof device identity.
AplazadaMedia (6.9)0.51%—SmartyAI7/8/20269/9/2026
Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. From 5.0.0 until 5.8.4, Smarty's stream: resource-name handling does not adequately restrict which PHP stream wrappers and filter chains can be referenced from a template, allowing a php://filter-wrapped…
AplazadaMedia (6.9)0.53%—SmartyAI7/8/20269/9/2026
Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prior to 5.8.2 (and 4.5.7 on the 4.x line), Security::_checkDir() does not fully resolve symbolic links before validating that a requested path lies within a configured secure directory. An attacker able…
AplazadaCrítica (9.8)0.86%—Fcba ZZM Smart Park Management SystemAI6/8/202631/8/2026
ICS-Park Smart Park Management System v2.0 contains an unrestricted file upload vulnerability in the file upload module. This allows a remote attacker to execute arbitrary code.
Pendiente de análisisMedia (5.6)0.11%—Elan Microelectronics Corp Elan Smart-padAIElan Microelectronics Corp Etd.sysAIElan Microelectronics Corp Etdsmbus.sysAI6/8/20263/9/2026
A stack-based buffer overflow vulnerability exists in ELAN Microelectronics Corp. ELAN Smart-Pad on Windows (ETD.sys and ETDSMBus.sys). During Intel SMBus recovery, ETDSMBus.sys does not enforce an upper-bound check on the hardware-derived report count, allowing an out-of-range value to be forwarded to ETD.sys where…