Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

1878 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaBaja (3.9)0.21%—ZTE Smart LifeAI5/8/202626/8/2026
The ZTE Smart Life app contains an SQL injection vulnerability that allows attackers to execute UNION SELECT statements to query sensitive data in the feedback.db database across tables, including user accounts, phone numbers, feedback content, and local debug log paths, thereby enabling the theft of local privacy…
AplazadaAlta (8.8)0.59%💥 PoCSupsystic Smart PopupAI5/8/202612/8/2026
The Smart Popup by Supsystic plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.12.0. This is due to a permission map collision in the `havePermissions()` function in `classes/frame.php`, where `array_merge()` overwrites the popup module's administrator-restricted method…
AnalizadaAlta (7.6)0.15%—Qualcomm Sm6225p FirmwareQualcomm Sm6450p FirmwareQualcomm Sm6475p FirmwareQualcomm Sm6475q Firmware+2074/8/20266/8/2026
Memory Corruption when processing untrusted user input in the fastboot command handler for audio framework configuration.
AplazadaAlta (7.1)0.27%—LG Electronics SmartshareAIMicrosoft Windows 10AI30/7/202630/7/2026
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in LG Electronics SmartShare allows SQL Injection. This issue affects SmartShare: through 2.3.1712.1202, which is supported on Microsoft Windows 10 and earlier versions.
AplazadaMedia (6.9)0.38%—Igloohome Smart Lock Mobile APPAI28/7/202630/7/2026
In igloohome Smart Lock Mobile App versions 3.2.3 and prior, an Inclusion of Sensitive Information in Source Code vulnerability could allow an unauthorized actor to access functions or backend services that were not sufficiently protected by authentication controls.
AplazadaMedia (4.8)0.18%—Procertum SmartsignAI27/7/202630/7/2026
proCertum SmartSign parses external XML entities from arbitrary crafted signature files, enabling SSRF and potentially allowing the reading of local files, depending on the parser's configuration. The XML External Entity (XXE) vulnerability is triggered simply by previewing a file in the file selection window, before…
AplazadaMedia (4.6)0.11%—Procertum SmartsignAI27/7/202630/7/2026
proCertum SmartSign opens Certificate Practice Statement (CPS) URI without schema validation. An attacker can prepare arbitrary certificate with CPS URI pointing to a local executable file or any URL, sign a document with it, and send it to the victim. When the victim opens the document in the application, the…
AplazadaMedia (4.8)0.24%—Smart ManagerAI27/7/202627/7/2026
The Smart Manager WordPress plugin before 8.92.0 does not properly encode a post field before rendering it into an HTML attribute in its management grid, allowing users with the Contributor role or above to inject JavaScript that executes in the browser session of an administrator who views the grid.
AplazadaMedia (6.5)0.22%—Wbolt Smart SEO ToolAI23/7/202623/7/2026
Contributor Cross Site Scripting (XSS) in Smart SEO Tool <= 4.1.2 versions.
AplazadaAlta (7.1)0.25%—Smart ManagerAI23/7/202623/7/2026
Unauthenticated Cross Site Scripting (XSS) in Smart Manager <= 8.90.0 versions.
AplazadaMedia (5.4)0.23%—Bifra Engineering Consulting LTD Q-smart Next PollAI20/7/202620/7/2026
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Bifra Engineering Consulting Ltd. Q-smart NexT Poll allows Stored XSS. This issue affects Q-smart NexT Poll: before 1.8.7.
AplazadaMedia (6.4)0.32%—Smart Custom FieldsAI17/7/202617/7/2026
The Smart Custom Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.0.7. This is due to insufficient input sanitization and output escaping of uploaded image attachment titles. This makes it possible for authenticated attackers, with Author-level access and…
Pendiente de análisisMedia (6.8)0.13%—Lenovo Smart ConnectAI16/7/202616/7/2026
During an internal security assessment, a potential improper access control vulnerability was discovered in Lenovo Smart Connect for Windows that could allow a local authenticated user to access files owned by a different user on the same system.
AplazadaMedia (4.3)0.41%—Nextendweb Smart Slider 3AI13/7/202614/7/2026
The Smart Slider 3 plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.5.1.37 via the 'keyword' parameter. This makes it possible for authenticated attackers, with contributor-level access and above, to extract titles and full content excerpts of private, draft,…
AplazadaMedia (6.9)0.41%—Sergomanov SmarthomeadatumAI12/7/202613/7/2026
A vulnerability was identified in sergomanov SmartHomeAdatum up to cf495353d81b680675eb8d9aa14a318aa45ce12c. This impacts an unknown function of the file users.php of the component Login. Such manipulation of the argument Login leads to sql injection. The attack may be launched remotely. This product operates on a…
AplazadaMedia (5.1)0.15%—Samsung SmartthingskitAI10/7/202610/7/2026
Improper access control in SmartThingsKit prior to SMR Jul-2026 Release 1 allows local attackers to access sensitive information.
AplazadaMedia (5.5)0.43%—Code-projects Smart Parking SystemAI5/7/20267/7/2026
A vulnerability has been found in code-projects Smart Parking System 1.0. The affected element is an unknown function of the file /parkings/parkings.php. Such manipulation of the argument street/city/status leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the public and…
AplazadaCrítica (9.3)0.40%—JetsmartfiltersAI26/6/202626/6/2026
Unauthenticated SQL Injection in JetSmartFilters <= 3.8.3 versions.
AplazadaAlta (7.5)0.43%—Shapedsmart Smart Post Show PROAIReal Testimonials PROAIProduct Slider FOR Woocommerce PROAI24/6/202625/6/2026
Multiple Shapedsmart-post-show-pro WordPress plugin before 4.0.2, Real Testimonials Pro WordPress plugin before 3.2.5, Product Slider for WooCommerce Pro WordPress plugin before 3.5.3 Pro smart-post-show-pro WordPress plugin before 4.0.2, Real Testimonials Pro WordPress plugin before 3.2.5, Product Slider for…
AplazadaAlta (8.1)0.44%—Presslayouts PressmartAI17/6/202617/6/2026
Unauthenticated PHP Object Injection in PressMart <= 1.2.26 versions.
AplazadaAlta (7.2)0.24%—Mitsubishielectric Room AIR ConditionersAIMitsubishielectric Wireless LAN Adapters FOR Room AIR ConditionersAIMitsubishielectric Wireless LAN Adapters FOR Packaged AIR ConditionersAIMitsubishielectric RefrigeratorsAI+1217/6/202617/6/2026
Use of Hard-coded Credentials vulnerability in Mitsubishi Electric Room Air Conditioners (for Japan and outside Japan); Wireless LAN Adapters for Room Air Conditioners (for Japan and outside Japan); Wireless LAN Adapters for Packaged Air Conditioners (for Japan and outside Japan); Refrigerators (for Japan); Heat Pump…
AplazadaCrítica (9.3)0.40%—JetsmartfiltersAI17/6/202617/6/2026
Unauthenticated SQL Injection in JetSmartFilters <= 3.8.1 versions.
AplazadaMedia (4.8)0.51%—Teldat Regesta Smart Hd-plcAI17/6/20261/7/2026
An attacker with access via network to the Regesta Smart HD-PLC of the provider Teldat (in this case, registration action IS required) who has the vulnerable software could, introduce arbitrary JavaScript by injecting a Cross-site Scripting (XSS) payload into the 'Hostname' field of the configuration file resulting in…
AplazadaMedia (6.9)0.52%—Teldat Regesta Smart Hd-plcAI17/6/20261/7/2026
An attacker with access via network to the Regesta Smart HD-PLC of the provider Teldat (in this case, NO registration action is required) who has the vulnerable software could, with a Slow Loris attack, cause Denial of Service (DoS) on the web interface of the device. This issue affects Regesta Smart HD-PLC -…
AplazadaMedia (6.9)0.52%—Teldat Regesta Smart Hd-plcAI17/6/20261/7/2026
An attacker with access via network to the Regesta Smart HD-PLC of the provider Teldat (in this case, NO registration action is required) who has the vulnerable software could obtain privilege information by using the command Version via the path: /upgrade/query.php?cmd=p+3&3Bversion resulting in a information…