Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2759▼ 357 respecto a la semana anterior
Críticas / altas1278▼ 254 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)223▼ 98 respecto a la semana anterior
–

1906 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)1.1%—Pymumu Smartdns28/4/202317/6/2026
SmartDNS through 41 before 56d0332 allows an out-of-bounds write because of a stack-based buffer overflow in the _dns_encode_domain function in the dns.c file, via a crafted DNS request.
ModificadaMedia (4.8)0.37%—Smartlogix Wp-insert25/4/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in namithjawahar Wp-Insert plugin <= 2.5.0 versions.
ModificadaMedia (6.5)0.18%—Electra-air Smart KIT FOR Split AC17/4/202317/6/2026
Electra Central AC unit – Adjacent attacker may cause the unit to load unauthorized FW.
ModificadaAlta (8.8)0.76%—Phoenixcontact Energy AXC PUPhoenixcontact Infobox FirmwarePhoenixcontact Smartrtu AXC SG FirmwarePhoenixcontact Smartrtu AXC IG Firmware17/4/202317/6/2026
In Phoenix Contacts ENERGY AXC PU Web service an authenticated restricted user of the web frontend can access, read, write and create files throughout the file system using specially crafted URLs via the upload and download functionality of the web service. This may lead to full control of the service.
ModificadaAlta (7.5)2.7%💥 ExploitWashington I-tech Trainsmart16/4/202317/6/2026
A SQL injection vulnerability in I-Tech Trainsmart r1044 exists via a evaluation/assign-evaluation?id= URI.
ModificadaAlta (7.2)2.1%💥 PoCSmartptt Scada14/4/202317/6/2026
SmartPTT SCADA 1.1.0.0 allows remote code execution (when the attacker has administrator privileges) by writing a malicious C# script and executing it on the server (via server settings in the administrator control panel on port 8101, by default).
ModificadaAlta (7.8)0.08%—Qualcomm 8998 FirmwareQualcomm 315 5G IOT Modem FirmwareQualcomm Apq8009 FirmwareQualcomm Aqt1000 Firmware+21513/4/202317/6/2026
Memory corruption due to double free in core while initializing the encryption key.
ModificadaMedia (4.8)0.39%—Catchsquare WP Smart Preloader30/3/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Catchsquare WP Smart Preloader plugin <= 1.15 versions.
ModificadaMedia (6.1)1.0%💥 PoCSmartyFedoraproject Fedora28/3/202317/6/2026
Smarty is a template engine for PHP. In affected versions smarty did not properly escape javascript code. An attacker could exploit this vulnerability to execute arbitrary JavaScript code in the context of the user's browser session. This may lead to unauthorized access to sensitive user data, manipulation of the web…
ModificadaMedia (5.4)0.48%—Nextendweb Smart Slider 327/3/202317/6/2026
The Smart Slider 3 WordPress plugin before 3.5.1.14 does not properly validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
ModificadaAlta (7.5)0.36%—Invernyx Smartcars 324/3/202317/6/2026
smartCARS 3 is flight tracking software. In version 0.5.8 and prior, all persons who have failed login attempts will have their password stored in error logs. This problem doesn't occur in version 0.5.9. As a workaround, delete the affected log file, and ensure one logs in correctly.
ModificadaMedia (5.4)0.38%—Nextendweb Smart Slider 323/3/202317/6/2026
Auth. (contributor+) Stored Cross-Site Scripting vulnerability in Nextend Smart Slider 3 plugin <= 3.5.1.9 versions.
ModificadaAlta (7.5)1.1%—Json-smart Project Json-smart22/3/202317/6/2026
[Json-smart](https://netplex.github.io/json-smart/) is a performance focused, JSON processor lib. When reaching a ‘[‘ or ‘{‘ character in the JSON input, the code parses an array or an object respectively. It was discovered that the code does not have any limit to the nesting of such arrays or objects. Since the…
ModificadaMedia (5.3)0.44%—Silabs Wireless Smart Ubiquitous Network Linux Border Router Firmware21/3/202317/6/2026
Missing MAC layer security in Silicon Labs Wi-SUN Linux Border Router v1.5.2 and earlier allows malicious node to route malicious messages through network.
ModificadaMedia (5.4)0.47%—Accesspressthemes Smart Logo Showcase Lite20/3/202317/6/2026
The Responsive Clients Logo Gallery Plugin for WordPress plugin through 1.1.9 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
ModificadaCrítica (9.1)0.69%—Smartconrtactgames Project Smartconrtactgames16/3/202317/6/2026
An issue found in DepositGame v.1.0 allows an attacker to gain sensitive information via the GetBonusWithdraw and withdraw functions.
ModificadaAlta (7.5)0.60%—Smartbear Zephyr Enterprise8/3/202317/6/2026
There exists an information disclosure vulnerability in SmartBear Zephyr Enterprise through 7.15.0 that could be exploited by unauthenticated users to read arbitrary files from Zephyr instances.
ModificadaAlta (8.1)0.51%—Smartbear Zephyr Enterprise8/3/202317/6/2026
There exists a privilege escalation vulnerability in SmartBear Zephyr Enterprise through 7.15.0 that could be exploited by authorized users to reset passwords for other accounts.
ModificadaAlta (7.5)0.64%—Smartbear Zephyr Enterprise8/3/202317/6/2026
SmartBear Zephyr Enterprise through 7.15.0 allows unauthenticated users to upload large files, which could exhaust the local drive space, causing a denial of service condition.
ModificadaCrítica (9.8)1.3%—Smartbear Zephyr Enterprise8/3/202317/6/2026
SmartBear Zephyr Enterprise through 7.15.0 mishandles user-defined input during report generation. This could lead to remote code execution by unauthenticated users.
ModificadaAlta (7.5)6.2%💥 ExploitSmartofficepayroll Smartoffice28/2/202317/6/2026
An issue was discovered in Smart Office Web 20.28 and earlier allows attackers to view sensitive information via DisplayParallelLogData.aspx.
ModificadaAlta (7.5)59%💥 ExploitSmartofficepayroll Smartoffice28/2/202317/6/2026
An issue was discovered in Smart Office Web 20.28 and earlier allows attackers to download sensitive information via the action name parameter to ExportEmployeeDetails.aspx, and to ExportReportingManager.aspx.
ModificadaCrítica (9.8)0.95%—Linuxfoundation Modular Open Smart Network17/2/202317/6/2026
Authentication vulnerability in MOSN v.0.23.0 allows attacker to escalate privileges via case-sensitive JWT authorization.
ModificadaCrítica (9.1)0.54%—Ricoh MP C307 FirmwareRicoh MP C407 FirmwareRicoh MP C406 FirmwareRicoh MP C306 Firmware+7316/2/202317/6/2026
Ricoh mp_c4504ex devices with firmware 1.06 mishandle credentials.
AnalizadaCrítica (9.8)98%⚠ Explotación activa💥 ExploitRuckuswireless Ruckus Wireless AdminRuckuswireless Smartzone APCommscope Ruckus Smartzone Firmware13/2/202317/6/2026
Ruckus Wireless Admin hasta la versión 10.4 permite la ejecución remota de código a través de una solicitud HTTP GET no autenticada, como lo demuestra /forms/doLogin?login_username=admin&amp;password=password$(curl substring.