Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2759▼ 357 respecto a la semana anterior
Críticas / altas1278▼ 254 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)223▼ 98 respecto a la semana anterior
1906 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.1% | — | Pymumu Smartdns | 28/4/2023 | 17/6/2026 | SmartDNS through 41 before 56d0332 allows an out-of-bounds write because of a stack-based buffer overflow in the _dns_encode_domain function in the dns.c file, via a crafted DNS request. | |
| Modificada | Media (4.8) | 0.37% | — | Smartlogix Wp-insert | 25/4/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in namithjawahar Wp-Insert plugin <= 2.5.0 versions. | |
| Modificada | Media (6.5) | 0.18% | — | Electra-air Smart KIT FOR Split AC | 17/4/2023 | 17/6/2026 | Electra Central AC unit – Adjacent attacker may cause the unit to load unauthorized FW. | |
| Modificada | Alta (8.8) | 0.76% | — | Phoenixcontact Energy AXC PUPhoenixcontact Infobox FirmwarePhoenixcontact Smartrtu AXC SG FirmwarePhoenixcontact Smartrtu AXC IG Firmware | 17/4/2023 | 17/6/2026 | In Phoenix Contacts ENERGY AXC PU Web service an authenticated restricted user of the web frontend can access, read, write and create files throughout the file system using specially crafted URLs via the upload and download functionality of the web service. This may lead to full control of the service. | |
| Modificada | Alta (7.5) | 2.7% | 💥 Exploit | Washington I-tech Trainsmart | 16/4/2023 | 17/6/2026 | A SQL injection vulnerability in I-Tech Trainsmart r1044 exists via a evaluation/assign-evaluation?id= URI. | |
| Modificada | Alta (7.2) | 2.1% | 💥 PoC | Smartptt Scada | 14/4/2023 | 17/6/2026 | SmartPTT SCADA 1.1.0.0 allows remote code execution (when the attacker has administrator privileges) by writing a malicious C# script and executing it on the server (via server settings in the administrator control panel on port 8101, by default). | |
| Modificada | Alta (7.8) | 0.08% | — | Qualcomm 8998 FirmwareQualcomm 315 5G IOT Modem FirmwareQualcomm Apq8009 FirmwareQualcomm Aqt1000 Firmware+215 | 13/4/2023 | 17/6/2026 | Memory corruption due to double free in core while initializing the encryption key. | |
| Modificada | Media (4.8) | 0.39% | — | Catchsquare WP Smart Preloader | 30/3/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Catchsquare WP Smart Preloader plugin <= 1.15 versions. | |
| Modificada | Media (6.1) | 1.0% | 💥 PoC | SmartyFedoraproject Fedora | 28/3/2023 | 17/6/2026 | Smarty is a template engine for PHP. In affected versions smarty did not properly escape javascript code. An attacker could exploit this vulnerability to execute arbitrary JavaScript code in the context of the user's browser session. This may lead to unauthorized access to sensitive user data, manipulation of the web… | |
| Modificada | Media (5.4) | 0.48% | — | Nextendweb Smart Slider 3 | 27/3/2023 | 17/6/2026 | The Smart Slider 3 WordPress plugin before 3.5.1.14 does not properly validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks | |
| Modificada | Alta (7.5) | 0.36% | — | Invernyx Smartcars 3 | 24/3/2023 | 17/6/2026 | smartCARS 3 is flight tracking software. In version 0.5.8 and prior, all persons who have failed login attempts will have their password stored in error logs. This problem doesn't occur in version 0.5.9. As a workaround, delete the affected log file, and ensure one logs in correctly. | |
| Modificada | Media (5.4) | 0.38% | — | Nextendweb Smart Slider 3 | 23/3/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting vulnerability in Nextend Smart Slider 3 plugin <= 3.5.1.9 versions. | |
| Modificada | Alta (7.5) | 1.1% | — | Json-smart Project Json-smart | 22/3/2023 | 17/6/2026 | [Json-smart](https://netplex.github.io/json-smart/) is a performance focused, JSON processor lib. When reaching a ‘[‘ or ‘{‘ character in the JSON input, the code parses an array or an object respectively. It was discovered that the code does not have any limit to the nesting of such arrays or objects. Since the… | |
| Modificada | Media (5.3) | 0.44% | — | Silabs Wireless Smart Ubiquitous Network Linux Border Router Firmware | 21/3/2023 | 17/6/2026 | Missing MAC layer security in Silicon Labs Wi-SUN Linux Border Router v1.5.2 and earlier allows malicious node to route malicious messages through network. | |
| Modificada | Media (5.4) | 0.47% | — | Accesspressthemes Smart Logo Showcase Lite | 20/3/2023 | 17/6/2026 | The Responsive Clients Logo Gallery Plugin for WordPress plugin through 1.1.9 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Modificada | Crítica (9.1) | 0.69% | — | Smartconrtactgames Project Smartconrtactgames | 16/3/2023 | 17/6/2026 | An issue found in DepositGame v.1.0 allows an attacker to gain sensitive information via the GetBonusWithdraw and withdraw functions. | |
| Modificada | Alta (7.5) | 0.60% | — | Smartbear Zephyr Enterprise | 8/3/2023 | 17/6/2026 | There exists an information disclosure vulnerability in SmartBear Zephyr Enterprise through 7.15.0 that could be exploited by unauthenticated users to read arbitrary files from Zephyr instances. | |
| Modificada | Alta (8.1) | 0.51% | — | Smartbear Zephyr Enterprise | 8/3/2023 | 17/6/2026 | There exists a privilege escalation vulnerability in SmartBear Zephyr Enterprise through 7.15.0 that could be exploited by authorized users to reset passwords for other accounts. | |
| Modificada | Alta (7.5) | 0.64% | — | Smartbear Zephyr Enterprise | 8/3/2023 | 17/6/2026 | SmartBear Zephyr Enterprise through 7.15.0 allows unauthenticated users to upload large files, which could exhaust the local drive space, causing a denial of service condition. | |
| Modificada | Crítica (9.8) | 1.3% | — | Smartbear Zephyr Enterprise | 8/3/2023 | 17/6/2026 | SmartBear Zephyr Enterprise through 7.15.0 mishandles user-defined input during report generation. This could lead to remote code execution by unauthenticated users. | |
| Modificada | Alta (7.5) | 6.2% | 💥 Exploit | Smartofficepayroll Smartoffice | 28/2/2023 | 17/6/2026 | An issue was discovered in Smart Office Web 20.28 and earlier allows attackers to view sensitive information via DisplayParallelLogData.aspx. | |
| Modificada | Alta (7.5) | 59% | 💥 Exploit | Smartofficepayroll Smartoffice | 28/2/2023 | 17/6/2026 | An issue was discovered in Smart Office Web 20.28 and earlier allows attackers to download sensitive information via the action name parameter to ExportEmployeeDetails.aspx, and to ExportReportingManager.aspx. | |
| Modificada | Crítica (9.8) | 0.95% | — | Linuxfoundation Modular Open Smart Network | 17/2/2023 | 17/6/2026 | Authentication vulnerability in MOSN v.0.23.0 allows attacker to escalate privileges via case-sensitive JWT authorization. | |
| Modificada | Crítica (9.1) | 0.54% | — | Ricoh MP C307 FirmwareRicoh MP C407 FirmwareRicoh MP C406 FirmwareRicoh MP C306 Firmware+73 | 16/2/2023 | 17/6/2026 | Ricoh mp_c4504ex devices with firmware 1.06 mishandle credentials. | |
| Analizada | Crítica (9.8) | 98% | ⚠ Explotación activa💥 Exploit | Ruckuswireless Ruckus Wireless AdminRuckuswireless Smartzone APCommscope Ruckus Smartzone Firmware | 13/2/2023 | 17/6/2026 | Ruckus Wireless Admin hasta la versión 10.4 permite la ejecución remota de código a través de una solicitud HTTP GET no autenticada, como lo demuestra /forms/doLogin?login_username=admin&password=password$(curl substring. |