Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 554 respecto a la semana anterior
Críticas / altas1325▼ 178 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 242 respecto a la semana anterior
–

1043 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.6)0.17%💥 PoCAirth Smart Home AQI Monitor Bootloader14/1/20265/7/2026
An issue in AIRTH SMART HOME AQI MONITOR Bootloader v.1.005 allows a physically proximate attacker to obtain sensitive information via the UART port of the BK7231N controller (Wi-Fi and BLE module) on the device is open to access
ModificadaAlta (8.6)1.3%—4homepages 4images13/1/202617/6/2026
4images 1.9 contains a remote command execution vulnerability that allows authenticated administrators to inject reverse shell code through template editing functionality. Attackers can save malicious code in the template and execute arbitrary commands by accessing a specific categories.php endpoint with a crafted…
AnalizadaAlta (7.8)0.13%—Qualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Immersive Home 214 Platform FirmwareQualcomm Immersive Home 216 Platform Firmware+1817/1/20267/10/2026
Memory corruption while deinitializing a HDCP session.
AnalizadaMedia (6.1)0.13%—Qualcomm Ar8031 FirmwareQualcomm Ar8035 FirmwareQualcomm Csr8811 FirmwareQualcomm Csra6620 Firmware+2957/1/20267/10/2026
Information disclosure while processing a firmware event.
AplazadaMedia (5.1)0.52%—Fibaro System Home CenterAI6/1/202617/6/2026
FIBARO System Home Center 5.021 contains a remote file inclusion vulnerability in the undocumented proxy API that allows attackers to include arbitrary client-side scripts. Attackers can exploit the 'url' GET parameter to inject malicious JavaScript and potentially hijack user sessions or manipulate page content.
AnalizadaBaja (2.1)0.37%—Phome Empirecms2/1/20267/10/2026
A vulnerability has been found in EmpireSoft EmpireCMS up to 8.0. Impacted is the function CheckSaveTranFiletype of the file e/class/connect.php. Such manipulation leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted…
AnalizadaMedia (5.5)1.3%—Phome Empirecms2/1/20267/10/2026
A flaw has been found in EmpireSoft EmpireCMS up to 8.0. This issue affects the function egetip of the file e/class/connect.php of the component IP Address Handler. This manipulation causes protection mechanism failure. The attack may be initiated remotely. The exploit has been published and may be used. The vendor…
AplazadaMedia (5.3)0.25%—Designthemes Homefix Elementor PortfolioAI30/12/20257/10/2026
Missing Authorization vulnerability in designthemes HomeFix Elementor Portfolio homefix-ele-portfolio allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects HomeFix Elementor Portfolio: from n/a through <= 1.0.1.
AplazadaAlta (8.8)0.48%—Smartwares Home EasyAI24/12/202517/6/2026
Smartwares HOME easy 1.0.9 contains an authentication bypass vulnerability that allows unauthenticated attackers to access administrative web pages by disabling JavaScript. Attackers can navigate to multiple administrative endpoints and to bypass client-side validation and access sensitive system information.
AnalizadaMedia (4)0.40%—Home-assistant23/12/202517/6/2026
Home Assistant Core before v2025.8.0 is vulnerable to Directory Traversal. The Downloader integration does not fully validate file paths during concatenation, leaving a path traversal vulnerability.
AplazadaCrítica (9.3)0.39%—Govee H6056AIGovee HomeAI18/12/202530/9/2026
A flaw in the binding process of Govee’s cloud platform and devices allows a remote attacker to bind an existing, online Govee device to the attacker’s account, resulting in full control of the device and removal of the device from its legitimate owner’s account. The server‑side API allows device association using a…
AplazadaMedia (5.3)0.33%—Favethemes Homey CoreAI16/12/202517/6/2026
Missing Authorization vulnerability in favethemes Homey Core homey-core allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Homey Core: from n/a through <= 2.4.3.
AplazadaAlta (8.7)0.35%—Commax Smart Home SystemAI9/12/202517/6/2026
COMMAX Smart Home System is a smart IoT home solution that allows an unauthenticated attacker to disclose RTSP credentials in plain-text by exploiting the /overview.asp endpoint. Attackers can access sensitive information, including login credentials and DVR settings, by submitting a GET request to this endpoint.
AplazadaAlta (8.7)0.35%—Commax Smart Home SystemAI9/12/202517/6/2026
COMMAX Smart Home System allows an unauthenticated attacker to change configuration and cause denial-of-service through the setconf endpoint. Attackers can trigger a denial-of-service scenario by sending a malformed request to the setconf endpoint.
AplazadaCrítica (9.3)0.53%—Commax Smart Home System Cdp-1020nAI9/12/202517/6/2026
COMMAX Smart Home System CDP-1020n contains an SQL injection vulnerability that allows attackers to bypass authentication by injecting arbitrary SQL code through the 'id' parameter in 'loginstart.asp'. Attackers can exploit this by sending a POST request with malicious 'id' values to manipulate database queries and…
AplazadaCrítica (9.3)2.0%—Fiberhome An5506-04-faAIFiberhome Hg6245dAI12/11/202517/6/2026
FiberHome AN5506-04-FA firmware versions up to and including RP2631 and HG6245D prior to RP2602 contain a stack-based buffer overflow, as the HTTP service ('webs') fails to enforce maximum lengths for Cookie header values. When a cookie longer than 511 bytes is processed, a stack buffer is overrun, leading to a crash…
AnalizadaCrítica (9.8)1.3%💥 PoCFiberhome Hg6145f1 Firmware12/11/202517/6/2026
A vulnerability in FiberHome GPON ONU HG6145F1 RP4423 allows the device's factory default Wi-Fi password (WPA/WPA2 pre-shared key) to be predicted from the SSID. The device generates default passwords using a deterministic algorithm that derives the router passphrase from the SSID, enabling an attacker who can observe…
AnalizadaAlta (7.8)0.09%—Qualcomm Apq8064au FirmwareQualcomm Csr8811 FirmwareQualcomm Immersive Home 214 Platform FirmwareQualcomm Immersive Home 216 Platform Firmware+914/11/202517/6/2026
Memory corruption while processing a GP command response.
AnalizadaMedia (6.1)0.08%—Qualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Immersive Home 3210 Platform FirmwareQualcomm Immersive Home 326 Platform Firmware+734/11/202517/6/2026
Information disclosure while registering commands from clients with diag through diagHal.
AplazadaAlta (8.5)0.42%—Home-assistant Home AssistantAI14/10/202517/6/2026
Home Assistant is open source home automation software that puts local control and privacy first. In versions 2025.1.0 through 2025.10.1, the energy dashboard is vulnerable to stored cross-site scripting. An authenticated user can inject malicious JavaScript code into an energy entity's name field, which is then…
AnalizadaAlta (7.1)0.13%—Dell Supportassist FOR Business PCSDell Supportassist FOR Home PCS13/10/202517/6/2026
SupportAssist for Home PCs versions 4.8.2 and prior and SupportAssist for Business PCs versions 4.5.3 and prior, contain an UNIX Symbolic Link (Symlink) following vulnerability. A low privileged attacker with local access to the system could potentially exploit this vulnerability to delete arbitrary files only in that…
AnalizadaAlta (8.8)0.09%—Qualcomm Immersive Home 214 Platform FirmwareQualcomm Immersive Home 216 Platform FirmwareQualcomm Immersive Home 316 Platform FirmwareQualcomm Immersive Home 318 Platform Firmware+219/10/202517/6/2026
Memory corruption while performing SCM call with malformed inputs.
AnalizadaAlta (7.8)0.09%—Qualcomm 315 5G IOT Modem FirmwareQualcomm 9205 LTE Modem FirmwareQualcomm Mdm9650 FirmwareQualcomm Msm8996au Firmware+3159/10/202517/6/2026
Memory corruption during PlayReady APP usecase while processing TA commands.
AnalizadaMedia (6.5)0.08%—Qualcomm Csr8811 FirmwareQualcomm Immersive Home 214 Platform FirmwareQualcomm Immersive Home 216 Platform FirmwareQualcomm Immersive Home 316 Platform Firmware+619/10/202517/6/2026
Information disclosure may occur while processing the hypervisor log.
AnalizadaAlta (8.8)0.09%—Qualcomm Immersive Home 214 Platform FirmwareQualcomm Immersive Home 216 Platform FirmwareQualcomm Immersive Home 316 Platform FirmwareQualcomm Immersive Home 318 Platform Firmware+219/10/202530/9/2026
Memory corruption while performing SCM call.