Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
1878 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.7) | 0.34% | — | Smartertools Smartermail | 8/5/2026 | 17/6/2026 | SmarterTools SmarterMail builds prior to 9560 contain a local file inclusion vulnerability in the /api/v1/report/summary/{type} API endpoint that allows authenticated users to read arbitrary .json files on the system. Attackers can exploit this vulnerability combined with weak encryption algorithms and hardcoded keys… | |
| Analizada | Alta (8) | 0.34% | — | Phoenixcontact FL Mguard 2102 FirmwarePhoenixcontact FL Mguard 2105 FirmwarePhoenixcontact FL Mguard 4102 PCI FirmwarePhoenixcontact FL Mguard 4102 Pcie Firmware+33 | 7/5/2026 | 17/6/2026 | A low privileged remote attacker can gain the root password due to improper removal of sensitive information before storage or transfer. | |
| Pendiente de análisis | Crítica (9.1) | 3.6% | 💥 Exploit | Meig Smart Forge Slt711AIGoaheadAI | 5/5/2026 | 5/7/2026 | The GoAhead web server on MeiG Smart FORGE_SLT711 devices (firmware MDM9607.LE.1.0-00110-STD.PROD-1) allows unauthenticated OS command injection via the /action/SetRemoteAccessCfg endpoint. | |
| Analizada | Alta (7.8) | 0.07% | — | Qualcomm Qxm1096 FirmwareQualcomm Robotics RB2 FirmwareQualcomm Robotics RB5 FirmwareQualcomm Sa4150p Firmware+172 | 4/5/2026 | 29/6/2026 | Memory Corruption when copying data from a freed source while executing performance counter deselect operation. | |
| Analizada | Alta (7.8) | 0.10% | — | Qualcomm Qca8695au FirmwareQualcomm Qca9367 FirmwareQualcomm Qca9377 FirmwareQualcomm Qcc710 Firmware+184 | 4/5/2026 | 7/10/2026 | Memory corruption when dynamically changing the size of a previously allocated buffer while its contents are being modified. | |
| Aplazada | Media (5.5) | 0.47% | — | 1024-lab Smart-adminAI | 30/4/2026 | 17/6/2026 | A security vulnerability has been detected in 1024-lab smart-admin up to 3.30.0. This affects an unknown function of the file /smart-admin-api/druid/index.html of the component Demo Site. The manipulation leads to improper access controls. The attack may be initiated remotely. The exploit has been disclosed publicly… | |
| Aplazada | Media (6.4) | 0.33% | — | Wpclever WPC Smart MessagesAI | 28/4/2026 | 17/6/2026 | The WPC Smart Messages for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'text' attribute of the `wpcsm_text_rotator` shortcode in all versions up to, and including, 4.2.8. This is due to insufficient input sanitization and output escaping on user supplied attributes. This makes… | |
| Analizada | Alta (8.2) | 0.26% | — | Smartertools Smartermail | 27/4/2026 | 17/6/2026 | SmarterTools SmarterMail builds prior to 9610 contain a cryptographic weakness in the file and email sharing endpoints that use DES-CBC encryption with keys and initialization vectors derived from System.Random seeded with insufficient entropy, reducing the seed space to approximately 19,000 possible values. An… | |
| Aplazada | Alta (8.6) | 0.15% | — | IsmartviewproAI | 26/4/2026 | 17/6/2026 | iSmartViewPro 1.5 contains a structured exception handling (SEH) buffer overflow vulnerability in the 'Save Path for Snapshot and Record file' field that allows local attackers to execute arbitrary code. Attackers can input a crafted payload exceeding 260 bytes through the System Setup interface to overwrite SEH… | |
| Pendiente de análisis | Media (4.3) | 0.32% | — | Wago Smart DesignerAI | 16/4/2026 | 17/6/2026 | In Wago Smart Designer in versions up to 2.33.1 a low privileged remote attacker may enumerate projects and usernames through iterative requests to an specific endpoint. | |
| Aplazada | Media (4.3) | 0.11% | — | Zaytech Smart Online Order FOR CloverAI | 15/4/2026 | 7/10/2026 | Cross-Site Request Forgery (CSRF) vulnerability in ZAYTECH Smart Online Order for Clover clover-online-orders allows Cross Site Request Forgery.This issue affects Smart Online Order for Clover: from n/a through <= 1.6.0. | |
| Aplazada | Alta (7.2) | 0.69% | — | Shapedplugin Smart Post ShowAI | 14/4/2026 | 17/6/2026 | The Smart Post Show – Post Grid, Post Carousel & Slider, and List Category Posts plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.0.12 via deserialization of untrusted input in the import_shortcodes() function. This makes it possible for authenticated attackers, with… | |
| Aplazada | Crítica (9.3) | 0.97% | — | Nextendweb Smart Slider 3AI | 9/4/2026 | 17/6/2026 | Smart Slider 3 Pro version 3.5.1.35 for WordPress and Joomla contains a multi-stage remote access toolkit injected through a compromised update system that allows unauthenticated attackers to execute arbitrary code and commands. Attackers can trigger pre-authentication remote shell execution via HTTP headers,… | |
| Aplazada | Media (5.4) | 0.32% | — | Nextendweb Smart Slider 3AI | 7/4/2026 | 24/7/2026 | The Smart Slider 3 plugin for WordPress is vulnerable to unauthorized access and modification of data due to missing capability checks on multiple wp_ajax_smart-slider3 controller actions in all versions up to, and including, 3.5.1.33. The display_admin_ajax() method does not call checkForCap() (which requires… | |
| Pendiente de análisis | Media (4.6) | 0.24% | — | Aziot Node Smart Switch 16ampAI | 6/4/2026 | 5/7/2026 | An information disclosure vulnerability exists in AZIOT 1 Node Smart Switch (16amp)- WiFi/Bluetooth Enabled Software Version: 1.1.9 due to improper access control on the UART debug interface. An attacker with physical access can connect to the UART interface and obtain sensitive information from the serial console… | |
| Aplazada | Media (6.9) | 0.19% | — | Smart VPNAI | 4/4/2026 | 21/7/2026 | Smart VPN 1.1.3.0 contains a denial of service vulnerability that allows local attackers to crash the application by submitting oversized input through the search interface. Attackers can paste a buffer of 2100 characters into the top right search bar to trigger an unhandled exception that crashes the application. | |
| Analizada | Crítica (9.8) | 0.91% | — | Cisco Smart Software Manager On-prem | 1/4/2026 | 1/7/2026 | A vulnerability in Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected SSM On-Prem host. This vulnerability is due to the unintentional exposure of an internal service. An attacker could… | |
| Analizada | Alta (7.3) | 0.27% | — | Cisco Smart Software Manager On-prem | 1/4/2026 | 8/7/2026 | A vulnerability in the web interface of Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an authenticated, remote attacker to elevate privileges on an affected system. This vulnerability is due to the improper transmission of sensitive user information. An attacker could exploit this vulnerability by… | |
| Analizada | Media (6.9) | 0.21% | — | Smartftp | 30/3/2026 | 17/6/2026 | SmartFTP Client 9.0.2615.0 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the Host field. Attackers can paste a buffer of 300 repeated characters into the Host connection parameter to trigger an application crash. | |
| Aplazada | Media (5.1) | 0.32% | — | Qdocs Smart School Management SystemAI | 27/3/2026 | 17/6/2026 | A vulnerability was detected in QDOCS Smart School Management System up to 7.2. The impacted element is an unknown function of the file /admin/enquiry of the component Admission Enquiry Module. Performing a manipulation of the argument Note results in cross site scripting. The attack is possible to be carried out… | |
| Pendiente de análisis | Media (6.5) | 0.36% | — | Softing Industrial Automation Gmbh PngateAISofting Industrial Automation Gmbh EpgateAISofting Industrial Automation Gmbh MbgateAISofting Industrial Automation Gmbh Smartlink Hw-pnAI+1 | 27/3/2026 | 17/6/2026 | Stack-based buffer overflow vulnerability in Softing Industrial Automation GmbH gateways allows overflow buffers. This issue affects pnGate: through 1.30 epGate: through 1.30 mbGate: through 1.30 smartLink HW-DP: through 1.30 smartLink HW-PN: through 1.01. | |
| Pendiente de análisis | Media (6.5) | 0.21% | — | Softing Smartlink Hw-dpAISofting Smartlink Hw-pnAI | 27/3/2026 | 17/6/2026 | Use after free vulnerability in Softing smartLink HW-DP or smartLink HW-PN webserver allows HTTP DoS. This issue affects: smartLink HW-DP: through 1.31 smartLink HW-PN: before 1.02. | |
| Aplazada | Media (6.5) | 0.41% | 💥 PoC | Nextendweb Smart Slider 3AI | 27/3/2026 | 17/6/2026 | The Smart Slider 3 plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 3.5.1.33 via the 'actionExportAll' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read the contents of arbitrary files on the server, which can… | |
| Pendiente de análisis | Alta (7.2) | 0.33% | — | LSC Smart Indoor IP CameraAI | 25/3/2026 | 17/6/2026 | A buffer overflow vulnerability in the dgiot binary in LSC Smart Indoor IP Camera V7.6.32. The flaw exists in the handling of the Time Zone (TZ) parameter within the ONVIF configuration interface. The time zone (TZ) parameter does not have its length properly validated before being copied into a fixed-size buffer… | |
| Aplazada | Media (4.3) | 0.34% | — | Smart Custom FieldsAI | 23/3/2026 | 17/6/2026 | The Smart Custom Fields plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the relational_posts_search() function in all versions up to, and including, 5.0.6. This makes it possible for authenticated attackers, with Contributor-level access and above, to read private… |