Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
–

1878 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.7)0.34%—Smartertools Smartermail8/5/202617/6/2026
SmarterTools SmarterMail builds prior to 9560 contain a local file inclusion vulnerability in the /api/v1/report/summary/{type} API endpoint that allows authenticated users to read arbitrary .json files on the system. Attackers can exploit this vulnerability combined with weak encryption algorithms and hardcoded keys…
AnalizadaAlta (8)0.34%—Phoenixcontact FL Mguard 2102 FirmwarePhoenixcontact FL Mguard 2105 FirmwarePhoenixcontact FL Mguard 4102 PCI FirmwarePhoenixcontact FL Mguard 4102 Pcie Firmware+337/5/202617/6/2026
A low privileged remote attacker can gain the root password due to improper removal of sensitive information before storage or transfer.
Pendiente de análisisCrítica (9.1)3.6%💥 ExploitMeig Smart Forge Slt711AIGoaheadAI5/5/20265/7/2026
The GoAhead web server on MeiG Smart FORGE_SLT711 devices (firmware MDM9607.LE.1.0-00110-STD.PROD-1) allows unauthenticated OS command injection via the /action/SetRemoteAccessCfg endpoint.
AnalizadaAlta (7.8)0.07%—Qualcomm Qxm1096 FirmwareQualcomm Robotics RB2 FirmwareQualcomm Robotics RB5 FirmwareQualcomm Sa4150p Firmware+1724/5/202629/6/2026
Memory Corruption when copying data from a freed source while executing performance counter deselect operation.
AnalizadaAlta (7.8)0.10%—Qualcomm Qca8695au FirmwareQualcomm Qca9367 FirmwareQualcomm Qca9377 FirmwareQualcomm Qcc710 Firmware+1844/5/20267/10/2026
Memory corruption when dynamically changing the size of a previously allocated buffer while its contents are being modified.
AplazadaMedia (5.5)0.47%—1024-lab Smart-adminAI30/4/202617/6/2026
A security vulnerability has been detected in 1024-lab smart-admin up to 3.30.0. This affects an unknown function of the file /smart-admin-api/druid/index.html of the component Demo Site. The manipulation leads to improper access controls. The attack may be initiated remotely. The exploit has been disclosed publicly…
AplazadaMedia (6.4)0.33%—Wpclever WPC Smart MessagesAI28/4/202617/6/2026
The WPC Smart Messages for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'text' attribute of the `wpcsm_text_rotator` shortcode in all versions up to, and including, 4.2.8. This is due to insufficient input sanitization and output escaping on user supplied attributes. This makes…
AnalizadaAlta (8.2)0.26%—Smartertools Smartermail27/4/202617/6/2026
SmarterTools SmarterMail builds prior to 9610 contain a cryptographic weakness in the file and email sharing endpoints that use DES-CBC encryption with keys and initialization vectors derived from System.Random seeded with insufficient entropy, reducing the seed space to approximately 19,000 possible values. An…
AplazadaAlta (8.6)0.15%—IsmartviewproAI26/4/202617/6/2026
iSmartViewPro 1.5 contains a structured exception handling (SEH) buffer overflow vulnerability in the 'Save Path for Snapshot and Record file' field that allows local attackers to execute arbitrary code. Attackers can input a crafted payload exceeding 260 bytes through the System Setup interface to overwrite SEH…
Pendiente de análisisMedia (4.3)0.32%—Wago Smart DesignerAI16/4/202617/6/2026
In Wago Smart Designer in versions up to 2.33.1 a low privileged remote attacker may enumerate projects and usernames through iterative requests to an specific endpoint.
AplazadaMedia (4.3)0.11%—Zaytech Smart Online Order FOR CloverAI15/4/20267/10/2026
Cross-Site Request Forgery (CSRF) vulnerability in ZAYTECH Smart Online Order for Clover clover-online-orders allows Cross Site Request Forgery.This issue affects Smart Online Order for Clover: from n/a through <= 1.6.0.
AplazadaAlta (7.2)0.69%—Shapedplugin Smart Post ShowAI14/4/202617/6/2026
The Smart Post Show – Post Grid, Post Carousel & Slider, and List Category Posts plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.0.12 via deserialization of untrusted input in the import_shortcodes() function. This makes it possible for authenticated attackers, with…
AplazadaCrítica (9.3)0.97%—Nextendweb Smart Slider 3AI9/4/202617/6/2026
Smart Slider 3 Pro version 3.5.1.35 for WordPress and Joomla contains a multi-stage remote access toolkit injected through a compromised update system that allows unauthenticated attackers to execute arbitrary code and commands. Attackers can trigger pre-authentication remote shell execution via HTTP headers,…
AplazadaMedia (5.4)0.32%—Nextendweb Smart Slider 3AI7/4/202624/7/2026
The Smart Slider 3 plugin for WordPress is vulnerable to unauthorized access and modification of data due to missing capability checks on multiple wp_ajax_smart-slider3 controller actions in all versions up to, and including, 3.5.1.33. The display_admin_ajax() method does not call checkForCap() (which requires…
Pendiente de análisisMedia (4.6)0.24%—Aziot Node Smart Switch 16ampAI6/4/20265/7/2026
An information disclosure vulnerability exists in AZIOT 1 Node Smart Switch (16amp)- WiFi/Bluetooth Enabled Software Version: 1.1.9 due to improper access control on the UART debug interface. An attacker with physical access can connect to the UART interface and obtain sensitive information from the serial console…
AplazadaMedia (6.9)0.19%—Smart VPNAI4/4/202621/7/2026
Smart VPN 1.1.3.0 contains a denial of service vulnerability that allows local attackers to crash the application by submitting oversized input through the search interface. Attackers can paste a buffer of 2100 characters into the top right search bar to trigger an unhandled exception that crashes the application.
AnalizadaCrítica (9.8)0.91%—Cisco Smart Software Manager On-prem1/4/20261/7/2026
A vulnerability in Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected SSM On-Prem host. This vulnerability is due to the unintentional exposure of an&nbsp;internal service. An attacker could…
AnalizadaAlta (7.3)0.27%—Cisco Smart Software Manager On-prem1/4/20268/7/2026
A vulnerability in the web interface of Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an authenticated, remote attacker to elevate privileges on an affected system. This vulnerability is due to the improper transmission of sensitive user information. An attacker could exploit this vulnerability by…
AnalizadaMedia (6.9)0.21%—Smartftp30/3/202617/6/2026
SmartFTP Client 9.0.2615.0 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the Host field. Attackers can paste a buffer of 300 repeated characters into the Host connection parameter to trigger an application crash.
AplazadaMedia (5.1)0.32%—Qdocs Smart School Management SystemAI27/3/202617/6/2026
A vulnerability was detected in QDOCS Smart School Management System up to 7.2. The impacted element is an unknown function of the file /admin/enquiry of the component Admission Enquiry Module. Performing a manipulation of the argument Note results in cross site scripting. The attack is possible to be carried out…
Pendiente de análisisMedia (6.5)0.36%—Softing Industrial Automation Gmbh PngateAISofting Industrial Automation Gmbh EpgateAISofting Industrial Automation Gmbh MbgateAISofting Industrial Automation Gmbh Smartlink Hw-pnAI+127/3/202617/6/2026
Stack-based buffer overflow vulnerability in Softing Industrial Automation GmbH gateways allows overflow buffers. This issue affects pnGate: through 1.30 epGate: through 1.30 mbGate: through 1.30 smartLink HW-DP: through 1.30 smartLink HW-PN: through 1.01.
Pendiente de análisisMedia (6.5)0.21%—Softing Smartlink Hw-dpAISofting Smartlink Hw-pnAI27/3/202617/6/2026
Use after free vulnerability in Softing smartLink HW-DP or smartLink HW-PN webserver allows HTTP DoS. This issue affects: smartLink HW-DP: through 1.31 smartLink HW-PN: before 1.02.
AplazadaMedia (6.5)0.41%💥 PoCNextendweb Smart Slider 3AI27/3/202617/6/2026
The Smart Slider 3 plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 3.5.1.33 via the 'actionExportAll' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read the contents of arbitrary files on the server, which can…
Pendiente de análisisAlta (7.2)0.33%—LSC Smart Indoor IP CameraAI25/3/202617/6/2026
A buffer overflow vulnerability in the dgiot binary in LSC Smart Indoor IP Camera V7.6.32. The flaw exists in the handling of the Time Zone (TZ) parameter within the ONVIF configuration interface. The time zone (TZ) parameter does not have its length properly validated before being copied into a fixed-size buffer…
AplazadaMedia (4.3)0.34%—Smart Custom FieldsAI23/3/202617/6/2026
The Smart Custom Fields plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the relational_posts_search() function in all versions up to, and including, 5.0.6. This makes it possible for authenticated attackers, with Contributor-level access and above, to read private…