Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
1879 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.34% | — | Smart Custom FieldsAI | 23/3/2026 | 17/6/2026 | The Smart Custom Fields plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the relational_posts_search() function in all versions up to, and including, 5.0.6. This makes it possible for authenticated attackers, with Contributor-level access and above, to read private… | |
| Aplazada | Media (5.3) | 0.48% | — | Smarter AnalyticsAI | 21/3/2026 | 17/6/2026 | The Smarter Analytics plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 2.0. This is due to missing authentication and capability checks on the configuration reset functionality in the global scope of smarter-analytics.php. This makes it possible for unauthenticated… | |
| Pendiente de análisis | Media (6.8) | 0.32% | — | Softing Smartlink Sw-htAI | 17/3/2026 | 17/6/2026 | NULL Pointer Dereference vulnerability in Softing Industrial Automation GmbH smartLink SW-HT (Webserver modules) allows HTTP DoS.This issue affects smartLink SW-HT: 1.43. | |
| Aplazada | Baja (1.9) | 0.14% | — | I-sens Smartlog APPAI | 16/3/2026 | 17/6/2026 | A weakness has been identified in i-SENS SmartLog App up to 2.6.8 on Android. This affects an unknown function of the component air.SmartLog.android. This manipulation causes hard-coded credentials. The attack can only be executed locally. The exploit has been made available to the public and could be used for… | |
| Analizada | Alta (7.1) | 0.24% | 💥 PoC | Samsung Smart Switch | 16/3/2026 | 17/6/2026 | Path traversal in Smart Switch prior to version 3.7.69.15 allows adjacent attackers to overwrite arbitrary files with Smart Switch privilege. | |
| Analizada | Media (6.9) | 0.18% | 💥 PoC | Samsung Smart Switch | 16/3/2026 | 17/6/2026 | Improper authentication in Smart Switch prior to version 3.7.69.15 allows adjacent attackers to trigger a denial of service. | |
| Analizada | Alta (7.1) | 0.31% | — | Samsung Smart Switch | 16/3/2026 | 17/6/2026 | Authentication bypass by replay in Smart Switch prior to version 3.7.69.15 allows remote attackers to trigger privileged functions. | |
| Analizada | Alta (7.1) | 0.55% | — | Samsung Smart Switch | 16/3/2026 | 17/6/2026 | Improper authentication in Smart Switch prior to version 3.7.69.15 allows remote attackers to bypass authentication. | |
| Analizada | Media (5.3) | 0.26% | — | Samsung Smart Switch | 16/3/2026 | 17/6/2026 | Improper verification of cryptographic signature in Smart Switch prior to version 3.7.69.15 allows remote attackers to potentially bypass authentication. | |
| Analizada | Alta (7.1) | 0.17% | — | Samsung Smart Switch | 16/3/2026 | 17/6/2026 | Use of a broken or risky cryptographic algorithm in Smart Switch prior to version 3.7.69.15 allows remote attackers to configure a downgraded scheme for authentication. | |
| Analizada | Media (5.3) | 0.28% | — | Samsung Smart Switch | 16/3/2026 | 17/6/2026 | Exposure of sensitive functionality to an unauthorized actor in Smart Switch prior to version 3.7.69.15 allows remote attackers to set a specific configuration. | |
| Pendiente de análisis | Alta (7.7) | 0.49% | — | Softing Industrial Automation Gmbh Smartlink Sw-pnAISofting Smartlink Sw-htAI | 16/3/2026 | 17/6/2026 | Heap-based buffer overflow vulnerability in Softing Industrial Automation GmbH smartLink SW-PN and smartLink SW-HT (Webserver modules) allows overflow buffers.This issue affects: smartLink SW-PN: through 1.03 smartLink SW-HT: through 1.42 | |
| Pendiente de análisis | Media (5.3) | 0.37% | — | Softing Industrial Automation Gmbh Smartlink SW HTAISofting Industrial Automation Gmbh Smartlink SW PNAI | 16/3/2026 | 17/6/2026 | Global file reads caused by improper URL checks in webserver in Softing Industrial Automation GmbH smartLinks on docker (filesystem modules) allows file access. This issue affects smartLink SW-HT: through 1.42 smartLink SW-PN: through 1.03. | |
| Aplazada | Media (4.3) | 0.25% | — | Wpclever WPC Smart WishlistAI | 13/3/2026 | 17/6/2026 | Missing Authorization vulnerability in WPClever WPC Smart Wishlist for WooCommerce woo-smart-wishlist allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPC Smart Wishlist for WooCommerce: from n/a through <= 5.0.8. | |
| Aplazada | Media (5.4) | 0.23% | — | Linethemes SmartfixAI | 13/3/2026 | 17/6/2026 | Missing Authorization vulnerability in linethemes SmartFix smartfix allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SmartFix: from n/a through < 1.2.4. | |
| Analizada | Media (6.8) | 0.09% | — | Lenovo Smart Connect | 11/3/2026 | 20/8/2026 | A potential divide by zero vulnerability was reported in the Lenovo Virtual Bus driver used in Smart Connect that could allow a local authenticated user to cause a Windows blue screen error. | |
| Analizada | Media (6.9) | 0.09% | — | Lenovo Smart Connect | 11/3/2026 | 20/8/2026 | A potential buffer overflow vulnerability was reported in the Lenovo Virtual Bus driver used in Smart Connect that could allow a local authenticated user to corrupt memory and cause a Windows blue screen error. | |
| Analizada | Baja (2.1) | 0.67% | — | Lab1024 Smartadmin | 8/3/2026 | 17/6/2026 | A flaw has been found in 1024-lab/lab1024 SmartAdmin up to 3.29. Affected by this issue is the function freemarkerResolverContent of the file sa-base/src/main/java/net/lab1024/sa/base/module/support/mail/MailService.java of the component FreeMarker Template Handler. Executing a manipulation of the argument… | |
| Analizada | Baja (2) | 0.36% | — | Lab1024 Smartadmin | 8/3/2026 | 17/6/2026 | A weakness has been identified in 1024-lab/lab1024 SmartAdmin up to 3.29. The affected element is an unknown function of the file sa-base/src/main/java/net/lab1024/sa/base/module/support/helpdoc/domain/form/HelpDocAddForm.java of the component Help Documentation Module. This manipulation causes cross site scripting.… | |
| Analizada | Baja (2) | 0.36% | — | Lab1024 Smartadmin | 8/3/2026 | 17/6/2026 | A security flaw has been discovered in 1024-lab/lab1024 SmartAdmin up to 3.29. Impacted is an unknown function of the file smart-admin-web-javascript/src/views/business/oa/notice/components/notice-form-drawer.vue of the component Notice Module. The manipulation results in cross site scripting. The attack can be… | |
| Aplazada | Alta (8.1) | 0.58% | — | Axiomthemes Smart SEOAI | 5/3/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes smart SEO smartSEO allows PHP Local File Inclusion.This issue affects smart SEO: from n/a through <= 2.9. | |
| Analizada | Alta (7.8) | 1.3% | ⚠ Explotación activa💥 PoC | Qualcomm Sm7675p FirmwareQualcomm Sm8475p FirmwareQualcomm Sm8550p FirmwareQualcomm Sm8635 Firmware+233 | 2/3/2026 | 17/6/2026 | Memory corruption while using alignments for memory allocation. | |
| Analizada | Alta (7.8) | 0.07% | — | Qualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 Firmware+160 | 2/3/2026 | 17/6/2026 | Memory Corruption when adding user-supplied data without checking available buffer space. | |
| Analizada | Alta (7.8) | 0.07% | — | Qualcomm Ar8031 FirmwareQualcomm Ar8035 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 Firmware+166 | 2/3/2026 | 17/6/2026 | Memory Corruption while invoking IOCTL calls when concurrent access to shared buffer occurs. | |
| Analizada | Alta (7.2) | 0.14% | — | Qualcomm 5G Fixed Wireless Access Platform FirmwareQualcomm 9206 LTE Modem FirmwareQualcomm 9207 LTE Modem FirmwareQualcomm Apq8098 Firmware+202 | 2/3/2026 | 17/6/2026 | Weak configuration may lead to cryptographic issue when a VoWiFi call is triggered from UE. |