Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
–

1906 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.5)0.41%💥 PoCNextendweb Smart Slider 3AI27/3/202617/6/2026
The Smart Slider 3 plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 3.5.1.33 via the 'actionExportAll' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read the contents of arbitrary files on the server, which can…
Pendiente de análisisAlta (7.2)0.33%—LSC Smart Indoor IP CameraAI25/3/202617/6/2026
A buffer overflow vulnerability in the dgiot binary in LSC Smart Indoor IP Camera V7.6.32. The flaw exists in the handling of the Time Zone (TZ) parameter within the ONVIF configuration interface. The time zone (TZ) parameter does not have its length properly validated before being copied into a fixed-size buffer…
AplazadaMedia (4.3)0.34%—Smart Custom FieldsAI23/3/202617/6/2026
The Smart Custom Fields plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the relational_posts_search() function in all versions up to, and including, 5.0.6. This makes it possible for authenticated attackers, with Contributor-level access and above, to read private…
AplazadaMedia (5.3)0.48%—Smarter AnalyticsAI21/3/202617/6/2026
The Smarter Analytics plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 2.0. This is due to missing authentication and capability checks on the configuration reset functionality in the global scope of smarter-analytics.php. This makes it possible for unauthenticated…
Pendiente de análisisMedia (6.8)0.32%—Softing Smartlink Sw-htAI17/3/202617/6/2026
NULL Pointer Dereference vulnerability in Softing Industrial Automation GmbH smartLink SW-HT (Webserver modules) allows HTTP DoS.This issue affects smartLink SW-HT: 1.43.
AplazadaBaja (1.9)0.14%—I-sens Smartlog APPAI16/3/202617/6/2026
A weakness has been identified in i-SENS SmartLog App up to 2.6.8 on Android. This affects an unknown function of the component air.SmartLog.android. This manipulation causes hard-coded credentials. The attack can only be executed locally. The exploit has been made available to the public and could be used for…
AnalizadaAlta (7.1)0.24%💥 PoCSamsung Smart Switch16/3/202617/6/2026
Path traversal in Smart Switch prior to version 3.7.69.15 allows adjacent attackers to overwrite arbitrary files with Smart Switch privilege.
AnalizadaMedia (6.9)0.18%💥 PoCSamsung Smart Switch16/3/202617/6/2026
Improper authentication in Smart Switch prior to version 3.7.69.15 allows adjacent attackers to trigger a denial of service.
AnalizadaAlta (7.1)0.31%—Samsung Smart Switch16/3/202617/6/2026
Authentication bypass by replay in Smart Switch prior to version 3.7.69.15 allows remote attackers to trigger privileged functions.
AnalizadaAlta (7.1)0.55%—Samsung Smart Switch16/3/202617/6/2026
Improper authentication in Smart Switch prior to version 3.7.69.15 allows remote attackers to bypass authentication.
AnalizadaMedia (5.3)0.26%—Samsung Smart Switch16/3/202617/6/2026
Improper verification of cryptographic signature in Smart Switch prior to version 3.7.69.15 allows remote attackers to potentially bypass authentication.
AnalizadaAlta (7.1)0.17%—Samsung Smart Switch16/3/202617/6/2026
Use of a broken or risky cryptographic algorithm in Smart Switch prior to version 3.7.69.15 allows remote attackers to configure a downgraded scheme for authentication.
AnalizadaMedia (5.3)0.28%—Samsung Smart Switch16/3/202617/6/2026
Exposure of sensitive functionality to an unauthorized actor in Smart Switch prior to version 3.7.69.15 allows remote attackers to set a specific configuration.
Pendiente de análisisAlta (7.7)0.49%—Softing Industrial Automation Gmbh Smartlink Sw-pnAISofting Smartlink Sw-htAI16/3/202617/6/2026
Heap-based buffer overflow vulnerability in Softing Industrial Automation GmbH smartLink SW-PN and smartLink SW-HT (Webserver modules) allows overflow buffers.This issue affects: smartLink SW-PN: through 1.03 smartLink SW-HT: through 1.42
Pendiente de análisisMedia (5.3)0.37%—Softing Industrial Automation Gmbh Smartlink SW HTAISofting Industrial Automation Gmbh Smartlink SW PNAI16/3/202617/6/2026
Global file reads caused by improper URL checks in webserver in Softing Industrial Automation GmbH smartLinks on docker (filesystem modules) allows file access. This issue affects smartLink SW-HT: through 1.42 smartLink SW-PN: through 1.03.
AplazadaMedia (4.3)0.25%—Wpclever WPC Smart WishlistAI13/3/202617/6/2026
Missing Authorization vulnerability in WPClever WPC Smart Wishlist for WooCommerce woo-smart-wishlist allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPC Smart Wishlist for WooCommerce: from n/a through <= 5.0.8.
AplazadaMedia (5.4)0.23%—Linethemes SmartfixAI13/3/202617/6/2026
Missing Authorization vulnerability in linethemes SmartFix smartfix allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SmartFix: from n/a through < 1.2.4.
AnalizadaMedia (6.8)0.09%—Lenovo Smart Connect11/3/202620/8/2026
A potential divide by zero vulnerability was reported in the Lenovo Virtual Bus driver used in Smart Connect that could allow a local authenticated user to cause a Windows blue screen error.
AnalizadaMedia (6.9)0.09%—Lenovo Smart Connect11/3/202620/8/2026
A potential buffer overflow vulnerability was reported in the Lenovo Virtual Bus driver used in Smart Connect that could allow a local authenticated user to corrupt memory and cause a Windows blue screen error.
AnalizadaBaja (2.1)0.67%—Lab1024 Smartadmin8/3/202617/6/2026
A flaw has been found in 1024-lab/lab1024 SmartAdmin up to 3.29. Affected by this issue is the function freemarkerResolverContent of the file sa-base/src/main/java/net/lab1024/sa/base/module/support/mail/MailService.java of the component FreeMarker Template Handler. Executing a manipulation of the argument…
AnalizadaBaja (2)0.36%—Lab1024 Smartadmin8/3/202617/6/2026
A weakness has been identified in 1024-lab/lab1024 SmartAdmin up to 3.29. The affected element is an unknown function of the file sa-base/src/main/java/net/lab1024/sa/base/module/support/helpdoc/domain/form/HelpDocAddForm.java of the component Help Documentation Module. This manipulation causes cross site scripting.…
AnalizadaBaja (2)0.36%—Lab1024 Smartadmin8/3/202617/6/2026
A security flaw has been discovered in 1024-lab/lab1024 SmartAdmin up to 3.29. Impacted is an unknown function of the file smart-admin-web-javascript/src/views/business/oa/notice/components/notice-form-drawer.vue of the component Notice Module. The manipulation results in cross site scripting. The attack can be…
AplazadaAlta (8.1)0.58%—Axiomthemes Smart SEOAI5/3/202617/6/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes smart SEO smartSEO allows PHP Local File Inclusion.This issue affects smart SEO: from n/a through <= 2.9.
AnalizadaAlta (7.8)1.3%⚠ Explotación activa💥 PoCQualcomm Sm7675p FirmwareQualcomm Sm8475p FirmwareQualcomm Sm8550p FirmwareQualcomm Sm8635 Firmware+2332/3/202617/6/2026
Memory corruption while using alignments for memory allocation.
AnalizadaAlta (7.8)0.07%—Qualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 Firmware+1602/3/202617/6/2026
Memory Corruption when adding user-supplied data without checking available buffer space.