Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2638▼ 297 respecto a la semana anterior
Críticas / altas1351▲ 82 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)58▼ 469 respecto a la semana anterior
14 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.29% | — | Favethemes Homey CoreAI | 22/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in favethemes Homey Core homey-core allows Reflected XSS.This issue affects Homey Core: from n/a through <= 2.4.3. | |
| Aplazada | Media (5.3) | 0.33% | — | Favethemes Homey CoreAI | 16/12/2025 | 17/6/2026 | Missing Authorization vulnerability in favethemes Homey Core homey-core allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Homey Core: from n/a through <= 2.4.3. | |
| Aplazada | Alta (7.1) | 0.26% | — | Favethemes HomeyAI | 4/7/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in favethemes Homey homey allows Reflected XSS.This issue affects Homey: from n/a through <= 2.4.5. | |
| Aplazada | Crítica (9.3) | 0.32% | — | Favethemes HomeyAI | 27/6/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in favethemes Homey homey allows SQL Injection.This issue affects Homey: from n/a through <= 2.4.7. | |
| Analizada | Media (4.3) | 0.24% | — | Favethemes Homey | 2/5/2025 | 17/6/2026 | The Homey theme for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.4.4 via the 'homey_delete_user_account' action due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-level access and above, to… | |
| Analizada | Media (4.3) | 0.24% | — | Favethemes Homey | 2/5/2025 | 17/6/2026 | The Homey theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the homey_reservation_del() function in all versions up to, and including, 2.4.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary… | |
| Aplazada | Crítica (9.8) | 0.45% | — | Favethemes HomeyAI | 4/4/2025 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in Favethemes Homey allows Privilege Escalation.This issue affects Homey: from n/a through 2.4.1. | |
| Aplazada | Alta (8.1) | 0.53% | — | HomeyAI | 7/3/2025 | 17/6/2026 | The Homey theme for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.4.3. This is due to the 'verification_id' value being set to empty, and the not empty check is missing in the dashboard user profile page. This makes it possible for unauthenticated attackers to log in to the first… | |
| Aplazada | Media (4.3) | 0.17% | — | HomeyAI | 7/3/2025 | 17/6/2026 | The Homey theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.4.3. This is due to missing or incorrect nonce validation on the 'homey_verify_user_manually' function. This makes it possible for unauthenticated attackers to update verify an user via a forged request,… | |
| Aplazada | Crítica (9.8) | 0.43% | — | HomeyAI | 5/3/2025 | 17/6/2026 | The Homey theme for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.4.2. This is due to the plugin allowing users who are registering new accounts to set their own role. This makes it possible for unauthenticated attackers to gain elevated privileges by creating an account with… | |
| Aplazada | Crítica (9.8) | 0.43% | — | Homey Login RegisterAI | 5/3/2025 | 17/6/2026 | The Homey Login Register plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.4.0. This is due to the plugin allowing users who are registering new accounts to set their own role. This makes it possible for unauthenticated attackers to gain elevated privileges by creating… | |
| Aplazada | Crítica (9.8) | 0.43% | — | Favethemes Homey Login RegisterAI | 21/1/2025 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in favethemes Homey Login Register homey-login-register allows Privilege Escalation.This issue affects Homey Login Register: from n/a through <= 2.4.0. | |
| Modificada | Alta (7.5) | 1.3% | — | Homey FirmwareHomey PRO Firmware | 9/3/2021 | 17/6/2026 | An issue was discovered on Athom Homey and Homey Pro devices before 5.0.0. ZigBee hub devices should generate a unique Standard Network Key that is then exchanged with all enrolled devices so that all inter-device communication is encrypted. However, the cited Athom products use another widely known key that is… | |
| Modificada | Media (4.3) | 0.33% | — | Homey FirmwareHomey PRO Firmware | 4/6/2020 | 17/6/2026 | An issue was discovered in all Athom Homey and Homey Pro devices up to the current version 4.2.0. An attacker within RF range can obtain a cleartext copy of the network configuration of the device, including the Wi-Fi PSK, during device setup. Upon success, the attacker is able to further infiltrate the target's Wi-Fi… |