Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2811▲ 64 respecto a la semana anterior
Críticas / altas1484▲ 296 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 448 respecto a la semana anterior
1871 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 0.48% | — | Trex Digital Smart Manufacturing Systems Trex MESAI | 30/9/2026 | 30/9/2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Trex Digital Smart Manufacturing Systems Inc. Trex MES allows Command Line Execution through SQL Injection. This issue affects Trex MES: through 2026-09-29. | |
| Aplazada | Media (6.4) | 0.16% | — | Nextendweb Smart Slider 3AI | 30/9/2026 | 30/9/2026 | The Smart Slider 3 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data-href' parameter in all versions up to, and including, 3.5.1.38 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to… | |
| Aplazada | Media (5.9) | 0.17% | — | Mh-developer Smart Home ModuleAI | 28/9/2026 | 28/9/2026 | mH-DEVELOPER smart home module is vulnerable to Denial of Service due to uncontrolled resource consumption. The Express bodyParser is configured with a 250 MB limit for JSON and URL-encoded request bodies. An authenticated attacker on the LAN can send large request bodies that exhausts buffers in RAM, causing… | |
| Aplazada | Media (6.9) | 0.37% | — | Mh-developer Smart Home ModuleAI | 28/9/2026 | 28/9/2026 | mH-DEVELOPER smart home module ships with an end-of-life, unsupported Debian 8 and Node.js runtime v17.0.1 in its production firmware. This exposes the device to publicly known vulnerabilities that will not receive security patches. An attacker could exploit these known flaws to execute arbitrary code, access… | |
| Aplazada | Media (6) | 0.21% | — | Mh-developer Smart Home ModuleAI | 28/9/2026 | 28/9/2026 | mH-DEVELOPER smart home module sends its web interface and API traffic over unencrypted HTTP. Passwords, authentication tokens, and device commands are transmitted in cleartext. An attacker on the same network can intercept this traffic, steal credentials and tokens, and hijack sessions. This issue was fixed in… | |
| Aplazada | Media (5.3) | 0.17% | — | Mh-developer Smart Home ModuleAI | 28/9/2026 | 28/9/2026 | mH-DEVELOPER smart home module does not load any firewall rules at startup. This leaves all listening services, including SSH, HTTP, WebSocket, and Node-RED, fully exposed on the LAN without access control. Any client on the same network can reach every service. This issue was fixed in version 3.0.30 | |
| Aplazada | Media (6.4) | 0.21% | — | Mh-developer Smart Home ModuleAI | 28/9/2026 | 28/9/2026 | mH-DEVELOPER smart home module does not verify tokens in its authorization middleware, leaving all HTTP API and WebSocket endpoints accessible without authentication. An unauthenticated attacker on the LAN can query these endpoints, access system information, and send raw control commands to manipulate building… | |
| Aplazada | Media (6.3) | 0.24% | — | Mh-developer Smart Home ModuleAI | 28/9/2026 | 28/9/2026 | mH-DEVELOPER smart home module uses the same hard-coded SSH host keys on every device, with no per-device key generation. An attacker who extracts these keys from the firmware can set up a rogue SSH server that clients will trust without warning, enabling man-in-the-middle attacks and credential interception. This… | |
| Aplazada | Alta (7.7) | 0.18% | — | Mh-developer Smart Home ModuleAI | 28/9/2026 | 28/9/2026 | mH-DEVELOPER smart home module contains a hardcoded SSH public key in /root/.ssh/authorized_keys, serving as a potential backdoor. The SSH daemon allows root login via key authentication and starts automatically. An attacker with the matching private key can gain a root shell on any affected device, resulting in full… | |
| Aplazada | Media (4.8) | 0.37% | — | Teldat Regesta Smart Hd-plcAI | 25/9/2026 | 30/9/2026 | An attacker with access via network to the Regesta Smart HD-PLC of the provider Teldat (in this case, registration action is required) who has the vulnerable firmware version could inject a specific payload via the parameter "cmdcookie" withing the /upgrade/index.html resulting in to a Cross-Site Scripting (XSS). This… | |
| Aplazada | Media (5.3) | 0.21% | — | Wpclever WPC Smart CompareAI | 23/9/2026 | 23/9/2026 | The WPC Smart Compare for WooCommerce WordPress plugin before 6.6.1 does not apply WordPress's post-password protection when returning product content through its comparison handler, allowing unauthenticated users to read the description of password-protected products. | |
| Aplazada | Baja (2.1) | 0.27% | — | Sourcecodester Smart Attendance System With QR Code ScannerAI | 23/9/2026 | 23/9/2026 | A vulnerability was found in SourceCodester Smart Attendance System with QR Code Scanner 1.0. This issue affects the function prepend of the file student_signup.php of the component Self-Registration. Performing a manipulation of the argument full_name results in cross site scripting. Remote exploitation of the attack… | |
| Aplazada | Media (6.2) | 0.20% | — | ZTE SmartlifeAI | 20/9/2026 | 22/9/2026 | The ZTE SmartLife application has a hardcoded key. The key used to decrypt account server information is stored in plaintext in the code. Once the key is obtained, the server information can be decrypted, thus exposing it. | |
| Aplazada | Media (4.3) | 0.33% | — | Smartlife APPAI | 20/9/2026 | 22/9/2026 | SmartLife app dynamically generates brand‑new SmartLife application authentication parameters within its runtime process. With the obtained SmartLife application authentication parameters, attackers can directly invoke the backend interface /account/verify.serv to determine whether a target email address is registered… | |
| Aplazada | Alta (8.8) | 0.52% | — | Smartlife APPAI | 20/9/2026 | 22/9/2026 | SmartLife app dynamically generates fresh SmartLife application authentication parameters inside its runtime process. Using the acquired SmartLife application authentication parameters, an attacker can directly call the backend interface /account/verify.serv to obtain the real account ID corresponding to a registered… | |
| Aplazada | Media (5.4) | 0.36% | — | Smartlife APPAI | 20/9/2026 | 22/9/2026 | SmartLife app dynamically generates brand‑new SmartLife application authentication parameters at runtime. With the acquired SmartLife application authentication credentials, an attacker can directly complete registration using any arbitrary email address via the backend interface /account/person/signup.serv. Email… | |
| Aplazada | Media (6.5) | 0.34% | — | Wpgraphql Smart CacheAI | 19/9/2026 | 21/9/2026 | The WPGraphQL Smart Cache WordPress plugin before 2.3.2 does not require authorisation or validate a caller-supplied query identifier before storing a persisted query from a request, allowing unauthenticated users to publish arbitrary query documents and claim query aliases before a site's own frontend registers them. | |
| En análisis | Baja (3.5) | 0.24% | — | Dell Smartfabric ManagerAI | 17/9/2026 | 18/9/2026 | Dell SmartFabric Manager, versions prior to 2.2.1, contains an Improper Handling of Insufficient Permissions or Privileges vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure. | |
| En análisis | Alta (8.1) | 0.20% | — | Dell Smartfabric ManagerAI | 17/9/2026 | 18/9/2026 | Dell SmartFabric Manager, versions prior to 2.2.1, contains an Insufficient Verification of Data Authenticity vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges. | |
| Analizada | Alta (7.5) | 0.19% | — | Qualcomm Q-7790 FirmwareQualcomm Qam8255p FirmwareQualcomm Qam8295p FirmwareQualcomm Qamsrv1h Firmware+372 | 17/9/2026 | 22/9/2026 | Transient DOS when processing authentication frames with invalid FILS information element header lengths. | |
| Aplazada | Alta (7.1) | 0.33% | — | TCH Qring Smart Ring R20 B006AI | 16/9/2026 | 22/9/2026 | TCH QRing smart ring model R20_B006 running firmware RT09R20_1.00.00_250318 contains an unauthenticated Bluetooth Low Energy access vulnerability that allows any nearby attacker to connect to the device without pairing, authentication, or user approval by exploiting the exposed Nordic UART Service which enforces no… | |
| Aplazada | Alta (7.5) | 0.37% | — | Prolink 13A Smart Plug Ds-3202m-ukv3AIMezeeAI | 15/9/2026 | 22/9/2026 | An issue in Prolink 13A Smart Plug Model Version: DS-3202M-UKv3 Wi-Fi and Application Version mEzee 2.6.7 allows attackers to cause a Denial of Service (DoS) or connection to an attacker-controlled device via supplying a crafted packet during the provisioning phase. | |
| Pendiente de análisis | Crítica (9.1) | 0.30% | — | Dell Smartfabric Os10AI | 15/9/2026 | 16/9/2026 | Dell SmartFabric OS10 Software, versions prior to 10.6.1.3, contains a Download of Code Without Integrity Check vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Code execution. | |
| Pendiente de análisis | Crítica (9.8) | 0.50% | — | Dell Smartfabric Os10AI | 15/9/2026 | 16/9/2026 | Dell SmartFabric OS10 Software, versions prior to 10.6.1.3, contains a Session Fixation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Session theft. | |
| Aplazada | Media (4.3) | 0.28% | — | Smartadmin APIAIOracle JavaAIVmware Spring BootAI | 15/9/2026 | 22/9/2026 | SmartAdmin API Java17 SpringBoot3 version 3.30.0 contains an improper authorization vulnerability in the /employee/queryAll endpoint. The endpoint does not enforce the required function-level permission or data-scope authorization, allowing an authenticated low-privileged employee to retrieve employee records… |