Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2553▼ 349 respecto a la semana anterior
Críticas / altas1314▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)76▼ 451 respecto a la semana anterior
–

7 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.2)0.20%—ZTE SmartlifeAI20/9/202622/9/2026
The ZTE SmartLife application has a hardcoded key. The key used to decrypt account server information is stored in plaintext in the code. Once the key is obtained, the server information can be decrypted, thus exposing it.
AplazadaMedia (4.3)0.33%—Smartlife APPAI20/9/202622/9/2026
SmartLife app dynamically generates brand‑new SmartLife application authentication parameters within its runtime process. With the obtained SmartLife application authentication parameters, attackers can directly invoke the backend interface /account/verify.serv to determine whether a target email address is registered…
AplazadaAlta (8.8)0.52%—Smartlife APPAI20/9/202622/9/2026
SmartLife app dynamically generates fresh SmartLife application authentication parameters inside its runtime process. Using the acquired SmartLife application authentication parameters, an attacker can directly call the backend interface /account/verify.serv to obtain the real account ID corresponding to a registered…
AplazadaMedia (5.4)0.36%—Smartlife APPAI20/9/202622/9/2026
SmartLife app dynamically generates brand‑new SmartLife application authentication parameters at runtime. With the acquired SmartLife application authentication credentials, an attacker can directly complete registration using any arbitrary email address via the backend interface /account/person/signup.serv. Email…
ModificadaAlta (8.8)0.17%—Tuya SmartlifeTuyaTuya Smart24/11/20255/7/2026
Cross-Site Request Forgery (CSRF) vulnerability in the OAuth implementation of the Tuya SDK 6.5.0 for Android and iOS, affects the Tuya Smart and Smartlife mobile applications, as well as other third-party applications that integrate the SDK, allows an attacker to link their own Amazon Alexa account to a victim's Tuya…
AplazadaAlta (7.5)0.38%—Tuya SmartlifeAI3/2/20255/7/2026
Nedis SmartLife android app v1.4.0 was discovered to contain an API key disclosure vulnerability.
AplazadaAlta (7.5)0.37%—Nedis Smartlife Video DoorbellAINedis Smartlife IOSAI3/2/20255/7/2026
An issue in Nedis SmartLife Video Doorbell (WIFICDP10GY), Nedis SmartLife IOS v1.4.0 causes users who are disconnected from a previous peer-to-peer connection with the device to still have access to live video feed.