Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2661▼ 437 respecto a la semana anterior
Críticas / altas1284▼ 85 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
12 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.22% | — | Merkulove SpeakerAI | 13/7/2026 | 13/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in merkulove Speaker speaker allows Stored XSS.This issue affects Speaker: from n/a through <= 4.1.13. | |
| Aplazada | Media (5.9) | 0.33% | — | Ken107 Sitespeaker-widgetAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ken107 SiteNarrator Text-to-Speech Widget sitespeaker-widget allows Stored XSS.This issue affects SiteNarrator Text-to-Speech Widget: from n/a through <= 1.9. | |
| Aplazada | Media (6.3) | 0.29% | — | Himalaya Xiaoya Nano Smart SpeakerAI | 29/7/2024 | 9/7/2026 | Incorrect access control in Himalaya Xiaoya nano smart speaker rom_version 1.6.96 allows a remote attacker to have an unspecified impact. | |
| Aplazada | Alta (7.5) | 0.57% | — | SpeakerAI | 10/7/2024 | 17/6/2026 | All versions of the package speaker are vulnerable to Denial of Service (DoS) when providing unexpected input types to the channels property of the Speaker object makes it possible to reach an assert macro. Exploiting this vulnerability can lead to a process crash. | |
| Modificada | Media (4.8) | 0.37% | — | 9seeds CPT - Speakers | 4/5/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in 9seeds.Com CPT – Speakers plugin <= 1.1 versions. | |
| Modificada | Baja (3.7) | 1.2% | — | Tonewinner Winner Desktop Speakers Firmware | 10/8/2021 | 5/7/2026 | Winner (aka ToneWinner) desktop speakers through 2021-08-09 allow remote attackers to recover speech signals from the power-indicator LED via a telescope and an electro-optical sensor, aka a "Glowworm" attack. | |
| Modificada | Crítica (9.8) | 1.2% | — | Xiaomi AI Speaker Firmware | 11/9/2020 | 17/6/2026 | Memory overflow in Xiaomi AI speaker Rom version <1.59.6 can happen when the speaker verifying a malicious firmware during OTA process. | |
| Modificada | Media (6.8) | 0.52% | — | Xiaomi Xiaoai Speaker PRO Lx06 Firmware | 8/4/2020 | 17/6/2026 | An issue was discovered on XIAOMI XIAOAI speaker Pro LX06 1.52.4. Attackers can get root shell by accessing the UART interface and then they can (i) read Wi-Fi SSID or password, (ii) read the dialogue text files between users and XIAOMI XIAOAI speaker Pro LX06, (iii) use Text-To-Speech tools pretend XIAOMI speakers'… | |
| Modificada | Media (6.8) | 0.55% | — | Xiaomi Xiaoai Speaker PRO Lx06 Firmware | 8/4/2020 | 17/6/2026 | An issue was discovered on XIAOMI XIAOAI speaker Pro LX06 1.58.10. Attackers can activate the failsafe mode during the boot process, and use the mi_console command cascaded by the SN code shown on the product to get the root shell password, and then the attacker can (i) read Wi-Fi SSID or password, (ii) read the… | |
| Modificada | Media (6.8) | 0.49% | — | Yeelight Smart AI Speaker Firmware | 16/5/2019 | 17/6/2026 | Yeelight Smart AI Speaker 3.3.10_0074 devices have improper access control over the UART interface, allowing physical attackers to obtain a root shell. The attacker can then exfiltrate the audio data, read cleartext Wi-Fi credentials in a log file, or access other sensitive device and user information. | |
| Modificada | Alta (7.5) | 0.95% | — | Martin Hess COM Sermonspeaker | 27/4/2010 | 16/6/2026 | SQL injection vulnerability in the SermonSpeaker (com_sermonspeaker) component before 3.2.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a speakerpopup action to index.php. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (7.5) | 1.2% | — | Martin Hess COM Sermonspeaker | 19/4/2010 | 16/6/2026 | SQL injection vulnerability in the SermonSpeaker (com_sermonspeaker) component before 3.2.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a latest_sermons action to index.php. |