Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2623▼ 237 respecto a la semana anterior
Críticas / altas1384▲ 151 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
11 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.1) | 0.34% | — | Arduino-tuyaopen | 16/3/2026 | 17/6/2026 | arduino-TuyaOpen before version 1.2.1 contains a null pointer dereference vulnerability in the WiFiUDP component. An attacker on the same local area network can send a large volume of malicious UDP packets that trigger a null pointer dereference, resulting in a denial-of-service condition. | |
| Analizada | Alta (7) | 0.19% | — | Arduino-tuyaopen | 16/3/2026 | 17/6/2026 | arduino-TuyaOpen before version 1.2.1 contains an out-of-bounds memory read vulnerability in the TuyaIoT component. An attacker who hijacks or controls the Tuya cloud service can issue malicious DP event data to victim devices, causing out-of-bounds memory access that may result in information disclosure or a… | |
| Analizada | Alta (8.6) | 0.22% | — | Arduino-tuyaopen | 16/3/2026 | 17/6/2026 | arduino-TuyaOpen before version 1.2.1 contains a single-byte buffer overflow vulnerability in the WiFiMulti component. When the victim's smart hardware connects to an attacker-controlled AP hotspot, the attacker can exploit the overflow to execute arbitrary code on the affected embedded device. | |
| Analizada | Alta (8.7) | 0.43% | — | Arduino-tuyaopen | 16/3/2026 | 17/6/2026 | arduino-TuyaOpen before version 1.2.1 contains a heap-based buffer overflow vulnerability in the DnsServer component. An attacker on the same local area network who controls the LAN DNS server can send malicious DNS responses to overflow the heap buffer, potentially allowing execution of arbitrary code on affected… | |
| Aplazada | Baja (1.3) | 0.46% | — | Tuya APP AND SDKAI | 3/3/2026 | 17/6/2026 | A vulnerability was determined in Tuya App and SDK 24.07.11 on Android. Affected by this vulnerability is an unknown functionality of the component JSON Data Point Handler. This manipulation of the argument cruise_time causes denial of service. Remote exploitation of the attack is possible. The complexity of an attack… | |
| Modificada | Alta (8.8) | 0.17% | — | Tuya SmartlifeTuyaTuya Smart | 24/11/2025 | 5/7/2026 | Cross-Site Request Forgery (CSRF) vulnerability in the OAuth implementation of the Tuya SDK 6.5.0 for Android and iOS, affects the Tuya Smart and Smartlife mobile applications, as well as other third-party applications that integrate the SDK, allows an attacker to link their own Amazon Alexa account to a victim's Tuya… | |
| Modificada | Crítica (9.1) | 0.31% | — | Tuya | 16/9/2025 | 5/7/2026 | An issue discovered in the Tuya Smart Life App 5.6.1 allows attackers to unprivileged control Matter devices via the Matter protocol. | |
| Aplazada | Alta (7.5) | 0.38% | — | Tuya SmartlifeAI | 3/2/2025 | 5/7/2026 | Nedis SmartLife android app v1.4.0 was discovered to contain an API key disclosure vulnerability. | |
| Aplazada | Alta (8.4) | 0.96% | — | Kerui HD 3MP 1080p Tuya CameraAI | 30/10/2024 | 17/6/2026 | KERUI HD 3MP 1080P Tuya Camera 1.0.4 has a command injection vulnerability in the module that connects to the local network via a QR code. This vulnerability allows an attacker to create a custom, unauthenticated QR code and abuse one of the parameters, either SSID or PASSWORD, in the JSON data contained within the QR… | |
| Aplazada | Baja (3.3) | 0.21% | — | Tuya Smart Camera U6NAI | 29/4/2024 | 17/6/2026 | An issue in Tuya Smart camera U6N v.3.2.5 allows a remote attacker to cause a denial of service via a crafted packet to the network connection component. | |
| Aplazada | Baja (2.7) | 0.59% | — | Tuya SDKAI | 14/4/2024 | 17/6/2026 | ** DISPUTED ** A vulnerability classified as problematic has been found in Tuya SDK up to 5.0.x. Affected is an unknown function of the component MQTT Packet Handler. The manipulation leads to denial of service. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.… |