Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2686▼ 84 respecto a la semana anterior
Críticas / altas1444▲ 301 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
–

494 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.5)0.25%—Media Library AssistantAI30/9/202630/9/2026
Contributor SQL Injection in Media LIbrary Assistant <= 3.41 versions.
Pendiente de análisisCrítica (9.3)0.39%—Home-assistant Home AssistantAI22/9/202623/9/2026
Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.7.0, the Statistics Graph card in src/components/chart/statistics-chart.ts passed entity names through getStatisticLabel and computeStateName and interpolated param.seriesName into ECharts tooltip HTML without…
Pendiente de análisisMedia (5.4)0.20%—Home-assistant Home AssistantAI22/9/202625/9/2026
Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.2.3, the IPP integration automatically processed unauthenticated _ipp._tcp.local mDNS announcements in homeassistant/components/ipp/config_flow.py, where async_step_zeroconf passed attacker-controlled host, port,…
Pendiente de análisisAlta (7.3)0.11%—HP Support AssistantAI22/9/202629/9/2026
A potential security vulnerability has been identified in the HP Support Assistant for versions prior to 9.55.10.0. The vulnerability could potentially allow a local attacker to escalate privileges due to insufficient access controls.
AplazadaAlta (7.4)0.53%—Gladysassistant Gladys AssistantAI21/9/202623/9/2026
Gladys Assistant before 5.1.0 contains a password reset link poisoning vulnerability that allows unauthenticated remote attackers to obtain valid password reset tokens for any account by exploiting the client-supplied origin parameter in the forgot_password endpoint without server-side validation. Attackers can send a…
AplazadaMedia (6.4)0.36%—Media Library AssistantAI11/9/202611/9/2026
The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the bulk edit preset export/import mechanism in versions up to and including 3.35. This is due to insufficient output escaping on preset field values when they are rendered in HTML attribute contexts in the…
AplazadaMedia (6.4)0.36%—Media Library AssistantAI11/9/202611/9/2026
The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mla_gallery' shortcode in versions up to and including 3.35. This is due to insufficient input sanitization and output escaping on the mla_link_href parameter when mla_output is set to 'paginate_links', where the…
AplazadaMedia (6.4)0.42%—Media Library AssistantAI11/9/202611/9/2026
The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mla_link_attributes' parameter in all versions up to, and including, 3.35 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access…
Pendiente de análisisMedia (5.1)0.10%—Samsung Cloud AssistantAI9/9/202610/9/2026
Improper verification of intent by broadcast receiver in Samsung Cloud Assistant prior to version 9.0.5 allows local attackers to disable enhanced data protection settings.
Pendiente de análisisAlta (7.3)0.09%—HP Support AssistantAI3/9/20268/9/2026
A potential security vulnerability has been identified in the HP Support Assistant for versions prior to 9.53.2.0. The vulnerability could potentially allow a local attacker to escalate privileges due to insufficient access controls.
AplazadaAlta (7.2)0.24%—Ifeelweb Affiliate Super AssistentAI1/9/20261/9/2026
The Affiliate Super Assistent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘doCommentShortcode’ function in all versions up to, and including, 1.10.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…
AplazadaMedia (4.8)0.24%—Bitapps BIT AssistAI28/8/20261/9/2026
WordPress plugin (Bit Assist) before 1.7.2 is affected by Stored Cross-Site Scripting in Call-To-Action feature. An authenticated attacker with the privileged role (admin) can exploit this to redirect user to malicious site or control the account.
AplazadaMedia (5.1)0.29%—Miraikan Assist APPAI21/8/202628/8/2026
Cross-site scripting vulnerability exists in Miraikan Assist App. If this vulnerability is exploited, an arbitrary script may be executed in the browser component (WebView) running on the affected product, resulting in the displayed content being altered.
AplazadaMedia (6.8)0.39%—Media Library AssistantAI21/8/202626/8/2026
The Media Library Assistant WordPress plugin before 3.40 does not validate a search parameter before concatenating it into a SQL query in one of its media-library query handlers, allowing users with the Author role to perform SQL injection.
AplazadaMedia (6.5)0.22%—Media Library AssistantAI20/8/202620/8/2026
Subscriber Cross Site Scripting (XSS) in Media LIbrary Assistant <= 3.39 versions.
AplazadaCrítica (9.1)0.50%—Media Library AssistantAI20/8/202620/8/2026
Author Arbitrary File Upload in Media LIbrary Assistant <= 3.39 versions.
AplazadaMedia (6.5)0.22%—Davidlingren Media Library AssistantAI18/8/202621/8/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Lingren Media LIbrary Assistant allows Stored XSS. This issue affects Media LIbrary Assistant: from n/a through 3.39.
AplazadaMedia (5.3)0.45%—Blueprint StudioAIHome-assistant Home AssistantAI18/8/20268/9/2026
Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files. Prior to 2.5.2, Blueprint Studio backend API handlers in custom_components/blueprint_studio/backend/api.py returned raw exception strings to authenticated Home Assistant users. Some exception messages could contain internal…
AplazadaMedia (5.1)0.76%—Blueprint StudioAIHome-assistant Home AssistantAI18/8/20268/9/2026
Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files. Prior to 2.5.2, the legacy stateless terminal command execution path in custom_components/blueprint_studio/backend/terminal_manager.py accepted a cwd working-directory parameter and checked only whether the directory existed,…
AplazadaAlta (8.6)0.50%—Blueprint StudioAIHome-assistant Home AssistantAI18/8/20268/9/2026
Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files. Prior to 2.5.2, Blueprint Studio generated a shell-based Git credential helper in custom_components/blueprint_studio/backend/git_manager.py by interpolating the configured Git username and token directly into executable helper…
AplazadaMedia (6.9)0.46%—GITAIHome-assistant Blueprint StudioAI18/8/20268/9/2026
Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files. Prior to 2.5.2, Blueprint Studio configured Git's credential.helper store when saving Git credentials, causing Git credential-store to persist usernames and access tokens in plaintext in the .git-credentials file for the user…
AplazadaAlta (8.7)0.45%—Blueprint StudioAIHome-assistant Home AssistantAI18/8/20268/9/2026
Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files. Prior to 2.5.2, Blueprint Studio exposed administrator-intended backend API actions to any authenticated Home Assistant user because the backend did not consistently enforce the panel's admin-only authorization boundary. Affected…
AplazadaAlta (7.1)0.25%—Knowledge Base FOR Documentation Faqs With AI AssistanceAI13/8/202614/8/2026
Unauthenticated Cross Site Scripting (XSS) in Knowledge Base for Documentation, FAQs with AI Assistance <= 17.211.0 versions.
AplazadaAlta (7.1)0.17%—Home-assistant IOS Companion APPAI7/8/20269/9/2026
Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.5.0, the iOS Companion app treats tag links (NFC or QR) delivered through an OS-level routing mechanism such as iOS universal links as if they were physically scanned, without validating the calling app or…
AplazadaAlta (7.1)0.17%—Home-assistant Companion APPAI7/8/20269/9/2026
Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.5.3, the Companion app treats tag links (NFC or QR) delivered through an OS-level routing mechanism as if they were physically scanned, without validating the calling app or prompting the user. As a result, any…