Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3047▲ 440 respecto a la semana anterior
Críticas / altas1452▲ 212 respecto a la semana anterior
Nueva explotación activa (KEV)8▼ 2 respecto a la semana anterior
Sin puntuar (sin CVSS)365▲ 151 respecto a la semana anterior
338 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.5) | 0.36% | — | Media Library AssistantAI | 30/9/2026 | 30/9/2026 | Contributor SQL Injection in Media LIbrary Assistant <= 3.41 versions. | |
| Pendiente de análisis | Crítica (9.3) | 0.39% | — | Home-assistant Home AssistantAI | 22/9/2026 | 23/9/2026 | Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.7.0, the Statistics Graph card in src/components/chart/statistics-chart.ts passed entity names through getStatisticLabel and computeStateName and interpolated param.seriesName into ECharts tooltip HTML without… | |
| Pendiente de análisis | Media (5.4) | 0.20% | — | Home-assistant Home AssistantAI | 22/9/2026 | 25/9/2026 | Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.2.3, the IPP integration automatically processed unauthenticated _ipp._tcp.local mDNS announcements in homeassistant/components/ipp/config_flow.py, where async_step_zeroconf passed attacker-controlled host, port,… | |
| Pendiente de análisis | Alta (7.3) | 0.11% | — | HP Support AssistantAI | 22/9/2026 | 29/9/2026 | A potential security vulnerability has been identified in the HP Support Assistant for versions prior to 9.55.10.0. The vulnerability could potentially allow a local attacker to escalate privileges due to insufficient access controls. | |
| Aplazada | Alta (7.4) | 0.53% | — | Gladysassistant Gladys AssistantAI | 21/9/2026 | 23/9/2026 | Gladys Assistant before 5.1.0 contains a password reset link poisoning vulnerability that allows unauthenticated remote attackers to obtain valid password reset tokens for any account by exploiting the client-supplied origin parameter in the forgot_password endpoint without server-side validation. Attackers can send a… | |
| Aplazada | Media (6.4) | 0.36% | — | Media Library AssistantAI | 11/9/2026 | 11/9/2026 | The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the bulk edit preset export/import mechanism in versions up to and including 3.35. This is due to insufficient output escaping on preset field values when they are rendered in HTML attribute contexts in the… | |
| Aplazada | Media (6.4) | 0.36% | — | Media Library AssistantAI | 11/9/2026 | 11/9/2026 | The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mla_gallery' shortcode in versions up to and including 3.35. This is due to insufficient input sanitization and output escaping on the mla_link_href parameter when mla_output is set to 'paginate_links', where the… | |
| Aplazada | Media (6.4) | 0.42% | — | Media Library AssistantAI | 11/9/2026 | 11/9/2026 | The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mla_link_attributes' parameter in all versions up to, and including, 3.35 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access… | |
| Pendiente de análisis | Media (5.1) | 0.10% | — | Samsung Cloud AssistantAI | 9/9/2026 | 10/9/2026 | Improper verification of intent by broadcast receiver in Samsung Cloud Assistant prior to version 9.0.5 allows local attackers to disable enhanced data protection settings. | |
| Pendiente de análisis | Alta (7.3) | 0.09% | — | HP Support AssistantAI | 3/9/2026 | 8/9/2026 | A potential security vulnerability has been identified in the HP Support Assistant for versions prior to 9.53.2.0. The vulnerability could potentially allow a local attacker to escalate privileges due to insufficient access controls. | |
| Aplazada | Media (6.8) | 0.39% | — | Media Library AssistantAI | 21/8/2026 | 26/8/2026 | The Media Library Assistant WordPress plugin before 3.40 does not validate a search parameter before concatenating it into a SQL query in one of its media-library query handlers, allowing users with the Author role to perform SQL injection. | |
| Aplazada | Media (6.5) | 0.22% | — | Media Library AssistantAI | 20/8/2026 | 20/8/2026 | Subscriber Cross Site Scripting (XSS) in Media LIbrary Assistant <= 3.39 versions. | |
| Aplazada | Crítica (9.1) | 0.50% | — | Media Library AssistantAI | 20/8/2026 | 20/8/2026 | Author Arbitrary File Upload in Media LIbrary Assistant <= 3.39 versions. | |
| Aplazada | Media (6.5) | 0.22% | — | Davidlingren Media Library AssistantAI | 18/8/2026 | 21/8/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Lingren Media LIbrary Assistant allows Stored XSS. This issue affects Media LIbrary Assistant: from n/a through 3.39. | |
| Aplazada | Media (5.3) | 0.45% | — | Blueprint StudioAIHome-assistant Home AssistantAI | 18/8/2026 | 8/9/2026 | Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files. Prior to 2.5.2, Blueprint Studio backend API handlers in custom_components/blueprint_studio/backend/api.py returned raw exception strings to authenticated Home Assistant users. Some exception messages could contain internal… | |
| Aplazada | Media (5.1) | 0.76% | — | Blueprint StudioAIHome-assistant Home AssistantAI | 18/8/2026 | 8/9/2026 | Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files. Prior to 2.5.2, the legacy stateless terminal command execution path in custom_components/blueprint_studio/backend/terminal_manager.py accepted a cwd working-directory parameter and checked only whether the directory existed,… | |
| Aplazada | Alta (8.6) | 0.50% | — | Blueprint StudioAIHome-assistant Home AssistantAI | 18/8/2026 | 8/9/2026 | Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files. Prior to 2.5.2, Blueprint Studio generated a shell-based Git credential helper in custom_components/blueprint_studio/backend/git_manager.py by interpolating the configured Git username and token directly into executable helper… | |
| Aplazada | Media (6.9) | 0.46% | — | GITAIHome-assistant Blueprint StudioAI | 18/8/2026 | 8/9/2026 | Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files. Prior to 2.5.2, Blueprint Studio configured Git's credential.helper store when saving Git credentials, causing Git credential-store to persist usernames and access tokens in plaintext in the .git-credentials file for the user… | |
| Aplazada | Alta (8.7) | 0.45% | — | Blueprint StudioAIHome-assistant Home AssistantAI | 18/8/2026 | 8/9/2026 | Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files. Prior to 2.5.2, Blueprint Studio exposed administrator-intended backend API actions to any authenticated Home Assistant user because the backend did not consistently enforce the panel's admin-only authorization boundary. Affected… | |
| Aplazada | Alta (7.1) | 0.17% | — | Home-assistant IOS Companion APPAI | 7/8/2026 | 9/9/2026 | Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.5.0, the iOS Companion app treats tag links (NFC or QR) delivered through an OS-level routing mechanism such as iOS universal links as if they were physically scanned, without validating the calling app or… | |
| Aplazada | Alta (7.1) | 0.17% | — | Home-assistant Companion APPAI | 7/8/2026 | 9/9/2026 | Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.5.3, the Companion app treats tag links (NFC or QR) delivered through an OS-level routing mechanism as if they were physically scanned, without validating the calling app or prompting the user. As a result, any… | |
| Aplazada | Media (4.3) | 0.38% | — | Home-assistant Android Companion APPAI | 7/8/2026 | 9/9/2026 | Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.6.1, the Android Companion app is vulnerable to an open redirect. The app passes the URL fragment from a homeassistant://invite deep link into the onboarding flow without ever displaying the destination hostname.… | |
| Aplazada | Alta (7.1) | 0.25% | — | Media Library AssistantAI | 6/8/2026 | 12/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Media LIbrary Assistant <= 3.38 versions. | |
| Analizada | Alta (7.3) | 0.15% | — | Synology Assistant | 3/8/2026 | 21/8/2026 | An incorrect default permissions vulnerability in Synology Assistant before 7.0.7-50095 allows local users to read or write arbitrary files and conduct denial-of-service during installation. | |
| Aplazada | Crítica (9) | 0.58% | — | Home-assistant CoreAI | 21/7/2026 | 21/7/2026 | Home Assistant Core before 2026.6.0 contains a path traversal vulnerability that allows unauthenticated attackers to write arbitrary files to any directory on the host filesystem by uploading a crafted backup archive during the initial onboarding window. Attackers can manipulate the 'name' field inside the uploaded… |