Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3047▲ 440 respecto a la semana anterior
Críticas / altas1452▲ 212 respecto a la semana anterior
Nueva explotación activa (KEV)8▼ 2 respecto a la semana anterior
Sin puntuar (sin CVSS)365▲ 151 respecto a la semana anterior
–

338 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.5)0.36%—Media Library AssistantAI30/9/202630/9/2026
Contributor SQL Injection in Media LIbrary Assistant <= 3.41 versions.
Pendiente de análisisCrítica (9.3)0.39%—Home-assistant Home AssistantAI22/9/202623/9/2026
Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.7.0, the Statistics Graph card in src/components/chart/statistics-chart.ts passed entity names through getStatisticLabel and computeStateName and interpolated param.seriesName into ECharts tooltip HTML without…
Pendiente de análisisMedia (5.4)0.20%—Home-assistant Home AssistantAI22/9/202625/9/2026
Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.2.3, the IPP integration automatically processed unauthenticated _ipp._tcp.local mDNS announcements in homeassistant/components/ipp/config_flow.py, where async_step_zeroconf passed attacker-controlled host, port,…
Pendiente de análisisAlta (7.3)0.11%—HP Support AssistantAI22/9/202629/9/2026
A potential security vulnerability has been identified in the HP Support Assistant for versions prior to 9.55.10.0. The vulnerability could potentially allow a local attacker to escalate privileges due to insufficient access controls.
AplazadaAlta (7.4)0.53%—Gladysassistant Gladys AssistantAI21/9/202623/9/2026
Gladys Assistant before 5.1.0 contains a password reset link poisoning vulnerability that allows unauthenticated remote attackers to obtain valid password reset tokens for any account by exploiting the client-supplied origin parameter in the forgot_password endpoint without server-side validation. Attackers can send a…
AplazadaMedia (6.4)0.36%—Media Library AssistantAI11/9/202611/9/2026
The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the bulk edit preset export/import mechanism in versions up to and including 3.35. This is due to insufficient output escaping on preset field values when they are rendered in HTML attribute contexts in the…
AplazadaMedia (6.4)0.36%—Media Library AssistantAI11/9/202611/9/2026
The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mla_gallery' shortcode in versions up to and including 3.35. This is due to insufficient input sanitization and output escaping on the mla_link_href parameter when mla_output is set to 'paginate_links', where the…
AplazadaMedia (6.4)0.42%—Media Library AssistantAI11/9/202611/9/2026
The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mla_link_attributes' parameter in all versions up to, and including, 3.35 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access…
Pendiente de análisisMedia (5.1)0.10%—Samsung Cloud AssistantAI9/9/202610/9/2026
Improper verification of intent by broadcast receiver in Samsung Cloud Assistant prior to version 9.0.5 allows local attackers to disable enhanced data protection settings.
Pendiente de análisisAlta (7.3)0.09%—HP Support AssistantAI3/9/20268/9/2026
A potential security vulnerability has been identified in the HP Support Assistant for versions prior to 9.53.2.0. The vulnerability could potentially allow a local attacker to escalate privileges due to insufficient access controls.
AplazadaMedia (6.8)0.39%—Media Library AssistantAI21/8/202626/8/2026
The Media Library Assistant WordPress plugin before 3.40 does not validate a search parameter before concatenating it into a SQL query in one of its media-library query handlers, allowing users with the Author role to perform SQL injection.
AplazadaMedia (6.5)0.22%—Media Library AssistantAI20/8/202620/8/2026
Subscriber Cross Site Scripting (XSS) in Media LIbrary Assistant <= 3.39 versions.
AplazadaCrítica (9.1)0.50%—Media Library AssistantAI20/8/202620/8/2026
Author Arbitrary File Upload in Media LIbrary Assistant <= 3.39 versions.
AplazadaMedia (6.5)0.22%—Davidlingren Media Library AssistantAI18/8/202621/8/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Lingren Media LIbrary Assistant allows Stored XSS. This issue affects Media LIbrary Assistant: from n/a through 3.39.
AplazadaMedia (5.3)0.45%—Blueprint StudioAIHome-assistant Home AssistantAI18/8/20268/9/2026
Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files. Prior to 2.5.2, Blueprint Studio backend API handlers in custom_components/blueprint_studio/backend/api.py returned raw exception strings to authenticated Home Assistant users. Some exception messages could contain internal…
AplazadaMedia (5.1)0.76%—Blueprint StudioAIHome-assistant Home AssistantAI18/8/20268/9/2026
Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files. Prior to 2.5.2, the legacy stateless terminal command execution path in custom_components/blueprint_studio/backend/terminal_manager.py accepted a cwd working-directory parameter and checked only whether the directory existed,…
AplazadaAlta (8.6)0.50%—Blueprint StudioAIHome-assistant Home AssistantAI18/8/20268/9/2026
Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files. Prior to 2.5.2, Blueprint Studio generated a shell-based Git credential helper in custom_components/blueprint_studio/backend/git_manager.py by interpolating the configured Git username and token directly into executable helper…
AplazadaMedia (6.9)0.46%—GITAIHome-assistant Blueprint StudioAI18/8/20268/9/2026
Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files. Prior to 2.5.2, Blueprint Studio configured Git's credential.helper store when saving Git credentials, causing Git credential-store to persist usernames and access tokens in plaintext in the .git-credentials file for the user…
AplazadaAlta (8.7)0.45%—Blueprint StudioAIHome-assistant Home AssistantAI18/8/20268/9/2026
Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files. Prior to 2.5.2, Blueprint Studio exposed administrator-intended backend API actions to any authenticated Home Assistant user because the backend did not consistently enforce the panel's admin-only authorization boundary. Affected…
AplazadaAlta (7.1)0.17%—Home-assistant IOS Companion APPAI7/8/20269/9/2026
Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.5.0, the iOS Companion app treats tag links (NFC or QR) delivered through an OS-level routing mechanism such as iOS universal links as if they were physically scanned, without validating the calling app or…
AplazadaAlta (7.1)0.17%—Home-assistant Companion APPAI7/8/20269/9/2026
Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.5.3, the Companion app treats tag links (NFC or QR) delivered through an OS-level routing mechanism as if they were physically scanned, without validating the calling app or prompting the user. As a result, any…
AplazadaMedia (4.3)0.38%—Home-assistant Android Companion APPAI7/8/20269/9/2026
Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.6.1, the Android Companion app is vulnerable to an open redirect. The app passes the URL fragment from a homeassistant://invite deep link into the onboarding flow without ever displaying the destination hostname.…
AplazadaAlta (7.1)0.25%—Media Library AssistantAI6/8/202612/8/2026
Unauthenticated Cross Site Scripting (XSS) in Media LIbrary Assistant <= 3.38 versions.
AnalizadaAlta (7.3)0.15%—Synology Assistant3/8/202621/8/2026
An incorrect default permissions vulnerability in Synology Assistant before 7.0.7-50095 allows local users to read or write arbitrary files and conduct denial-of-service during installation.
AplazadaCrítica (9)0.58%—Home-assistant CoreAI21/7/202621/7/2026
Home Assistant Core before 2026.6.0 contains a path traversal vulnerability that allows unauthenticated attackers to write arbitrary files to any directory on the host filesystem by uploading a crafted backup archive during the initial onboarding window. Attackers can manipulate the 'name' field inside the uploaded…