Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
1742 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.18% | — | Amauri Wpmobile.appAI | 6/11/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Amauri WPMobile.App wpappninja.This issue affects WPMobile.App: from n/a through <= 11.71. | |
| Analizada | Media (6.5) | 0.12% | — | Qualcomm Ar8035 FirmwareQualcomm Csrb31024 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 Firmware+132 | 4/11/2025 | 17/6/2026 | Transient DOS when a remote device sends an invalid connection request during BT connectable LE scan. | |
| Analizada | Alta (7.8) | 0.09% | — | Qualcomm Apq8064au FirmwareQualcomm Csr8811 FirmwareQualcomm Immersive Home 214 Platform FirmwareQualcomm Immersive Home 216 Platform Firmware+91 | 4/11/2025 | 17/6/2026 | Memory corruption while processing a GP command response. | |
| Analizada | Alta (7.8) | 0.06% | — | Qualcomm Qcs615 FirmwareQualcomm Qcs6490 FirmwareQualcomm Qcs8300 FirmwareQualcomm Qcs8550 Firmware+171 | 4/11/2025 | 17/6/2026 | Memory corruption while performing encryption and decryption commands. | |
| Analizada | Media (6.1) | 0.08% | — | Qualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Immersive Home 3210 Platform FirmwareQualcomm Immersive Home 326 Platform Firmware+73 | 4/11/2025 | 17/6/2026 | Information disclosure while registering commands from clients with diag through diagHal. | |
| Aplazada | Alta (7.5) | 0.30% | — | Glority Global Group LTD Mobile ScannerAI | 30/10/2025 | 17/6/2026 | Mobile Scanner Android App version 2.12.38 (package name com.glority.everlens), developed by Glority Global Group Ltd., contains a credential leakage vulnerability. Improper handling of cloud service credentials may allow attackers to obtain them and carry out unauthorized actions, such as sensitive information… | |
| Aplazada | Media (6.3) | 0.15% | — | Watchguard Mobile VPN With SSLAI | 29/10/2025 | 10/8/2026 | A local privilege escalation vulnerability in the WatchGuard Mobile VPN with SSL client on Windows enables a local user to execute arbitrary commands with elevated privileges on the Windows system. This vulnerability is an additional unmitigated attack path for CVE-2024-4944. This vulnerability is resolved in the… | |
| Aplazada | Alta (7.1) | 0.25% | — | Toast Plugins Toast Mobile MenuAI | 22/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Toast Plugins Toast Mobile Menu toast-responsive-menu allows Stored XSS.This issue affects Toast Mobile Menu: from n/a through <= 1.0.8. | |
| Analizada | Media (6.1) | 0.30% | — | Hcltech Bigfix MobileHcltech Bigfix Modern Client Management | 16/10/2025 | 17/6/2026 | HCL BigFix Mobile 3.3 and earlier are vulnerable to certain insecure directives within the Content Security Policy (CSP). An attacker could trick users into performing actions by not properly restricting the sources of scripts and other content. | |
| Analizada | Media (6.1) | 0.30% | — | Hcltech Bigfix MobileHcltech Bigfix Modern Client Management | 16/10/2025 | 17/6/2026 | HCL BigFix Modern Client Management (MCM) 3.3 and earlier are vulnerable to certain insecure directives within the Content Security Policy (CSP). An attacker could trick users into performing actions by not properly restricting the sources of scripts and other content. | |
| Analizada | Media (4.3) | 0.26% | — | Hcltech Bigfix MobileHcltech Bigfix Modern Client Management | 16/10/2025 | 17/6/2026 | HCL BigFix Mobile 3.3 and earlier is affected by improper access control. Unauthorized users can access a small subset of endpoint actions, potentially allowing access to select internal functions. | |
| Analizada | Media (4.3) | 0.26% | — | Hcltech Bigfix MobileHcltech Bigfix Modern Client Management | 16/10/2025 | 17/6/2026 | HCL BigFix Modern Client Management (MCM) 3.3 and earlier is affected by improper access control. Unauthorized users can access a small subset of endpoint actions, potentially allowing access to select internal functions. | |
| Analizada | Media (5.5) | 0.62% | — | Ivanti Endpoint Manager Mobile | 14/10/2025 | 17/6/2026 | Path traversal in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote authenticated attacker with admin privileges to write data in unintended locations on disk. | |
| Analizada | Alta (7.2) | 20% | — | Ivanti Endpoint Manager Mobile | 14/10/2025 | 17/6/2026 | OS command injection in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote authenticated attacker with admin privileges to achieve remote code execution. | |
| Analizada | Alta (7.2) | 20% | — | Ivanti Endpoint Manager Mobile | 14/10/2025 | 17/6/2026 | OS command injection in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote authenticated attacker with admin privileges to achieve remote code execution. | |
| Analizada | Alta (7.2) | 20% | — | Ivanti Endpoint Manager Mobile | 14/10/2025 | 30/9/2026 | OS command injection in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote authenticated attacker with admin privileges to achieve remote code execution. | |
| Aplazada | Baja (0.9) | 0.20% | — | Tomofun Furbo Mobile APPAI | 12/10/2025 | 17/6/2026 | A security vulnerability has been detected in Tomofun Furbo Mobile App up to 7.57.0a on Android. This affects an unknown part of the component Authentication Token Handler. The manipulation leads to insecure storage of sensitive information. It is possible to launch the attack on the physical device. The exploit has… | |
| Analizada | Alta (7.8) | 0.09% | — | Qualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Qmp1000 Firmware+34 | 9/10/2025 | 17/6/2026 | Memory corruption while allocating buffers in DSP service. | |
| Analizada | Alta (7.8) | 0.09% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm 9205 LTE Modem FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 Firmware+295 | 9/10/2025 | 17/6/2026 | Memory corruption while processing a malformed license file during reboot. | |
| Analizada | Alta (7.8) | 0.09% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm 9205 LTE Modem FirmwareQualcomm Mdm9650 FirmwareQualcomm Msm8996au Firmware+315 | 9/10/2025 | 17/6/2026 | Memory corruption during PlayReady APP usecase while processing TA commands. | |
| Analizada | Media (5.5) | 0.08% | — | Qualcomm Ar8035 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Qca6174a Firmware+59 | 9/10/2025 | 17/6/2026 | Transient DOS while processing video packets received from video firmware. | |
| Aplazada | Media (4.7) | 0.18% | — | Yosmart Yolink HUBAIYosmart Yolink Mobile ApplicationAIYosmart Yolink Mqtt BrokerAI | 6/10/2025 | 17/6/2026 | Components of the YoSmart YoLink ecosystem through 2025-10-02 leverage unencrypted MQTT to communicate over the internet. An attacker with the ability to monitor network traffic could therefore obtain sensitive information or tamper with the traffic to control affected devices. This affects YoLink Hub 0382, YoLink… | |
| Aplazada | Media (6.1) | 0.16% | — | Mobile Site RedirectAI | 3/10/2025 | 17/6/2026 | The Mobile Site Redirect plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.1. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a… | |
| Analizada | Alta (7.8) | 0.17% | — | Dell PRO Rugged 13 Ra13250 FirmwareDell PRO Rugged 14 Rb14250 FirmwareDell Latitude 5350 FirmwareDell Latitutde 5450 Firmware+10 | 25/9/2025 | 17/6/2026 | Dell Wireless 5932e and Qualcomm Snapdragon X62 Firmware and GNSS/GPS Driver, versions prior to 3.2.0.22 contain an Unquoted Search Path or Element vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Code Execution. | |
| Analizada | Alta (7.8) | 0.09% | — | Qualcomm Fastconnect 7800 FirmwareQualcomm Qam8255p FirmwareQualcomm Qam8775p FirmwareQualcomm Qca6574 Firmware+34 | 24/9/2025 | 17/6/2026 | Memory corruption while handling invalid inputs in application info setup. |