Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
9126 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.6) | 0.39% | — | Canva Android APPAI | 4/9/2026 | 8/9/2026 | The Canva Android App before 2.376.0 allowed an external origin to be loaded in a privileged WebView. A threat actor who controls the page loaded by the user is able to communicate with Canva using the user’s session. | |
| Aplazada | Alta (8.7) | 0.52% | — | Androidbubbles Keep Backup DailyAI | 31/8/2026 | 8/9/2026 | Keep Backup Daily plugin for WordPress before 2.1.4 contains a sensitive information exposure vulnerability that allows unauthenticated attackers to trigger a full MySQL database dump by accessing the publicly exposed `kbd_cron_process` parameter without authentication. Attackers can predict the partially predictable… | |
| Aplazada | Alta (7.5) | 0.39% | — | Androidbubble WP Sort OrderAI | 18/8/2026 | 20/8/2026 | Unauthenticated Broken Access Control in WP Sort Order <= 1.3.5 versions. | |
| Aplazada | Baja (1.9) | 1.2% | — | Jiantao88 Android-mcp-serverAI | 17/8/2026 | 20/8/2026 | A flaw has been found in jiantao88 android-mcp-server up to cfb872b2446794193b58edd63f4dbf6af48a6292. The impacted element is the function child_process.exec of the file build/index.js of the component Command Execution. Executing a manipulation of the argument… | |
| Aplazada | Crítica (9.3) | 0.42% | — | Mira Android APKAI | 11/8/2026 | 1/9/2026 | The distributed Mira Android APK v4.5.15.4 allows an attacker read/write access to reproductive health profiles from internet connected hosts, which could result in forgery, deletion, or destruction of health information. | |
| Aplazada | Alta (8.2) | 0.27% | — | Mira Android Companion APPAI | 11/8/2026 | 1/9/2026 | The Mira Android companion app v4.5.15.4 identifies the paired Mira hormone analyzer by performing a substring match against the BLE advertisement name only, with no cryptographic peripheral authentication, MAC allowlist, or bonded-identity check. An attacker could capture live session token information and inject… | |
| Aplazada | Media (6.9) | 0.39% | — | Mira Android APPAI | 11/8/2026 | 1/9/2026 | When the Mira Android app opens in-app WebView content (e.g., shop redirect flows), the user's live session token is appended to the URL as a query string parameter, and a persistent user identifier is included in the WebView's User-Agent header. Both are then transmitted to third-party web properties, referrer logs,… | |
| Aplazada | Media (4.4) | 0.12% | — | Estonian Information System Authority LibdigidocppAIEstonian Information System Authority Digidoc4AIEstonian Information System Authority Digidoc ON AndroidAIEstonian Information System Authority Digidoc ON IOSAI | 10/8/2026 | 1/9/2026 | Improper verification of cryptographic signature and Improper Check for Unusual or Exceptional Conditions vulnerability in Estonian Information System Authority (RIA) libdigidocpp, DigiDoc4, DigiDoc on Android, and DigiDoc on iOS. This issue affects libdigidocpp: from 4.1.0 before 4.2.1; DigiDoc4: from 4.7.0 before… | |
| Aplazada | Baja (2.3) | 0.17% | — | Ecovacs PRO APPAIApple IOSAIGoogle AndroidAI | 10/8/2026 | 28/8/2026 | Android and iOS apps ECOVACS PRO App improperly validate server certificates. Communication may be retrieved and/or altered. | |
| Analizada | Media (5.2) | 0.21% | — | Samsung Android | 10/8/2026 | 19/8/2026 | Improper input validation in Galaxy Themes prior to SMR Aug-2026 Release 1 allows physical attackers to launch arbitrary activity. | |
| Analizada | Media (5.1) | 0.15% | — | Samsung Android | 10/8/2026 | 19/8/2026 | Improper input validation in VC1 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. | |
| Analizada | Media (5.1) | 0.15% | — | Samsung Android | 10/8/2026 | 19/8/2026 | Improper input validation in MPEG4 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. | |
| Analizada | Media (5.1) | 0.21% | — | Samsung Android | 10/8/2026 | 19/8/2026 | Improper input validation in Samsung Message prior to SMR Aug-2026 Release 1 allows physical attackers to access sensitive information. | |
| Analizada | Media (5.1) | 0.15% | — | Samsung Android | 10/8/2026 | 19/8/2026 | Incorrect conversion between numeric types in VC1 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. | |
| Analizada | Alta (8.4) | 0.17% | — | Samsung Android | 10/8/2026 | 19/8/2026 | Stack-based buffer overflow in libril_sem.so prior to SMR Aug-2026 Release 1 allows privileged local attackers to execute arbitrary code. | |
| Analizada | Media (5.1) | 0.15% | — | Samsung Android | 10/8/2026 | 19/8/2026 | Improper input validation in libsmsd.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. | |
| Analizada | Media (5.1) | 0.15% | — | Samsung Android | 10/8/2026 | 19/8/2026 | Improper input validation in libcodec2_sec_flacdec.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. | |
| Analizada | Media (4.8) | 0.15% | — | Samsung Android | 10/8/2026 | 19/8/2026 | Out-of-bounds write in libcodec2secqcelpdec.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. | |
| Analizada | Alta (7) | 0.12% | — | Samsung Android | 10/8/2026 | 19/8/2026 | Improper access control in Weaver prior to SMR Aug-2026 Release 1 allows local attackers to cause device inoperability. | |
| Analizada | Media (6.8) | 0.20% | — | Samsung Android | 10/8/2026 | 19/8/2026 | Improper export of android application components in AppLock prior to SMR Aug-2026 Release 1 allows physical attackers to bypass app lock function. | |
| Analizada | Media (4.8) | 0.09% | — | Samsung Android | 10/8/2026 | 19/8/2026 | Authorization bypass in SemClipboardService prior to SMR Aug-2026 Release 1 allows local attackers to access clipboard data. | |
| Analizada | Media (6) | 0.41% | — | Samsung Android | 10/8/2026 | 19/8/2026 | Improper input validation in Samsung Dialer prior to SMR Aug-2026 Release 1 allows remote attackers to access SIM related functions. User interaction is required for triggering this vulnerability. | |
| Analizada | Media (6.7) | 0.21% | — | Samsung Android | 10/8/2026 | 19/8/2026 | Improper input validation in Samsung Contacts prior to SMR Aug-2026 Release 1 allows physical attackers to access data across multiple user profiles. | |
| Analizada | Media (6.9) | 0.13% | — | Samsung Android | 10/8/2026 | 19/8/2026 | Improper export of android application components in Samsung Contacts prior to SMR Aug-2026 Release 1 allows local attackers to delete file with Samsung Contacts' privilege. | |
| Analizada | Media (6.9) | 0.14% | — | Samsung Android | 10/8/2026 | 19/8/2026 | Improper input validation in Samsung Contacts prior to SMR Aug-2026 Release 1 allows local attackers to delete file with Samsung Contacts' privilege. |