Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
–

9126 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.6)0.39%—Canva Android APPAI4/9/20268/9/2026
The Canva Android App before 2.376.0 allowed an external origin to be loaded in a privileged WebView. A threat actor who controls the page loaded by the user is able to communicate with Canva using the user’s session.
AplazadaAlta (8.7)0.52%—Androidbubbles Keep Backup DailyAI31/8/20268/9/2026
Keep Backup Daily plugin for WordPress before 2.1.4 contains a sensitive information exposure vulnerability that allows unauthenticated attackers to trigger a full MySQL database dump by accessing the publicly exposed `kbd_cron_process` parameter without authentication. Attackers can predict the partially predictable…
AplazadaAlta (7.5)0.39%—Androidbubble WP Sort OrderAI18/8/202620/8/2026
Unauthenticated Broken Access Control in WP Sort Order <= 1.3.5 versions.
AplazadaBaja (1.9)1.2%—Jiantao88 Android-mcp-serverAI17/8/202620/8/2026
A flaw has been found in jiantao88 android-mcp-server up to cfb872b2446794193b58edd63f4dbf6af48a6292. The impacted element is the function child_process.exec of the file build/index.js of the component Command Execution. Executing a manipulation of the argument…
AplazadaCrítica (9.3)0.42%—Mira Android APKAI11/8/20261/9/2026
The distributed Mira Android APK v4.5.15.4 allows an attacker read/write access to reproductive health profiles from internet connected hosts, which could result in forgery, deletion, or destruction of health information.
AplazadaAlta (8.2)0.27%—Mira Android Companion APPAI11/8/20261/9/2026
The Mira Android companion app v4.5.15.4 identifies the paired Mira hormone analyzer by performing a substring match against the BLE advertisement name only, with no cryptographic peripheral authentication, MAC allowlist, or bonded-identity check. An attacker could capture live session token information and inject…
AplazadaMedia (6.9)0.39%—Mira Android APPAI11/8/20261/9/2026
When the Mira Android app opens in-app WebView content (e.g., shop redirect flows), the user's live session token is appended to the URL as a query string parameter, and a persistent user identifier is included in the WebView's User-Agent header. Both are then transmitted to third-party web properties, referrer logs,…
AplazadaMedia (4.4)0.12%—Estonian Information System Authority LibdigidocppAIEstonian Information System Authority Digidoc4AIEstonian Information System Authority Digidoc ON AndroidAIEstonian Information System Authority Digidoc ON IOSAI10/8/20261/9/2026
Improper verification of cryptographic signature and Improper Check for Unusual or Exceptional Conditions vulnerability in Estonian Information System Authority (RIA) libdigidocpp, DigiDoc4, DigiDoc on Android, and DigiDoc on iOS. This issue affects libdigidocpp: from 4.1.0 before 4.2.1; DigiDoc4: from 4.7.0 before…
AplazadaBaja (2.3)0.17%—Ecovacs PRO APPAIApple IOSAIGoogle AndroidAI10/8/202628/8/2026
Android and iOS apps ECOVACS PRO App improperly validate server certificates. Communication may be retrieved and/or altered.
AnalizadaMedia (5.2)0.21%—Samsung Android10/8/202619/8/2026
Improper input validation in Galaxy Themes prior to SMR Aug-2026 Release 1 allows physical attackers to launch arbitrary activity.
AnalizadaMedia (5.1)0.15%—Samsung Android10/8/202619/8/2026
Improper input validation in VC1 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory.
AnalizadaMedia (5.1)0.15%—Samsung Android10/8/202619/8/2026
Improper input validation in MPEG4 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory.
AnalizadaMedia (5.1)0.21%—Samsung Android10/8/202619/8/2026
Improper input validation in Samsung Message prior to SMR Aug-2026 Release 1 allows physical attackers to access sensitive information.
AnalizadaMedia (5.1)0.15%—Samsung Android10/8/202619/8/2026
Incorrect conversion between numeric types in VC1 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory.
AnalizadaAlta (8.4)0.17%—Samsung Android10/8/202619/8/2026
Stack-based buffer overflow in libril_sem.so prior to SMR Aug-2026 Release 1 allows privileged local attackers to execute arbitrary code.
AnalizadaMedia (5.1)0.15%—Samsung Android10/8/202619/8/2026
Improper input validation in libsmsd.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory.
AnalizadaMedia (5.1)0.15%—Samsung Android10/8/202619/8/2026
Improper input validation in libcodec2_sec_flacdec.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory.
AnalizadaMedia (4.8)0.15%—Samsung Android10/8/202619/8/2026
Out-of-bounds write in libcodec2secqcelpdec.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory.
AnalizadaAlta (7)0.12%—Samsung Android10/8/202619/8/2026
Improper access control in Weaver prior to SMR Aug-2026 Release 1 allows local attackers to cause device inoperability.
AnalizadaMedia (6.8)0.20%—Samsung Android10/8/202619/8/2026
Improper export of android application components in AppLock prior to SMR Aug-2026 Release 1 allows physical attackers to bypass app lock function.
AnalizadaMedia (4.8)0.09%—Samsung Android10/8/202619/8/2026
Authorization bypass in SemClipboardService prior to SMR Aug-2026 Release 1 allows local attackers to access clipboard data.
AnalizadaMedia (6)0.41%—Samsung Android10/8/202619/8/2026
Improper input validation in Samsung Dialer prior to SMR Aug-2026 Release 1 allows remote attackers to access SIM related functions. User interaction is required for triggering this vulnerability.
AnalizadaMedia (6.7)0.21%—Samsung Android10/8/202619/8/2026
Improper input validation in Samsung Contacts prior to SMR Aug-2026 Release 1 allows physical attackers to access data across multiple user profiles.
AnalizadaMedia (6.9)0.13%—Samsung Android10/8/202619/8/2026
Improper export of android application components in Samsung Contacts prior to SMR Aug-2026 Release 1 allows local attackers to delete file with Samsung Contacts' privilege.
AnalizadaMedia (6.9)0.14%—Samsung Android10/8/202619/8/2026
Improper input validation in Samsung Contacts prior to SMR Aug-2026 Release 1 allows local attackers to delete file with Samsung Contacts' privilege.