Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
1742 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 0.68% | — | Mdjm Mobile DJ ManagerAI | 1/4/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in MDJM Mobile DJ Manager mobile-dj-manager allows Object Injection.This issue affects Mobile DJ Manager: from n/a through <= 1.7.5.2. | |
| Analizada | Crítica (9.8) | 0.47% | — | Opensecurity Mobile Security Framework | 31/3/2025 | 17/6/2026 | Mobile Security Framework (MobSF) is a pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis. The mitigation for CVE-2024-29190 in valid_host() uses socket.gethostbyname(), which is vulnerable to SSRF abuse using DNS rebinding technique. This vulnerability is… | |
| Aplazada | Media (6.3) | 0.14% | — | Watchguard Mobile VPN With SSL ClientAI | 28/3/2025 | 8/8/2026 | The WatchGuard Mobile VPN with SSL Client on Windows does not properly configure directory permissions when installed in a non-default directory. This could allow an authenticated local attacker to escalate to SYSTEM privileges on a vulnerable system. | |
| Aplazada | Media (4.3) | 0.42% | — | Jose Mortellaro Specific Content FOR MobileAI | 27/3/2025 | 17/6/2026 | Missing Authorization vulnerability in Jose Mortellaro Specific Content For Mobile specific-content-for-mobile allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Specific Content For Mobile: from n/a through <= 0.5.3. | |
| Aplazada | Media (5.1) | 0.52% | — | SambaAIChinamobile P22g-ciacAI | 24/3/2025 | 17/6/2026 | A vulnerability classified as problematic was found in China Mobile P22g-CIac 1.0.00.488. This vulnerability affects unknown code of the component Samba Path Handler. The manipulation leads to path traversal. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor… | |
| Analizada | Media (6.5) | 0.38% | — | Mattermost Mobile | 24/3/2025 | 17/6/2026 | Mattermost Mobile Apps versions <=2.25.0 fail to properly validate GIF images prior to rendering which allows a malicious user to cause the Android application to crash via message containing a maliciously crafted GIF. | |
| Aplazada | Media (5.9) | 0.35% | — | Jenst Mobile NavigationAI | 24/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jenst Mobile Navigation mobile-navigation allows Stored XSS.This issue affects Mobile Navigation: from n/a through <= 1.5. | |
| Aplazada | Alta (8.6) | 0.58% | — | Chinamobile P22g-ciacAIChinamobile Zxwt-mig-p4g4vAIChinamobile Zxwt-mig-p8g8vAIChinamobile Gt3200-4g4pAI+1 | 17/3/2025 | 17/6/2026 | A vulnerability was found in China Mobile P22g-CIac, ZXWT-MIG-P4G4V, ZXWT-MIG-P8G8V, GT3200-4G4P and GT3200-8G8P up to 20250305. It has been rated as critical. This issue affects some unknown processing of the component CLI su Command Handler. The manipulation leads to use of default credentials. The attack may be… | |
| Aplazada | Media (4.8) | 0.24% | — | Chinamobile P22g-ciacAIChinamobile Zxwt-mig-p4g4vAIChinamobile Zxwt-mig-p8g8vAIChinamobile Gt3200-4g4pAI+1 | 17/3/2025 | 17/6/2026 | A vulnerability was found in China Mobile P22g-CIac, ZXWT-MIG-P4G4V, ZXWT-MIG-P8G8V, GT3200-4G4P and GT3200-8G8P up to 20250305. It has been declared as problematic. This vulnerability affects unknown code of the component Telnet Service. The manipulation leads to improper authorization. The attack can only be… | |
| Aplazada | Media (6.9) | 0.43% | — | Iroad X5 Mobile APPAI | 16/3/2025 | 17/6/2026 | A vulnerability classified as critical has been found in IROAD X5 Mobile App up to 5.2.5 on Android. Affected is an unknown function of the component API Endpoint. The manipulation leads to hard-coded credentials. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be… | |
| Aplazada | Media (4.3) | 0.17% | — | Mg12 Mobile ThemesAI | 11/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in mg12 Mobile Themes wp-mobile-themes allows Cross Site Request Forgery.This issue affects Mobile Themes: from n/a through <= 1.1.1. | |
| Aplazada | Alta (7.1) | 0.39% | — | Muneeb Mobile Rocket-wp-mobileAI | 3/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Muneeb Mobile rocket-wp-mobile allows Reflected XSS.This issue affects Mobile: from n/a through <= 1.3.3. | |
| Analizada | Alta (7.8) | 0.12% | — | Qualcomm Ar8035 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Qam8255p Firmware+99 | 3/3/2025 | 17/6/2026 | Memory corruption may occur while accessing a variable during extended back to back tests. | |
| Analizada | Alta (7.9) | 0.12% | — | Qualcomm Snapdragon 8+ GEN 1 Mobile Platform FirmwareQualcomm Snapdragon 8+ GEN 2 Mobile Platform FirmwareQualcomm Snapdragon AR1 GEN 1 Platform "luna1" FirmwareQualcomm Fastconnect 6700 Firmware+79 | 3/3/2025 | 17/6/2026 | Information disclosure may occur due to improper permission and access controls to Video Analytics engine. | |
| Analizada | Media (5.3) | 0.27% | — | Qualcomm 315 5G IOT FirmwareQualcomm 9205 LTE FirmwareQualcomm Ar8035 FirmwareQualcomm Csra6620 Firmware+160 | 3/3/2025 | 17/6/2026 | While processing the authentication message in UE, improper authentication may lead to information disclosure. | |
| Analizada | Baja (2.4) | 0.20% | — | IBM Cognos Analytics Mobile | 2/3/2025 | 17/6/2026 | IBM Cognos Analytics Mobile 1.1 for Android could allow a user with physical access to the device, to obtain sensitive information from debugging code log messages. | |
| Analizada | Media (5.3) | 0.27% | — | IBM Cognos Analytics Mobile | 2/3/2025 | 17/6/2026 | IBM Cognos Analytics Mobile 1.1 for iOS application could allow an attacker to reverse engineer the codebase to gain knowledge about the programming technique, interface, class definitions, algorithms and functions used due to weak obfuscation. | |
| Analizada | Media (6.1) | 0.76% | 💥 Exploit | Amauri Wpmobile.app | 20/2/2025 | 17/6/2026 | The WPMobile.App plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 11.56. This is due to insufficient validation on the redirect URL supplied via the 'redirect' parameter. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if… | |
| Aplazada | Alta (8.5) | 0.37% | — | PTT INC HGS Mobile APPAI | 14/2/2025 | 17/6/2026 | Exposed Dangerous Method or Function vulnerability in PTT Inc. HGS Mobile App allows Manipulating User-Controlled Variables. This issue affects HGS Mobile App: before 6.5.0. | |
| Analizada | Alta (8.5) | 0.36% | — | Opensecurity Mobile Security Framework | 5/2/2025 | 17/6/2026 | Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework. A local user with minimal privileges is able to make use of an access token for materials for scopes which it should not be accepted. This issue has… | |
| Analizada | Media (4.8) | 0.46% | — | Opensecurity Mobile Security Framework | 5/2/2025 | 17/6/2026 | Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework. According to Apple's documentation for bundle ID's, it must contain only alphanumeric characters (A–Z, a–z, and 0–9), hyphens (-), and periods (.).… | |
| Analizada | Alta (8.4) | 0.39% | — | Opensecurity Mobile Security Framework | 5/2/2025 | 17/6/2026 | Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework. According to Apple's documentation for bundle ID's, it must contain only alphanumeric characters (A–Z, a–z, and 0–9), hyphens (-), and periods (.).… | |
| Aplazada | Alta (7.3) | 0.32% | — | Prolink 4G LTE Mobile Wi-fi Dl-7203eAI | 3/2/2025 | 17/6/2026 | Prolink 4G LTE Mobile Wi-Fi DL-7203E V4.0.0B05 is vulnerable to SQL Injection in in the /reqproc/proc_get endpoint. The vulnerability allows an attacker to manipulate SQL queries by injecting malicious SQL code into the order_by parameter. | |
| Aplazada | Media (6.3) | 0.28% | — | Prolink 4G LTE Mobile Wi-fi Dl-7203eAI | 3/2/2025 | 17/6/2026 | Prolink 4G LTE Mobile Wi-Fi DL-7203E V4.0.0B05 is vulnerable to Cross Site Scripting (XSS) in the /reqproc/proc_get endpoint. The vulnerability arises because the cmd parameter does not properly sanitize input and the response is served with a Content-Type of text/html. This behavior allows the browser to execute… | |
| Analizada | Alta (7.8) | 0.11% | — | Qualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Qca6391 FirmwareQualcomm Qcm6125 Firmware+48 | 3/2/2025 | 17/6/2026 | Memory corruption while processing IOCTL from user space to handle GPU AHB bus error. |