Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
1742 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.7) | 0.32% | — | WNC T-mobile 5G BOX IDU RouterAI | 16/9/2026 | 28/9/2026 | WNC T-Mobile 5G Box IDU router contains an authentication bypass vulnerability in the portal.cgi component. The session verification mechanism improperly validates the sessionid cookie by checking for the existence of a corresponding file in /tmp/login_user. An attacker can bypass authentication by using directory… | |
| Pendiente de análisis | Alta (8.1) | 0.37% | — | Oracle Mobile Application ServerAIOracle E-business SuiteAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Terminal Server). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Mobile Application… | |
| Pendiente de análisis | Alta (7.5) | 0.24% | — | Oracle Mobile Application ServerAIOracle E-business SuiteAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Terminal Server). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the… | |
| Pendiente de análisis | Crítica (9.8) | 0.48% | — | Oracle Mobile Application ServerAIOracle E-business SuiteAI | 15/9/2026 | 16/9/2026 | Vulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Terminal Server). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Mobile Application… | |
| Pendiente de análisis | Alta (8.2) | 0.31% | — | Oracle Mobile Application ServerAIOracle E-business SuiteAI | 15/9/2026 | 21/9/2026 | Vulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Terminal Server). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Mobile Application… | |
| Pendiente de análisis | Alta (8.2) | 0.42% | — | Oracle Mobile Application ServerAI | 15/9/2026 | 21/9/2026 | Vulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Terminal Server). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Mobile Application… | |
| Analizada | Alta (8.8) | 0.35% | — | Mozilla Firefox Mobile | 15/9/2026 | 5/10/2026 | Privilege escalation in Firefox for Android. This vulnerability was fixed in Firefox 156. | |
| Aplazada | Alta (7.5) | 0.40% | — | Mdjm Event ManagementAIMobileeventsmanager Mobile Events ManagerAI | 13/9/2026 | 14/9/2026 | The MDJM Event Management WordPress plugin before 1.7.8.5 and the Mobile Events Manager WordPress plugin through 1.4.8.3 do not check a capability, a nonce or the type of the record before permanently deleting the post identified in a request to their playlist entry removal, allowing unauthenticated attackers to… | |
| Analizada | Media (5) | 0.19% | — | Adobe Photoshop Mobile | 8/9/2026 | 9/9/2026 | Photoshop Mobile is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to access unauthorized files or directories outside the intended restrictions.… | |
| Analizada | Alta (7.4) | 0.21% | — | Adobe Photoshop Mobile | 8/9/2026 | 9/9/2026 | Photoshop Mobile is affected by a Session Fixation vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain access to sensitive resources. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue requires user interaction in that a… | |
| Analizada | Alta (8.8) | 1.0% | — | Ivanti Endpoint Manager Mobile | 8/9/2026 | 9/9/2026 | Missing authorization in Ivanti Endpoint Manager Mobile before version 12.10.0.0, 12.9.0.2, and 12.8.0.4 allows a remote authenticated attacker to escalate their privileges to admin. | |
| Analizada | Media (4.3) | 0.28% | — | Mozilla Firefox Mobile | 8/9/2026 | 5/10/2026 | A malicious webpage could repeatedly trigger external URL schemes, causing system prompts or external application launches. This could make Firefox for iOS temporarily unusable until the page is closed. This vulnerability was fixed in Firefox for iOS 155.1. | |
| Modificada | Crítica (9.8) | 0.45% | — | Mozilla Firefox Mobile | 1/9/2026 | 3/9/2026 | Other issue in Firefox Focus for Android. This vulnerability was fixed in Firefox 155. | |
| Analizada | Media (4.3) | 0.26% | — | Mozilla Firefox Mobile | 1/9/2026 | 3/9/2026 | Information disclosure in the WebExtensions component in Firefox for Android. This vulnerability was fixed in Firefox 155. | |
| Analizada | Alta (8.8) | 0.35% | — | Mozilla Firefox Mobile | 1/9/2026 | 3/9/2026 | Privilege escalation in Firefox for Android. This vulnerability was fixed in Firefox 155. | |
| Analizada | Media (5.4) | 0.26% | — | Mozilla Firefox Mobile | 31/8/2026 | 3/9/2026 | A malicious webpage could stall a popup's cross-origin navigation after commit, causing the address bar to display the destination origin while continuing to render attacker-controlled content. This vulnerability was fixed in Firefox for iOS 155.0. | |
| Aplazada | Baja (1.9) | 1.1% | — | Alexgladkov Claude-in-mobileAI | 27/8/2026 | 28/8/2026 | A security flaw has been discovered in AlexGladkov claude-in-mobile 3.10.2. This affects the function execSync of the file src/adb/client.ts. Performing a manipulation results in os command injection. The attack requires a local approach. The exploit has been released to the public and may be used for attacks.… | |
| Aplazada | Alta (8.6) | 0.36% | — | Mobile APP FOR WoocommerceAI | 27/8/2026 | 28/8/2026 | Unauthenticated Broken Access Control in Mobile App for WooCommerce <= 0.4.62 versions. | |
| Aplazada | Media (4.3) | 0.15% | — | Shopapper Mobile APP BuilderAI | 27/8/2026 | 28/8/2026 | The Mobile App for WooCommerce: ShopApper Mobile App Builder Service for WooCommerce WordPress plugin through 0.4.62 does not check the user's capabilities before allowing a stock-update operation through one of its REST endpoints, allowing any authenticated user, such as a customer or subscriber, to change the stock… | |
| Aplazada | Alta (8.1) | 0.33% | — | Classified Listing Mobile Number VerificationAI | 26/8/2026 | 26/8/2026 | The Classified Listing - Mobile Number Verification plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.6.0. This is due to missing server-side Firebase OTP validation in the process_otp_login() function. This makes it possible for unauthenticated attackers to… | |
| Analizada | Media (6.5) | 0.35% | — | Oracle Mobile Application Server | 18/8/2026 | 28/8/2026 | Vulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Terminal Server). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Mobile Application… | |
| Analizada | Media (6.5) | 0.27% | — | Mozilla Firefox Mobile | 18/8/2026 | 25/8/2026 | Clickjacking issue in the Downloads component in Firefox for Android. This vulnerability was fixed in Firefox 154. | |
| Analizada | Media (5.4) | 0.25% | — | Mozilla Firefox Mobile | 18/8/2026 | 25/8/2026 | Spoofing issue in the Downloads component in Firefox for Android. This vulnerability was fixed in Firefox 154. | |
| Analizada | Media (6.5) | 0.27% | — | Mozilla Firefox Mobile | 18/8/2026 | 19/8/2026 | Clickjacking issue in Firefox for Android. This vulnerability was fixed in Firefox 154. | |
| Aplazada | Alta (7.5) | 0.39% | — | Wpmobile APPAI | 13/8/2026 | 14/8/2026 | Unauthenticated Broken Access Control in WPMobile.App <= 11.77 versions. |