Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

1742 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (8.7)0.32%—WNC T-mobile 5G BOX IDU RouterAI16/9/202628/9/2026
WNC T-Mobile 5G Box IDU router contains an authentication bypass vulnerability in the portal.cgi component. The session verification mechanism improperly validates the sessionid cookie by checking for the existence of a corresponding file in /tmp/login_user. An attacker can bypass authentication by using directory…
Pendiente de análisisAlta (8.1)0.37%—Oracle Mobile Application ServerAIOracle E-business SuiteAI15/9/202617/9/2026
Vulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Terminal Server). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Mobile Application…
Pendiente de análisisAlta (7.5)0.24%—Oracle Mobile Application ServerAIOracle E-business SuiteAI15/9/202617/9/2026
Vulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Terminal Server). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the…
Pendiente de análisisCrítica (9.8)0.48%—Oracle Mobile Application ServerAIOracle E-business SuiteAI15/9/202616/9/2026
Vulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Terminal Server). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Mobile Application…
Pendiente de análisisAlta (8.2)0.31%—Oracle Mobile Application ServerAIOracle E-business SuiteAI15/9/202621/9/2026
Vulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Terminal Server). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Mobile Application…
Pendiente de análisisAlta (8.2)0.42%—Oracle Mobile Application ServerAI15/9/202621/9/2026
Vulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Terminal Server). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Mobile Application…
AnalizadaAlta (8.8)0.35%—Mozilla Firefox Mobile15/9/20265/10/2026
Privilege escalation in Firefox for Android. This vulnerability was fixed in Firefox 156.
AplazadaAlta (7.5)0.40%—Mdjm Event ManagementAIMobileeventsmanager Mobile Events ManagerAI13/9/202614/9/2026
The MDJM Event Management WordPress plugin before 1.7.8.5 and the Mobile Events Manager WordPress plugin through 1.4.8.3 do not check a capability, a nonce or the type of the record before permanently deleting the post identified in a request to their playlist entry removal, allowing unauthenticated attackers to…
AnalizadaMedia (5)0.19%—Adobe Photoshop Mobile8/9/20269/9/2026
Photoshop Mobile is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to access unauthorized files or directories outside the intended restrictions.…
AnalizadaAlta (7.4)0.21%—Adobe Photoshop Mobile8/9/20269/9/2026
Photoshop Mobile is affected by a Session Fixation vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain access to sensitive resources. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue requires user interaction in that a…
AnalizadaAlta (8.8)1.0%—Ivanti Endpoint Manager Mobile8/9/20269/9/2026
Missing authorization in Ivanti Endpoint Manager Mobile before version 12.10.0.0, 12.9.0.2, and 12.8.0.4 allows a remote authenticated attacker to escalate their privileges to admin.
AnalizadaMedia (4.3)0.28%—Mozilla Firefox Mobile8/9/20265/10/2026
A malicious webpage could repeatedly trigger external URL schemes, causing system prompts or external application launches. This could make Firefox for iOS temporarily unusable until the page is closed. This vulnerability was fixed in Firefox for iOS 155.1.
ModificadaCrítica (9.8)0.45%—Mozilla Firefox Mobile1/9/20263/9/2026
Other issue in Firefox Focus for Android. This vulnerability was fixed in Firefox 155.
AnalizadaMedia (4.3)0.26%—Mozilla Firefox Mobile1/9/20263/9/2026
Information disclosure in the WebExtensions component in Firefox for Android. This vulnerability was fixed in Firefox 155.
AnalizadaAlta (8.8)0.35%—Mozilla Firefox Mobile1/9/20263/9/2026
Privilege escalation in Firefox for Android. This vulnerability was fixed in Firefox 155.
AnalizadaMedia (5.4)0.26%—Mozilla Firefox Mobile31/8/20263/9/2026
A malicious webpage could stall a popup's cross-origin navigation after commit, causing the address bar to display the destination origin while continuing to render attacker-controlled content. This vulnerability was fixed in Firefox for iOS 155.0.
AplazadaBaja (1.9)1.1%—Alexgladkov Claude-in-mobileAI27/8/202628/8/2026
A security flaw has been discovered in AlexGladkov claude-in-mobile 3.10.2. This affects the function execSync of the file src/adb/client.ts. Performing a manipulation results in os command injection. The attack requires a local approach. The exploit has been released to the public and may be used for attacks.…
AplazadaAlta (8.6)0.36%—Mobile APP FOR WoocommerceAI27/8/202628/8/2026
Unauthenticated Broken Access Control in Mobile App for WooCommerce <= 0.4.62 versions.
AplazadaMedia (4.3)0.15%—Shopapper Mobile APP BuilderAI27/8/202628/8/2026
The Mobile App for WooCommerce: ShopApper Mobile App Builder Service for WooCommerce WordPress plugin through 0.4.62 does not check the user's capabilities before allowing a stock-update operation through one of its REST endpoints, allowing any authenticated user, such as a customer or subscriber, to change the stock…
AplazadaAlta (8.1)0.33%—Classified Listing Mobile Number VerificationAI26/8/202626/8/2026
The Classified Listing - Mobile Number Verification plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.6.0. This is due to missing server-side Firebase OTP validation in the process_otp_login() function. This makes it possible for unauthenticated attackers to…
AnalizadaMedia (6.5)0.35%—Oracle Mobile Application Server18/8/202628/8/2026
Vulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Terminal Server). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Mobile Application…
AnalizadaMedia (6.5)0.27%—Mozilla Firefox Mobile18/8/202625/8/2026
Clickjacking issue in the Downloads component in Firefox for Android. This vulnerability was fixed in Firefox 154.
AnalizadaMedia (5.4)0.25%—Mozilla Firefox Mobile18/8/202625/8/2026
Spoofing issue in the Downloads component in Firefox for Android. This vulnerability was fixed in Firefox 154.
AnalizadaMedia (6.5)0.27%—Mozilla Firefox Mobile18/8/202619/8/2026
Clickjacking issue in Firefox for Android. This vulnerability was fixed in Firefox 154.
AplazadaAlta (7.5)0.39%—Wpmobile APPAI13/8/202614/8/2026
Unauthenticated Broken Access Control in WPMobile.App <= 11.77 versions.