Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
79 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.8) | 0.28% | — | AudiobookshelfAudiobookshelf Mobile APP | 26/2/2026 | 17/6/2026 | Audiobookshelf is a self-hosted audiobook and podcast server. A stored cross-site scripting (XSS) vulnerability exists in versions prior to 0.12.0-beta of the Audiobookshelf mobile application that allows arbitrary JavaScript execution through malicious library metadata. Attackers with library modification privileges… | |
| Aplazada | Alta (7.1) | 0.18% | — | Nebelhorn Blappsta Mobile APP PluginAI | 31/12/2025 | 23/9/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in nebelhorn Blappsta Mobile App Plugin – Your native, mobile iPhone App and Android App yournewsapp allows Reflected XSS.This issue affects Blappsta Mobile App Plugin – Your native, mobile iPhone App and Android App:… | |
| Aplazada | Alta (7.5) | 0.25% | — | Knowband Mobile APP BuilderAI | 31/12/2025 | 17/6/2026 | The Knowband Mobile App Builder WordPress plugin before 3.0.0 does not have authorisation when deleting users via its REST API, allowing unauthenticated attackers to delete arbitrary users. | |
| Aplazada | Alta (7.5) | 0.31% | — | Menulux Software INC Mobile APPAI | 16/12/2025 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Menulux Software Inc. Mobile App allows Exploitation of Trusted Identifiers. This issue affects Mobile App: before 9.5.8. | |
| Aplazada | Media (5.3) | 0.28% | — | Hippoo Mobile APPAI | 12/12/2025 | 17/6/2026 | The Hippoo Mobile App for WooCommerce plugin for WordPress is vulnerable to arbitrary file write via a missing authorization check in all versions up to, and including, 1.7.1. This is due to the REST API endpoint `/wp-json/hippoo/v1/wc/token/save_callback/{token_id}` being registered with `permission_callback =>… | |
| Aplazada | Alta (7.5) | 2.2% | 💥 Exploit | Hippoo Mobile APP FOR WoocommerceAI | 10/12/2025 | 25/9/2026 | The Hippoo Mobile App for WooCommerce plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.7.1 via the template_redirect() function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive… | |
| Aplazada | Crítica (9.8) | 0.33% | — | Mstoreapp Mobile APPAIMstoreapp Mobile MultivendorAI | 21/11/2025 | 17/6/2026 | The Mstoreapp Mobile App WordPress plugin through 2.08 and Mstoreapp Mobile Multivendor through 9.0.1 do not properly verify users identify when using an AJAX action, allowing unauthenticated users to retrieve a valid session for arbitrary users by knowing their email address. | |
| Aplazada | Alta (7.1) | 0.17% | — | Amauri Wpmobile.appAI | 6/11/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Amauri WPMobile.App wpappninja.This issue affects WPMobile.App: from n/a through <= 11.71. | |
| Aplazada | Baja (0.9) | 0.20% | — | Tomofun Furbo Mobile APPAI | 12/10/2025 | 17/6/2026 | A security vulnerability has been detected in Tomofun Furbo Mobile App up to 7.57.0a on Android. This affects an unknown part of the component Authentication Token Handler. The manipulation leads to insecure storage of sensitive information. It is possible to launch the attack on the physical device. The exploit has… | |
| Aplazada | Media (4.7) | 0.18% | — | Yosmart Yolink HUBAIYosmart Yolink Mobile ApplicationAIYosmart Yolink Mqtt BrokerAI | 6/10/2025 | 17/6/2026 | Components of the YoSmart YoLink ecosystem through 2025-10-02 leverage unencrypted MQTT to communicate over the internet. An attacker with the ability to monitor network traffic could therefore obtain sensitive information or tamper with the traffic to control affected devices. This affects YoLink Hub 0382, YoLink… | |
| Aplazada | Media (6.5) | 0.30% | — | Axis Bank Limited Axis Mobile APPAI | 12/9/2025 | 5/7/2026 | An issue was discovered in AXIS BANK LIMITED Axis Mobile App 9.9 that allows attackers to obtain sensitive information without a UPI PIN, such as account information, balances, transaction history, and unspecified other information. NOTE: the Supplier's perspective is that this is an intended feature and "does not… | |
| Aplazada | Alta (8.8) | 0.36% | — | Touch Lebanon Mobile APPAI | 20/8/2025 | 17/6/2026 | A vulnerability in the password reset workflow of the Touch Lebanon Mobile App 2.20.2 allows an attacker to bypass the OTP reset password mechanism. By manipulating the reset process, an unauthorized user may be able to reset the password and gain access to the account without needing to provide a legitimate… | |
| Aplazada | Crítica (9.8) | 2.1% | — | Gardyn Home KIT FirmwareAIGardyn Home KIT Mobile ApplicationAIGardyn Home KIT Cloud APIAI | 25/7/2025 | 17/6/2026 | Gardyn Home Kit firmware before master.619, Home Kit Mobile Application before 2.11.0, and Home Kit Cloud API before 2.12.2026 allow command injection through vulnerable methods that do not sanitize input before passing content to the operating system for execution. The vulnerability may allow an attacker to execute… | |
| Aplazada | Crítica (9.1) | 0.49% | — | Gardyn Home KIT FirmwareAIGardyn Home KIT Mobile ApplicationAIGardyn Home KIT Cloud APIAI | 25/7/2025 | 17/6/2026 | Gardyn Home Kit firmware before master.619, Home Kit Mobile Application before 2.11.0, and Home Kit Cloud API before 2.12.2026 use weak default credentials for secure shell access. This may result in attackers gaining access to exposed Gardyn Home Kits. | |
| Aplazada | Crítica (9.4) | 0.28% | 💥 PoC | Gardyn Home KIT FirmwareAIGardyn Home KIT Mobile ApplicationAIGardyn Home KIT Cloud APIAI | 25/7/2025 | 17/6/2026 | A Gardyn Azure IoT Hub connection string is downloaded over an insecure HTTP connection in Gardyn Home Kit firmware before master.619, Home Kit Mobile Application before 2.11.0, and Home Kit Cloud API before 2.12.2026 leaving the string vulnerable to interception and modification through a Man-in-the-Middle attack.… | |
| Aplazada | Crítica (10) | 0.32% | — | Ataturk University Ata-aof Mobile ApplicationAI | 24/6/2025 | 17/6/2026 | Cleartext Transmission of Sensitive Information, Use of Hard-coded Credentials vulnerability in Ataturk University ATA-AOF Mobile Application allows Authentication Abuse, Authentication Bypass. This issue affects ATA-AOF Mobile Application: before 20.06.2025. | |
| Aplazada | Alta (7.1) | 0.29% | — | Weptile Mobile APP FOR WoocommerceAI | 17/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in weptile Mobile App for WooCommerce mobile-app-for-woocommerce allows Stored XSS.This issue affects Mobile App for WooCommerce: from n/a through <= 0.4.61. | |
| Aplazada | Media (5.4) | 0.45% | — | Pietro Mobile APP CanvasAI | 1/4/2025 | 17/6/2026 | Missing Authorization vulnerability in pietro Mobile App Canvas mobile-app allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Mobile App Canvas: from n/a through <= 3.8.2. | |
| Aplazada | Media (6.9) | 0.43% | — | Iroad X5 Mobile APPAI | 16/3/2025 | 17/6/2026 | A vulnerability classified as critical has been found in IROAD X5 Mobile App up to 5.2.5 on Android. Affected is an unknown function of the component API Endpoint. The manipulation leads to hard-coded credentials. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be… | |
| Analizada | Media (6.1) | 0.76% | 💥 Exploit | Amauri Wpmobile.app | 20/2/2025 | 17/6/2026 | The WPMobile.App plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 11.56. This is due to insufficient validation on the redirect URL supplied via the 'redirect' parameter. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if… | |
| Aplazada | Alta (8.5) | 0.37% | — | PTT INC HGS Mobile APPAI | 14/2/2025 | 17/6/2026 | Exposed Dangerous Method or Function vulnerability in PTT Inc. HGS Mobile App allows Manipulating User-Controlled Variables. This issue affects HGS Mobile App: before 6.5.0. | |
| Aplazada | Media (6.5) | 0.38% | — | Wpmobile APPAI | 13/12/2024 | 17/6/2026 | The The WPMobile.App — Android and iOS Mobile Application plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 11.52. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it… | |
| Modificada | Alta (7.5) | 0.45% | — | Stacksmarket Stacks Mobile APP Builder | 4/11/2024 | 17/6/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Stacks Stacks Mobile App Builder stacks-mobile-app-builder allows Retrieve Embedded Sensitive Data.This issue affects Stacks Mobile App Builder: from n/a through <= 5.2.3. | |
| Modificada | Crítica (9.8) | 0.51% | — | Stacksmarket Stacks Mobile APP Builder | 4/11/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Stacks Stacks Mobile App Builder stacks-mobile-app-builder allows Upload a Web Shell to a Web Server.This issue affects Stacks Mobile App Builder: from n/a through <= 5.2.3. | |
| Aplazada | Media (4.3) | 0.28% | — | Amauri Wpmobile.appAI | 31/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Amauri WPMobile.App wpappninja allows Stored XSS.This issue affects WPMobile.App: from n/a through <= 11.48. |