Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
1742 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.3) | 0.36% | — | Mattermost Mobile | 16/1/2025 | 17/6/2026 | Mattermost Mobile Apps versions <=2.22.0 fail to properly handle specially crafted attachment names, which allows an attacker to crash the mobile app for any user who opened a channel containing the specially crafted attachment | |
| Analizada | Media (6.5) | 0.52% | — | Mattermost Mobile | 15/1/2025 | 17/6/2026 | Mattermost Mobile Apps versions <=2.22.0 fail to properly validate post props which allows a malicious authenticated user to cause a crash via a malicious post. | |
| Analizada | Media (6.5) | 0.52% | — | Mattermost Mobile | 15/1/2025 | 17/6/2026 | Mattermost Mobile Apps versions <=2.22.0 fail to properly validate post props which allows a malicious authenticated user to cause a crash via a malicious post. | |
| Aplazada | Media (6.1) | 0.45% | — | Opencode Mobile Collect CallAI | 9/1/2025 | 17/6/2026 | A PHP Code Injection vulnerability that can lead to Remote Code Execution (RCE) and XSS in Opencode Mobile Collect Call v5.4.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the op_func parameter at /occontrolpanel/index.php. | |
| Aplazada | Media (6.5) | 0.34% | — | JOE Rhoney Addfunc Mobile DetectAI | 7/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Joe Rhoney AddFunc Mobile Detect addfunc-mobile-detect allows Stored XSS.This issue affects AddFunc Mobile Detect: from n/a through <= 3.1. | |
| Aplazada | Media (6.3) | 0.22% | — | Asianmobile CallcolorAI | 6/1/2025 | 17/6/2026 | The com.asianmobile.callcolor (aka Color Phone Call Screen App) application through 24 for Android enables any application (with no permissions) to place phone calls without user interaction by sending a crafted intent via the com.asianmobile.callcolor.ui.component.call.CallActivity component. | |
| Analizada | Alta (7.5) | 0.36% | — | Qualcomm Ar8035 FirmwareQualcomm Csr8811 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 Firmware+179 | 6/1/2025 | 17/6/2026 | Transient DOS can occur when the driver parses the per STA profile IE and tries to access the EXTN element ID without checking the IE length. | |
| Analizada | Alta (7.8) | 0.13% | — | Qualcomm Ar8035 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 Firmware+124 | 6/1/2025 | 17/6/2026 | Memory corruption can occur when process-specific maps are added to the global list. If a map is removed from the global list while another thread is using it for a process-specific task, issues may arise. | |
| Analizada | Media (4.7) | 0.09% | — | Qualcomm Qam8255p FirmwareQualcomm Qam8295p FirmwareQualcomm Qam8620p FirmwareQualcomm Qam8650p Firmware+26 | 6/1/2025 | 17/6/2026 | Uncontrolled resource consumption when a driver, an application or a SMMU client tries to access the global registers through SMMU. | |
| Analizada | Media (5.5) | 0.10% | — | Qualcomm Ar8035 FirmwareQualcomm C-v2x 9150 FirmwareQualcomm Csrb31024 FirmwareQualcomm Fastconnect 6800 Firmware+73 | 6/1/2025 | 17/6/2026 | Information disclosure while invoking callback function of sound model driver from ADSP for every valid opcode received from sound model driver. | |
| Analizada | Alta (7.8) | 0.13% | — | Qualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Qcm8550 FirmwareQualcomm Qcs8550 Firmware+12 | 6/1/2025 | 17/6/2026 | Memory corruption while processing frame command IOCTL calls. | |
| Analizada | Alta (7.8) | 0.10% | — | Qualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Qam8295p FirmwareQualcomm Qca6574au Firmware+35 | 6/1/2025 | 17/6/2026 | Memory corruption while invoking IOCTL calls to unmap the DMA buffers. | |
| Analizada | Alta (7.8) | 0.13% | — | Qualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Qam8295p FirmwareQualcomm Qca6574au Firmware+31 | 6/1/2025 | 17/6/2026 | Memory corruption when input parameter validation for number of fences is missing for fence frame IOCTL calls, | |
| Analizada | Alta (7.8) | 0.15% | — | Qualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Qcm4490 Firmware+17 | 6/1/2025 | 17/6/2026 | Memory corruption while processing IPA statistics, when there are no active clients registered. | |
| Aplazada | Media (4.3) | 0.18% | — | Freshlightlab WP Mobile MenuAI | 2/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Rui Guerreiro WP Mobile Menu mobile-menu allows Cross Site Request Forgery.This issue affects WP Mobile Menu: from n/a through <= 2.8.4.3. | |
| Aplazada | Media (5.4) | 0.32% | — | Vowelweb VW Automobile LiteAI | 31/12/2024 | 17/6/2026 | Missing Authorization vulnerability in vowelweb VW Automobile Lite vw-automobile-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects VW Automobile Lite: from n/a through <= 2.1. | |
| Analizada | Alta (7.5) | 0.33% | — | IBM Cognos Analytics Mobile | 19/12/2024 | 17/6/2026 | IBM Cognos Analytics Mobile for Android 1.1.14 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. | |
| Analizada | Media (6.1) | 0.29% | — | Ampforwp Accelerated Mobile Pages | 18/12/2024 | 17/6/2026 | The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the disqus_name parameter in all versions up to, and including, 1.1.1 due to insufficient input validation. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages… | |
| Analizada | Media (5.5) | 0.12% | — | Mattermost Mobile | 16/12/2024 | 17/6/2026 | Mattermost Android Mobile Apps versions <=2.21.0 fail to properly configure file providers which allows an attacker with local access to access files via file provider. | |
| Aplazada | Crítica (9.8) | 0.75% | — | Fluxbuilder Listapp Mobile ManagerAI | 13/12/2024 | 17/6/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in FluxBuilder ListApp Mobile Manager listapp-mobile-manager allows Authentication Bypass.This issue affects ListApp Mobile Manager: from n/a through <= 1.7.7. | |
| Aplazada | Media (5.4) | 0.60% | — | Mobilemonkey Wp-chatbot FOR MessengerAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in MobileMonkey WP-Chatbot for Messenger allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP-Chatbot for Messenger: from n/a through 4.7. | |
| Aplazada | Media (6.5) | 0.38% | — | Wpmobile APPAI | 13/12/2024 | 17/6/2026 | The The WPMobile.App — Android and iOS Mobile Application plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 11.52. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it… | |
| Aplazada | Alta (8.2) | 0.36% | — | Gricemobile Com.grice.callAI | 4/12/2024 | 17/6/2026 | The GriceMobile com.grice.call application 4.5.2 for Android enables any installed application (with no permissions) to place phone calls without user interaction by sending a crafted intent via the com.iui.mobile.presentation.MobileActivity. | |
| Analizada | Alta (7.5) | 0.41% | — | Opensecurity Mobile Security Framework | 3/12/2024 | 17/6/2026 | Mobile Security Framework (MobSF) is a pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis. In versions prior to 3.9.7, the requests.get() request in the _check_url method is specified as allow_redirects=True, which allows a server-side request forgery when… | |
| Analizada | Media (5.4) | 0.52% | — | Opensecurity Mobile Security Framework | 3/12/2024 | 17/6/2026 | Mobile Security Framework (MobSF) is a pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis. The application allows users to upload files with scripts in the filename parameter. As a result, a malicious user can upload a script file to the system. When users… |