Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

1742 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (4.3)0.36%—Mattermost Mobile16/1/202517/6/2026
Mattermost Mobile Apps versions <=2.22.0 fail to properly handle specially crafted attachment names, which allows an attacker to crash the mobile app for any user who opened a channel containing the specially crafted attachment
AnalizadaMedia (6.5)0.52%—Mattermost Mobile15/1/202517/6/2026
Mattermost Mobile Apps versions <=2.22.0 fail to properly validate post props which allows a malicious authenticated user to cause a crash via a malicious post.
AnalizadaMedia (6.5)0.52%—Mattermost Mobile15/1/202517/6/2026
Mattermost Mobile Apps versions <=2.22.0 fail to properly validate post props which allows a malicious authenticated user to cause a crash via a malicious post.
AplazadaMedia (6.1)0.45%—Opencode Mobile Collect CallAI9/1/202517/6/2026
A PHP Code Injection vulnerability that can lead to Remote Code Execution (RCE) and XSS in Opencode Mobile Collect Call v5.4.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the op_func parameter at /occontrolpanel/index.php.
AplazadaMedia (6.5)0.34%—JOE Rhoney Addfunc Mobile DetectAI7/1/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Joe Rhoney AddFunc Mobile Detect addfunc-mobile-detect allows Stored XSS.This issue affects AddFunc Mobile Detect: from n/a through <= 3.1.
AplazadaMedia (6.3)0.22%—Asianmobile CallcolorAI6/1/202517/6/2026
The com.asianmobile.callcolor (aka Color Phone Call Screen App) application through 24 for Android enables any application (with no permissions) to place phone calls without user interaction by sending a crafted intent via the com.asianmobile.callcolor.ui.component.call.CallActivity component.
AnalizadaAlta (7.5)0.36%—Qualcomm Ar8035 FirmwareQualcomm Csr8811 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 Firmware+1796/1/202517/6/2026
Transient DOS can occur when the driver parses the per STA profile IE and tries to access the EXTN element ID without checking the IE length.
AnalizadaAlta (7.8)0.13%—Qualcomm Ar8035 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 Firmware+1246/1/202517/6/2026
Memory corruption can occur when process-specific maps are added to the global list. If a map is removed from the global list while another thread is using it for a process-specific task, issues may arise.
AnalizadaMedia (4.7)0.09%—Qualcomm Qam8255p FirmwareQualcomm Qam8295p FirmwareQualcomm Qam8620p FirmwareQualcomm Qam8650p Firmware+266/1/202517/6/2026
Uncontrolled resource consumption when a driver, an application or a SMMU client tries to access the global registers through SMMU.
AnalizadaMedia (5.5)0.10%—Qualcomm Ar8035 FirmwareQualcomm C-v2x 9150 FirmwareQualcomm Csrb31024 FirmwareQualcomm Fastconnect 6800 Firmware+736/1/202517/6/2026
Information disclosure while invoking callback function of sound model driver from ADSP for every valid opcode received from sound model driver.
AnalizadaAlta (7.8)0.13%—Qualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Qcm8550 FirmwareQualcomm Qcs8550 Firmware+126/1/202517/6/2026
Memory corruption while processing frame command IOCTL calls.
AnalizadaAlta (7.8)0.10%—Qualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Qam8295p FirmwareQualcomm Qca6574au Firmware+356/1/202517/6/2026
Memory corruption while invoking IOCTL calls to unmap the DMA buffers.
AnalizadaAlta (7.8)0.13%—Qualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Qam8295p FirmwareQualcomm Qca6574au Firmware+316/1/202517/6/2026
Memory corruption when input parameter validation for number of fences is missing for fence frame IOCTL calls,
AnalizadaAlta (7.8)0.15%—Qualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Qcm4490 Firmware+176/1/202517/6/2026
Memory corruption while processing IPA statistics, when there are no active clients registered.
AplazadaMedia (4.3)0.18%—Freshlightlab WP Mobile MenuAI2/1/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Rui Guerreiro WP Mobile Menu mobile-menu allows Cross Site Request Forgery.This issue affects WP Mobile Menu: from n/a through <= 2.8.4.3.
AplazadaMedia (5.4)0.32%—Vowelweb VW Automobile LiteAI31/12/202417/6/2026
Missing Authorization vulnerability in vowelweb VW Automobile Lite vw-automobile-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects VW Automobile Lite: from n/a through <= 2.1.
AnalizadaAlta (7.5)0.33%—IBM Cognos Analytics Mobile19/12/202417/6/2026
IBM Cognos Analytics Mobile for Android 1.1.14 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
AnalizadaMedia (6.1)0.29%—Ampforwp Accelerated Mobile Pages18/12/202417/6/2026
The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the disqus_name parameter in all versions up to, and including, 1.1.1 due to insufficient input validation. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages…
AnalizadaMedia (5.5)0.12%—Mattermost Mobile16/12/202417/6/2026
Mattermost Android Mobile Apps versions <=2.21.0 fail to properly configure file providers which allows an attacker with local access to access files via file provider.
AplazadaCrítica (9.8)0.75%—Fluxbuilder Listapp Mobile ManagerAI13/12/202417/6/2026
Authentication Bypass Using an Alternate Path or Channel vulnerability in FluxBuilder ListApp Mobile Manager listapp-mobile-manager allows Authentication Bypass.This issue affects ListApp Mobile Manager: from n/a through <= 1.7.7.
AplazadaMedia (5.4)0.60%—Mobilemonkey Wp-chatbot FOR MessengerAI13/12/202417/6/2026
Missing Authorization vulnerability in MobileMonkey WP-Chatbot for Messenger allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP-Chatbot for Messenger: from n/a through 4.7.
AplazadaMedia (6.5)0.38%—Wpmobile APPAI13/12/202417/6/2026
The The WPMobile.App — Android and iOS Mobile Application plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 11.52. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it…
AplazadaAlta (8.2)0.36%—Gricemobile Com.grice.callAI4/12/202417/6/2026
The GriceMobile com.grice.call application 4.5.2 for Android enables any installed application (with no permissions) to place phone calls without user interaction by sending a crafted intent via the com.iui.mobile.presentation.MobileActivity.
AnalizadaAlta (7.5)0.41%—Opensecurity Mobile Security Framework3/12/202417/6/2026
Mobile Security Framework (MobSF) is a pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis. In versions prior to 3.9.7, the requests.get() request in the _check_url method is specified as allow_redirects=True, which allows a server-side request forgery when…
AnalizadaMedia (5.4)0.52%—Opensecurity Mobile Security Framework3/12/202417/6/2026
Mobile Security Framework (MobSF) is a pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis. The application allows users to upload files with scripts in the filename parameter. As a result, a malicious user can upload a script file to the system. When users…