Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
79 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 8.1% | 💥 Exploit | Stacksmarket Stacks Mobile APP Builder | 28/10/2024 | 17/6/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Stacks Stacks Mobile App Builder stacks-mobile-app-builder allows Authentication Bypass.This issue affects Stacks Mobile App Builder: from n/a through <= 5.2.3. | |
| Aplazada | Alta (7.1) | 0.32% | — | Amauri Wpmobile.appAI | 6/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Amauri WPMobile.App wpappninja.This issue affects WPMobile.App: from n/a through <= 11.50. | |
| Aplazada | Alta (7.1) | 0.35% | — | Appmaker - Convert Woocommerce TO Android & IOS Native Mobile AppsAI | 20/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Appmaker Appmaker – Convert WooCommerce to Android & iOS Native Mobile Apps allows Reflected XSS.This issue affects Appmaker – Convert WooCommerce to Android & iOS Native Mobile Apps: from n/a through 1.36.12. | |
| Aplazada | Media (6.2) | 0.17% | — | HP Advance Mobile ApplicationsAIApple IOSAIGoogle AndroidAI | 12/6/2024 | 17/6/2026 | HP Advance Mobile Applications for iOS and Android are potentially vulnerable to information disclosure when using an outdated version of the application via mobile devices. | |
| Modificada | Media (6.1) | 0.66% | 💥 Exploit | Amauri Wpmobile.app | 8/6/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Amauri WPMobile.App wpappninja.This issue affects WPMobile.App: from n/a through <= 11.41. | |
| Analizada | Media (5.5) | 0.61% | — | Microsoft Intune Mobile Application Management | 14/5/2024 | 17/6/2026 | Microsoft Intune for Android Mobile Application Management Tampering Vulnerability | |
| Modificada | Media (4.8) | 0.37% | — | Amauri Wpmobile.app | 10/5/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WPMobile.App WPMobile.App — Android and iOS Mobile Application plugin <= 11.20 versions. | |
| Modificada | Media (4.8) | 0.37% | — | Amauri Wpmobile.app | 4/5/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WPMobile.App plugin <= 11.18 versions. | |
| Modificada | Media (5.4) | 0.38% | — | Amauri Wpmobile.app | 23/3/2023 | 17/6/2026 | Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in WPMobile.App WPMobile.App — Android and iOS Mobile Application plugin <= 11.13 versions. | |
| Modificada | Alta (7.2) | 0.44% | — | Amodat Mobile Application Gateway | 13/6/2022 | 17/6/2026 | attacker needs to craft a SQL payload. the vulnerable parameter is "agentid" must be authenticated to the admin panel. | |
| Modificada | Crítica (9.8) | 0.45% | — | Amodat Mobile Application Gateway | 13/6/2022 | 17/6/2026 | The attacker could get access to the database. The SQL injection is in the username parameter at the login panel: username: admin'-- | |
| Modificada | Media (6.1) | 1.0% | — | Keycloak Gatekeeper Project Keycloak GatekeeperRedhat Mobile Application Platform | 28/1/2021 | 17/6/2026 | A flaw was found in Keycloak Gatekeeper (Louketo). The logout endpoint can be abused to redirect logged-in users to arbitrary web pages. Affected versions of Keycloak Gatekeeper (Louketo): 6.0.1, 7.0.0 | |
| Modificada | Crítica (9.8) | 8.9% | 💥 Exploit | Themerex AddonsThemerex Ozeum-museumThemerex Chit Club-board GamesThemerex Yottis-simple Portfolio+59 | 10/3/2020 | 17/6/2026 | The ThemeREX Addons plugin before 2020-03-09 for WordPress lacks access control on the /trx_addons/v2/get/sc_layout REST API endpoint, allowing for PHP functions to be executed by any users, because includes/plugin.rest-api.php calls trx_addons_rest_get_sc_layout with an unsafe sc parameter. | |
| Modificada | Media (6.5) | 1.0% | — | Jenkins Data Theorem Mobile APP Security | 25/9/2019 | 17/6/2026 | Jenkins Data Theorem: CI/CD Plugin 1.3 and earlier stored credentials unencrypted in job config.xml files on the Jenkins master where they could be viewed by users with Extended Read permission, or access to the master file system. | |
| Modificada | Media (6.1) | 87% | 💥 Exploit | JqueryDebian LinuxDrupalBackdropcms Backdrop+101 | 20/4/2019 | 17/6/2026 | jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype. | |
| Modificada | Alta (7.8) | 0.29% | — | Intel Remote Keyboard Mobile APP | 3/4/2018 | 17/6/2026 | Escalation of privilege in all versions of the Intel Remote Keyboard allows a local attacker to inject keystrokes into another remote keyboard session. | |
| Modificada | Crítica (9.8) | 1.1% | — | Intel Remote Keyboard Mobile APP | 3/4/2018 | 17/6/2026 | Escalation of privilege in all versions of the Intel Remote Keyboard allows a network attacker to inject keystrokes as a local user. | |
| Modificada | Alta (7.8) | 0.37% | — | Intel Remote Keyboard Mobile APP | 3/4/2018 | 17/6/2026 | Escalation of privilege in all versions of the Intel Remote Keyboard allows an authorized local attacker to execute arbitrary code as a privileged user. | |
| Modificada | Media (6.1) | 0.93% | — | Redhat Mobile Application Platform | 29/9/2017 | 17/6/2026 | It was found that the App Studio component of RHMAP 4.4 executes javascript provided by a user. An attacker could use this flaw to execute a stored XSS attack on an application administrator using App Studio. | |
| Modificada | Media (6.3) | 0.70% | — | Redhat Mobile Application Platform | 29/9/2017 | 17/6/2026 | The external_request api call in App Studio (millicore) allows server side request forgery (SSRF). An attacker could use this flaw to probe the network internal resources, and access restricted endpoints. | |
| Modificada | Crítica (9.8) | 1.4% | — | Redhat Mobile Application Platform | 29/9/2017 | 17/6/2026 | A flaw was discovered in the file editor of millicore, affecting versions before 3.19.0 and 4.x before 4.5.0, which allows files to be executed as well as created. An attacker could use this flaw to compromise other users or teams projects stored in source control management of the RHMAP Core installation. | |
| Modificada | Media (6.5) | 0.89% | — | Redhat Feedhenry Enterprise Mobile Application Platform | 20/9/2017 | 17/6/2026 | Reflected file download vulnerability in Red Hat Feedhenry Enterprise Mobile Application Platform. | |
| Modificada | Crítica (9.8) | 11% | 💥 Exploit | Mobile-app-builder-by-wappress Project Mobile-app-builder-by-wappress | 14/9/2017 | 17/6/2026 | Vulnerability in wordpress plugin mobile-app-builder-by-wappress v1.05, The plugin includes unlicensed vulnerable CMS software from http://www.invedion.com. | |
| Modificada | Alta (7.5) | 7.3% | 💥 Exploit | ZEN Mobile APP Native Project ZEN Mobile APP Native | 2/3/2017 | 17/6/2026 | Remote file upload vulnerability in Wordpress Plugin Mobile App Native 3.0. | |
| Modificada | Media (4.3) | 1.4% | — | IBM Security Access Manager FOR Mobile 8.0 FirmwareIBM Security Access Manager FOR Mobile ApplianceIBM Security Access Manager FOR WEB 7.0 FirmwareIBM Security Access Manager FOR WEB Appliance+1 | 3/10/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Local Management Interface in IBM Security Access Manager for Web 7.x before 7.0.0-ISS-WGA-IF0009 and 8.x before 8.0.0-ISS-WGA-FP0005, and Security Access Manager for Mobile 8.x before 8.0.0-ISS-ISAM-FP0005, allows remote attackers to inject arbitrary web script or HTML… |