Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
–

79 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)8.1%💥 ExploitStacksmarket Stacks Mobile APP Builder28/10/202417/6/2026
Authentication Bypass Using an Alternate Path or Channel vulnerability in Stacks Stacks Mobile App Builder stacks-mobile-app-builder allows Authentication Bypass.This issue affects Stacks Mobile App Builder: from n/a through <= 5.2.3.
AplazadaAlta (7.1)0.32%—Amauri Wpmobile.appAI6/10/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Amauri WPMobile.App wpappninja.This issue affects WPMobile.App: from n/a through <= 11.50.
AplazadaAlta (7.1)0.35%—Appmaker - Convert Woocommerce TO Android & IOS Native Mobile AppsAI20/7/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Appmaker Appmaker – Convert WooCommerce to Android & iOS Native Mobile Apps allows Reflected XSS.This issue affects Appmaker – Convert WooCommerce to Android & iOS Native Mobile Apps: from n/a through 1.36.12.
AplazadaMedia (6.2)0.17%—HP Advance Mobile ApplicationsAIApple IOSAIGoogle AndroidAI12/6/202417/6/2026
HP Advance Mobile Applications for iOS and Android are potentially vulnerable to information disclosure when using an outdated version of the application via mobile devices.
ModificadaMedia (6.1)0.66%💥 ExploitAmauri Wpmobile.app8/6/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Amauri WPMobile.App wpappninja.This issue affects WPMobile.App: from n/a through <= 11.41.
AnalizadaMedia (5.5)0.61%—Microsoft Intune Mobile Application Management14/5/202417/6/2026
Microsoft Intune for Android Mobile Application Management Tampering Vulnerability
ModificadaMedia (4.8)0.37%—Amauri Wpmobile.app10/5/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WPMobile.App WPMobile.App — Android and iOS Mobile Application plugin <= 11.20 versions.
ModificadaMedia (4.8)0.37%—Amauri Wpmobile.app4/5/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WPMobile.App plugin <= 11.18 versions.
ModificadaMedia (5.4)0.38%—Amauri Wpmobile.app23/3/202317/6/2026
Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in WPMobile.App WPMobile.App — Android and iOS Mobile Application plugin <= 11.13 versions.
ModificadaAlta (7.2)0.44%—Amodat Mobile Application Gateway13/6/202217/6/2026
attacker needs to craft a SQL payload. the vulnerable parameter is "agentid" must be authenticated to the admin panel.
ModificadaCrítica (9.8)0.45%—Amodat Mobile Application Gateway13/6/202217/6/2026
The attacker could get access to the database. The SQL injection is in the username parameter at the login panel: username: admin'--
ModificadaMedia (6.1)1.0%—Keycloak Gatekeeper Project Keycloak GatekeeperRedhat Mobile Application Platform28/1/202117/6/2026
A flaw was found in Keycloak Gatekeeper (Louketo). The logout endpoint can be abused to redirect logged-in users to arbitrary web pages. Affected versions of Keycloak Gatekeeper (Louketo): 6.0.1, 7.0.0
ModificadaCrítica (9.8)8.9%💥 ExploitThemerex AddonsThemerex Ozeum-museumThemerex Chit Club-board GamesThemerex Yottis-simple Portfolio+5910/3/202017/6/2026
The ThemeREX Addons plugin before 2020-03-09 for WordPress lacks access control on the /trx_addons/v2/get/sc_layout REST API endpoint, allowing for PHP functions to be executed by any users, because includes/plugin.rest-api.php calls trx_addons_rest_get_sc_layout with an unsafe sc parameter.
ModificadaMedia (6.5)1.0%—Jenkins Data Theorem Mobile APP Security25/9/201917/6/2026
Jenkins Data Theorem: CI/CD Plugin 1.3 and earlier stored credentials unencrypted in job config.xml files on the Jenkins master where they could be viewed by users with Extended Read permission, or access to the master file system.
ModificadaMedia (6.1)87%💥 ExploitJqueryDebian LinuxDrupalBackdropcms Backdrop+10120/4/201917/6/2026
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype.
ModificadaAlta (7.8)0.29%—Intel Remote Keyboard Mobile APP3/4/201817/6/2026
Escalation of privilege in all versions of the Intel Remote Keyboard allows a local attacker to inject keystrokes into another remote keyboard session.
ModificadaCrítica (9.8)1.1%—Intel Remote Keyboard Mobile APP3/4/201817/6/2026
Escalation of privilege in all versions of the Intel Remote Keyboard allows a network attacker to inject keystrokes as a local user.
ModificadaAlta (7.8)0.37%—Intel Remote Keyboard Mobile APP3/4/201817/6/2026
Escalation of privilege in all versions of the Intel Remote Keyboard allows an authorized local attacker to execute arbitrary code as a privileged user.
ModificadaMedia (6.1)0.93%—Redhat Mobile Application Platform29/9/201717/6/2026
It was found that the App Studio component of RHMAP 4.4 executes javascript provided by a user. An attacker could use this flaw to execute a stored XSS attack on an application administrator using App Studio.
ModificadaMedia (6.3)0.70%—Redhat Mobile Application Platform29/9/201717/6/2026
The external_request api call in App Studio (millicore) allows server side request forgery (SSRF). An attacker could use this flaw to probe the network internal resources, and access restricted endpoints.
ModificadaCrítica (9.8)1.4%—Redhat Mobile Application Platform29/9/201717/6/2026
A flaw was discovered in the file editor of millicore, affecting versions before 3.19.0 and 4.x before 4.5.0, which allows files to be executed as well as created. An attacker could use this flaw to compromise other users or teams projects stored in source control management of the RHMAP Core installation.
ModificadaMedia (6.5)0.89%—Redhat Feedhenry Enterprise Mobile Application Platform20/9/201717/6/2026
Reflected file download vulnerability in Red Hat Feedhenry Enterprise Mobile Application Platform.
ModificadaCrítica (9.8)11%💥 ExploitMobile-app-builder-by-wappress Project Mobile-app-builder-by-wappress14/9/201717/6/2026
Vulnerability in wordpress plugin mobile-app-builder-by-wappress v1.05, The plugin includes unlicensed vulnerable CMS software from http://www.invedion.com.
ModificadaAlta (7.5)7.3%💥 ExploitZEN Mobile APP Native Project ZEN Mobile APP Native2/3/201717/6/2026
Remote file upload vulnerability in Wordpress Plugin Mobile App Native 3.0.
ModificadaMedia (4.3)1.4%—IBM Security Access Manager FOR Mobile 8.0 FirmwareIBM Security Access Manager FOR Mobile ApplianceIBM Security Access Manager FOR WEB 7.0 FirmwareIBM Security Access Manager FOR WEB Appliance+13/10/201417/6/2026
Cross-site scripting (XSS) vulnerability in the Local Management Interface in IBM Security Access Manager for Web 7.x before 7.0.0-ISS-WGA-IF0009 and 8.x before 8.0.0-ISS-WGA-FP0005, and Security Access Manager for Mobile 8.x before 8.0.0-ISS-ISAM-FP0005, allows remote attackers to inject arbitrary web script or HTML…
Orbitaley — Vulnerabilidades