Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2849▼ 221 respecto a la semana anterior
Críticas / altas1332▼ 165 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)222▼ 99 respecto a la semana anterior
–

1742 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)0.89%—Hcltech Bigfix Mobile27/7/202317/6/2026
HCL BigFix Mobile es vulnerable a ataques de inyección de comandos. Un atacante autenticado podría ejecutar comandos shell arbitrarios en el servidor WebUI.
AnalizadaCrítica (9.8)100%⚠ Explotación activa💥 ExploitIvanti Endpoint Manager Mobile25/7/20235/8/2026
Una vulnerabilidad de omisión de autenticación en Ivanti EPMM permite a usuarios no autorizados acceder a funciones o recursos restringidos de la aplicación sin la autenticación adecuada.
ModificadaMedia (6.5)0.22%—Wpmobilepack Wordpress Mobile Pack11/7/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in WPMobilePack.Com WordPress Mobile Pack – Mobile Plugin for Progressive Web Apps & Hybrid Mobile Apps plugin <= 3.4.1 versions.
ModificadaAlta (8.8)1.6%💥 ExploitOzette Simple Mobile URL Redirect10/7/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Ozette Plugins Simple Mobile URL Redirect plugin <= 1.7.2 versions.
ModificadaAlta (8.8)0.32%—Digitalinspiration Google XML Sitemap FOR Mobile10/7/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Amit Agarwal Google XML Sitemap for Mobile plugin <= 1.6.1 versions.
ModificadaCrítica (9.8)1.3%—Stw-mobile-machines Tcg-4 FirmwareStw-mobile-machines Tcg-4lite Firmware29/6/202317/6/2026
STW (aka Sensor-Technik Wiedemann) TCG-4 Connectivity Module DeploymentPackage_v3.03r0-Impala and DeploymentPackage_v3.04r2-Jellyfish and TCG-4lite Connectivity Module DeploymentPackage_v3.04r2-Jellyfish allow an attacker to gain full remote access with root privileges without the need for authentication, giving an…
ModificadaAlta (7.5)1.5%—Trendmicro Mobile Security26/6/202317/6/2026
A remote attacker could leverage a vulnerability in Trend Micro Mobile Security (Enterprise) 9.8 SP5 to download a particular log file which may contain sensitive information regarding the product.
ModificadaAlta (8.8)3.0%—Trendmicro Mobile Security26/6/202317/6/2026
Trend Micro Mobile Security (Enterprise) 9.8 SP5 contains vulnerable .php files that could allow a remote attacker to execute arbitrary code on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. This…
ModificadaAlta (8.8)2.9%—Trendmicro Mobile Security26/6/202317/6/2026
Trend Micro Mobile Security (Enterprise) 9.8 SP5 contains vulnerable .php files that could allow a remote attacker to execute arbitrary code on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. This…
ModificadaMedia (6.5)2.0%—Trendmicro Mobile Security26/6/202317/6/2026
Trend Micro Mobile Security (Enterprise) 9.8 SP5 contains widget vulnerabilities that could allow a remote attacker to create arbitrary files on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.…
ModificadaMedia (6.5)2.0%—Trendmicro Mobile Security26/6/202317/6/2026
Trend Micro Mobile Security (Enterprise) 9.8 SP5 contains widget vulnerabilities that could allow a remote attacker to create arbitrary files on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.…
ModificadaAlta (8.8)2.6%—Trendmicro Mobile Security26/6/202317/6/2026
Affected versions of Trend Micro Mobile Security (Enterprise) 9.8 SP5 contain some widgets that would allow a remote user to bypass authentication and potentially chain with other vulnerabilities. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to…
ModificadaAlta (8.8)2.6%—Trendmicro Mobile Security26/6/202317/6/2026
Affected versions of Trend Micro Mobile Security (Enterprise) 9.8 SP5 contain some widgets that would allow a remote user to bypass authentication and potentially chain with other vulnerabilities. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to…
ModificadaAlta (8.1)3.3%—Trendmicro Mobile Security26/6/202317/6/2026
A path traversal exists in a specific dll of Trend Micro Mobile Security (Enterprise) 9.8 SP5 which could allow an authenticated remote attacker to delete arbitrary files. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
ModificadaCrítica (9.1)67%—Trendmicro Mobile Security26/6/202317/6/2026
A path traversal exists in a specific service dll of Trend Micro Mobile Security (Enterprise) 9.8 SP5 which could allow an unauthenticated remote attacker to delete arbitrary files.
ModificadaMedia (6.5)0.49%—Mozilla Firefox FocusMozilla Firefox Mobile19/6/202319/8/2026
When recording the screen while in Private Browsing on Firefox for Android the address bar and keyboard were not hidden, potentially leaking sensitive information. *This bug only affects Firefox for Android. Other operating systems are unaffected.* This vulnerability affects Firefox for Android < 112 and Focus for…
ModificadaCrítica (9.1)0.71%—Mozilla Firefox FocusMozilla Firefox Mobile19/6/202319/8/2026
Different techniques existed to obscure the fullscreen notification in Firefox and Focus for Android. These could have led to potential user confusion and spoofing attacks. *This bug only affects Firefox and Focus for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox for Android <…
ModificadaAlta (7.5)0.60%—Mozilla Firefox Mobile19/6/202319/8/2026
A potential use-after-free in libaudio was fixed by disabling the AAudio backend when running on Android API below version 30. *This bug only affects Firefox for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox for Android < 110.1.0.
ModificadaAlta (7.8)0.23%—HP Dragonfly Folio G3 2-in-1 FirmwareHP Elite Dragonfly FirmwareHP Elite Dragonfly G3 FirmwareHP Elite Dragonfly G2 Firmware+32314/6/202317/6/2026
Se han identificado posibles vulnerabilidades en el BIOS del sistema de ciertos productos de PC HP, que podrían permitir la ejecución de código arbitrario, la escalada de privilegios, la denegación de servicio y la divulgación de información.
ModificadaAlta (7.8)0.20%—HP Dragonfly Folio G3 2-in-1 FirmwareHP Elite Dragonfly FirmwareHP Elite Dragonfly G3 FirmwareHP Elite Dragonfly G2 Firmware+32314/6/202317/6/2026
Se han identificado posibles vulnerabilidades en el BIOS del sistema de ciertos productos de PC HP, que podrían permitir la ejecución de código arbitrario, la escalada de privilegios, la denegación de servicio y la divulgación de información.
ModificadaAlta (7.8)0.23%—HP Dragonfly Folio G3 2-in-1 FirmwareHP Elite Dragonfly FirmwareHP Elite Dragonfly G3 FirmwareHP Elite Dragonfly G2 Firmware+32314/6/202317/6/2026
Se han identificado posibles vulnerabilidades en el BIOS del sistema de ciertos productos de PC HP, que podrían permitir la ejecución de código arbitrario, la escalada de privilegios, la denegación de servicio y la divulgación de información.
ModificadaAlta (7)0.14%—HP Elite Dragonfly FirmwareHP Elite Dragonfly G3 FirmwareHP Elite X2 1012 G2 FirmwareHP Elite X2 1013 G3 Firmware+28714/6/202317/6/2026
Se han identificado posibles vulnerabilidades en el BIOS del sistema de ciertos productos de PC HP, que podrían permitir la ejecución de código arbitrario, la escalada de privilegios, la denegación de servicio y la divulgación de información.
ModificadaAlta (7)0.17%—HP Elite Dragonfly FirmwareHP Elite Dragonfly G3 FirmwareHP Elite X2 1012 G2 FirmwareHP Elite X2 1013 G3 Firmware+28714/6/202317/6/2026
Se han identificado posibles vulnerabilidades en el BIOS del sistema de ciertos productos de PC HP, que podrían permitir la ejecución de código arbitrario, la escalada de privilegios, la denegación de servicio y la divulgación de información.
ModificadaAlta (7)0.17%—HP Elite Dragonfly FirmwareHP Elite Dragonfly G3 FirmwareHP Elite X2 1012 G2 FirmwareHP Elite X2 1013 G3 Firmware+28714/6/202317/6/2026
Se han identificado posibles vulnerabilidades en el BIOS del sistema de ciertos productos de PC HP, que podrían permitir la ejecución de código arbitrario, la escalada de privilegios, la denegación de servicio y la divulgación de información.
ModificadaAlta (7.8)0.14%—HP Zcentral 4R Workstation FirmwareHP Z1 All-in-one G3 Workstation FirmwareHP Elitebook 725 G4 FirmwareHP Elitebook 745 G4 Firmware+39913/6/202317/6/2026
Potential time-of-check to time-of-use (TOCTOU) vulnerabilities have been identified in the BIOS for certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure.