Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2849▼ 221 respecto a la semana anterior
Críticas / altas1332▼ 165 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)222▼ 99 respecto a la semana anterior
1742 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.89% | — | Hcltech Bigfix Mobile | 27/7/2023 | 17/6/2026 | HCL BigFix Mobile es vulnerable a ataques de inyección de comandos. Un atacante autenticado podría ejecutar comandos shell arbitrarios en el servidor WebUI. | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Ivanti Endpoint Manager Mobile | 25/7/2023 | 5/8/2026 | Una vulnerabilidad de omisión de autenticación en Ivanti EPMM permite a usuarios no autorizados acceder a funciones o recursos restringidos de la aplicación sin la autenticación adecuada. | |
| Modificada | Media (6.5) | 0.22% | — | Wpmobilepack Wordpress Mobile Pack | 11/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WPMobilePack.Com WordPress Mobile Pack – Mobile Plugin for Progressive Web Apps & Hybrid Mobile Apps plugin <= 3.4.1 versions. | |
| Modificada | Alta (8.8) | 1.6% | 💥 Exploit | Ozette Simple Mobile URL Redirect | 10/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Ozette Plugins Simple Mobile URL Redirect plugin <= 1.7.2 versions. | |
| Modificada | Alta (8.8) | 0.32% | — | Digitalinspiration Google XML Sitemap FOR Mobile | 10/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Amit Agarwal Google XML Sitemap for Mobile plugin <= 1.6.1 versions. | |
| Modificada | Crítica (9.8) | 1.3% | — | Stw-mobile-machines Tcg-4 FirmwareStw-mobile-machines Tcg-4lite Firmware | 29/6/2023 | 17/6/2026 | STW (aka Sensor-Technik Wiedemann) TCG-4 Connectivity Module DeploymentPackage_v3.03r0-Impala and DeploymentPackage_v3.04r2-Jellyfish and TCG-4lite Connectivity Module DeploymentPackage_v3.04r2-Jellyfish allow an attacker to gain full remote access with root privileges without the need for authentication, giving an… | |
| Modificada | Alta (7.5) | 1.5% | — | Trendmicro Mobile Security | 26/6/2023 | 17/6/2026 | A remote attacker could leverage a vulnerability in Trend Micro Mobile Security (Enterprise) 9.8 SP5 to download a particular log file which may contain sensitive information regarding the product. | |
| Modificada | Alta (8.8) | 3.0% | — | Trendmicro Mobile Security | 26/6/2023 | 17/6/2026 | Trend Micro Mobile Security (Enterprise) 9.8 SP5 contains vulnerable .php files that could allow a remote attacker to execute arbitrary code on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. This… | |
| Modificada | Alta (8.8) | 2.9% | — | Trendmicro Mobile Security | 26/6/2023 | 17/6/2026 | Trend Micro Mobile Security (Enterprise) 9.8 SP5 contains vulnerable .php files that could allow a remote attacker to execute arbitrary code on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. This… | |
| Modificada | Media (6.5) | 2.0% | — | Trendmicro Mobile Security | 26/6/2023 | 17/6/2026 | Trend Micro Mobile Security (Enterprise) 9.8 SP5 contains widget vulnerabilities that could allow a remote attacker to create arbitrary files on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.… | |
| Modificada | Media (6.5) | 2.0% | — | Trendmicro Mobile Security | 26/6/2023 | 17/6/2026 | Trend Micro Mobile Security (Enterprise) 9.8 SP5 contains widget vulnerabilities that could allow a remote attacker to create arbitrary files on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.… | |
| Modificada | Alta (8.8) | 2.6% | — | Trendmicro Mobile Security | 26/6/2023 | 17/6/2026 | Affected versions of Trend Micro Mobile Security (Enterprise) 9.8 SP5 contain some widgets that would allow a remote user to bypass authentication and potentially chain with other vulnerabilities. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to… | |
| Modificada | Alta (8.8) | 2.6% | — | Trendmicro Mobile Security | 26/6/2023 | 17/6/2026 | Affected versions of Trend Micro Mobile Security (Enterprise) 9.8 SP5 contain some widgets that would allow a remote user to bypass authentication and potentially chain with other vulnerabilities. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to… | |
| Modificada | Alta (8.1) | 3.3% | — | Trendmicro Mobile Security | 26/6/2023 | 17/6/2026 | A path traversal exists in a specific dll of Trend Micro Mobile Security (Enterprise) 9.8 SP5 which could allow an authenticated remote attacker to delete arbitrary files. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. | |
| Modificada | Crítica (9.1) | 67% | — | Trendmicro Mobile Security | 26/6/2023 | 17/6/2026 | A path traversal exists in a specific service dll of Trend Micro Mobile Security (Enterprise) 9.8 SP5 which could allow an unauthenticated remote attacker to delete arbitrary files. | |
| Modificada | Media (6.5) | 0.49% | — | Mozilla Firefox FocusMozilla Firefox Mobile | 19/6/2023 | 19/8/2026 | When recording the screen while in Private Browsing on Firefox for Android the address bar and keyboard were not hidden, potentially leaking sensitive information. *This bug only affects Firefox for Android. Other operating systems are unaffected.* This vulnerability affects Firefox for Android < 112 and Focus for… | |
| Modificada | Crítica (9.1) | 0.71% | — | Mozilla Firefox FocusMozilla Firefox Mobile | 19/6/2023 | 19/8/2026 | Different techniques existed to obscure the fullscreen notification in Firefox and Focus for Android. These could have led to potential user confusion and spoofing attacks. *This bug only affects Firefox and Focus for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox for Android <… | |
| Modificada | Alta (7.5) | 0.60% | — | Mozilla Firefox Mobile | 19/6/2023 | 19/8/2026 | A potential use-after-free in libaudio was fixed by disabling the AAudio backend when running on Android API below version 30. *This bug only affects Firefox for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox for Android < 110.1.0. | |
| Modificada | Alta (7.8) | 0.23% | — | HP Dragonfly Folio G3 2-in-1 FirmwareHP Elite Dragonfly FirmwareHP Elite Dragonfly G3 FirmwareHP Elite Dragonfly G2 Firmware+323 | 14/6/2023 | 17/6/2026 | Se han identificado posibles vulnerabilidades en el BIOS del sistema de ciertos productos de PC HP, que podrían permitir la ejecución de código arbitrario, la escalada de privilegios, la denegación de servicio y la divulgación de información. | |
| Modificada | Alta (7.8) | 0.20% | — | HP Dragonfly Folio G3 2-in-1 FirmwareHP Elite Dragonfly FirmwareHP Elite Dragonfly G3 FirmwareHP Elite Dragonfly G2 Firmware+323 | 14/6/2023 | 17/6/2026 | Se han identificado posibles vulnerabilidades en el BIOS del sistema de ciertos productos de PC HP, que podrían permitir la ejecución de código arbitrario, la escalada de privilegios, la denegación de servicio y la divulgación de información. | |
| Modificada | Alta (7.8) | 0.23% | — | HP Dragonfly Folio G3 2-in-1 FirmwareHP Elite Dragonfly FirmwareHP Elite Dragonfly G3 FirmwareHP Elite Dragonfly G2 Firmware+323 | 14/6/2023 | 17/6/2026 | Se han identificado posibles vulnerabilidades en el BIOS del sistema de ciertos productos de PC HP, que podrían permitir la ejecución de código arbitrario, la escalada de privilegios, la denegación de servicio y la divulgación de información. | |
| Modificada | Alta (7) | 0.14% | — | HP Elite Dragonfly FirmwareHP Elite Dragonfly G3 FirmwareHP Elite X2 1012 G2 FirmwareHP Elite X2 1013 G3 Firmware+287 | 14/6/2023 | 17/6/2026 | Se han identificado posibles vulnerabilidades en el BIOS del sistema de ciertos productos de PC HP, que podrían permitir la ejecución de código arbitrario, la escalada de privilegios, la denegación de servicio y la divulgación de información. | |
| Modificada | Alta (7) | 0.17% | — | HP Elite Dragonfly FirmwareHP Elite Dragonfly G3 FirmwareHP Elite X2 1012 G2 FirmwareHP Elite X2 1013 G3 Firmware+287 | 14/6/2023 | 17/6/2026 | Se han identificado posibles vulnerabilidades en el BIOS del sistema de ciertos productos de PC HP, que podrían permitir la ejecución de código arbitrario, la escalada de privilegios, la denegación de servicio y la divulgación de información. | |
| Modificada | Alta (7) | 0.17% | — | HP Elite Dragonfly FirmwareHP Elite Dragonfly G3 FirmwareHP Elite X2 1012 G2 FirmwareHP Elite X2 1013 G3 Firmware+287 | 14/6/2023 | 17/6/2026 | Se han identificado posibles vulnerabilidades en el BIOS del sistema de ciertos productos de PC HP, que podrían permitir la ejecución de código arbitrario, la escalada de privilegios, la denegación de servicio y la divulgación de información. | |
| Modificada | Alta (7.8) | 0.14% | — | HP Zcentral 4R Workstation FirmwareHP Z1 All-in-one G3 Workstation FirmwareHP Elitebook 725 G4 FirmwareHP Elitebook 745 G4 Firmware+399 | 13/6/2023 | 17/6/2026 | Potential time-of-check to time-of-use (TOCTOU) vulnerabilities have been identified in the BIOS for certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure. |