Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2778▼ 418 respecto a la semana anterior
Críticas / altas1332▼ 108 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
1742 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.7) | 0.14% | — | Qualcomm Csra6620 FirmwareQualcomm Csra6640 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 Firmware+142 | 7/1/2026 | 7/10/2026 | Memory corruption while processing shared command buffer packet between camera userspace and kernel. | |
| Analizada | Media (6.6) | 0.12% | — | Qualcomm Sa6150p FirmwareQualcomm Sa6155 FirmwareQualcomm Sa6155p FirmwareQualcomm Sa7255p Firmware+235 | 7/1/2026 | 7/10/2026 | Memory corruption while handling buffer mapping operations in the cryptographic driver. | |
| Analizada | Media (6.4) | 0.11% | — | Qualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 Firmware+70 | 7/1/2026 | 7/10/2026 | Memory corruption while processing a config call from userspace. | |
| Analizada | Media (6.1) | 0.13% | — | Qualcomm Ar8031 FirmwareQualcomm Ar8035 FirmwareQualcomm Csr8811 FirmwareQualcomm Csra6620 Firmware+295 | 7/1/2026 | 7/10/2026 | Information disclosure while processing a firmware event. | |
| Analizada | Media (5.5) | 0.12% | — | Qualcomm Qca6678aq FirmwareQualcomm Qca6688aq FirmwareQualcomm Qca6696 FirmwareQualcomm Qca6698aq Firmware+219 | 7/1/2026 | 7/10/2026 | Transient DOS while parsing video packets received from the video firmware. | |
| Aplazada | Alta (7.1) | 0.18% | — | Nebelhorn Blappsta Mobile APP PluginAI | 31/12/2025 | 23/9/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in nebelhorn Blappsta Mobile App Plugin – Your native, mobile iPhone App and Android App yournewsapp allows Reflected XSS.This issue affects Blappsta Mobile App Plugin – Your native, mobile iPhone App and Android App:… | |
| Aplazada | Alta (7.5) | 0.25% | — | Knowband Mobile APP BuilderAI | 31/12/2025 | 17/6/2026 | The Knowband Mobile App Builder WordPress plugin before 3.0.0 does not have authorisation when deleting users via its REST API, allowing unauthenticated attackers to delete arbitrary users. | |
| Aplazada | Crítica (9.8) | 0.54% | 💥 PoC | Mobile BuilderAI | 29/12/2025 | 17/6/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Mobile Builder Mobile builder mobile-builder allows Authentication Abuse.This issue affects Mobile builder: from n/a through <= 1.4.2. | |
| Aplazada | Alta (8.2) | 0.57% | — | Mitsubishielectric Genesis64AIMitsubishielectric Iconics SuiteAIMitsubishielectric MobilehmiAIMitsubishielectric MC Works64AI | 19/12/2025 | 7/10/2026 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the software keyboard function (hereinafter referred to as "keypad function") of Mitsubishi Electric GENESIS64 versions 10.97.2 CFR3 and prior, Mitsubishi Electric Iconics Digital Solutions GENESIS64 versions… | |
| Analizada | Alta (7.8) | 0.09% | — | Qualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 Firmware+95 | 18/12/2025 | 17/6/2026 | Memory corruption while loading an invalid firmware in boot loader. | |
| Analizada | Alta (7.8) | 0.10% | — | Qualcomm Ar8031 FirmwareQualcomm Ar8035 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 Firmware+107 | 18/12/2025 | 17/6/2026 | Memory corruption while handling IOCTL calls to set mode. | |
| Analizada | Alta (7.8) | 0.08% | — | Qualcomm Ar8031 FirmwareQualcomm Ar8035 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 Firmware+111 | 18/12/2025 | 17/6/2026 | Memory corruption while copying packets received from unix clients. | |
| Analizada | Alta (7.8) | 0.08% | — | Qualcomm 9206 LTE Modem FirmwareQualcomm Apq8017 FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 Firmware+209 | 18/12/2025 | 17/6/2026 | Memory corruption while processing MFC channel configuration during music playback. | |
| Analizada | Media (6.7) | 0.09% | — | Qualcomm Ar8035 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 Firmware+114 | 18/12/2025 | 17/6/2026 | Information disclosure while exposing internal TA-to-TA communication APIs to HLOS | |
| Analizada | Alta (7.8) | 0.10% | — | Qualcomm Csra6620 FirmwareQualcomm Csra6640 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 Firmware+107 | 18/12/2025 | 17/6/2026 | Memory corruption during video playback when video session open fails with time out error. | |
| Analizada | Alta (7.8) | 0.09% | — | Qualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Qam8255p FirmwareQualcomm Qam8295p Firmware+174 | 18/12/2025 | 30/9/2026 | Memory corruption while routing GPR packets between user and root when handling large data packet. | |
| Aplazada | Alta (7.5) | 0.31% | — | Menulux Software INC Mobile APPAI | 16/12/2025 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Menulux Software Inc. Mobile App allows Exploitation of Trusted Identifiers. This issue affects Mobile App: before 9.5.8. | |
| Aplazada | Media (5.3) | 0.28% | — | Hippoo Mobile APPAI | 12/12/2025 | 17/6/2026 | The Hippoo Mobile App for WooCommerce plugin for WordPress is vulnerable to arbitrary file write via a missing authorization check in all versions up to, and including, 1.7.1. This is due to the REST API endpoint `/wp-json/hippoo/v1/wc/token/save_callback/{token_id}` being registered with `permission_callback =>… | |
| Aplazada | Alta (7.5) | 2.2% | 💥 Exploit | Hippoo Mobile APP FOR WoocommerceAI | 10/12/2025 | 25/9/2026 | The Hippoo Mobile App for WooCommerce plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.7.1 via the template_redirect() function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive… | |
| Aplazada | Media (6.3) | 0.27% | 💥 PoC | Watchguard Mobile VPN With SSL ClientAI | 4/12/2025 | 25/9/2026 | The WatchGuard Mobile VPN with SSL Client on Windows allows a locally authenticated non-administrative Windows user to escalate their privileges to NT AUTHORITY/SYSTEM on the Windows machine where the VPN Client is installed. | |
| Aplazada | Media (6.1) | 0.24% | — | Mobile-industrial-robots MIR RobotAIMobile-industrial-robots MIR FleetAI | 1/12/2025 | 17/6/2026 | Open redirect in the web server component of MiR Robot and Fleet software allows a remote attacker to redirect users to arbitrary external websites via a crafted parameter, facilitating phishing or social engineering attacks. | |
| Aplazada | Media (4.4) | 0.18% | — | Zweb Social MobileAI | 25/11/2025 | 17/6/2026 | The Zweb Social Mobile – Ứng Dụng Nút Gọi Mobile plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘vithanhlam_zsocial_save_messager’, 'vithanhlam_zsocial_save_zalo', 'vithanhlam_zsocial_save_hotline', and 'vithanhlam_zsocial_save_contact' parameters in all versions up to, and including, 1.0.0… | |
| Aplazada | Crítica (9.8) | 0.33% | — | Mstoreapp Mobile APPAIMstoreapp Mobile MultivendorAI | 21/11/2025 | 17/6/2026 | The Mstoreapp Mobile App WordPress plugin through 2.08 and Mstoreapp Mobile Multivendor through 9.0.1 do not properly verify users identify when using an AJAX action, allowing unauthenticated users to retrieve a valid session for arbitrary users by knowing their email address. | |
| Analizada | Media (6.5) | 0.14% | — | Mattermost Mobile | 13/11/2025 | 17/6/2026 | Mattermost Mobile Apps versions <=2.32.0 fail to verify that SSO redirect tokens originate from the trusted server, which allows a malicious Mattermost instance or on-path attacker to obtain user session credentials via crafted token-in-URL responses | |
| Aplazada | Media (6.5) | 0.32% | — | Specific Content FOR MobileAI | 12/11/2025 | 17/6/2026 | The Specific Content For Mobile – Customize the mobile version without redirections plugin for WordPress is vulnerable to SQL Injection via the eos_scfm_duplicate_post_as_draft() function in all versions up to, and including, 0.5.5 due to insufficient escaping on the user supplied parameter and lack of sufficient… |