Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2635▼ 213 respecto a la semana anterior
Críticas / altas1376▲ 145 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
10 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.5) | 0.14% | — | Spsoftmobile ApplockAI | 27/5/2026 | 17/6/2026 | SpSoft AppLock (com.sp.protector.free) 7.9.40 for Android allows a local attacker with physical access to bypass fingerprint or PIN authentication. Although the app integrates Android's biometric mechanisms, the lock is implemented with a custom overlay that fails to consistently enforce authentication. By navigating… | |
| Aplazada | Baja (2.4) | 0.19% | — | Applock ZAIGoogle AndroidAI | 26/5/2026 | 23/7/2026 | AppLockZ App Lock and Fingerprint Lock (applock.passwordfingerprint.applockz) 4.2.11 for Android allows a local attacker with physical access to bypass the PIN lock. The lock is implemented as an overlay rather than by using Android's secure authentication APIs. By navigating cascading interface flows - insecure… | |
| Aplazada | Baja (2.4) | 0.19% | — | Spsoftmobile ApplockAI | 26/5/2026 | 24/7/2026 | SailingLab AppLock (aka com.alpha.applock) 4.3.8 for Android allows a local attacker with physical access to bypass the PIN lock. The lock is implemented as an overlay rather than by using Android's secure authentication APIs. By navigating cascading interface flows - insecure navigation through exposed routes… | |
| Aplazada | Media (5.2) | 0.18% | — | Spsoftmobile ApplockAI | 26/5/2026 | 24/7/2026 | SailingLab AppLock (aka com.alpha.applock) 4.3.8 for Android allows a local attacker to trigger arbitrary JavaScript execution via BrowserMainActivity, which accepts VIEW intents with javascript: URIs. This unsafe navigation path results in script execution and may allow UI spoofing or privilege escalation. | |
| Aplazada | Alta (8.3) | 0.20% | — | Kruger Matz SmartphoneAISpsoftmobile ApplockAI | 30/5/2025 | 17/6/2026 | An application "com.pri.applock", which is pre-loaded on Kruger&Matz smartphones, allows a user to encrypt any application using user-provided PIN code or by using biometric data. Exposed ”com.pri.applock.LockUI“ activity allows any other malicious application, with no granted Android system permissions, to inject an… | |
| Aplazada | Media (6.9) | 0.18% | — | Spsoftmobile ApplockAI | 30/5/2025 | 17/6/2026 | An application "com.pri.applock", which is pre-loaded on Kruger&Matz smartphones, allows a user to encrypt any application using user-provided PIN code or by using biometric data. Exposed ”com.android.providers.settings.fingerprint.PriFpShareProvider“ content provider's public method query() allows any other malicious… | |
| Aplazada | Crítica (9.8) | 0.55% | — | Transsion ApplockAI | 13/12/2024 | 17/6/2026 | A logic vulnerability in the the mobile application (com.transsion.applock) can lead to bypassing the application password. | |
| Modificada | Media (6.6) | 0.45% | — | Spsoftmobile Applock | 30/9/2022 | 17/6/2026 | AppLock version 7.9.29 allows an attacker with physical access to the device to bypass biometric authentication. This is possible because the application did not correctly implement fingerprint validations. | |
| Modificada | Alta (8.8) | 0.98% | — | Tapplock One+ Firmware | 8/8/2019 | 17/6/2026 | The Bluetooth Low Energy (BLE) subsystem on Tapplock devices before 2018-06-12 allows replay attacks. | |
| Modificada | Media (6.5) | 0.50% | — | Tapplock Firmware | 7/8/2019 | 17/6/2026 | The Bluetooth Low Energy (BLE) subsystem on Tapplock devices before 2018-06-12 relies on Key1 and SerialNo for unlock operations; however, these are derived from the MAC address, which is broadcasted by the device. |