Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2882▼ 181 respecto a la semana anterior
Críticas / altas1279▼ 60 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)487▼ 22 respecto a la semana anterior
–

6 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.9)0.13%—Joyland AIAI1/10/20261/10/2026
The Joyland AI app accepts invalid SSL certificates in the invisible advertisement WebView by default.
AplazadaMedia (5.3)0.11%—Joyland AIAI1/10/20261/10/2026
Joyland AI app explicitly permits cleartext HTTP traffic on Android 9+ where the default is to block it.
AplazadaMedia (6.9)0.18%—Joyland AIAI1/10/20261/10/2026
Joyland AI app does not verify hostnames, allowing a malicious host to connect or intercept chat messages.
AplazadaMedia (6.9)0.12%—Joyland AIAI1/10/20261/10/2026
The Joyland AI app accepts any TLS certificates from any server without validation.
AplazadaCrítica (9)0.19%—Joyland AIAI1/10/20262/10/2026
Joyland AI app allows an attacker with shared network access to inject JavaScript into content loaded in WebView. Without user-granted permissions, an attacker could access the clipboard, make arbitrary HTTP requests via the Weex 'stream' module, or access app-internal storage. If the installed app has been granted…
AplazadaMedia (6.9)0.17%—Joyland AIAI1/10/20261/10/2026
The Joyland AI app contains hard-coded credentials for the GeTui push notification service, allowing an attacker to access the GeTui REST API and send push notifications containing arbitrary content to any user, group of users, or all users of the app at once.